EU Data Act Compliance Information
EU Regulation 2023/2854
Last updated: May 2026
Company:
Quandify AB
Address:
Gustavslundsvägen 151E
167 51, Bromma
Sweden
Website:
https://quandify.com
Email:
support@quandify.com
privacy@quandify.com
This document provides the information required under Article 3(2) of the EU Data Act (EU 2023/2854) relating to connected products and affiliated services offered by Quandify AB, including all Quandify devices and the Quandify Platform.
I. Information obligations before concluding a contract for connected products
1. Product
a. The type, format, and estimated amount of product data that the connected product can generate.
Quandify devices generate operational, environmental, and diagnostic data, including:
- Water or environmental consumption measurements (depending on device type)
- Temperature and flow readings (depending on device type)
- Device configuration and performance data
- Event notifications (e.g., alerts, faults, anomalies)
Format
Structured digital data transmitted in secure, industry-standard formats suitable for cloud storage and analytics.
Estimated amount
Approximately a 200 kilobytes per day, typically less than 10 MB per month per device depending on reporting frequency.
2. Data processing
a. Whether the connected product is capable of generating data continuously and in real time.
Yes. Quandify devices continuously monitor usage/telemetry data and transmit data periodically (typically every 60 minutes). Critical events or alerts are transmitted immediately.
b. An indication of whether the connected product is capable of storing data on a device or a remote server, including, if applicable, the intended storage period.
Quandify devices temporarily store limited usage/telemetry data locally before transmitting it securely to Quandify Platform servers within the EEA.
Storage location
Secure EEA-based cloud data centres (primary region: Belgium).
Storage period
Account identifiers (e.g., username, email): retained while the account is active, then deleted or anonymised.Device logs: retained up to 90 days, then deleted.Usage/telemetry data: retained for the life of the account and anonymised upon deletion.Backups: stored securely and rotated according to internal retention policies.
3. Data access by the user
a. The indication of how the user can access, retrieve or, where applicable, delete the data, including:
i. the technical means for this,
ii. the relevant terms of use,
iii. the quality of service in question.
Access
Users access their data via the Quandify App (iOS/Android) and associated account.
Retrieve
Users may request full data export by contacting privacy@quandify.com or support@quandify.com (identity verification required).
Delete
Users can delete their data and account via Quandify App or by contacting the privacy team. Data is permanently deleted or anonymised within standard retention windows.
Technical means
Secure authenticated connections between Quandify devices, app, and cloud platform using industry-standard encryption and security practices.
Terms of Use
Governed by Quandify’s Terms of Service and Privacy Policy.
Quality of Service
Continuous access (24/7) with >99% uptime.Typical data update frequency: hourly, with immediate updates for critical events.Data integrity and security are ensured through secure transmission and monitoring.
II. Information obligations before concluding a contract for affiliated services
1. Product data on the connected service
a. The nature, estimated scope and frequency of collection of the Product Data that the potential Data Holder is expected to receive and, where applicable, the modalities by which the User may access or retrieve such Data, including:
i. the modalities of the future data controller with regard to the storage,
ii. the duration of data retention.
Nature
Consumption measurements, environmental data, temperature readings, device diagnostics, and event alerts.
Scope
Limited to the minimum data required for device functionality, analytics, and alerting.
Frequency
Hourly uploads; real-time for alerts and critical updates.
Access and retrieval
Data available through the Quandify App and Quandify Portal as well as on request via support channels.
Storage (modalities)
Secure EEA-based cloud infrastructure under Quandify’s management, using industry-standard security and encryption methods.
Duration
Personal and account data retained for the duration of the account; device logs ≤90 days; anonymised after account deletion.
2. Service data
a. The type and estimated scope of the Connected Service Data to be generated, as well as the methods by which the User may access or retrieve such Data, including:
i. the modalities of the future data controller with regard to the storage,
ii. the duration of data retention.
Type
App usage data, configuration preferences, connectivity status, and diagnostics.
Scope
Limited to maintaining service functionality and performance.
Access and retrieval
Users may access this data within the Quandify App, Quandify Portal or via data-export requests.
Storage
Stored securely in EEA-based cloud infrastructure.
Duration
While the account remains active; deleted or anonymised after closure.
3. Use of data by the data holder
a. Whether the potential data owner expects to readily use available data themselves, and:
i. the purposes for which this data is to be used,
ii. whether it intends to authorise one or more third parties to use the data for purposes agreed with the user.
Quandify’s use of data
Operate and improve the functionality and security of devices and services.Perform diagnostics, provide alerts, and support customers.Generate anonymised analytics for service optimisation and sustainability insights.
Third-party use
Quandify does not sell user data. Third-party processing (e.g., hosting providers) occurs only under GDPR-compliant data-processing agreements.
No data sharing without consent
Any external data-sharing requires explicit user authorisation.
4. Identity and contact
a. The identity of the potential data owner, e.g.:
i. trade name,
ii. address of establishment,
iii. other data processing parties, if applicable.
b. The means of communication through which the potential data holder can be contacted quickly and communicated with efficiently.
Trade name
Quandify AB
Address
Gustavslundsvägen 151E
167 51, Bromma
Sweden
Other processors
Cloud hosting and analytics service providers under GDPR Article 28 Data Processing Agreements.
Contact
📧 support@quandify.com📧 privacy@quandify.com🌐 https://quandify.com
5. Disclosure
a. The indication of how the user can request that the data be disclosed to a third party and, if necessary, how to stop the data transfer.
Users may request disclosure or transfer of their data to a third party by contacting privacy@quandify.com. Transfers are performed securely and only with the user’s explicit consent. Users can withdraw consent or stop transfers at any time.
b. Right of appeal
Users have the right to lodge complaints regarding data processing with the Swedish Authority for Privacy Protection (IMY).
6. Trade secrets
a. An indication of whether a potential data holder is the owner of trade secrets contained in the data accessible through the connected product or generated in the provision of a connected service, and:
i. if the potential data owner is not a trade secret owner, the identity of the trade secret owner.
Quandify AB owns the proprietary algorithms, software, and analytics methods embedded in its devices and platform. User data does not contain third-party trade secrets. Quandify remains the trade secret holder for all software and system logic.
7. Period of contract
a. The duration of the contract between the User and the potential Data Owner, as well as the arrangements for the early termination of such a contract.
The contract remains active while the user maintains a Quandify account. Users may terminate the relationship at any time by deleting their account via the Quandify App or by contacting privacy@quandify.com. Upon termination, Quandify deletes or anonymises all personal data in accordance with GDPR and internal retention schedules.

