BlueGate privacy policy

Last updated: 11 September 2026

1. Controller

GO Systemelektronik GmbH
Faluner Weg 1
24109 Kiel
Germany

Managing partner: Gunnar Schlumbohm
Managing director: Jonas Gordon Schlumbohm

Phone: +49 431 58080-0
Email: info@go-sys.de

BlueGate is operated exclusively on servers of GO Systemelektronik GmbH. The portal is not installed on customer premises.

2. What data we process

2.1 User account and login

To provide access to the portal we process: user name, password (stored as a hash value only), email address, mobile phone number, name, the assignment to a customer or installation, as well as the time of the last login and failed login attempts. If you use recovery codes for account access, we store those codes and the time at which they were used.

Purpose: provision of the contractually agreed access, assignment of permissions, detection of misuse.
Legal basis: Article 6(1)(b) GDPR (performance of a contract); for the detection of failed login attempts additionally Article 6(1)(f) GDPR (security of the system).

2.2 Measurement data from the BlueBox devices

The measurement, status and diagnostic data transmitted to BlueGate by the BlueBox devices are installation data and as a rule not personal data. Where a device transmits location coordinates, we process those as well. An indirect reference to a person may arise from the location of the installation, from the contact persons on file and from the attribution of operating or acknowledgement actions to a user account. In the case of devices used in mobile applications, the location may also allow conclusions to be drawn about the whereabouts of the accompanying personnel.

Purpose: provision of the contractually agreed remote monitoring.
Legal basis: Article 6(1)(b) GDPR.

2.3 Alarm notification by SMS and email

If limit values are exceeded or a device fails, we send notifications to the contact details stored in the account. In doing so we process the mobile phone number or email address, the alarm text and a dispatch log (time, recipient, delivery status, error code).

To send SMS messages, we transmit the mobile phone number and the message text via the gateway interface of CM.com N.V., Konijnenberg 30, 4825 BD Breda, Netherlands. The transmission takes place on the basis of a data processing agreement pursuant to Article 28 GDPR. The service provider passes the message on to the respective mobile network operator for delivery; if the number is located outside the EU/EEA, delivery necessarily takes place via the network there.

Alarm emails are sent via the mail infrastructure of DomainFactory GmbH, Neuturmstraße 5, 80331 Munich, Germany, on the basis of a data processing agreement pursuant to Article 28 GDPR.

Purpose: contractually agreed alarm notification, proof of delivery.
Legal basis: Article 6(1)(b) GDPR.
Retention period of the dispatch log: 90 days, then automatic deletion.

2.4 Server log files

When the portal is accessed, the web server logs: IP address, date and time, the resource requested, HTTP status code, volume of data transferred, referrer and user agent. In order to ward off automated attacks, suspicious IP addresses are blocked temporarily (Fail2Ban).

Purpose: operation, troubleshooting, IT security.
Legal basis: Article 6(1)(f) GDPR. The legitimate interest is the secure and undisturbed operation of the system.
Retention period: web server log files 14 days, logs of the attack defence (Fail2Ban) four weeks, then automatic deletion in each case. In the event of a specific security incident, retention until the matter has been clarified.

2.5 Logging of activities in the portal

We log activities in the portal that are relevant to security and to providing evidence, in particular logins and actions of a user account as well as changes to the alarm configuration (in each case with the time and the account that triggered them).

Purpose: traceability of configuration changes, investigation of false alarms and malfunctions, IT security.
Legal basis: Article 6(1)(b) GDPR and Article 6(1)(f) GDPR.
The legitimate interest is the secure and traceable operation of the system.

2.6 Cookies

We use a technically necessary session cookie only, which maintains the login for the duration of the session. It is deleted when you log out or close your browser. No consent is required for this under Section 25(2) no. 2 TDDDG (German Digital Services Data Protection Act). We do not use analytics, tracking or advertising cookies. Third-party content (fonts, maps, videos) is not loaded from external servers.

2.7 Remote access for support and maintenance purposes

For fault clearance and maintenance, employees of GO Systemelektronik GmbH access the portal and the connected BlueBox devices.

Access to the BlueBox devices is encrypted and takes place via gateway software developed by ourselves. No service provider is involved in this; the connection runs exclusively over our own infrastructure.

In the course of administrative work on the portal, the data listed under 2.1 to 2.5 may become visible. All access is logged.

Purpose: fulfilment of the contractual support and maintenance obligations.
Legal basis: Article 6(1)(b) GDPR.

2.8 Map display

Where a device transmits location coordinates, we show its position on a map in the portal. The map material originates from the OpenStreetMap project, but is delivered exclusively via our own server and cached there. Your browser does not establish any connection to third-party servers; IP address, browser identification and the map section being viewed are not transmitted to third parties.

Purpose: display of installation and device locations as part of the contractually agreed service.
Legal basis: Article 6(1)(b) GDPR.

3. Recipients

BlueGate runs on servers owned by GO Systemelektronik GmbH. The servers are housed in a data centre of ADDIX GmbH in Kiel (access control, uninterruptible power supply). Administration and data storage lie exclusively with us; the data centre operator provides the physical space and the infrastructure.

Transfer to third countries

The servers on which BlueGate is operated are located in Kiel, Germany. No personal data is transferred to processors outside the EU/EEA.

A third-country element arises where notifications are addressed to recipients outside the EU/EEA, for example to contact persons of our customers in the United States. In that case the alarm SMS is delivered via the network of the mobile network operator there, and an email via the recipient's mail server. The recipient of the data is the data subject themselves; the transfer is necessary for the performance of the contractual relationship and is based on Article 49(1)(b) GDPR. We have no influence on the level of protection in the network of the receiving operator.

Users outside the EU/EEA access the portal themselves over the internet. Here, too, no data is passed on to third parties; the data remains on our servers.

4. Retention periods

Type of dataPeriod
User accountuntil the end of the contractual relationship or deletion of the account
Measurement datauntil one month after the end of the contractual relationship
Dispatch logs of alarm SMS and alarm email90 days
Recovery codes that have been used90 days after use
Log of the alarm configuration365 days
Activity and access log of the portal365 days
Maintenance logs365 days after archiving
Server log files14 days
Logs of the attack defence (Fail2Ban)4 weeks

Backups

We create regular backups to ensure availability. If data is deleted in the production system, it may still be contained in backups already created for up to twelve months. Those backups are used solely to restore the system after a failure; individual records are not accessed for any other purpose. After that period the backups are overwritten or deleted.

Statutory retention obligations, in particular the commercial and tax law periods under Section 257 of the German Commercial Code (HGB) and Section 147 of the German Fiscal Code (AO), remain unaffected.

5. Obligation to provide data

Providing a user name, an email address and — where notification by SMS is desired — a mobile phone number is necessary in order to use the portal. Without that information, access cannot be set up and notifications cannot be sent.

6. Your rights

You have the right of access (Article 15 GDPR), to rectification (Article 16 GDPR), to erasure (Article 17 GDPR), to restriction of processing (Article 18 GDPR) and to data portability (Article 20 GDPR).

Right to object: where we process data on the basis of Article 6(1)(f) GDPR (sections 2.4 and 2.5), you may object to the processing on grounds relating to your particular situation pursuant to Article 21 GDPR.

A message to info@go-sys.de is sufficient to exercise these rights.

Irrespective of this, you have the right to lodge a complaint with a supervisory authority; the authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.

7. Automated decision-making

Automated decision-making including profiling within the meaning of Article 22 GDPR does not take place. Alarms are triggered automatically on the basis of fixed, configured limit values and have no legal effect on persons.