Privacy Policy
Last updated: 22 February 2026
1. Data Controller
Woon IoT BV, registered with the Dutch Chamber of Commerce (KvK), is the data controller for personal data processed through the Situara Water platform (water.situara.com). We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR).
2. Data We Collect
We collect and process the following categories of data:
- Postcode lookups: When you search for water quality data, the postcode you enter is used transiently to query the relevant water supplier. Postcodes and addresses are not stored in our systems.
- API key registration: If you register for an API key, we store your email address, name, and organisation name for account management purposes.
- Usage logs: We collect anonymised usage data including IP address, user agent, endpoints accessed, and timestamps for service improvement and abuse prevention.
3. How We Use Your Data
- To provide and operate the Situara Water service
- To manage your API key and enforce rate limits
- To monitor service performance and detect abuse
- To communicate important service updates (API key holders only)
4. Legal Basis (GDPR Art. 6)
We process your data based on: legitimate interest (service operation and security), contract performance (API key accounts), and consent (where applicable).
5. Data Retention
- Usage logs: retained for 12 months, then automatically deleted
- API key data: retained until you request deletion of your account
- Postcode queries: not retained (transient processing only)
6. Cookies & Local Storage
We do not use tracking cookies. We use only functional storage: a language preference saved in your browser's localStorage. No third-party tracking scripts are present on our site.
7. Third Parties
We use the following third-party services:
- Cloudflare: CDN and security (traffic passes through Cloudflare infrastructure)
- Hetzner: Server hosting located in Germany, EU
We do not sell, rent, or share your personal data with any other third parties.
8. Your Rights Under GDPR
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Port your data to another service
- Object to processing based on legitimate interest
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
9. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via the platform. Continued use of the service after changes constitutes acceptance of the updated policy.
10. Contact
For privacy-related inquiries, contact us at privacy@situara.com.