The Aalto Privacy Center contains the answers to frequently asked questions about how we collect and use personal data, the rights that individuals have in relation to personal data held by Aalto, and how Aalto complies with data protection laws. It supplements our Privacy Policy.
Welcome to the Aalto Privacy Center
Aalto respects the privacy of everyone that engages with our platform, and we are committed to being transparent about our privacy processes and policies. We provide infrastructure for energy: drivers use our apps to find and pay for EV charging, and businesses use our technology to operate charging stations and other energy devices, manage fleets, and participate in energy programs. In order to provide our services to our Business Users and End Users, we collect and process personal data.
All materials have been prepared for general information purposes only. The information presented is not legal advice, is not to be acted on as such, may not be current and is subject to change without notice.
Below is a list of terms that will help “you” navigate the Privacy Center:
| “YOU” | MEANING | AALTO EXAMPLES |
|---|---|---|
| Business User | Aalto provides services to entities (“Business Users”) who directly and indirectly provide us with “End Customer” Personal Data in connection with those Business Users’ own business and activities. | Charging operator using Centro Fleet operator using Aalto Fleets Charging network using Aalto Roam |
| End Customer | When you are not directly transacting with Aalto, but we receive your Personal Data to provide services to a Business User (for example, you charge at a station an operator runs on Centro through the operator’s own channels, or you drive a vehicle your employer connected to Aalto Fleets), we refer to you as an “End Customer.” | Driver at an operator’s station Fleet driver |
| End User | When you directly use an End User Service for your personal use (such as using the Aalto app to find a station, save a payment method, and start a charging session), we refer to you as an “End User.” | Driver using the Aalto app |
| Representative | When you are acting on behalf of an existing or potential Business User (e.g. you are a founder of a company, or administering an account for a charging operator), we refer to you as a “Representative.” | Account owner or admin Officer, director |
| Visitor | When you visit a Site without being logged into an Aalto account or otherwise communicate with Aalto, we refer to you as a “Visitor” (e.g. you send Aalto a message asking for more information about our products). | aalto.energy visitor |
Contents
How We Collect, Disclose, and Use Personal Data
- Is Aalto acting as a data controller or a data processor?
- Which Aalto entities are involved?
- What are Aalto’s data controller activities?
- How does Aalto use Personal Data to improve its products and Services?
- Does Aalto collect precise location data?
- Does Aalto record calls?
- Who are Aalto’s sub-processors and how are they vetted?
- From where does Aalto collect information used for fraud prevention and security purposes?
- As a Business User, what notice do I provide to my End Customers about Aalto?
U.S. Privacy Disclosures
Data Processing Agreement
Information about Aalto Products
Data Protection Officer
International Data Transfers
Your Rights and Choices
Cookies & Other Technology
Contact Us
How We Collect, Disclose, and Use Personal Data
Is Aalto acting as a data controller or a data processor?
The answer is both.
The “data controller” is the entity which determines the purposes and means of the data processing taking place. The “data processor” is an entity acting on behalf and under the instructions of a controller in processing Personal Data.
Aalto is a data controller when it determines the purposes and means of the processing taking place: for example, for drivers using the Aalto app, and for our own fraud prevention, compliance, and product improvement activities.
Aalto is a data processor where it is providing the Aalto services to Business Users at their direction: for example, when we process charging sessions and payments at a Business User’s stations, collect vehicle telematics for a fleet operator, or respond to a Business User’s support request. As a platform provider, we need to ensure consistency across our platform, including the commitments we give about how we operate it, and we contract with all of our Business Users on this basis. See our Data Processing Agreement for the details.
Which Aalto entities are involved?
Aalto Energy, Inc., a Delaware corporation in the United States, is the entity responsible for your Personal Data, acting as data controller and/or data processor depending on the context described above. If we add affiliated entities as we expand internationally, we will update this page and our Sub-Processors List.
What are Aalto’s data controller activities?
- Determine and utilize third parties (including Financial Providers and Charging Network Partners);
- Monitor, prevent and detect fraudulent transactions and other fraudulent activity on the Aalto platform;
- Monitor, prevent and mitigate financial loss, security risks, and other harm;
- Implement, maintain and perform internal processes that enable Aalto to provide its products and services, including relationship management, billing and invoicing;
- Comply with Law, including applicable anti-money laundering screening and know-your-customer obligations, and Financial Provider and Governmental Authority requirements and requests; and
- Analyze and develop Aalto’s products and services.
How does Aalto use Personal Data to improve its products and Services?
Aalto collects data, including Personal Data, while providing services to its users, and uses some of that data to improve its products and services as permitted by applicable law and agreements. For example, we analyze charging session data to improve the accuracy of the station information shown in our apps (such as availability and reliability), to power analytics, forecasting, and pricing recommendations in Aalto Vision, and to train the models we use to detect fraud and prevent losses. When we communicate the results of these analytics to Business Users or use them in marketing, we do so only in aggregated or de-identified form that does not permit third parties outside of Aalto to associate that data with any particular individual.
Does Aalto collect precise location data?
Yes, in limited contexts and with your permission. If you grant the Aalto app location permission, we collect your device’s precise location to show nearby charging stations and provide directions; you can withdraw that permission at any time in your device settings and still search for stations manually. If a fleet operator connects a vehicle you drive to Aalto Fleets, we collect vehicle location through OEM and telematics integrations at the fleet operator’s direction; the fleet operator is responsible for obtaining driver consents. We may also derive approximate location from IP addresses to provide region-appropriate content and to detect fraud. Learn more in our Privacy Policy.
Does Aalto record calls?
Sometimes, and only where the law allows it. If you ask us to call you or otherwise speak with our support or sales teams, that call may be recorded, monitored, and transcribed so we can resolve your issue, check the quality of the help we gave you, and train our support teams; the telephony provider that carries our support line generates the transcript automatically. We tell you before a recording starts, and where the law requires your consent to record we ask for it; if you would rather not be recorded, you can ask us to continue by email or in-app chat instead. We do not use call recordings or transcripts to train the models that power our products, we do not use them for advertising, and we do not create voiceprints or use them for biometric identification. Learn more in our Privacy Policy.
Who are Aalto’s sub-processors and how are they vetted?
Please see our Aalto Sub-Processors List, where we list our sub-processors and key service providers. Aalto identifies, evaluates, and engages sub-processors through vendor due diligence, including a security assessment proportionate to the data the provider will handle. We enter into a contract with each sub-processor before sharing data with them, with terms designed to ensure they process personal data only to provide services to Aalto and in accordance with our commitments to Business Users and applicable data protection laws.
From where does Aalto collect information used for fraud prevention and security purposes?
To prevent fraud and strengthen our security, we may collect information from Business Users, End Customers, End Users, Financial Providers, Charging Network Partners, and in some cases third parties. For example, we collect and analyze information that helps us identify bad actors and bots, including transactional data (such as session amounts and payment outcomes) and device and activity signals. We may also receive information from third parties about security threats, such as IP addresses that malicious actors have compromised.
As a Business User, what notice do I provide to my End Customers about Aalto?
Under the terms of our agreements, Business Users are required to provide all necessary notices and obtain all necessary rights and consents from their End Customers (including, for fleet operators, their drivers) to enable Aalto to lawfully collect, use, retain and disclose Personal Data as part of the Aalto services. Business Users, as data controllers and/or the End Customer-facing entity, are responsible for the contents of their own privacy notices. As an example, here is a paragraph you can consider adapting for your privacy notice (this is for illustrative purposes only and is not legal advice; please talk to your legal advisor):
We use Aalto for EV charging operations, payments, analytics, and other business services. Aalto may collect personal data, including via cookies and similar technologies. The personal data Aalto collects may include charging session and transactional data and identifying information about devices and vehicles that connect to its services. Aalto uses this information to operate and improve the services it provides to us, including for fraud detection, loss prevention, authentication, and analytics related to the performance of its services. You can learn more about Aalto and read its privacy policy at https://aalto.energy/privacy.
U.S. Privacy Disclosures
Does Aalto “sell” or “share” my personal information under the CCPA?
We do not transfer your Personal Data to third parties in exchange for payment. However, we may provide your Personal Data to third-party partners, such as advertising partners and analytics providers, who assist us in advertising our products and services to you. Because these third parties may use the data Aalto provides for their own purposes, Aalto’s provision of data to these parties may be considered a data “sale” or “sharing” as those terms are defined under the CCPA and other applicable US privacy laws. See our Privacy Policy (Jurisdiction-specific provisions) for how to opt out. To our knowledge, Aalto does not sell personal information of minors under 16 years of age.
How long will Aalto keep my data?
Aalto keeps Personal Data as necessary to achieve the purposes described in our Privacy Policy. To determine the appropriate retention periods, we consider criteria such as the jurisdiction you are located in, the nature of our relationship with you, the types of products or services provided to you, the nature and sensitivity of your Personal Data, retention requirements under applicable laws and regulations (including those that apply to payment records), and other legitimate interests such as detecting and preventing fraud and defending our legal rights. Even after you close your account, we may retain certain Personal Data to comply with our legal, tax, and financial reporting obligations.
Data Processing Agreement
What is a Data Processing Agreement (DPA) and how can I get one with Aalto?
A Data Processing Agreement (“DPA”) is a contract between a data controller and a data processor that describes the roles and responsibilities of the parties when personal data is processed. Aalto’s DPA is incorporated into the Aalto Services Agreement, so every Business User benefits from it automatically; no separate signature is needed. Please contact us if you have any questions.
Information about Aalto Products
How does each Aalto product handle personal data?
| Product | What it does | Personal data highlights |
|---|---|---|
| Centro | Energy management system for operating charging stations and other energy devices, with device control and settlement. | Aalto processes Representative account data as a controller, and processes End Customer session and device data on the operator’s behalf as a processor. |
| Aalto Charge | The driver apps (iOS, Android, web) for finding stations and starting and paying for charging sessions. | Aalto acts as a controller for driver accounts, saved payment methods (tokenized by our payment processor), session history, and, with permission, device location. |
| Aalto Fleets | Connects fleet vehicles via OEM and telematics integrations (e.g., Smartcar) to manage and consolidate charging. | Aalto processes vehicle data (location, state of charge, charging activity) at the fleet operator’s direction as a processor; the operator is responsible for driver notices and consents. |
| Aalto Vision | Analytics, pricing recommendations, and DER orchestration planning. | Works primarily on aggregated and de-identified operational data; underlying session data is handled as described in the Privacy Policy. |
| Aalto Roam | Lets charging networks connect their stations to Aalto’s platform via OCPI roaming. | Aalto exchanges session authorization and charge detail records with Charging Network Partners to start, complete, and settle roaming sessions. |
Data Protection Officer
Does Aalto have a Data Protection Officer (DPO)?
Aalto has not appointed a Data Protection Officer at this time. Our privacy team is responsible for our privacy program and can be reached at privacy@aalto.energy. We will update this page if we appoint a DPO.
International Data Transfers
How is Aalto dealing with its international data transfers?
We are based in the United States, and Personal Data may be transferred to, and processed in, the United States and any other country where we do business or where our service providers do business. When transferring data across borders, we take measures to comply with applicable data protection laws, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum where required. Our Data Transfers Addendum sets out the data transfer mechanisms that Aalto relies on.
How do I get a copy of the SCCs or UK Addendum?
You can review our Data Transfers Addendum, which includes the latest data transfer mechanisms, including the SCCs, the UK Addendum, and the Swiss adaptations.
Is Aalto certified under the EU-U.S. Data Privacy Framework or CBPR/PRP?
Not at this time. Aalto currently relies on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum for transfers that require a transfer mechanism, as set out in our Data Transfers Addendum. If Aalto obtains Data Privacy Framework or CBPR/PRP certifications, we will update this page and the Data Transfers Addendum.
Your Rights and Choices
How do I exercise my data protection rights?
Depending on your location and subject to applicable law, you may have rights including: confirmation of processing, access, rectification/correction, data portability, restriction of processing, objection to processing, withdrawal of consent, erasure/ deletion, opt-out of targeted advertising or “sales,” non-discrimination for exercising your rights, and appeal. Our Privacy Policy (Your rights and choices) describes these rights in detail. To submit a request, email us at privacy@aalto.energy. We may need to verify your identity and your relationship with us before we can proceed with your request. If you are the End Customer of a Business User (for example, a fleet driver), the Business User is the correct party to respond to requests about data we process on their behalf; we will refer you to them where we can identify them. You also have the right to complain to your local data protection authority if you are unhappy with our privacy practices.
How do I delete my account?
Drivers can close their Aalto account from the app’s settings or by contacting support; Business Users can close their account from the dashboard or by contacting us. Please be aware that we will delete some, but not all, of the information that we hold: as a provider of charging and payment-related services, Aalto is required to comply with regulations (including anti-money laundering and tax laws) that may require us to retain transactional records for a prescribed period after the relationship ends. You can read more in our Privacy Policy (Security and retention).
Does Aalto honor the Global Privacy Control (GPC) opt-out preference signal?
Yes. Where required by applicable law, we honor the GPC signal as a valid request to opt out of targeted advertising and any related “sharing.” You can learn more about opt-out preference signals at the Global Privacy Control website.
Cookies & Other Technology
How does Aalto use cookies?
We use cookies and similar technologies to (1) ensure that our services function properly, (2) prevent and detect fraud and violations of our terms of service, (3) understand how Visitors use and engage with our Sites, (4) advertise our products and services, where allowed, and (5) analyze and improve our services and your experience. Cookies play an important role in helping Aalto provide personal, effective and safe services, and we change the cookies periodically as we improve or add to our services. For more information, please see our Cookies Policy.
Can I turn off tracking and fraud signals?
Yes — you can opt out of non-essential cookies through our cookie settings. Your web browser may also allow you to manage your cookie preferences, including deleting or disabling Aalto cookies; see the browser links in our Cookies Policy. If you choose to disable cookies, some features of our Sites or services may not operate as intended. Note that our payment processor sets fraud-prevention cookies on pages where payments occur; these signals are used to enable secure payments and prevent fraud, not to build advertising profiles.
Contact Us
Contact our Privacy team
If you have any outstanding privacy questions after reviewing the Privacy Policy and this Privacy Center, please don’t hesitate to reach out to us at privacy@aalto.energy.
If you’d like to send us physical mail, please send to:
Aalto Energy, Inc.
524 Broadway, #02-110
New York, NY 10012
United States
Attention: Aalto Legal
If you become aware of any unauthorized use or any other breach of security regarding the Aalto services, please contact us immediately.