Privacy Notice

This Privacy Notice explains how Ochno AB collects and uses personal data when you visit our website, communicate with us, do business with us, create an account or register and manage connected products.

Personal data means information that identifies you or can reasonably be linked to you.

Who is responsible for your personal data?

Ochno AB is the data controller where we determine why and how your personal data is processed.

You can contact us at:

Email: legal@ochno.com
Address: Badhusgatan 8, 722 15 Västerås, Sweden

When we process personal data on behalf of a business customer, the customer is the data controller and Ochno acts as a data processor under the applicable agreement. In those cases, the customer’s privacy information explains the processing, and requests concerning that data should be directed to the customer.

What personal data do we process, and why?

When you contact us or do business with us

We process your name, business contact details, organisation, role and information you provide in correspondence. Our business records may also contain information relating to quotations, orders, deliveries, invoices, payments and support.

We use this information to answer enquiries, manage customer and partner relationships, fulfil orders and provide support.

Legal basis: Our legitimate interests in communicating with business contacts and managing business relationships. Where you personally enter into an agreement with us, processing necessary to fulfil that agreement or take steps you request beforehand is based on contract. Mandatory accounting and other records are processed to meet legal obligations.

When you create or use an account

We process account and profile information, contact details, organisation connections, access permissions, preferences and records of accepted terms. We also process authentication information and sign-in records, which may include IP addresses and browser or device information.

We use this information to administer your account, provide access, communicate important information and protect your account. Authentication may include multi-factor authentication or passkeys.

Legal basis: Performance of our agreement with you, where applicable, or our legitimate interests in providing and administering access for your organisation. Security processing is based on our legitimate interests in protecting accounts and preventing misuse.

When you register and manage connected products

We process information about registered products, including their identifiers, names, configuration and association with customer accounts and spaces. Connected products also provide operational status, connectivity and usage information.

We use this information to register and manage products, monitor their operation, troubleshoot problems and provide analytics, including insights into product use and energy consumption.

Applications used for product registration support account sign-in and registration of products to the cloud platform. We do not track application downloads or collect other data held locally in those applications.

Product information is not necessarily personal data. It may become personal data when linked to an identifiable person, including through account information or names and descriptions supplied by users.

Where we process personal data on your organisation’s behalf, we follow its instructions under our data processing agreement. Your organisation determines the legal basis for that processing. Our own processing for account administration and security is described in the other sections of this notice.

When you visit our website

We process technical information such as IP addresses, browser information, requests, timestamps and error or security events.

We use this information to deliver and maintain the website, investigate problems and prevent abuse.

Legal basis: Our legitimate interests in operating a reliable and secure website. Where consent is required for optional cookies or similar technologies, we ask for it separately.

When you choose to receive marketing

We process your contact details and communication preferences to manage and send the marketing communications you choose to receive.

Legal basis: Your consent for opted-in marketing communications. You can withdraw it through your account preferences or by contacting us. This does not affect essential account, security or service messages.

Where do we obtain personal data?

We collect information directly from you and automatically when you use our website, sign in or connect registered products. We may also receive information from your organisation, its administrators, authorised business partners and connected business systems.

Some information is necessary to respond to a request, provide an account or fulfil an order. If you do not provide it, we may be unable to fulfil your request. Optional information and choices are identified where they are requested.

Who receives personal data?

Personal data may be accessed by authorised Ochno personnel and providers that help us with hosting, communications, authentication, customer management, accounting, support and content delivery.

Your organisation’s authorised administrators may access information needed to manage accounts and connected products. Information may also be shared through integrations enabled for your organisation.

We may disclose personal data to authorities where required by law, or to professional advisers where necessary to meet legal obligations or establish, exercise or defend legal claims.

External websites and services have their own privacy notices.

Is personal data transferred internationally?

Our website is hosted in Sweden. Providers and integrations may involve processing in other countries, including outside the European Economic Area.

Where personal data is transferred outside the EEA, an applicable transfer mechanism is required, such as an adequacy decision or approved contractual safeguards, together with additional protections where necessary.

You can contact us for information about the processing locations and safeguards applicable to your personal data, including how to obtain a copy of relevant safeguards.

How long do we keep personal data?

The retention period depends on the purpose of the processing:

  • Enquiries and support records are kept while handling the matter and any relevant follow-up, warranty issue or dispute.

  • Business and transaction records are kept for the relationship and applicable accounting or other statutory retention periods.

  • Account information is kept while administering your account, with relevant records retained longer where needed for legal obligations or claims.

  • Security and technical records are kept for the period needed to investigate incidents, resolve problems and protect the website and accounts.

  • Marketing preferences are kept while managing your choices, including information needed to respect a request not to receive marketing.

  • Personal data processed on a customer’s behalf, including information associated with connected products, is retained according to the applicable agreement and customer instructions.

The trusted-device feature described below has a separate 30-day expiry. Removing it does not delete your account or other security records.

Cookies and similar technologies

We use cookies and browser storage for sign-in, security and preferences. We do not use cookies for analytics or advertising.

If you choose to remember your device, a security token in your browser is linked to a record associated with your account. This reduces repeated MFA requests for up to 30 days. You can remove it through User profile → Security → Forget this device; signing out does not remove it.

See our Cookie Policy for further information and available controls.

What are your rights?

Subject to applicable law, you have the right to:

  • Request access to your personal data and a copy of it.

  • Have inaccurate information corrected.

  • Request deletion or restriction of processing.

  • Object to processing based on legitimate interests.

  • Receive certain information in a portable format.

  • Withdraw consent where processing relies on it.

You may object to direct marketing at any time. Withdrawing consent does not affect the lawfulness of processing before withdrawal.

To exercise your rights, contact legal@ochno.com. We may need information to verify your identity. We normally respond within one month and will explain any permitted extension.

You also have the right to complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.

Changes to this notice

We may update this notice to reflect changes to our processing or legal requirements. The current version will be available at www.ochno.com/legal/privacy. We will communicate significant changes where required.

Effective date: 30 September 2026