Last updated: 11 September 2026
GO Systemelektronik GmbH
Faluner Weg 1
24109 Kiel
Germany
Managing partner: Gunnar Schlumbohm
Managing director: Jonas Gordon Schlumbohm
Phone: +49 431 58080-0
Email: info@go-sys.de
BlueGate is operated exclusively on servers of GO Systemelektronik GmbH. The portal is not installed on customer premises.
To provide access to the portal we process: user name, password (stored as a hash value only), email address, mobile phone number, name, the assignment to a customer or installation, as well as the time of the last login and failed login attempts. If you use recovery codes for account access, we store those codes and the time at which they were used.
Purpose: provision of the contractually agreed access, assignment of permissions, detection of misuse.
Legal basis: Article 6(1)(b) GDPR (performance of a contract); for the detection of failed login attempts additionally Article 6(1)(f) GDPR (security of the system).
The measurement, status and diagnostic data transmitted to BlueGate by the BlueBox devices are installation data and as a rule not personal data. Where a device transmits location coordinates, we process those as well. An indirect reference to a person may arise from the location of the installation, from the contact persons on file and from the attribution of operating or acknowledgement actions to a user account. In the case of devices used in mobile applications, the location may also allow conclusions to be drawn about the whereabouts of the accompanying personnel.
Purpose: provision of the contractually agreed remote monitoring.
Legal basis: Article 6(1)(b) GDPR.
If limit values are exceeded or a device fails, we send notifications to the contact details stored in the account. In doing so we process the mobile phone number or email address, the alarm text and a dispatch log (time, recipient, delivery status, error code).
To send SMS messages, we transmit the mobile phone number and the message text via the gateway interface of CM.com N.V., Konijnenberg 30, 4825 BD Breda, Netherlands. The transmission takes place on the basis of a data processing agreement pursuant to Article 28 GDPR. The service provider passes the message on to the respective mobile network operator for delivery; if the number is located outside the EU/EEA, delivery necessarily takes place via the network there.
Alarm emails are sent via the mail infrastructure of DomainFactory GmbH, Neuturmstraße 5, 80331 Munich, Germany, on the basis of a data processing agreement pursuant to Article 28 GDPR.
Purpose: contractually agreed alarm notification, proof of delivery.
Legal basis: Article 6(1)(b) GDPR.
Retention period of the dispatch log: 90 days, then automatic deletion.
When the portal is accessed, the web server logs: IP address, date and time, the resource requested, HTTP status code, volume of data transferred, referrer and user agent. In order to ward off automated attacks, suspicious IP addresses are blocked temporarily (Fail2Ban).
Purpose: operation, troubleshooting, IT security.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is the secure and undisturbed operation of the system.
Retention period: web server log files 14 days, logs of the attack defence (Fail2Ban) four weeks, then automatic deletion in each case. In the event of a specific security incident, retention until the matter has been clarified.
We log activities in the portal that are relevant to security and to providing evidence, in particular logins and actions of a user account as well as changes to the alarm configuration (in each case with the time and the account that triggered them).
Purpose: traceability of configuration changes, investigation of false alarms and malfunctions, IT security.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
The legitimate interest is the secure and traceable operation of the system.
We use a technically necessary session cookie only, which maintains the login for the duration of the session. It is deleted when you log out or close your browser. No consent is required for this under Section 25(2) no. 2 TDDDG (German Digital Services Data Protection Act). We do not use analytics, tracking or advertising cookies. Third-party content (fonts, maps, videos) is not loaded from external servers.
For fault clearance and maintenance, employees of GO Systemelektronik GmbH access the portal and the connected BlueBox devices.
Access to the BlueBox devices is encrypted and takes place via gateway software developed by ourselves. No service provider is involved in this; the connection runs exclusively over our own infrastructure.
In the course of administrative work on the portal, the data listed under 2.1 to 2.5 may become visible. All access is logged.
Purpose: fulfilment of the contractual support and maintenance obligations.
Legal basis: Article 6(1)(b) GDPR.
Where a device transmits location coordinates, we show its position on a map in the portal. The map material originates from the OpenStreetMap project, but is delivered exclusively via our own server and cached there. Your browser does not establish any connection to third-party servers; IP address, browser identification and the map section being viewed are not transmitted to third parties.
Purpose: display of installation and device locations as part of the contractually agreed service.
Legal basis: Article 6(1)(b) GDPR.
BlueGate runs on servers owned by GO Systemelektronik GmbH. The servers are housed in a data centre of ADDIX GmbH in Kiel (access control, uninterruptible power supply). Administration and data storage lie exclusively with us; the data centre operator provides the physical space and the infrastructure.
The servers on which BlueGate is operated are located in Kiel, Germany. No personal data is transferred to processors outside the EU/EEA.
A third-country element arises where notifications are addressed to recipients outside the EU/EEA, for example to contact persons of our customers in the United States. In that case the alarm SMS is delivered via the network of the mobile network operator there, and an email via the recipient's mail server. The recipient of the data is the data subject themselves; the transfer is necessary for the performance of the contractual relationship and is based on Article 49(1)(b) GDPR. We have no influence on the level of protection in the network of the receiving operator.
Users outside the EU/EEA access the portal themselves over the internet. Here, too, no data is passed on to third parties; the data remains on our servers.
| Type of data | Period |
|---|---|
| User account | until the end of the contractual relationship or deletion of the account |
| Measurement data | until one month after the end of the contractual relationship |
| Dispatch logs of alarm SMS and alarm email | 90 days |
| Recovery codes that have been used | 90 days after use |
| Log of the alarm configuration | 365 days |
| Activity and access log of the portal | 365 days |
| Maintenance logs | 365 days after archiving |
| Server log files | 14 days |
| Logs of the attack defence (Fail2Ban) | 4 weeks |
We create regular backups to ensure availability. If data is deleted in the production system, it may still be contained in backups already created for up to twelve months. Those backups are used solely to restore the system after a failure; individual records are not accessed for any other purpose. After that period the backups are overwritten or deleted.
Statutory retention obligations, in particular the commercial and tax law periods under Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO), remain unaffected.
Providing a user name, an email address and — where notification by SMS is desired — a mobile phone number is necessary in order to use the portal. Without that information, access cannot be set up and notifications cannot be sent.
You have the right of access (Article 15 GDPR), to rectification (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction of processing (Article 18 GDPR) and to data portability (Article 20 GDPR).
Right to object: where we process data on the basis of Article 6(1)(f) GDPR (sections 2.4 and 2.5), you may object to the processing on grounds relating to your particular situation pursuant to Article 21 GDPR.
A message to info@go-sys.de is sufficient to exercise these rights.
Irrespective of this, you have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.
Automated decision-making including profiling within the meaning of Article 22 GDPR does not take place. Alarms are triggered automatically on the basis of fixed, configured limit values and have no legal effect on persons.