Navvion

Legal

Data Policy

This Data Policy describes how Navvion governs operational and telemetry data from deployed energy storage systems — who can access it, how it is secured, and how it supports service and warranty.

Last updated: July 8, 2026

1. Data we process from assets

Deployed systems generate telemetry such as state of charge, power, temperature, alarms, and health metrics, linked to an asset serial number and site. This data drives monitoring, diagnostics, and warranty evidence.

2. Access control

Access is role-scoped: customers see their own sites, installers and EPCs see assigned projects, and Navvion staff access data on a least-privilege basis. All access to regulated workflows is logged.

3. Security

We align our enterprise controls to recognized frameworks (e.g., NIST CSF) and separate IT cloud, OT edge, EMS, and BMS zones consistent with IEC 62443. Cloud and AI systems recommend and schedule actions; local controllers enforce real-time safety. AI never directly controls safety functions.

4. AI governance

Where AI assists with summaries, triage, or recommendations, it operates within permissions, cites approved sources, and routes high-risk actions to human approval. Prompts, sources, and outputs for regulated workflows are logged.

5. Sub-processors, sharing, and retention

Operational data is shared only with parties assigned to a site — the customer, their installer or EPC, and Navvion service. We also rely on vetted sub-processors, such as cloud hosting and infrastructure providers, that are bound by contract to equivalent security and confidentiality obligations and process data only on our instructions. Data is retained for the asset's service life and warranty period. Governance details, including the current sub-processor list, are available under NDA — contact sales@navvion.com.