ElecRoute
Privacy Policy
Effective 20 September 2026
This Policy explains how ElecRoute processes personal data relating to website visitors, prospects, Customers, and Authorised Users. It does not govern Paddle's separate processing during a purchase or third-party websites.
1. Controller
Bysterecká 2066/7, 026 01 Dolný Kubín, Slovakia
Company ID: 45 880 751 · Tax ID: 2023119439 · VAT ID: SK2023119439
Commercial Register of the District Court Žilina, Section Sro, Insert No. 53616/L
Privacy enquiries and rights requests: support@elecroute.com
Tel.: +421 904 929 520
FlashDev, s.r.o. (“ElecRoute”, “we”) is the controller for website visits, registrations, user accounts, workspace administration, support, and operation of the Service. We have not appointed a data protection officer.
2. Scope and roles for project content
ElecRoute is a business and professional service. The Customer decides what data to enter in floor plans, projects, and notes and who receives access.
We are the controller for account data and our own operation of the Service. Where a Customer enters another person's personal data in project content, the Customer will generally be the controller and FlashDev the processor acting on the Customer's instructions to provide the Service. A Data Processing Agreement is available on request.
The Customer must inform its Authorised Users and other data subjects, establish a legal basis, and avoid entering unnecessary data. The Service is not designed for the intentional processing of special-category data.
3. Personal data we process
- Identity and contact data: name, email, telephone number, and details provided in communications.
- Account and authentication: internal identifiers, email verification, login session, and security/login records. Passwords are handled by the authentication service in protected form; we do not see plaintext passwords.
- Workspace and team: organisation name, membership, role, access, invitations, assigned licences, and relevant activity records.
- Project content: project names, PDF/JPG/PNG floor plans, technical drawings, geometry, devices, circuits, distribution boards, notes, and site-status information entered by users.
- Subscription: Paddle customer, transaction, and subscription identifiers, plan, licence quantity, payment status, and period. We do not receive complete payment-card details.
- Support and sales communications: emails, demo requests, attachments, and troubleshooting information.
- Technical data: IP address, request time, URL, browser/device information, error and security records, and information needed to operate an editing session. An application error report may include a stack trace, application release, environment, sanitised page path, and a limited technical sequence of events preceding the error. Aggregated analytics may include visit time, sanitised path, referrer, approximate location, operating system, browser, and device type.
- Browser preferences: language, active workspace, room-display preference, and a temporary editing-lease identifier.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Registration, authentication, workspaces, projects, collaboration, export, and support | Performance of a contract or pre-contract steps; for users of a corporate Customer, legitimate interests in performing the B2B contract |
| Managing access, licences, and subscriptions | Performance of a contract and legitimate interests in administering the Service |
| Billing, accounting, tax, and legal requirements | Performance of a contract and legal obligations |
| Responding to enquiries, demos, and support requests | Pre-contract steps, performance of a contract, or legitimate interests in communication and support |
| Security, abuse prevention, incident response, and legal claims | Legitimate interests in safe and reliable operation and, where applicable, legal obligations |
| Detecting, diagnosing, and correcting technical errors | Legitimate interests in providing a reliable, secure, and high-quality service |
| Remembering language, sessions, and necessary settings | Performance of a contract and legitimate interests; storage is necessary for the requested function |
| Improvement using anonymised, aggregated service statistics | Legitimate interests in improving the product; anonymous information is no longer personal data |
When relying on legitimate interests, we consider necessity and the effect on individual rights. ElecRoute does not use data for behavioural advertising or marketing profiling. Cloudflare Web Analytics on the static website and Vercel Web Analytics in the application provide anonymous aggregated statistics without analytics cookies; Cloudflare does not collect query parameters, and URL parameters, fragments, and UUID identifiers are removed before transmission to Vercel. Application error reports are technically filtered: we do not intentionally send floor plans, project content, passwords, authentication tokens, payment data, form contents, email addresses, or user, workspace, and project identifiers.
5. Sources of personal data
We obtain data directly from you; from a workspace owner or administrator who invites you or manages your access; automatically from your browser when you use the Service; and from Paddle to the extent needed to activate and administer a subscription.
6. Recipients and service providers
We disclose data only as needed for the purposes above:
- Supabase, Inc. provides authentication, database, and file storage. Primary project data is hosted in AWS region eu-west-1 (Ireland).
- Cloudflare, Inc. provides hosting, content delivery, security and operational metrics, and anonymous aggregated analytics for the static website.
- Vercel Inc. provides application hosting, content delivery, technical operational processing, and anonymous aggregated application analytics.
- Functional Software, Inc. (Sentry) processes limited technical error reports from the application; the project is configured for Sentry's Germany data region.
- Paddle is an independent controller and Merchant of Record for purchasing, payment, taxes, invoicing, fraud prevention, and refunds. The relevant Paddle entity depends on the buyer's location.
- Plus Five Five, Inc. (Resend) delivers and processes customer-support communications.
- Professional advisers, insurers, auditors, a business acquirer, and public authorities where reasonably necessary or required by law.
Workspace members can see information according to their role and access. Our processor list may change; material changes will be notified as required by our contracts and applicable law.
7. Transfers outside the European Economic Area
The primary Supabase database and files are hosted in Ireland and Sentry error data is stored in Germany. Some providers or their subprocessors may nevertheless process limited data in the United States, United Kingdom, or other countries. For transfers outside the EEA we rely on appropriate safeguards such as an adequacy decision, the EU–US Data Privacy Framework for certified recipients, or the European Commission's Standard Contractual Clauses and supplementary measures where needed.
You may request information about relevant safeguards at support@elecroute.com; portions may be redacted for security or confidentiality.
8. Cookies and browser storage
We use only browser storage required to provide requested functionality. We do not use advertising or analytics cookies. Neither Cloudflare Web Analytics nor Vercel Web Analytics creates analytics cookies or local storage or builds a visitor profile across websites. Sentry is used only in the application and is configured without session replay, profiling, performance tracing, or persistent browser-session tracking.
| Name / type | Purpose | Duration |
|---|---|---|
ELECROUTE_LOCALE · cookie | Remembers the selected language | 1 year |
ELECROUTE_PRIVACY_NOTICE_DISMISSED · cookie | Remembers dismissal of the informational privacy notice; it is not a record of consent | 1 year |
| Supabase authentication cookies (name includes the project reference) | Maintain login and the secure authentication flow | According to session validity; refreshed and removed on sign-out as applicable |
electrical-planner.activeWorkspaceId · localStorage | Remembers the last active workspace | Until browser storage is cleared or the value changes |
elecroute.roomFillOpacity · localStorage | Remembers the room-fill display preference | Until browser storage is cleared or the value changes |
electrical-planner.editLeases · sessionStorage | Keeps this tab's editing-lease identifier across navigation and reloads | Until the tab closes or editing ends |
Cloudflare Web Analytics, Vercel Web Analytics, and application error reporting through Sentry do not use advertising cookies or local storage to track a user and do not rely on cookie consent. You can block or clear storage in your browser, but login and requested functionality may then fail. If we later introduce marketing or other technology requiring consent, we will update this Policy and the consent mechanism before enabling it.
9. Retention
- active account and project data: for the account or contract lifetime;
- projects after subscription cancellation: while the workspace exists, so they remain viewable and exportable;
- unsuccessful pilot or demo enquiries: 12 months after the last communication;
- support correspondence: 3 years after the request closes, longer for an active dispute;
- ElecRoute-controlled security and audit records: normally 12 months, longer for an incident or legal claim;
- Sentry technical error reports from the application: 30 days under the currently selected plan;
- aggregated Cloudflare Web Analytics data: according to the service settings and retention period, currently available in reports for the previous six months;
- aggregated Vercel Web Analytics data: according to the selected plan and account settings; the visitor-session identifier is discarded after 24 hours;
- hosting logs: according to the provider's default retention and selected plan; and
- accounting, tax, and transaction records: for the period required by applicable law.
After a verified deletion request, we delete active data without undue delay unless continued retention is required. Residual encrypted backups expire through the normal backup cycle, targeted within no more than 30 days, and are not used for ordinary operations in the meantime. Data may be kept longer to comply with law, resolve a dispute, or protect legal claims.
10. Your rights
Subject to the GDPR's conditions, you may request access, correction, erasure, restriction, and portability and object to processing based on legitimate interests. If processing were based on consent, you could withdraw it at any time without affecting earlier lawful processing.
Send requests to support@elecroute.com. We may reasonably verify your identity and authority. For data controlled by a Customer, we may direct you to the workspace administrator or assist that Customer with the request.
You may lodge a complaint with the Office for Personal Data Protection of the Slovak Republic or the supervisory authority where you habitually live or work.
11. Security
We use appropriate technical and organisational measures, including encrypted transport, authentication, access controls, database-enforced workspace separation, restricted administrative access, and controlled backups. No system can be guaranteed completely secure. Users must protect login credentials and report suspected incidents.
12. Contact and Policy changes
Send questions and requests to support@elecroute.com. The business owner is responsible for requests until that responsibility is delegated.
We will notify users by email of a material change to this Policy. The current version will remain published here with its effective date. The Slovak version controls; the English version is a convenience translation unless mandatory law requires otherwise.