Privacy Policy
Last updated: October 2025
1. Introduction
SUNEO (“we”, “our”, or “us”) respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, process, and protect your information when you visit our website www.suneo.solar, communicate with us, or use our services.
We process your data in accordance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
​
2. Data Controller
SUNEO
c/o Light Technology Institute (LTI)
Karlsruhe Institute of Technology (KIT)
Engesserstrasse 13, Building 30.34
76131 Karlsruhe, Germany
Email: hi@suneo.solar
​
3. Categories of Personal Data
We may collect and process the following types of personal data:
-
Contact data: name, email address, phone number, company name, job title
-
Communication data: messages and correspondence with SUNEO (e.g., via email, forms, or Microsoft Teams)
-
Website usage data: IP address, browser type, device information, referral source, and browsing behavior
-
Marketing data: consent preferences, newsletter subscriptions, interaction with campaigns
-
Technical data: cookies, log files, and analytics identifiers
​
4. Purposes of Processing
We process your personal data for the following purposes:
-
To operate and maintain our website (via Wix)
-
To respond to inquiries and provide information about our products or services
-
To manage and analyze customer relationships (HubSpot CRM)
-
To perform website analytics and improve user experience (Google Analytics)
-
To manage social media communication and advertising (LinkedIn)
-
To handle business communication and internal collaboration (Google Workspace, Microsoft 365, Microsoft Teams)
-
To comply with legal obligations and protect our rights
​
5. Legal Basis for Processing
We process your data on the following legal bases under Art. 6 GDPR:
-
Consent (Art. 6(1)(a)) — e.g., for newsletters, cookies, analytics, and marketing
-
Performance of a contract (Art. 6(1)(b)) — e.g., to communicate about partnerships or collaborations
-
Legal obligation (Art. 6(1)(c)) — e.g., record-keeping and compliance
-
Legitimate interest (Art. 6(1)(f)) — e.g., maintaining IT security, optimizing services, B2B communication
​
6. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to provide core functionality and analyze usage.
When you first visit our site, you can choose whether to allow or reject non-essential cookies.
Tools used:
-
Google Analytics (Google Ireland Ltd.)
Used for anonymized website analytics. IP anonymization is enabled.
You can opt out via Google’s browser add-on. -
HubSpot (HubSpot Inc., USA / HubSpot Germany GmbH)
Used for contact forms, newsletters, and CRM. Cookies may track form submissions and site visits. -
LinkedIn Insight Tag (LinkedIn Ireland Unlimited Company)
Used for LinkedIn ad performance and audience insights.
You can revoke your consent to cookies at any time via the website’s cookie banner or your browser settings.
​
7. Data Sharing and International Transfers
We may share your personal data with:
-
Service providers (HubSpot, Wix, Google, Microsoft, LinkedIn)
-
Hosting and IT infrastructure providers
-
Public authorities when legally required
Some of these providers are located outside the EU/EEA (e.g., the USA).
In such cases, we ensure adequate data protection through EU Standard Contractual Clauses (SCCs) or other approved safeguards.
​
8. Data Retention
We retain personal data only as long as necessary for the purposes stated in this policy, unless longer retention is required by law.
Typically:
-
Contact form data: up to 12 months
-
CRM data (HubSpot): as long as the business relationship is active
-
Analytics data: anonymized or deleted after 26 months
​
9. Your Rights (under GDPR)
You have the following rights:
-
Right of access – to obtain confirmation and a copy of your data
-
Right to rectification – to correct inaccurate data
-
Right to erasure – to request deletion (“right to be forgotten”)
-
Right to restriction of processing – to limit data use
-
Right to data portability – to receive your data in a machine-readable format
-
Right to object – to object to processing based on legitimate interest or for marketing
-
Right to withdraw consent – at any time, without affecting prior processing
To exercise these rights, contact us at hi@suneo.solar.
You also have the right to lodge a complaint with the Baden-Württemberg State Commissioner for Data Protection and Freedom of Information
(https://www.baden-wuerttemberg.datenschutz.de/).
​
10. Security
We use industry-standard technical and organizational measures to protect your personal data from unauthorized access, loss, or misuse.
All data is transmitted securely using SSL/TLS encryption.
​
11. Updates to this Policy
We may update this Privacy Policy from time to time to reflect new legal or technological developments.
The most recent version will always be available at www.suneo.solar/privacy-policy.
​