1. Introduction
Ride Awake ApS ("Awake", "we", "us", or "our") is the data controller for personal data processed in connection with our website (awakeboards.com), the Awake Link mobile application, our electric watercraft products and batteries, customer support, and related services (together, the "Services").
This Privacy Policy explains what personal data we collect, why we use it, how long we keep it, who we share it with, and what rights you have. It should be read together with our Terms and Conditions, Cookie Policy, and any product-specific terms that apply to you.
If you provide personal data about another person, you must ensure that you are allowed to do so and that they have been informed about this policy.
2. Contact details
- Data controller: Ride Awake ApS, Bredgade 58, 1260 Copenhagen, Denmark
- Privacy enquiries and data subject requests: privacy@awakeboards.com
- General enquiries: info@awakeboards.com
You can reach us at privacy@awakeboards.com for any questions about this policy or your personal data.
3. Scope
This policy applies to personal data we process about:
- customers and registered product owners;
- users of the Awake Link app;
- visitors to our website and online store;
- people who contact customer support;
- end users of products rented through Awake rental partners, where Awake processes data for safety, anti-theft, or operational purposes;
- charter and yacht users whose ride data may be collected indirectly through product use; and
- parents or guardians acting on behalf of users under 16.
Rental centres that operate Awake products may also process your data as separate controllers for their own rental activities. Where that applies, their privacy information will be provided by the rental centre.
4. Personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data:
4.1 Account and contact information
- name and email address;
- telephone number (where provided);
- username and password (stored in hashed form);
- optional postal address;
- marketing preferences, where you have chosen to receive marketing from us.
4.2 Product, device, and connectivity data
- battery and product serial numbers and identifiers (such as UUID and Bluetooth MAC address);
- IMEI and SIM-related identifiers for LTE-enabled batteries;
- warranty, registration, and ownership records;
- firmware, configuration, and connectivity status.
4.3 Location and ride data
- GPS location from the battery or product while it is active, typically to within a few metres when precise location processing applies;
- reduced-accuracy location (approximately 11 km) where precise location is not required or not enabled;
- ride sessions, routes, speed, direction, timestamps, and related ride statistics;
- phone-based location data only if you choose to allow this in the app or on your device.
4.4 Technical and telemetry data
- battery voltage, current, temperature, cell status, state of charge, system status, motor RPM, and related diagnostic information;
- error, safety, and performance data needed to monitor product health, safety, warranty, and regulatory requirements;
- Battery Passport information required under EU battery regulation (EU) 2023/1542.
4.5 App, website, and support data
- IP address, browser or device type, app version, language settings, and log data;
- support tickets, emails, and other communications with us;
- information you enter in website forms, checkout flows, or account settings, including information saved temporarily to help complete a purchase or support request;
- push notification tokens linked to your account.
4.6 User-generated and social content
- profile photo, ride photos, feed posts, follower relationships, and visibility settings;
- social interactions within the app where you choose to use those features.
4.7 Pre-onboarding and logistics data
Before a battery is registered to a user account, limited technical data may be collected locally on the device for storage, transport, and safety monitoring. In most cases this data cannot be linked to an identifiable person. Where a link may exist in limited direct-sale scenarios, we treat it in line with the rules described in this policy.
5. How we collect personal data
- directly from you when you create an account, register a product, make a purchase, use the app, contact support, or change your settings;
- from your product or battery through Bluetooth when the app is connected;
- automatically from LTE-enabled batteries when the product is active, including for safety and anti-theft purposes independent of the app;
- from local storage on the battery that is later transferred after onboarding or connection;
- from service providers that help us operate maps, geolocation, messaging, support, error monitoring, and cloud hosting; and
- from cookies and similar technologies on our website, as described in our Cookie Policy.
6. Why we use personal data and our legal bases
We process personal data only where we have a valid legal basis under the GDPR. The main bases we rely on are set out below.
6.1 Contract
We process personal data where necessary to provide the Services you request, including to:
- create and manage your account;
- register and connect your product;
- deliver core app and product functionality;
- provide warranty, service, and customer support; and
- process orders and related communications.
6.2 Legitimate interests
We process personal data where necessary for our legitimate interests, or those of users and third parties, provided your interests and rights do not override ours. This includes processing for:
- user and product safety, including detection of critical faults, water ingress, overheating, and emergency situations;
- theft prevention, recovery support, remote safety controls, and rental geofencing;
- operating, securing, and improving the safety of our products and systems;
- preventing misuse, fraud, and abuse;
- monitoring storage and transport conditions before onboarding;
- network and information security, including access logging and incident handling; and
- responding to support requests and defending legal claims.
Where we rely on legitimate interests for location processing, we use reduced location accuracy by default and limit precise location to what is needed for these purposes.
6.3 Legal obligation
We process certain battery traceability and technical information to comply with legal obligations, including requirements under the EU Battery Regulation (EU) 2023/1542 relating to the Battery Passport.
6.4 Consent
Where required, we ask for your consent before processing personal data for:
- product improvement, usage statistics, gamification, and analytics beyond what is necessary for core operation;
- sharing rides, leaderboards, social features, and public profile visibility;
- uploading photos or other optional content;
- using precise location for optional app features;
- optional marketing communications; and
- other processing that is not necessary to provide the Services.
You can manage these choices in the app and through our consent management platform. If you withdraw consent, we will stop the related processing going forward. Withdrawal does not affect processing that was lawful before withdrawal.
6.5 Vital interests
In rare emergency situations involving serious risk to life or physical safety, we may process limited location or safety data where necessary to protect vital interests.
7. IoT, LTE, and location processing
Because Awake products are connected devices, the following information is important:
- Awake batteries collect technical and location data while the product is active.
- If you use Bluetooth, data is transferred when your app is connected to the battery.
- LTE-enabled batteries can send data automatically while active, including when the app is not connected.
- A safety and anti-theft communications channel remains active on LTE-enabled products and cannot be fully switched off, because disabling it would prevent critical safety functions and theft response.
- You can limit non-essential telemetry transmission through app privacy settings.
- Without consent for optional location features, location is stored and used at reduced accuracy (approximately 11 km) for safety, service, and anti-theft purposes.
- With consent, precise location may be used for ride history, sharing, statistics, gamification, and related optional features.
- If you change your consent choices, we adjust how existing location data is processed, including by reducing precision where appropriate.
- Before a product is onboarded to an account, LTE transmission is not active, and only limited local technical monitoring applies.
- Ride sessions are private by default. Location and ride details are visible to others only if you choose a public profile and mark a specific ride as public, or share content with approved followers.
8. How we share personal data
We do not sell your personal data. We share personal data only with service providers and partners that help us deliver the Services, under contracts that require appropriate data protection safeguards.
8.1 Categories of recipients
- cloud hosting and infrastructure providers (Amazon Web Services, EU regions);
- LTE connectivity providers (Onomondo ApS, Denmark);
- customer support tools (Zendesk);
- error monitoring providers (Sentry, configured for EU processing without IP address collection);
- messaging providers for rental notifications (Twilio, EU region, and WhatsApp Business API operated by Meta);
- push notification services (Expo);
- mapping and geolocation providers (Mapbox, Google Maps, and MaxMind GeoIP);
- content moderation tools (Amazon Rekognition, EU region, used only for automated moderation without long-term storage of submitted images or biometric processing);
- payment, logistics, and other vendors where needed to complete a transaction or provide support; and
- professional advisers, authorities, or other parties where required by law or to protect rights and safety.
8.2 Rental, charter and partner operations
Where Awake products are used in rental operations, we may send operational notifications to authorised rental centre operators through messaging services. These messages are limited to what is needed for rental operations, such as battery serial numbers and operational alerts. Rental end users should also receive information from the rental centre about local processing.
Where Awake products are operated by indirect end users—such as guests on charter yachts or users at rental centers—we rely on the yacht operator, charter company, or rental partner to inform end users about our data processing prior to use. We require these commercial operators through our terms to make this Privacy Policy accessible to end users.
9. International transfers
We primarily store and process personal data in the European Union. Our core AWS infrastructure, IoT services, primary databases, and content moderation are hosted in EU regions.
Some service providers are located outside the European Economic Area, including in the United States. Where personal data is transferred internationally, we use appropriate safeguards such as the EU-US Data Privacy Framework, EU Standard Contractual Clauses, and supplementary measures identified in our transfer impact assessments.
Current international recipients may include:
- Mapbox, Inc. (United States) for map services. We send map area information rather than precise user coordinates.
- MaxMind, Inc. (United States) for IP-based geolocation through an online service.
- Expo (650 Industries, Inc., United States) for push notification delivery.
- Google LLC (United States), where Google Cloud EMEA contracts apply, and limited processing may occur in the United States.
- Meta Platforms, Inc. (United States) for WhatsApp Business messaging used in rental operations.
You may contact us for more information about international transfers and the safeguards we use.
10. Data retention
We keep personal data only for as long as necessary for the purposes described in this policy, unless a longer period is required by law.
- Account data: kept while your account is active. If you request deletion, we delete or anonymise account data unless retention is required by law. Accounts inactive for two years are deleted automatically after advance notice.
- Precise location and ride data: if your account is inactive for one year, location precision is reduced to approximately 11 km, and ownership links are removed where applicable. After two years of inactivity, links to your account are anonymised, and feed content is deleted.
- Technical battery data linked to you: retained while needed for safety, warranty, service, and account management, then anonymised where possible. Irreversibly anonymised technical data may be kept for analysis and product safety.
- Battery Passport data: retained for the lifetime of the battery where required by law.
- Support tickets: deleted three years after the ticket is closed.
- Messaging logs (Twilio/WhatsApp): retained for 90 days.
- Error monitoring data (Sentry): retained for 90 days.
- Push tokens: deactivated when you log out or delete your account.
- Content moderation images: processed temporarily for moderation and not stored.
- IP addresses for GeoIP and location lookups: processed transiently at the time of request and not stored long-term. Server and network logs containing IP addresses are retained for up to two years solely for security and access control purposes, including incident response and system integrity. Finally, our error monitoring tools (Sentry) are explicitly configured to strip IP addresses prior to storing any diagnostic logs.
- Pre-onboarding technical data: retained for up to five years where linked to an order or owner in direct-sale scenarios to manage inventory and warranty history. Purely unlinked technical diagnostic data collected before onboarding is non-personal and kept in anonymized form.
- Security and access logs: retained for up to two years.
- Backups: deleted from backup systems within our backup cycle, currently seven days.
When you delete your account, we disconnect operational links between you and your product data. Location data is anonymised to reduce precision and personal identifiers are removed, except where we must retain limited information to comply with law or establish, exercise, or defend legal claims.
11. Your rights
Under the GDPR, you have the following rights in relation to your personal data:
- Right of access: to obtain confirmation of processing and a copy of your personal data.
- Right to rectification: to correct inaccurate or incomplete data.
- Right to erasure: to request deletion in certain circumstances.
- Right to restriction: to request that we limit processing in certain circumstances.
- Right to data portability: to receive personal data you provided to us in a structured, commonly used, machine-readable format.
- Right to object: to object to processing based on legitimate interests. Please note that where processing is strictly necessary for critical product safety (e.g., monitoring battery temperature or cell stability to prevent thermal hazards) or anti-theft response as described in Section 7, our compelling legitimate grounds may override an objection request.
- Right to withdraw consent: where processing is based on consent.
You can exercise many of these rights in the Awake Link app, including account deletion and data export. You can also contact us at privacy@awakeboards.com. We may need to verify your identity before responding.
We respond to requests within one month, unless an extension is permitted by law. If we cannot fulfil a request in full, for example because of legal obligations or safety requirements, we will explain why.
You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Danish Data Protection Agency (Datatilsynet): www.datatilsynet.dk.
12. Security
We use technical and organisational measures designed to protect personal data, including encryption in transit, access controls, secure development practices, logging, and contractual safeguards with service providers. No method of transmission or storage is completely secure, but we work to reduce risk to an appropriate level.
13. Children
Our Services are intended for general audiences. Users under 16 years of age may only use Awake products, batteries, and the Awake Link app under the supervision and with the explicit consent of a parent or legal guardian.
Where products are used in rental settings involving minors, we limit data collection to what is strictly necessary and rely on rental partners to ensure appropriate parental consent is obtained. Parents or guardians may contact us at privacy@awakeboards.com to exercise data rights on behalf of a minor.
14. Automated decision-making and profiling
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. Automated tools may be used for technical functions such as content moderation or safety monitoring, but these do not make decisions about your legal or similarly significant status.
15. Changes to this policy
We may update this Privacy Policy from time to time. The current version will always be published on our website with the effective date shown at the top. If we make material changes, we will provide additional notice where required by law.
16. More information
For questions about this Privacy Policy or our processing of personal data, contact privacy@awakeboards.com.