Version: V2.0
Scope: ShineServer Web-based PV monitoring platform and its related services (hereinafter referred to as "this Platform" or "ShineServer")
Please read this Policy carefully before using this Platform. Upon first login, we will present this Policy to you via a pop-up window. You may also access the latest version at any time via the "Privacy Policy" link at the bottom of the Platform pages.
If you are a UK user:
Growatt New Energy Technology Limited is the data controller of your personal data.
>
Company Registration No.: 08660706
>
Registered Address: Unit 1, The Cromwell Centre, Hainault Business Park, Roebuck Road, Ilford, England, IG6 3UG, UK
If you are a user in Mainland China or other regions:
Shenzhen Growatt New Energy Co., Ltd. (深圳古瑞瓦特新能源有限公司) is the data controller of your personal data.
>
Registered Address: 4-13/F, Building A, Sino-German (European) Industrial Demonstration Park, Hangcheng Avenue, Guxing Community, Xixiang Street, Bao'an District, Shenzhen, P.R. China
The development, technical operation and maintenance, and customer support of this Platform are provided by our affiliated companies located around the world. Each affiliated company processes your data as a data processor, is bound by a Data Processing Agreement (DPA), and adheres to the Group's unified data protection standards.
ShineServer is a Web-based PV monitoring platform and does not integrate any third-party mobile SDKs (Software Development Kits).
Other products within our Group (such as the ShinePhone mobile application) may integrate mobile SDKs such as Amap SDK, Alipay SDK, WeChat Pay SDK, JPush SDK, Xiaomi Push SDK, Huawei Push SDK, and Umeng SDK. However, none of the above SDKs are applicable to the ShineServer Web platform. As a browser-based web application, ShineServer does not involve the data collection activities of the aforementioned mobile SDKs.
If you also use our mobile applications (such as ShinePhone), please refer to the respective application's privacy policy for information on its SDK usage.
We collect only the information necessary to deliver Platform functionality, in accordance with the principles of lawfulness, fairness, necessity and data minimisation. The following sets out the categories of data we may collect.
Information you actively provide when registering for and using a ShineServer account:
Information you provide when creating and managing PV stations through this Platform:
Automatically collected when your PV inverter devices are connected to this Platform:
Collected when you contact customer service or submit feedback:
Automatically collected when you access this Platform:
The following table sets out each specific purpose for which we process your personal data and its corresponding legal basis:
| Processing Purpose | Data Involved | Legal Basis |
|---|---|---|
| Creating and managing your ShineServer account | Account data | Contractual Necessity — Performing our service agreement with you, providing platform access (Art. 6(1)(b)) |
| Providing PV station remote monitoring services | Device and product data, station data, location data | Contractual Necessity — Core functionality of this Platform, providing real-time device data display, historical data query, and station management (Art. 6(1)(b)) |
| Device fault alarms and remote diagnostics | Device operational data, fault/alarm codes, configuration data | Contractual Necessity — Ensuring normal device operation, timely detection and handling of device faults (Art. 6(1)(b)) |
| Responding to your customer service requests and technical support | Account data, customer support data, device data | Contractual Necessity — Handling your service requests, fault repairs and complaints (Art. 6(1)(b)) |
| Improving Platform functionality and user experience | Technical data, aggregated device data (anonymised) | Legitimate Interests — Understanding how users use this Platform to continuously improve service quality (Art. 6(1)(f)) |
| Ensuring system security and preventing fraud | IP address, login information, device information | Legitimate Interests — Protecting our systems and users from unauthorised access, cyber-attacks, and fraudulent activities (Art. 6(1)(f)) |
| Sending you device alarm and service-related notifications | Account data, device information | Legitimate Interests — Sending you necessary notifications closely related to the normal operation of the service (such as device faults, important safety reminders) (Art. 6(1)(f)) |
| Sharing device operational data with your installer/distributor | Device and product data | Legitimate Interests — Ensuring complete after-sales operation, maintenance, and technical support services for you (Art. 6(1)(f)) |
| Conducting data statistics and analysis (aggregated level) | Anonymised usage data and device data | Legitimate Interests — Used for industry trend research, product planning, energy efficiency analysis, etc., without identifying you personally (Art. 6(1)(f)) |
| Sending you marketing and promotional information | Account data, marketing preferences | Consent — Only sent with your explicit consent. You may withdraw consent at any time without affecting other services (Art. 6(1)(a)) |
| Complying with legal obligations | Account data, transaction data | Legal Obligation — Including but not limited to tax reporting, regulatory reporting, lawful requests from judicial or administrative authorities (Art. 6(1)(c)) |
| Protecting your or another person's vital interests | Relevant necessary data | Vital Interests — Protecting your or another person's life, health or safety in emergency situations (Art. 6(1)(d)) |
| Responding to data requests from statutory public authorities | As required by law | Public Interest — Cooperating in matters of public interest as provided by law (Art. 6(1)(e)) |
About "Legitimate Interests" :
Where we process your data on the basis of legitimate interests, we have completed a Legitimate Interests Assessment (LIA) confirming that the processing does not override your rights and freedoms. You have the right to object at any time to our processing based on legitimate interests — please see Section 3 "Right to Object" below.
About "Consent" :
The majority of core functions (device monitoring, fault alarms, customer support, etc.) are based on contractual necessity or legitimate interests and do not require your consent. We only request your separate consent for:
You can manage your consent at any time within the Platform under "Account Settings → Privacy Preferences". Withdrawal of consent does not affect the lawfulness of processing carried out based on consent before its withdrawal.
Under applicable data protection laws, you enjoy the following rights. We will not discriminate against you for exercising any of your rights.
You have the right to obtain a copy of your personal data that we hold, along with information about how we process that data.
How to exercise: Send an email to the DPO mailbox (linda@growatt.com) describing your request. We will provide a copy of your data after verifying your identity.
You have the right to correct inaccurate or incomplete personal data.
How to exercise: You can self-correct basic information within the Platform under "Account Settings → Personal Profile". For device-related data, please contact customer service or email the DPO.
You have the right to request deletion of your personal data in the following circumstances:
How to exercise: You can submit a deletion request within the Platform under "Account Settings → Account Security → Delete Account". You may also send an email to the DPO. After account deletion, we will delete or anonymise your data within 30 days, unless longer retention is required by law.
You have the right to request restriction of processing in the following circumstances:
How to exercise: Send an email to the DPO, specifying the grounds and scope of the restriction.
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.
How to exercise: Send an email to the DPO indicating which categories of data you wish to receive. We will respond within one month.
You have the right to object to our processing of your data in the following circumstances:
How to exercise: Send an email to the DPO, or manage via "Privacy Preferences" within the Platform.
You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you.
We do not currently engage in such automated decision-making. Should we introduce relevant functionality in the future, we will inform you in advance of the logic involved, the envisaged consequences, and the measures you may take.
You have the right to withdraw any consent you have given at any time. Withdrawal does not affect the lawfulness of processing carried out based on consent before its withdrawal.
How to exercise: You can view and manage all consents given within the Platform under "Account Settings → Privacy Preferences".
You have the right to lodge a complaint with the applicable data protection supervisory authority. For specific supervisory authorities and complaint channels by region, please see Section 13 "Region-Specific Terms" below.
Response Times and Fees:
We do not sell your personal information or device data to any third party.
Where your equipment is installed and maintained by an installer/distributor, that installer/distributor may, within their authorised scope of access, view relevant device data (including device basic information, operational data, fault alarms, etc.) for the purposes of providing after-sales operation and maintenance, fault diagnosis, and technical support services. This sharing is based on our contractual relationship with the installer/distributor and our legitimate interest in providing after-sales operation and maintenance services.
We may engage third-party service providers to assist us in providing relevant operational and service support, and may transfer or grant access to your personal information for technical reasons (including but not limited to cloud service providers and data analysis service providers). We have signed Data Processing Agreements (DPAs) with all processors, ensuring that they process your data in accordance with our instructions and this Policy.
We may disclose your data in the following circumstances:
Your data may be transferred to and stored on servers outside your country/region. Currently, core data of global users is stored by default on servers in Mainland China, and some data may be stored on servers in other regions.
When we transfer your data from one country to another, we ensure that at least one of the following safeguards is in place:
For UK users:
Your data transfers are protected by the following mechanisms:
>
- UK International Data Transfer Agreement (UK IDTA), or
- UK Addendum to EU SCC
>
These are lawful cross-border transfer mechanisms approved by the UK Information Commissioner's Office (ICO).
For Mainland China users:
Your data transfers comply with the requirements of China's Personal Information Protection Law (PIPL), including:
>
- Passing the security assessment by the national cyberspace administration
- Entering into the Standard Contract for Cross-Border Transfer of Personal Information
- Obtaining the necessary personal information protection certification
>
Personal information collected within Mainland China is stored within Mainland China.
For users in other regions:
We provide transfer safeguards in accordance with the data protection laws of your jurisdiction, using GDPR standards as a baseline:
>
- Entering into EU Standard Contractual Clauses (EU SCC 2021 version) or equivalent transfer agreements
- Implementing appropriate technical and organisational security measures to ensure data transfer security
>
For any questions or to obtain a copy of the relevant cross-border transfer agreements, please contact the DPO.
We provide appropriate security safeguards for your information to prevent loss, misuse, unauthorised access, or disclosure.
Despite our best efforts, no internet transmission or electronic storage can be guaranteed to be 100% secure.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
| Data Category | Retention Period |
|---|---|
| Account Data | Duration of account + 30 days after deletion (for handling possible subsequent complaints and disputes) |
| Device and Product Data | Duration of device connection + 90 days after unbinding for deletion or anonymisation |
| Station Data | Duration of account + 90 days after deletion for deletion or anonymisation |
| Technical Logs (IP address, browser information, etc.) | Retained for no more than 12 months |
| Customer Support Records | 3 years after ticket closure (for service quality analysis and dispute resolution) |
| Marketing Consent Records | Duration of consent validity + 6 years after withdrawal (as proof of compliance) |
| Backup Data | Rolling retention of 3 months (for disaster recovery; expired backups deleted immediately after restoration) |
Upon expiry of the above periods, data will be securely deleted or irreversibly anonymised. Where longer retention is required by law, we will retain the data only to the extent and for the duration required by law.
Where this Platform ceases operations, we will notify you via email, Platform announcements, or other means, and delete or anonymise your personal data within a reasonable period.
We take the protection of minors' personal data very seriously. Our services are not intended for minors below the legal age of consent.
We do not actively or directly collect personal information from minors. If there is evidence that a minor has registered for and used this Platform without parental or guardian consent, we will consult with the relevant guardian and take steps to delete the relevant personal information as soon as possible.
If you are a parent or guardian and discover that your child has provided personal data to us, please contact us immediately. Upon verification, we will promptly delete the relevant data.
As a web application, this Platform uses Cookies and similar technologies to ensure proper service operation and optimise user experience.
You may manage or clear Cookies in your browser settings. Disabling essential Cookies may affect the normal use of the Platform.
We do not currently engage in decisions based solely on automated processing (including profiling) that produce legal effects concerning you or similarly significantly affect you.
Should we introduce such functionality in the future, we will inform you in advance of:
In the event of a personal data breach involving your data, we will:
We may update this Privacy Policy from time to time. We will notify you in the following circumstances:
We recommend that you review this Policy periodically for the latest version.
The following supplementary terms apply depending on your region. Please refer to the section corresponding to your actual location.
Applicable Data Protection Law: UK GDPR and the Data Protection Act 2018.
Supervisory Authority:
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) about our processing of your personal data.
>
- Website: https://ico.org.uk/make-a-complaint/
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, UK
- Telephone: 0303 123 1113
>
We encourage you to contact us before lodging a complaint with the ICO. We will do our best to resolve your concerns.
International Data Transfers:
When your personal data is transferred from the UK to other countries, we use one of the following mechanisms to ensure adequate protection:
Legal Basis: The legal bases referenced in Section 2 of this Policy are based on UK GDPR Art. 6. References to "EU or Member State law" in Art. 6(1)(c) shall be read as "UK law", and "public interest" in Art. 6(1)(e) as "public interest recognised under UK law".
Data Subject Rights: All rights listed in Section 3 are based on the relevant provisions of UK GDPR (Art. 15-22 and Art. 77).
Governing Law and Dispute Resolution:
This Policy is governed by the UK GDPR and the laws of England and Wales. Disputes relating to this Policy shall first be resolved through amicable negotiation between the parties. If negotiation fails, the dispute shall be submitted to the exclusive jurisdiction of the courts of England and Wales. You retain your statutory right to lodge a complaint with the ICO.
Language: This Policy is available in both Chinese and English. In the event of any inconsistency, the English version shall prevail.
Applicable Data Protection Laws: Personal Information Protection Law of the People's Republic of China (PIPL), Data Security Law, Cybersecurity Law, and related laws and regulations.
Personal Information Processing Notification:
Personal information collected and generated in the course of our operations within Mainland China is, in principle, stored within Mainland China.
Sensitive Personal Information:
Where we need to process your sensitive personal information (such as precise location information), we will:
>
- Inform you of the necessity of the processing and its impact on you
- Obtain your separate consent
- Implement stricter security protection measures
Data Subject Rights:
Under Chapter IV of the PIPL, you enjoy the right to know and decide (Art. 44), the right to access and copy (Art. 45), the right to rectification (Art. 46), the right to erasure (Art. 47), the right to explanation (Art. 48), and the right to data portability. You also enjoy the right to restrict and refuse processing, and rights relating to automated decision-making (Art. 24).
>
How to exercise: Please refer to the instructions in Section 3 "Your Rights" of this Policy. The substance of each right is consistent with the requirements of Chinese law.
Withdrawal of Consent:
You have the right to withdraw consent for personal information processed on the basis of consent. Withdrawal of consent does not affect the validity of personal information processing activities carried out based on consent before its withdrawal.
Personal Information Protection Officer:
Personal information protection matters in Mainland China are centrally managed by the DPO (contact details in Section 14).
Right to Complain:
You have the right to lodge complaints and reports with departments responsible for personal information protection (such as the Cyberspace Administration of China).
Protection of Minors:
ShineServer is not intended for minors under the age of 14. If we inadvertently collect personal information from a minor under the age of 14, please contact us and we will promptly delete it upon verification.
For users in other regions (including but not limited to the European Economic Area and other countries/regions not separately listed), we provide an equivalent level of data protection using GDPR as a baseline standard:
To exercise your data subject rights, or if you have any questions, comments, or complaints about this Policy, please contact us:
| Item | Information |
|---|---|
| Name | Linda Wang (王清媛) |
| linda@growatt.com | |
| Postal Address | Same as the company registered address; please mark "DPO" |
This Policy is published in both Chinese and English. In the event of any inconsistency between versions, the provisions of the applicable law at your location shall prevail. For UK users, in the event of any inconsistency between the Chinese and English versions, the English version shall prevail.
>
*This Privacy Policy was last updated on: June 15, 2026*