Privacy Policy
We look forward to your visit to the websites and app (applications) of JUWEL Aquarium AG & Co. KG. Our company attaches great importance to the protection of personal data and respects your desire for privacy. We are committed to protecting your personal data. With this Privacy Policy, we want to inform you about the handling of your personal data when you visit our applications and about your rights. In addition, if you have any questions regarding the handling of your personal data, please do not hesitate to contact our Data Protection Officer.
In advance, we want to point out that the terms used below are not gender-specific.
1. Controller:
A) The controller within the meaning of the General Data Protection Regulation (GDPR) is:
JUWEL Aquarium AG & Co. KG
Karl-Göx-Str. 1
27356 Rotenburg (Wümme)
B) The controller's Data Protection Officer is:
Datect UG
Tangstedter Weg 18a
22851 Norderstedt
Tel. +49 0152 262 929 63
Email: surmann@pjm-partner.de
You can reach our Data Protection Officer at privacy@juwel-aquarium.de or under our postal address with the addition "Data Protection Officer".
2. Contact:
When you contact us by email or via the contact form, we save the data provided by you (your email address, if applicable your name and your phone number) in order to respond to or process your query. The legal basis for this is Art. 6 para. 1 sentence 1 lit. f GDPR. If we request that you make entries via our contact form that are not required to make contact, these entries are always labelled as being optional. We use this information to specify your enquiry and to improve processing of your request. This information is provided expressly on a voluntary basis and with your consent, according to Art. 6 para. 1 sentence 1 lit. a GDPR. If the data relates to information on channels of communication (e.g. e-mail address, phone number), you also agree that we shall contact you, if necessary also via this channel of communication, in order to respond to your enquiry. Naturally, you can revoke this consent at any time in for the future.
Any of your data that we receive in the context of you contacting us will be deleted as soon as it is no longer needed for the purpose for which it was collected, your request is fully processed and no further communication with you is required or desired by you.
As the data protection controller, our company has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. However, Internet-based data transmissions can generally have security vulnerabilities. Absolute protection cannot be guaranteed, in any case the sending of unencrypted emails is not secure. We therefore ask you not to send sensitive data by means of unencrypted email, but to use either encrypted communication channels (e.g. our contact form) or the postal route.
3. Your rights:
We would be happy to inform you about whether your personal data are being processed; if you want to find out, you have the right to information about such personal data and to the information listed in more detail in Art. 15 GDPR. In addition, under the respective legal conditions, you have the right to correction (Art. 16 GDPR), the right to a restriction of processing (Art. 18 GDPR), the right to erasure (Art. 17 GDPR) and the right to data portability (Art. 20 GDPR).
Under the legal conditions, you have the right to object at any time to the processing of personal data concerning you (Art. 21 GDPR), which is based, inter alia, on Art. 6 para. 1 lit. e) or lit. f). Should you lodge an objection, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.
To exercise your rights above, please contact us by email at privacy@juwel-aquarium.de or by post to JUWEL Aquarium AG & Co. KG, Karl-Göx-Str. 1, 27356 Rotenburg (Wümme). It is free of charge for you to exercise above your rights.
Without prejudice to these rights and the possibility of any other administrative or judicial remedy, you have the option at any time to assert your right to lodge a complaint with a supervisory authority, in particular in the Member State of your place of residence, your place of work or the place of the alleged infringement, if you are of the opinion that the processing of your personal data violates data protection regulations (Art. 77 GDPR).
The supervisory authority responsible for us is:
The State Commissioner for Data Protection of Lower Saxony.
4. Legal basis of our data processing:
The processing of personal data may be based on various legal foundations. If we need your data to fulfil a contract with you or to answer your inquiries regarding a contract, the legal basis for this data processing is Art. 6 para. 1 sentence 1 lit. B GDPR. If we obtain your consent for a particular data processing, the legal basis is Art. 6 para. 1. sentence 1 lit. a GDPR. We carry out some data processing on the basis of our legitimate interest, whereby a balance is always made between your legitimate interests and our legitimate interests. The legal basis for this is Art. 6 para. 1, sentence 1 lit. f GDPR. Insofar as the processing is necessary for the fulfilment of a legal obligation to which we are subject, the legal basis is Art. 6 para. 1 sentence 1 lit. c GDPR.
Below we inform you about which data are collected when using our applications, for which purposes they are processed, on which legal basis the data processing takes place, what options you have to control the collection and processing of the data yourself and when the data are deleted.
5. Log files:
5.1 Data collected:
When using our applications, requests are made to our servers (API) and the following data are automatically transmitted:
· Your IP address
· The time of the request
· The name of your Internet Service Provider
· The operating system of your end device
5.2 Purposes of the data processing:
Temporary storage of the data is necessary to enable the data to be delivered to your terminal and to ensure the functionality of the application. In addition, we collect the data in order to be able to trace and prevent unauthorized access to the server and the misuse of the API and to secure our information technology systems.
5.3 Legal basis for data processing:
We store the data temporarily on the basis of your registration in our app and accordingly in fulfilment of our contractual obligations (Art. 6 para. 1 lit. b GDPR) and on the basis of legitimate interests (Art. 6 para. 1 lit. f GDPR). Our legitimate interest is to achieve the purposes described above. In addition, it is necessary to temporarily store the IP address for delivery of the applications by you. An evaluation and use of the stored data for advertising purposes does not take place in this context.
5.4 Duration of storage:
The data will be deleted as soon as they are no longer necessary for the purpose for which they were collected. If the data are collected to provide the applications, this is the case when the session has ended. If the are is stored in log files, this is the case after 30 days at the latest. Further storage is possible. In this case, the IP addresses of the users are deleted or distorted, so that an assignment of the accessing client is no longer possible.
5.5 Possibility of objection and elimination:
It is absolutely necessary to collect data for the provision of the website and the storage of the data in log files in order to be able to operate the applications.
6. General use of the applications:
6.1 Device permissions for accessing features and data:
The use of our application or its functionalities may require the user to grant authorization to access certain functions of the devices used or to the data stored on the devices or accessible via the devices. By default, these permissions must be granted by the users and can be revoked at any time in the settings of the respective devices. Insofar as, in the course of using our applications, information is accessed that is already stored on the user’s terminal equipment, or information is stored on the terminal equipment, the lawfulness of such access is also governed by Section 25(1) and Section 25(2)(2) of the TDDDG.
6.2 Data collected:
Inventory data (e.g. names, addresses), meta-/communication data (e.g. device information, IP addresses), location information (necessary for finding WiFi), WiFi SSIDs in the environment.
6.3 Data subjects:
Users of the applications.
6.4 Purposes of the data processing:
Contractual performance and services.
6.5 Service providers deployed:
Amazon Web Services (AWS)
We use Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, 1855 Luxembourg (hereinafter called: AWS). Ultimately, it cannot be ruled out that the American company Amazon Web Service Inc., 410 Terry Avenue North, Seattle WA 98109, USA, must also be regarded as a service provider.
In individual cases, Amazon may process your data in the United States. Amazon is an active participant in the EU-US Data Privacy Framework, which regulates the lawful and secure transfer of personal data from EU citizens to the US. For more information, please visit https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en .
The Data Privacy Framework is a so-called adequacy decision within the meaning of Art. 45 para. 1 GDPR. Participation in the Data Privacy Framework generally means that a data transfer to a third country – in this case the USA – is permitted, provided that the further requirements for data transfer are met.
Because Amazon also uses the standard contractual clauses within the meaning of Art. 46 para. 2 and 3 GDPR, Amazon has pledged to comply with the European level of data protection when processing your personal data, even if the data are stored, processed and managed in the USA. Further information on the standard contractual clauses and the implementing decision of the EU Commission can be found here: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj?locale=de
The data are provided and the processes of our application offering (hosting) are handled at the German AWS data centre in Frankfurt am Main. We have entered into a data processing agreement with the European subsidiary of Amazon. Amazon sufficiently guarantees that it will implement appropriate technical and organizational measures to ensure processing in accordance with the requirements of the General Data Protection Regulation and the protection of the rights of the data subject. Amazon is, among other things, certified according to ISO 27001 (technology), ISO 27017 (cloud security) and ISO 27018 (cloud data protection). In addition, it holds a certificate according to the Cloud Computing Compliance Controls Catalogue (C5) of the Federal Office for Information Security (BSI).
For information on AWS privacy, please visit https://aws.amazon.com/de/compliance/gdpr-center/
Completion of a contract for order processing
We have entered into an agreement with Amazon requiring Amazon to protect our customers' information and not share it with third parties.
6.6 Legal basis:
Insofar as access to information stored in the user's terminal equipment or the storage of information in the terminal equipment is concerned, such access or storage is based on Section 25(1) TDDDG or, where such access is strictly necessary, on Section 25(2) No. 2 TDDDG. Depending on the respective area of application, we access internal device functions either for the performance of our contractual obligations pursuant to Art. 6(1)(b) GDPR or on the basis of our legitimate interests pursuant to Art. 6(1)(f) GDPR. Our legitimate interest lies in ensuring the proper functioning of our application and its optimal usability. In all other respects, the legal basis for the processing is your consent when granting access permissions for the applications within the meaning of Art. 6(1)(a) GDPR.
6.7 Duration of storage:
The data will be deleted or anonymised as soon as they are no longer necessary for the purpose for which they were collected. Unless specified otherwise, we store your personal data via the app for the duration of the usage or contractual relationship plus a period of 14 days during which we retain backup copies after deletion, insofar as the data are not longer required for criminal prosecution or for securing, asserting or enforcing legal claims. This does not affect specific information in this Privacy Policy nor legal requirements for the storage and deletion of personal data, in particular those that must be retained for tax reasons.
7. Contact, feedback, and communication through the applications:
7.1 Data collected:
We collect and process the data you provide, such as your contact details, your name and your inquiry, when you contact us via a contact form or by email. All data that you transmit to us will be encrypted between your device or browser and our server.
7.2 Purposes of the data processing:
Our legitimate interest in using this service is to be able to respond to user requests quickly and efficiently.
7.3 Data subjects:
Customers, communication partners, users
7.4 Services and service providers used:
The following services will be included in the contact/feedback process:
a) Sentry
Our website uses the Sentry service by the company Functional Software,
. dba Sentry, 45 Fremont Street, 8th Floor, , CA 94105 San Francisco, United States, Email: compliance@sentry.io, website: http://sentry.io/ to improve the technical stability of our services by monitoring system stability and identifying code errors. Sentry serves these objectives alone and does not evaluate data for advertising purposes. The data will also be transferred to the USA. With regard to the transfer of personal data to the USA, an adequacy decision is in place for the EU-US Data Privacy Framework of the EU Commission within the meaning of Art. 45 GDPR (hereinafter called: DPF - https://commission.europa.eu/document/fa09cbad-dd7d-4684-ae60-be03fcb0fddf_en ). The service provider is certified under the DPF, so that the usual level of protection of the GDPR applies to the transmission. The legal basis for the processing of personal data is your consent pursuant to Art. 6 para. 1 lit. a GDPR or Art. 9 para. 2 lit. a GDPR, which you have made on our website. You can access the certification under the EU-US Data Privacy Framework at https://www.dataprivacyframework.gov/s/participant-search/participant-detail?id=a2zt0000000YdenAAC .
You can revoke your consent at any time. You can find more information on revocation of your consent either with the consent itself or at the end of this Privacy Policy.
Completion of a contract for order processing
We have entered into an agreement with Sentry requiring Sentry to protect our customers' information and not share it with third parties.
For more information on the handling of the transferred data, see the provider's privacy policy at https://sentry.io/privacy/.
The user data, such as information about the device or the error timing, are collected anonymously, not used for personal purposes and subsequently deleted.
b) Brevo
We use the Brevo service to send emails and to communicate in or through the applications, such as in connection with sending registration emails, etc.
Basically, the type of services provided by Brevo is used to manage a database of email contacts, phone numbers or any other contact information to communicate with you. The services may also collect data about the date and time that the user read the message and when the user interacts with incoming messages, for example by clicking on links contained within it.
Brevo Email (Sendinblue GmbH) Brevo is a service provided by Sendinblue GmbH for the management of email addresses and the sending of messages. Personal data collected: Cookie; email; usage data.
Place of processing: Germany, France
Privacy Policy: https://www.brevo.com/en/legal/privacypolicy/
Completion of a contract for order processing
We have entered into an agreement with Brevo requiring Brevo to protect our customers' information and not share it with third parties.
7.5 Legal basis:
The legal basis for the processing described above is in our legitimate interest, see above (Art. 6 para. 1 lit. f GDPR) or, in the consent you have given (Art. 6 para. 1 lit. a GDPR).
7.6 Possibility of objection and elimination:
Insofar as the data processing is based on your consent (Art. 6 para. 1 lit. a GDPR), you can revoke this consent at any time. The legality of the data processing operations already carried out remains unaffected by the revocation.
7.7 Duration of storage:
The data will be deleted or anonymised as soon as they are no longer necessary for the purpose for which they were collected. Unless specified otherwise, we store your personal data via the app for the duration of the usage or contractual relationship plus a period of 14 days during which we retain backup copies after deletion, insofar as the data are not longer required for criminal prosecution or for securing, asserting or enforcing legal claims. This does not affect specific information in this Privacy Policy nor legal requirements for the storage and deletion of personal data, in particular those that must be retained for tax reasons.
8. User account:
It is not necessary to create a personal user account to use the applications. You can decide whether to open an account when the correct execution of services requires this. In particular, an account is necessary to operate the associated app. The data processing procedures when opening a personal user account are shown below.
8.1 Data collected:
We collect and process the data you provide, such as your name and email address, the name of your organization and your telephone number, when you contact us via the registration form. All data that you transmit to us will be encrypted between your device and our server.
8.2 Data subjects:
Customers, users.
8.3 Purposes of the data processing:
Data processing is carried out by our customer service or service providers commissioned by us exclusively on the basis of and for the processing of your registration.
8.4 Services and service providers used:
a) Brevo
We also use the services of the provider Brevo when creating and using a personal user account. In this context, we refer to the explanations under 5.4 lit. b) of this Privacy Policy. There you will find all the necessary information about the third party and the presentation of an order processing contract with this provider.
b) Amazon Web Services (AWS)
In this context, we also use the services of the service provider Amazon. To avoid repetition, please refer to the corresponding statements in our Privacy Policy under section 5.5.
8.5 Legal basis:
We use technically necessary tokens on the basis of our legitimate interest (Art. 6 para. 1 lit. f GDPR). Our legitimate interest may be to ensure the functioning of our application and its optimal operability. The data that you provide to us in the course of your registration (contact details, etc.) are stored in accordance with Art. 6 para. 1 lit. b GDPR and processed for you under the necessity of providing our service.
8.6 Duration of storage:
The data will be deleted or anonymised as soon as they are no longer necessary for the purpose for which they were collected. Unless specified otherwise, we store your personal data via the app for the duration of the usage or contractual relationship plus a period of 14 days during which we retain backup copies after deletion, insofar as the data are not longer required for criminal prosecution or for securing, asserting or enforcing legal claims. This does not affect specific information in this Privacy Policy nor legal requirements for the storage and deletion of personal data, in particular those that must be retained for tax reasons.
9. Passing on and transfer of data:
9.1 In addition to the cases explicitly mentioned in this Privacy Policy, your personal data will only be disclosed without your express prior consent if permitted or required by law.
9.2 If it is necessary to clarify an illegal or improper use of the app or for legal proceedings, personal data will be forwarded to the law enforcement authorities or other authorities as well as to damaged third parties or legal advisors, if necessary. However, this only happens if there are indications of illegal or abusive behaviour. A transfer may also take place if this serves the enforcement of Terms of Use or other legal claims. We are also legally obliged to provide information to certain public bodies upon request. These are law enforcement agencies, authorities that prosecute fine offences, and the financial authorities.
9.3 Legal basis:
The legal basis for a possible transfer according to the above are on the one hand the provisions of Art. 21(1) and (2) TDDDG – here information obligations on our part are regulated on the basis of official orders – and Art. 22 TDDDG.
The legal basis may also be Art. 6 para. 1 lit. c GDPR in conjunction with the national legal requirements, according to which we are subject to an obligation to pass on to law enforcement authorities.
In the event that our interest prevail where there is evidence of abusive behaviour or to enforce our Terms of Use, other conditions or legal claims with regard to your interests in the protection of your personal data, the legal basis can be found in Article 6, Paragraph 1, lit. f) GDPR.
10. Information pursuant to the EU Data Act (Regulation (EU) 2023/2854)
With this section, we inform you about the data generated by your smart device and the use of our app. At the same time, we inform you about your expanded access and portability rights in accordance with the EU Data Act (Regulation (EU) 2023/2854) (hereinafter referred to as "Data Act").
10.1 Types and Categories of Data Generated by the Device
Your smart device generates and transmits data necessary for the provision, proper operation, and optimization of the app's functions.
We distinguish between the following, non-exhaustive, categories of data:
Operational Data
• Operating data,
• Device settings,
• Timer settings,
• Time controls,
• Feeding times,
• Status and diagnostic data,
• Connection status (WLAN/Bluetooth),
• Current device operating state,
• Error messages.
Device Data
• Product ID,
• Unique device identifier (serial number),
• Firmware version.
Usage Data
• Feeding history,
• Logs of interactions with the device.
• Specific Data Categories for the EccoFlow AppControl Product Component:
- Operational and Control Settings. Set pump output (in %), active power profile (including profile name and assigned aquarium volume), Night- Control settings (activation status, time period, and reduced pump output), set minimum and maximum water temperature, as well as device-specific settings (temperature and volume units).
- Thresholds and Settings for Warning/Notification Functions. Configured notification settings/thresholds for pump dry run, pump blockage, pump cleaning, impeller replacement, overvoltage, undervoltage, system overheating, excessively high/low water temperature, and water temperature sensor error. Transparency Note: Only the configured notification parameters are recorded and exported. A history or event log of actual warning events is not maintained.
- Device, Connection, and System Data: Wi-Fi SSID, Product ID, Cloud Device ID, Local Device ID, Manufacturer ID, firmware version, hardware revision, and time zone setting.
Statutory Notice pursuant to Art. 3 Para. 2 Data Act: Currently, no real-time measured values or historical data regarding water temperature, no motor speed (rpm), and no event-related history logs are processed or included in the data export via the EccoFlow AppControl. Data transmission does not take place continuously in real time, but on an event- and synchronization-related basis when the app connection is active.
10.2 Purpose of Data Processing
We process the data mentioned above exclusively for the following purposes:
a) Provision of Functions:
Enabling the control and use of the device's specific functions via the app.
b) Error Analysis:
Identifying and resolving technical issues and malfunctions.
c) Optimization and Proper Operation:
Ensuring the functionality and improving the performance of the device and the app.
10.3 Your Access and Portability Rights (Articles 4 and 5 Data Act)
As a user, and in reference to the rights regulated in Articles 4 and 5 of the Data Act, you have the right to access and transfer the data generated through the use of your smart device. These rights include:
a) Right of Access: You can access the data generated by your device.
b) Right to Data Portability: You have the right to receive this data in a machine-readable format and to use it for your own purposes.
c) Right to Transmission to Third Parties: Upon your explicit request, we will transmit the data generated by your device directly to a third party designated by you (e.g., another service provider).
Note on Non-Applicable Data:
The aforementioned rights do not extend to our internal system data, derived/enriched data or trade secrets. JUWEL Aquarium AG & Co. KG is the owner of trade secrets relating to the source codes, control algorithms, system architectures and diagnostic formulas used in the smart devices (including EccoFlow AppControl) and in the MyJUWEL app. The access and transfer rights apply exclusively to the original raw data generated through your use. Should a data transfer requested by you, in individual cases, affect trade secrets of JUWEL Aquarium AG & Co. KG, we reserve the right to make the provision of such data conditional upon the prior agreement of appropriate technical and organisational safeguards (in particular confidentiality agreements in accordance with Article 4(6) to (8) of the Data Act) or to refuse it in the event of imminent disclosure in accordance with Article 4(8) of the Data Act.
10.4 Procedure for Exercising Data Access and Data Portability
To make the exercise of your rights as simple and efficient as possible, we provide a fully
automated export function:
a) Initiating the Export: You can initiate the export of your device data directly within the app via the menu item "Export My Data",
b) Procedure: Upon your confirmation, the export process is triggered fully automatically.
c) Format and Cost: The data will be provided to you in the common, structured, and machine-readable JSON format. The export is free of charge.
d) Transmission: The export will be sent as an encrypted file or download link to the email address verified in your user account.
10.5 Transfer of Data to Third Parties at Your Request
If you wish for a direct transfer of device data to a third party (Art. 5 Data Act), you can also mandate this via the designated function in the app. The transmission will then take place in JSON format to the third party specified by you and is also free of charge.
10.6 Right of Withdrawal for Data Transmission and Export
You can revoke your order for data export or transmission to third parties at any time, as long as the process has not yet been completed (i.e., before the data has been sent to you or the third party). A withdrawal is no longer possible once the transmission or export is complete, as the data is then already under your control or that of the third party. You can declare the withdrawal via the app or by sending an email to service@juwel-aquarium.de.
10.7 Storage Period of Device Data
We fundamentally store the data generated by your smart device only for as long as is necessary to achieve the processing purposes mentioned in Section 2 (provision of functions, error analysis, optimization, etc.).
Maximum Term:
The maximum permissible storage period for the original device data is linked to the duration of your usage agreement or your active user account. Upon termination of your user account or permanent deactivation of the device, the stored device data will be deleted immediately, unless statutory retention obligations prevent this.
Storage of the Export:
The export file generated for you will be kept available on our systems for a maximum period of 30 days for a one-time download and will then be automatically deleted.
10.8 Right to Lodge a Complaint with the Federal Network Agency (BNetzA) pursuant to Art. 37 Data Act
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint, individually or, where appropriate, jointly, with the competent authority of the Member State of your habitual residence, your place of work, or your establishment, if you believe that your rights under the EU Data Act (Regulation (EU) 2023/2854) have been violated. The Data Coordinator will provide you with all necessary information upon request so that you can lodge a complaint with the competent authority.
11. Changes to the Privacy Policy:
We reserve the right to change this Privacy Policy at any time in compliance with applicable data protection regulations. Current version as of September 2026.
© JUWEL Aquarium– All rights reserved • Privacy Policy • Terms of Use