SmartBatt Energy Solutions
S
SmartBatt Energy Solutions

Platform Acceptable Use Policy

Internal Ops Console — SmartBatt Staff Only

CONFIDENTIAL — For SmartBatt Employees & Designated Staff Only

Version 1.0 | April 2026 | Confidential — Internal Draftwww.smartbattenergy.com · info@smartbattenergy.com

1. Access Roles & Principles

  • The Ops Console operates on a Role-Based Access Control (RBAC) model. Two access levels exist: ops_admin (standard operations access) and super_admin (full platform access including system configuration).
  • Access is granted based on the principle of least privilege — you will only have the permissions required for your specific role and responsibilities.
  • Access requests and role assignments are managed exclusively by the designated SmartBatt system administrator (currently: Sandeep Sonpatki or Amit Malakar).
  • You must never share your login credentials with any other person, including colleagues.
  • Temporary access for contractors or interns must be time-bound, approved in writing, and revoked immediately upon end of engagement.

2. Permitted Use

You may use the Ops Console only for the following authorised purposes:

  • Fleet monitoring: viewing live and historical device Telemetry Data for all deployed BESS units.
  • Deployment management: creating, updating, and managing client deployments and asset assignments.
  • Client management: viewing and managing client accounts, users, and deployment records.
  • Device configuration: adjusting inverter settings, work modes, and system parameters — only if your role permits.
  • Reporting: generating operational, financial, and sustainability reports for internal use.
  • System administration: managing platform configuration via system_config — super_admin only.

3. Prohibited Activities

  • You must not access, copy, or export data beyond what is necessary for your assigned tasks.
  • You must not modify, delete, or manipulate client data, financial records, Telemetry Data, or audit logs without a documented business reason and approval from a Designated Partner.
  • You must not access the platform from unsecured public networks (e.g., public Wi-Fi) without a VPN or equivalent security control.
  • You must not install, integrate, or test third-party software, APIs, or scripts against the live production environment without explicit written approval.
  • You must not share screenshots, exports, or reports from the Ops Console with external parties (including clients, partners, or vendors) without authorisation.
  • You must not attempt to elevate your own access privileges or bypass RLS policies.
  • You must not access another user's account, even if you have their credentials.

4. Data Handling & Confidentiality

  • All data you access through the Ops Console — including client details, asset financial data, Telemetry Data, revenue reports, and system configuration — is Confidential Information of SmartBatt.
  • You must not retain copies of data on personal devices, personal cloud storage, or personal email accounts.
  • If you need to work with data offline, it must be stored on SmartBatt-approved, password-protected devices.
  • Upon termination of your employment or engagement, all data must be returned or securely deleted, and you must confirm this in writing to SmartBatt.
  • Confidentiality obligations under this AUP survive termination of your employment or engagement by 5 (five) years.

5. Client & Asset Owner Data — Special Obligations

  • Client and Asset Owner data is particularly sensitive. You must process it only for legitimate operational purposes and never for personal benefit.
  • You must not contact clients or asset owners using their Platform-registered contact details for any purpose outside your official SmartBatt duties.
  • Financial data (revenue, earnings, commission) accessed via the Ops Console must be treated as strictly confidential and shared only on a need-to-know basis.
  • You are obligated to report any suspected unauthorised access to client or asset owner data immediately to the Designated Partners.

6. Device Configuration & Control — Safety Protocol

  • Remote device configuration (inverter settings, work modes, SOC thresholds, TOU parameters) must only be executed by authorised technical staff.
  • Configuration changes to live deployed units must be pre-approved by the ops lead or a Designated Partner except in emergency safety situations.
  • All remote configuration actions are logged. Logs must not be altered.
  • In the event of a configuration error causing device fault or client disruption, you must immediately escalate to a Designated Partner regardless of the time.
  • You must not use production device configuration tools for experimentation. A staging/test environment must be used for development and testing purposes.

7. Security Incident Reporting

  • You must report any suspected security breach, data loss, unauthorised access, or system anomaly immediately to info@smartbattenergy.com and directly to Sandeep or Amit.
  • Suspected incidents include: unusual login activity, inability to access the Platform, evidence of data export by unknown parties, phishing attempts, or device control anomalies.
  • You must not attempt to independently investigate or remediate a suspected security incident — escalate immediately.
  • Failure to report a known security incident is a serious policy violation and may result in disciplinary action.

8. Monitoring & Audit

  • SmartBatt reserves the right to monitor, log, and audit all activities conducted on the Ops Console, including login events, data access, queries executed, and configuration changes.
  • You have no expectation of privacy with respect to activities conducted on the Platform in your official capacity.
  • Audit logs are retained for a minimum of 3 (three) years.
  • Periodic access reviews will be conducted to ensure permissions remain appropriate. You are required to cooperate fully with such reviews.

9. Disciplinary Consequences

  • Violations of this AUP may result in: (a) immediate suspension of Platform access, (b) disciplinary action up to and including termination of employment or engagement, and (c) legal action where the violation involves data theft, fraud, or wilful damage.
  • Inadvertent violations must be reported promptly. Self-reporting will be considered a mitigating factor.

10. Acknowledgement & Agreement

By accessing the Ops Console, you acknowledge that you have read, understood, and agree to comply with this Acceptable Use Policy in its entirety. This AUP forms part of your employment or engagement terms with SmartBatt.

Employee / Staff Name: ____________________________

Designation: ____________________________

Signature: ____________________________

Date: ____________________________

Witnessed by (SmartBatt): ____________________________

11. Governing Law

  • This AUP is governed by the laws of India and forms part of your employment/engagement agreement.
  • For queries or clarifications, contact: info@smartbattenergy.com
Version 1.0 | April 2026 | Confidential — Internal DraftSmartBatt Energy Solutions LLP — Confidential