Privacy Policy

Privacy Policy — EcoEdge AI
EcoEdge AI Pvt Limited

Privacy Policy

Effective Date: 01 April 2025  |  Last Updated: 01 April 2025

1. Introduction

EcoEdge AI Pvt Limited (“EcoEdge AI,” “we,” “us,” or “our“) is committed to protecting the privacy and security of the personal information entrusted to us by our users, customers, partners, and visitors. This Privacy Policy explains how we collect, use, disclose, store, and protect information when you interact with any part of the EcoEdge AI ecosystem, including:

  • Our website at ecoedgeai.com and any associated subdomains;
  • The EcoEdge AI building intelligence platform, including the web-based dashboard, analytics modules, and all platform features (the “Platform“);
  • Application Programming Interfaces (“APIs“) and developer integrations;
  • IoT gateways, data connectors, and edge devices deployed as part of our building intelligence services;
  • All other products, services, tools, and communications offered by EcoEdge AI (collectively, the “Services“).

By accessing or using any of our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any part of this Privacy Policy, you should discontinue use of our Services immediately.

2. Who We Are

EcoEdge AI Pvt Limited is a building technology company that develops AI-powered building intelligence solutions. Our platform integrates with Building Management Systems (BMS), HVAC systems, and other building infrastructure to provide predictive analytics, energy optimization, fault detection, and intelligent automation for commercial and enterprise buildings.

For the purposes of applicable data protection legislation (including the EU General Data Protection Regulation and the UK GDPR), EcoEdge AI Pvt Limited acts as the data controller for personal data collected through our website, marketing activities, and account management. When processing building operational data on behalf of our enterprise customers through the Platform, we act as a data processor under the terms of our customer agreements.

Contact Details:

3. Information We Collect

We collect information through various means depending on how you interact with our Services. The categories of information we collect are described below.

3.1 Information You Provide Directly

Category Examples
Account & Registration Data Full name, email address, phone number, job title, company name, department, role designation, password (encrypted), and profile preferences.
Communication Data Messages, emails, support tickets, feedback, survey responses, and any information you provide when contacting us through any channel.
Professional Data Company information, building portfolio details, facility information, job function, and professional credentials provided during onboarding.
User-Generated Content Custom dashboard configurations, report templates, alert rules, annotations, notes, and any content you create within the platform.

3.2 Information Collected Automatically

Category Examples
Device & Technical Data IP address, browser type and version, operating system, device type, device identifiers, screen resolution, language preferences, and time zone settings.
Usage & Analytics Data Pages visited, features accessed, click patterns, session duration, navigation paths, search queries within the platform, frequency of use, and interaction timestamps.
Log Data Server logs, error reports, API call logs, access timestamps, referring URLs, and system performance data.
Cookies & Tracking Technologies Cookies, web beacons, pixel tags, local storage tokens, and similar technologies (see Section 8 for full details).

3.3 Building & Operational Data

When our Services are deployed in building environments, the Platform and associated gateways may collect building operational data, including but not limited to:

  • HVAC system telemetry (temperatures, pressures, flow rates, humidity levels, setpoints, valve positions, fan speeds, compressor states);
  • BMS data points transmitted via BACnet, Modbus, or other building automation protocols;
  • Energy consumption and demand data (electricity, gas, water, steam, chilled water);
  • Equipment runtime, status, mode of operation, and fault/alarm data;
  • Indoor environmental quality data (CO₂ levels, air quality indices, light levels, occupancy counts);
  • Weather data and external environmental conditions relevant to building operations;
  • Zone and space utilization data.

Important: Building operational data is typically non-personal in nature. However, where such data could be combined with other information to identify an individual (for example, occupancy data for single-occupant zones), we treat it with the same care as personal data and apply appropriate safeguards.

3.4 Information from Third Parties

We may receive information about you from third-party sources, including:

  • Business partners, resellers, and channel partners who refer you to our Services;
  • Identity verification and fraud prevention service providers;
  • Publicly available sources such as company websites, professional networking platforms, and business directories;
  • Third-party applications or services that you choose to integrate with our platform;
  • Analytics and advertising partners who provide aggregated insights.

4. How We Use Your Information

We process your information for the following purposes, each supported by a lawful basis under applicable data protection law:

4.1 Service Delivery & Operations

  • To create, maintain, and manage your account and user profile;
  • To provide, operate, and maintain the Platform, APIs, web-based dashboard, and all associated Services;
  • To process building data and deliver analytics, predictions, fault detection, energy insights, and optimization recommendations;
  • To execute AI and machine learning models for building intelligence, including predictive maintenance, anomaly detection, and automated control optimization;
  • To provide technical support, customer service, and training.

4.2 Improvement & Development

  • To analyze usage patterns and platform performance to improve our Services;
  • To train, validate, and enhance our AI and machine learning models using aggregated and anonymized building operational data;
  • To conduct research and development for new features, products, and services;
  • To perform A/B testing, benchmarking, and usability studies;
  • To develop and improve our algorithms for energy optimization, fault detection, predictive analytics, and building intelligence.

4.3 Communication

  • To send service-related notifications, alerts, system updates, and maintenance notices;
  • To respond to your inquiries, support requests, and feedback;
  • To send marketing communications, product announcements, newsletters, and educational content (where you have opted in or where permitted by law);
  • To invite you to participate in surveys, webinars, events, and beta programs.

4.4 Safety, Security & Compliance

  • To detect, prevent, and address fraud, security threats, and unauthorized access;
  • To monitor and enforce compliance with our Terms and Conditions and Acceptable Use Policy;
  • To comply with applicable laws, regulations, legal processes, and government requests;
  • To protect the rights, property, and safety of EcoEdge AI, our customers, and the public;
  • To conduct audits, assessments, and due diligence as required by law or business practice.

4.5 Legal Bases for Processing (GDPR)

Legal Basis Applicable Processing Activities
Contract Performance Account management, service delivery, billing, support, and platform functionality.
Legitimate Interests Service improvement, analytics, AI model training on anonymized data, security monitoring, fraud prevention, and direct marketing to existing customers.
Consent Marketing communications (where required), cookie placement (non-essential), and processing of special category data where applicable.
Legal Obligation Tax reporting, regulatory compliance, law enforcement cooperation, and record-keeping obligations.

5. How We Share Your Information

We do not sell your personal information. We may share your information with the following categories of recipients, only to the extent necessary for the purposes described in this Privacy Policy:

5.1 Service Providers & Processors

We engage trusted third-party companies and individuals to perform services on our behalf, including cloud hosting and infrastructure (e.g., Amazon Web Services, Microsoft Azure, Google Cloud Platform), payment processing, email delivery, customer relationship management, analytics, monitoring, and customer support tools. These providers are contractually bound to process your data only on our instructions and in compliance with applicable data protection laws.

5.2 Business Partners & Integrations

Where you choose to connect third-party services to the Platform (such as BMS systems, energy management tools, or utility data providers), we may share relevant data with those third parties to enable the integration. Such sharing is governed by your instructions and the applicable third-party’s own privacy policy.

5.3 Within the EcoEdge AI Group

We may share information among EcoEdge AI subsidiaries, affiliates, and related entities for the purposes described in this Privacy Policy, including operational support, product development, and centralized services. All group entities are bound by equivalent data protection standards.

5.4 Legal & Regulatory Disclosures

We may disclose your information where required by law, regulation, court order, or governmental authority, or where we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.

5.5 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, asset sale, or similar transaction, your information may be transferred as part of the business assets. We will notify you before your information becomes subject to a different privacy policy.

5.6 Aggregated & Anonymized Data

We may share aggregated, de-identified, or anonymized data that cannot reasonably be used to identify you. This includes aggregated building performance benchmarks, industry insights, energy efficiency trends, and anonymized AI model training datasets. Such data is not considered personal data under applicable law.

6. International Data Transfers

EcoEdge AI operates globally and may transfer your personal data to countries other than the country in which it was originally collected. These countries may have different data protection laws than the laws of your country of residence.

When we transfer personal data internationally, we implement appropriate safeguards to ensure your data is protected in compliance with applicable laws, including:

  • Standard Contractual Clauses (SCCs): We use EU-approved Standard Contractual Clauses where required for transfers of data from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not received an adequacy determination;
  • Adequacy Decisions: We may rely on adequacy decisions issued by the European Commission, the UK Secretary of State, or equivalent regulatory bodies;
  • Binding Corporate Rules: Where applicable within the EcoEdge AI group of companies;
  • Contractual Protections: All data processing agreements with third-party providers include obligations regarding cross-border data protection;
  • Additional Measures: Where necessary, we implement supplementary technical and organizational measures such as encryption in transit and at rest, pseudonymization, and access controls.

You may contact us at info@ecoedgeai.com to obtain further details regarding the specific safeguards applied to any transfer of your personal data.

7. Data Retention

We retain your personal information only for as long as reasonably necessary to fulfill the purposes for which it was collected, comply with our legal and contractual obligations, resolve disputes, enforce our agreements, and support legitimate business operations.

Data Category Retention Period
Account & Profile Data Duration of the account relationship, plus up to 12 months after account closure for re-activation purposes, then deleted or anonymized.
Building Operational Data As specified in the customer service agreement. In the absence of a specified period, retained for the duration of the active subscription plus 90 days, after which it is deleted or returned to the customer.
AI Model Training Data Aggregated and anonymized data used for model training may be retained indefinitely as it is no longer personal data.
Support & Communication Records Up to 3 years from the last interaction for quality assurance, training, and dispute resolution.
Marketing & Consent Records Until you withdraw consent or opt out, plus any additional period required to demonstrate compliance.
Log & Security Data Up to 12 months for operational purposes; longer if required for ongoing security investigations or legal proceedings.

When personal data is no longer required, we securely delete or irreversibly anonymize it using industry-standard methods.

8. Cookies & Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience, analyze usage, and support our marketing activities.

8.1 Types of Cookies We Use

Cookie Type Purpose
Strictly Necessary Essential for the operation of our website and platform. These include session cookies, authentication tokens, load-balancing cookies, and security cookies. These cannot be disabled.
Functional Enable enhanced functionality and personalization, such as remembering your preferences, language settings, dashboard configurations, and display choices.
Analytics & Performance Help us understand how visitors interact with our Services by collecting information about page views, traffic sources, session durations, and feature usage. We use services such as Google Analytics, Mixpanel, or similar tools.
Marketing & Advertising Used to deliver relevant advertisements, track campaign effectiveness, and build audience profiles for retargeting across platforms. These may be set by third-party advertising partners.

8.2 Managing Cookies

When you first visit our website, you will be presented with a cookie consent banner that allows you to accept or reject non-essential cookies. You can change your cookie preferences at any time by accessing our cookie settings panel, which is available in the footer of our website.

You may also manage cookies through your browser settings. Most browsers allow you to block or delete cookies, though doing so may impair the functionality of certain features of our Services. For more information about cookies and how to manage them, visit www.allaboutcookies.org.

8.3 Do Not Track

Some web browsers offer a “Do Not Track” (DNT) signal. There is currently no industry standard for how companies should respond to DNT signals. At this time, our website does not respond to DNT signals, but we honor the cookie preferences you set through our consent mechanism.

9. Data Security

We take the security of your information seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction. Our security practices include, but are not limited to:

  • Encryption: Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256 encryption or equivalent standards;
  • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA), and the principle of least privilege are enforced across all systems;
  • Infrastructure Security: Our cloud infrastructure is hosted with industry-leading providers that maintain SOC 2, ISO 27001, and other relevant certifications;
  • Network Security: Firewalls, intrusion detection and prevention systems, network segmentation, and continuous monitoring;
  • Application Security: Regular code reviews, vulnerability assessments, penetration testing, and secure software development lifecycle (SDLC) practices;
  • Employee & Contractor Security: Background checks, confidentiality agreements, mandatory security training, and access auditing;
  • Incident Response: A documented incident response plan is maintained and tested regularly. In the event of a data breach affecting your personal data, we will notify you and relevant authorities in accordance with applicable law;
  • Business Continuity: Regular data backups, disaster recovery planning, and redundancy measures to ensure continuity of service.

While we strive to protect your personal information, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your data.

10. Your Rights

Depending on your location and applicable law, you may have the following rights regarding your personal information:

10.1 Rights Under GDPR (EEA & UK Residents)

  • Right of Access: You have the right to request a copy of the personal data we hold about you, along with information about how it is processed.
  • Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data.
  • Right to Erasure (“Right to Be Forgotten”): You have the right to request deletion of your personal data where there is no compelling reason for its continued processing.
  • Right to Restrict Processing: You have the right to request that we limit the processing of your personal data in certain circumstances.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
  • Right to Object: You have the right to object to processing based on legitimate interests or for direct marketing purposes at any time.
  • Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
  • Right Not to Be Subject to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects concerning you, except where permitted by law.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.

10.2 Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your information.
  • Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale or Sharing: We do not sell personal information as defined by the CCPA. If this practice ever changes, we will provide a clear opt-out mechanism.
  • Right to Limit Use of Sensitive Personal Information: Where applicable, you may direct us to limit the use and disclosure of sensitive personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

10.3 Rights Under Other Jurisdictions

We respect the privacy rights granted by other jurisdictions, including but not limited to Brazil’s LGPD, Canada’s PIPEDA, Australia’s Privacy Act, and other applicable data protection frameworks. If you reside in a jurisdiction with specific privacy rights, please contact us and we will accommodate your request in accordance with applicable law.

10.4 Exercising Your Rights

To exercise any of your rights, please contact us at info@ecoedgeai.com. We will respond to your request within the timeframe required by applicable law (typically 30 days for GDPR requests and 45 days for CCPA requests). We may need to verify your identity before processing your request. If we require additional time, we will inform you of the reason and the expected extension period.

11. Children’s Privacy

Our Services are designed for business and professional use and are not directed to individuals under the age of 18 (or the applicable age of majority in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected personal data from a child, we will take immediate steps to delete such information. If you believe a child has provided personal information to us, please contact us at info@ecoedgeai.com.

12. Third-Party Links & Services

Our Services may contain links to third-party websites, applications, or services that are not operated or controlled by EcoEdge AI. This Privacy Policy does not apply to any third-party services. We are not responsible for the privacy practices, content, or security of third-party services. We encourage you to review the privacy policies of any third-party services before providing your personal information.

13. AI & Automated Processing

EcoEdge AI employs artificial intelligence, machine learning, and automated processing as core components of our Services. This section provides transparency about how these technologies are used in relation to your data.

13.1 How We Use AI

Our AI systems analyze building operational data to generate predictions, detect faults and anomalies, optimize energy consumption, recommend control adjustments, and provide actionable intelligence. These AI systems are designed to process building-level operational data and do not make automated decisions that produce legal effects concerning individuals.

13.2 AI Model Training

We may use aggregated, anonymized, and de-identified building operational data to train, validate, and improve our AI and machine learning models. This data is stripped of any personally identifiable information before use in model training. Customer-specific building data is not shared across customer accounts for model training purposes unless the customer has provided explicit written consent.

13.3 Human Oversight

While our AI systems provide recommendations and insights, critical building control decisions maintain human oversight mechanisms. Users retain the ability to override, modify, or disable AI-driven recommendations and automated control actions through the platform’s control interfaces.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations. When we make changes, we will update the “Last Updated” date at the top of this page.

For material changes that significantly affect how we process your personal data, we will provide prominent notice through one or more of the following methods: a notification within the Platform, an email to the address associated with your account, or a prominent notice on our website. Where required by applicable law, we will obtain your consent before implementing material changes.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information.

15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, our data protection practices, or your personal information, please contact us through any of the following channels:

We aim to respond to all legitimate inquiries within 30 days. If you feel that your concern has not been adequately addressed, you have the right to lodge a complaint with your local data protection authority.

Scroll to Top