ENSEK's Public Privacy Notice

ENSEK GENERAL PRIVACY NOTICE (2026-07-30 V4.0)

 

This document is our privacy notice with respect to personal data we process concerning client and marketing contacts, office and website visitors, users of our products and services, and customers of our clients.



1. INTRODUCTION

1.1 Publisher

This is a privacy notice published by ENSEK Ltd.

We are a company registered in England and Wales (part of the UK), with company number 07167027 and registered office at Hounds Gate, 30-34 Hounds Gate, Nottingham, England, NG1 7AB. This is also our postal address and head office.

Our website is at https://ensek.com/.

We have a data protection officer, who can be contacted at dataprotection@ensek.co.uk.

We are registered with the UK Information Commissioner's Office with registered number ZA058283.

1.2 Data Subjects

This privacy notice is for those categories of data subjects who are not covered by our other privacy notices.

It is addressed in particular to the categories listed in Section 2 below.

1.3 Data Subjects As Processor

Note that we are controller in some cases and processor in others.

We process personal data on behalf of other businesses and organisations as part of our cloud and other services.

Those clients may contract direct with us, or we may partner with a third party reseller to resell our products and services of their clients, in which case we would be a sub-processor.

References in this notice to our "clients" include controllers we directly contract with as processor and controllers for whom we are a sub-processor (e.g. clients of our reseller partners).

Your rights as data subject should be exercised against the client, who will contact us if we need to be involved or support.

1.4 Other Notices

This notice does not cover our data subjects in the following capacities: (a) employees; (b) job candidates; (c) job applicants; and (d) contractors.

We have a privacy notice for employees, which is published internally only.

We have a privacy notice for job candidates and job applicants, which is published internally and published on our website.

We have a privacy notice for our contractors and their workers, which is published internally and published on our website.

If you are an individual who is using any home energy management app directly under an arrangement with us, then a separate published privacy policy applies to that app and is published in that app.

1.5 Any Questions?

If you have any questions, please contact our Data Protection Officer through the contact details above in this notice.


2. WHO ARE THE DATA SUBJECTS THIS NOTICE IS ADDRESSED TO?

2.1 Data Subjects As Controller

These are our data subjects for the purposes of this notice where we are acting as controller.

Contacts - Marketing & Enquiries

  • Individuals who make a sales or other enquiry with us, whether for themselves or on behalf of a potential client or other business; including by submitting a contact or request form through our website.
  • Individuals we may identify as a contact for a business that we would like to approach to become a client of ours.
  • Individuals who consent to receive any marketing communications from us.

Contacts - Clients

Individuals who are contacts for our clients (or of any client of a reseller partner).

Contacts - Other

  • Individuals who are contacts for other third parties we may deal with, such as suppliers, industry bodies, group companies, and partners.
  • Contractors include development companies, professional services companies, and software and system suppliers.

Visitors

  • Individuals who visit and browse our website.
  • Individuals who visit our offices or attend meetings we arrange.
  • Individuals who join any video or audio conference call that we may set up.

Client Customers

  • Individuals who are customers of our clients, whose data is processed by us in our services, SaaS systems and apps.
  • We hold this data as processor principally, as detailed in Section 2.2.
  • As controller, we may also process your data in respect of EV vehicles, because our systems are operating in a chain of messaging and other processing between your vehicle and the manufacturers' systems, and manufacturers require that we act as controller for our role in that processing.
  • As controller, we may also process your data that consists of enquiries and complaints made to our clients (including calls, chats, messages, and logs) for the purposes of using that data to: (a) learn from; (b) develop and improve our products and services; and (c) help our clients in improving their responses to types of enquiries and complaints.

Client Complainants

  • Individuals who may make enquiries or complaints to our clients, but are not a customer of our clients, where that enquiry or complaint is processed in or using our systems.
  • We hold this data principally as processor for our clients, as detailed in the next section.
  • As controller, we may also process your data that consists of such enquiries and complaints made to our clients (including calls, chats, messages, and logs) for the purposes of using that data to: (a) learn from; (b) develop and improve our products and services; and (c) help our clients in improving their responses to types of enquiries and complaints.

Client User Agents

  • Individuals who are employed or engaged by our clients to use our SaaS systems on behalf of our clients, such as where you have a user account in our SaaS systems; and they may be referred to as users or agents.
  • Individuals who are given a log-in or account to any system of ours, such as individuals given access to our product help system or SaaS systems or support ticket system.
  • Individuals who are given a sharing link to access any resources on any system of ours, including SharePoint files, or a user interface testing service.
  • These individuals are mainly staff and workers of our clients who are using our systems.
  • We hold this data principally as processor for our clients.
  • As controller, we may use logs of your system usage for security and protection of privacy, and incident and system administration related purposes.
  • As controller we may obtain and use feedback from you to improve our products and services.

2.2 Data Subjects As Processor

These are data subjects for the purposes of this notice where we are acting as processor. The controllers noted below should issue or publish their own privacy notices to you in this respect.

Client Customers

  • Individuals who are customers of our clients whose data is processed in our services, SaaS systems and apps.
  • For example: (a) energy supply customers of energy suppliers; (b) owners of electric vehicles that connect to our SaaS systems; (c) occupiers of houses that use our systems to monitor and manage home energy devices such as solar panels, batteries, inverters and connected energy consuming devices
  • We hold this data principally as processor for our clients in connection with their energy supply and other business data processing needs, and the controller is the client that ultimately supplies you with energy or supplies you with our services or apps.

Client Complainants

  • Individuals who may make enquiries or complaints to our clients, where that enquiry or complaint is processed by them in our SaaS applications.
  • We hold this data principally as processor for our clients, and the controller is the client business you are enquiring with or complaining to.

Client Broker Contacts

Individuals who are contacts of energy or other brokers or intermediaries who work with out clients, whose contact details are recorded in our SaaS systems.

Client Users / Agents

Individuals who are employed or engaged by our clients to use our SaaS systems on behalf of those clients; such as where they have a user account in our SaaS systems.


3. WHAT THIS THIS PRIVACY NOTICE ABOUT?

3.1 Scope

This privacy notice explains what personal data we hold about you, how we collect it, how we use it, who we share it with, and what your rights are.

We are required to notify you of this information, under data protection laws.

Set out below are some general points to note before reading further.

3.2 What is the applicable law?

This document is a privacy notice is published primarily to comply with Article 13 and Article 14 of the UK GDPR, as updated by the UK Data (Use And Access) Act 2025.

You can find out more information through the useful links section of this document.

3.3 What is our commitment as controller?

This sub-section sets out our commitments where we are controller of your data.

We are ultimately responsible for the processing of your data.

We are committed to complying with our legal obligations as controller of your personal data, and to transparency about what we use your data for.

Our legal obligations are principally set out in: (a) the UK GDPR; (b) the Data Protection Act 2018 (supplements the UK GDPR); and (c) the Data (Use And Access) Act 2025.

We comply with the data protection principles in the UK GDPR when gathering and using personal data.

We seek to ensure that our collection and processing of your personal data is proportionate.

We will inform you of any material changes to our processing of your personal data through updates to this policy.

3.4 What is our commitment as processor?

This sub-section sets out our commitments where we are a processor or sub-processor of your personal data.

A processor of your data is the person who is processing data on behalf of the controller.

We are committed to complying with our legal obligations as processor of your personal data, and to transparency about our processing of your personal data.

Our legal obligations are set out in: (a) the UK GDPR; (b) the Data Protection Act 2018 (supplements the UK GDPR); and (c) the Data (Use And Access) Act 2025.

Our main obligations are to keep your data secure, and only to process it in accordance with the instructions or permissions of the controller (e.g. our clients).


4. WHAT CATEGORIES OF PERSONAL DATA DO WE PROCESS?

This section lists the key categories of personal data we may process relating to you.

4.1 Client, Marketing & Other Contacts

This is the key personal data we may record about you if you are a contact for a client or other business or organisation.

Name

Your name.

Organisation

  • The organisation you represent.
  • The name of any company or other organisation you are representing or work for.

Role

Your role or job title within the business you work for or in relation to the business you are representing.

Email Address

  • Your email address.
  • It may be a work or private email address depending on what is supplied or available.

Phone

Your telephone number supplied to us, and/or any public telephone number published by any company or organisation you represent.

Relationship

Your relationship with us, such as whether you are a client, potential sales opportunity, supplier, visitor or other.

Web Forms

The contents of any website forms you complete and submit,.

Emails

The contents of all emails which we exchange with you.

Messages

The contents of all messages and chats we exchange with you.

Calls & Meetings

  • The details of, contents of, screenshots from, recordings of, and transcripts from any calls (audio or video) we have with you.
  • Your image and voice may be captured if you allow your video feed or audio to feature in any video call or conference we arrange and record.

Communications

Records and minutes of all communications, meeting, enquiries, complaints, feedback and responses exchanged between us.

Consents

Records of your consents to receive any newsletters or other messages from us.

Feedback

Any feedback you provide concerning us or our products and services.

4.2 Office Visitors

This is the key personal data that we may record about you if you visit our offices.

Name

Your name.

Organisation

The organisation you represent.

Entry & Exit Times

  • Your times of entry and exit from the offices.
  • If you are assigned an access card to use any of our offices, the times of your entry and exit will be captured automatically.

Purpose of Visit

The purpose of your visit and who you are meeting with.

CCTV

  • You may be captured on CCTV if you visit our premises.
  • There is CCTV located in the main building reception and the car park. It is owned and operated by the landlords of the building.
  • There is CCTV located in our communications room, where our networking and other equipment is located. This is owned and operated by ourselves.

Access Card Detials

Records of any access card assigned to you.

Access Card Photograph

We may take and use a photograph of you for card access.

4.3 Website Visitors

This is key personal data we may record about you if you are a general visitor to our website, but it will normally be held anonymously.

Website Usage Information

  • We capture and record information about visits to our website, and our cookies notice gives further information on this.
  • This may include when you visited, the IP address you visited from, browser information, your location in the globe, the pages you visited, the parts of the pages you viewed, and server session information concerning any processes you are undertaking through our website.
  • This information may be captured by means of JavaScript, and by cookies or other local browser storage technologies, which are detailed further in our cookies notice.
  • This is not recorded against you personally, and is stored and used in an anonymous form, except that if you are added to our marketing database HubSpot, the information may be linked to you at that point.

4.4 System Users / Client User Agents

This is key personal data we may record about you if you are a user of any of our products or systems or given access to any files or folders in our systems. This includes data subjects who are client customers, client complainants, client brokers, and client user agents.

Name

Your name.

Organisation

  • The organisation you represent.
  • The name of any company or other organisation you are representing or work for.

Role

Your role within the business you work for or in relation to the business you are representing.

Email Address

Your email address, which will normally be a work email.

Account

Details of any user account granted to you, including log-in details, for any of our products, environments or systems.

Access Permissions

Details of any access permissions and sharing links granted to you in respect of any of our products, environments, systems, files or folders.

Access Logs

Logs of your access to and use of your systems and files, and activities in those systems or with those files; including when you logged in and out; API calls; what activities you carried out, and what files you viewed, downloaded and edited.

Product Usage Information

  • Your visits to the web based user interfaces and API interfaces for our products and systems.
  • Data includes: (a) page views, browser name, browser version, server name; (b) first visit, last visit, sample group, client you work for, language, your user roles and permissions, number of days active, average usage per day, total usage time, usage trend, quantity of events, page usage time, feature clicks and API call history.

Task Audit Information

If you are given user rights to effect any changes or actions in our products or other systems, then we may record and store audit information that links you to the activities and tasks you undertook in our products and systems.

Product Testing

  • If you are asked to participate in any user interface, user feedback or other product testing and feedback activities then me may capture and store information concerning that testing and the results of any testing and feedback.
  • This include: (a) how you interacted with user interface designs; and (b) audio, written or visual feedback you provide on user interface designs.

General Feedback

Records of any feedback you provided in connection with our products and systems, including as recorded through meetings, video calls, and other communications and messages; and any shared with us by our clients.

4.5 As Controller - Client Customer Enquiries and Complaints

This is key personal data we may record about you if you are a customer or other individual making a call to our clients (such as an enquiry or complaint by email, chat, telephone or other method).

Core Details:

 

Name

Your name.

Call Details:

 

Account Link

A number or other identifier to link to a customer's account with our products and systems.

Date of Call

Date & timestamp of contact call to client.

Category

Category of query; e.g., tariff enquiry, problem with bill, moving home etc.

Reason for Call

What was the reason for the call?

Handle Time

Agent handle time

Complaint?

Was the contact logged as a complaint?

Quality Metrics

Quality metrics, e.g. CSAT, FCR, or other markers of successful resolution

Channel

Contact channel (chat/phone/email/other)

Full Transcripts

Transcript (with sensitive info redacted), and including agent responses.

AI Reason Analysis

AI analysis of the call to give a view as to why the call happened.

4.6 As Processor - Client Customers & Complainants

This is key personal data we may record about you as processor for our clients.

Name

Your name.

Contact Data

Your address and contact details, including address of any energy supply or to which any home energy management services are provided.

Vulnerability Data

Data relating to any vulnerabilities at your home that need to be accounted for, such as under the UK Priority Services Register.

Contract Data

Data relating to any contract with our client, such as a contract for the supply of electricity or gas, and any moves.

Device Data

Data relating to meters, electric vehicles, solar panels, batteries, inverters and home devices.

Consumption and Export Data

Data relating to consumption, charging, export and generation associated with your devices.

Billing & Payment Data

Data relating to billing, charges, statements, payments and debt (and associated litigation and repayments) relating to you.

Calls, Contacts and Complaints

Data relating to calls, contacts and complaints you make to a client, and any subject access requests you make to a client.

Industry

Data relating to industry related activities relating to you connected with the clients, such as change of energy supplier or submission of meter readings.


5. HOW DO WE OBTAIN YOUR DATA?

This section sets out how we obtain your data, including from you and other sources.

From Forms You Complete

We obtain it from forms you complete, including any general enquiries, sales, media contacts, demo requests forms on our website, any newsletter sign-up, any surveys or interviews your participate in, and any testing web pages you participate in.

From Your Documents

From files and documents you provide to us, and emails and messages you send, and from your public LinkedIn account.

From Conversation With You

We obtain it from conversation with you, which may include phone calls and video calls, emails, and instant messaging.

From Your Devices

From your energy devices (such as meters, batteries, inverters, electric vehicles) that you enable to be connected to our SaaS systems.

From Your Web Browser and Email Client

  • From data automatically supplied by your web browser.
  • From data we collect through your browser by means of cookies, JavaScripts and other technologies.
  • From tracking images downloaded in our marketing emails, that capture when the email was opened and whether you clicked on links in it.

From Our SaaS Systems

  • From any data you or our clients input into any customer facing portals or user agent facing interfaces provided by our SaaS systems.
  • Where we are collecting analytics concerning usage of our SaaS systems by staff of our client or our own staff, we will again collect data from your web browser (including on any work or personal equipment you use to access our systems) and we may also collect data from events in our SaaS system that are associated with your user account.

From Our Back Office Systems

Where you are provided with a link to any back office system, file sharing service or other resource of ENSEK, that system may monitor and log your access, viewing, downloading or other use of that resource.

From Our Clients

From our clients, either through: (a) user agent input into our SaaS system user interfaces; (b) from file uploads and sharing; (c) from data supplied through calls to APIs to our SaaS systems.

From Integrations

From integrations we host on behalf of our clients with third party systems, such as energy industry systems, payment processors, smart meter systems, home and business premises device connectivity services, and electric vehicle manufacturers.

From Our Own Research

From research we do of publicly available data, including through internet searches or AI searches.


6. WHAT IS OUR LAWFUL BASIS FOR PROCESSING YOUR DATA??

To be able to process your data we need to have a lawful basis for doing so under the law.

This section sets out the types of lawful basis we use, and the next section gives some specific (non-exhaustive) examples against each purpose of use.

Sales

To enter into or perform a contract for the supply of services with you or the business or organisation you represent.

Legal Obligation

To comply with a legal obligation or exercise a legal right.

Our Legitimate Interests

  • We do so for our "legitimate interests".
  • This is flexible ground, and is a balance between ENSEK's interests and your own.
  • It requires a judgement on our part, but is typically doing something you would normally expect, or there is a compelling justification.
  • You have a right to object if you don't agree with our judgement (see later in this notice), and we must stop if it is clear you have overriding reasons for asking us to stop.
  • Most of our processing would fall within legitimate interests.
  • Examples of legitimate interests include: (a) to administer, operate and grow our business; (b) to operate a proper and secure procurement process; (c) verification of identity and address; (d) assessment of suitability; (e) security checks; (f) making informed decisions; (g) negotiating and enforcing contracts; (h) managing the supply of services to us and monitoring that it is in accordance with the contract; (i) monitoring use of our networks, systems, and offices; (j) performing our contractual commitments with our clients; (k) securing work and services outputs; (l) financing and insuring our business; (m) developing and improving our software and services; (n) training individuals working for or with us; (o) operating to public and contractual standards; (p) have sufficient competent personnel, and supporting personnel; (q) complying with legislation, regulations, or mandatory industry codes; (r) bringing or defending legal claims; (s) maintaining reasonable records and evidence; and (t) operating ENSEK's reasonable business policies.

Special Category Data

  • We do not process any data concerning your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetics, biometrics, health, or sex life or sexual orientation.
  • However, we may process dietary information where we are providing any food.

Security

  • We may process your data for the purposes of ensure the security of our network and information systems; for example for network monitoring, access monitoring, data loss prevention, and enforcement of security and privacy policies and standards.
  • This is expressly recognised now as a lawful basis of processing under the Data (Use And Access) Act 2025.

Intragroup data

We may process your data for the purposes intra-group data transfers for group administration purposes.

Your Interests

  • We need to do so, to protect you vital interests.
  • This could include care for your health and safety.

Your Consent

  • If the above do not apply, we would need to get your consent to the specific use.
  • This could be an explicit documented consent, or it could be implicit because you have requested some action to be taken involving your data.

Our Clients

Where we are acting as processor, the lawful basis will be a matter for our clients, but is typically processing in connection with the supply of electricity or gas to you, or in connection with their resale of our home and EV energy management and optimisation services to you.


7. WHAT PURPOSES DO WE PROCESS YOUR DATA FOR?

This part sets out the key purposes we use your data for and the associated lawful basis.

PURPOSE

DESCRIPTION

EXAMPLES

LAWFUL BASIS

Audits

To carry out audits of our business and to enable third parties to audit our business and controls, including audits under ISO 27001 & ISO 27701, audits under the UK Smart Energy Code and other industry codes, and SOC (Service Organisation Controls) audits.

Providing evidence (which may include your personal data) to demonstrate the operation of ENSEK's policies and controls in the business (such as performance reviews, access logs).

Legitimate Interest = To operate our business to a good standard and provide assurance of this to clients and other third parties we deal with.

Client SaaS Services

To provide our SaaS products and services to our clients, and the processing of your personal data that is inherently part of those services.

  • For energy supply customers, we process a large range of data relating to your energy supply, including your supply contract details, your contact details, your meter and address details, your meter readings, your prices, bills and payments, your debt, and complaints.
  • For home energy customers, we process a large range of data relating to your home energy devices and electric vehicles, including your contact details, your home details, your home devices and vehicles, consumption and export information, your solar panels, battery, and inverter, your energy rates, battery and EV charging information, and consumption and export models of behaviour.

Legitimate Interest = Providing our products and services to our clients, who will define their own lawful basis to you.

Client Relations Management

To manage our relationship with our clients.

  • Communications relating to our products, services, and relationship.
  • Meetings with you, including remotely by video / auditor.
  • Up-selling new features.
  • Client account management, contract management, support, and delivery purposes, to deal with matters arising in relation to a service contract with us, and to deliver on the service contract with us.
  • Legitimate Interest = Management of good relations with our clients and enabling our clients to successfully use our products and services.
  • Contract = To perform and manage a contract between you and us, or between the company or organisation you work for and us.
  • Legitimate Interest = We would not be able to manage our contracts properly without being able to contract our client or other party to the contract.

Enquiry Follow-Up

To follow-up on enquiries or requests you made, including any follow-up sales processes.

  • Telephoning or emailing you following an enquiry by you.
  • Arranging meetings and video conferences with you.
  • Providing a demonstration to you.
  • Pursuing a sales process with you.
  • Preparing and signing an NDA or heads of terms for a sale discussion or proposed contracts.
  • Providing information you have requested.
  • Legitimate Interest = We are responding to an enquiry you made, as you would expect, and you have implicitly requested our response by submitting your form.
  • Legitimate interest = Acquiring new clients for and retaining clients for our products and services.

Marketing

To market our products to you or to the business or organisation you represent or work for.

  • Email marketing messages.
  • Linked-in campaigns.
  • Consent = We will have asked for your consent, including in any website forms.
  • Legitimate Interest = Finding new clients for our products and services and growing our business.

Newsletter

Where you have signed-up, we will use your data to send to our regular newsletter until you ask us to stop.

Client update newsletters.

  • Consent = We will have asked for your consent, including in any website forms.
  • Legitimate Interest = Client relations and updating our clients as to our products and services.

Security Monitoring

  • To monitor our systems for misuse and unauthorised access.
  • To monitor our offices for misuse and unauthorised access.
  • Logging your access to and use of our systems, and tasks and activities you carry out in our systems.
  • We use CCTV to monitor access to our offices and secure areas in our offices.
  • To check if any unauthorised persons are accessing our systems, and to verify that our systems are being used correctly.
  • Legitimate Interest = Protecting the security of our systems and data and the privacy of data on them, and to protect against fraud.
  • Legitimate Interest = Protecting the confidentiality, integrity and availability of all data we handle.
  • Legitimate Interest = Protecting the security of our information, property and assets, and to detect and evidence any wrong-doing.
  • Legitimate Interest = To protect the rights interests of our clients' in relation to their data you may have access to.

Visit & Event Management

To manage your visits with us and your attendance at any events with us.

  • Arranging and administering face-to-face meetings and visits, and virtual meetings through videos.
  • Managing dietary requirements.
  • Legitimate Interest = To be able to manage the day to day operation of our business effectively, and know who we are dealing with.
  • Legitimate Interest = Ensuring that you have the correct dietary food where we are providing any food.

System Management

  • To monitor and manage the performance of our SaaS products and systems, including identifying issues affecting availability and errors.
  • To be able to manage access to and use of the systems you are given access to.
  • To monitor all API calls, errors, usage and other operational metrics and data flows relating to our systems.
  • To be able to give you the access intended.
  • To authenticate and authorise your access, and revoke your access.
  • To communicate with you about your access.
  • Legitimate Interest = Providing our products and services.
  • Contract = To perform a contract with a client whom you work for.

Product & Services Improvement

  • To develop and improve our products and services.
  • To support our clients in improving their handling of your calls, enquiries and complaints, and in reducing the need for such calls, enquiries and complaints.

Our main products are SaaS products, which are accessed by our clients using a web user interface. The quality of that user interface determines how well and efficiently our clients and their staff are able to use our products. We therefore, as with a web site, we seek to capture information about how our SaaS products and their interfaces are used by our staff, which we then use to consider and improve the design of our products and the user guidance we provide.

Legitimate interest = To be able to improve our products. Contract - To be able to deliver SaaS products that meet the standards expected by our clients in their contracts with us.

Website Improvement

To assess the use of our website and improve it so that it is visited and used more, and has better rankings in search engines, and provides a better outcome for our visitors

Capturing how many unique visitors there are and how often they are visiting and which parts of the site are used most.

Legitimate Interest = To be able to promote and grow our business through an effective and relevant website.


8. WHO DO WE SHARE YOUR DATA WITH?

This section details who we may share your information with. We will normally share in confidence unless the law requires otherwise

8.1 Auditors

We may share your personal data with any third party that is auditing our business and controls, including our security measures and operational controls, for the purposes of evidence, but only to the extent reasonably required for such evidence.

It will be shared securely, and under a non-disclosure agreement; and is shared normally to the auditors secure evidence repository.

They use it as ENSEK's sub-processor, to provide audit services to ENSEK.

They may retain this in archive for up to 7 years, as evidence of the audit services provided.

8.2 Cloud System Providers

We may share your data with our systems providers, through putting your data into any cloud systems that we procure, as part of their hosting of those systems; but they are not expected to access or use it, except for technical support purposes; and your data otherwise resides on and is processed in those systems as part of their cloud service, and is encrypted at rest.

They will receive it as ENSEK's sub-processor.

They will retain data in the system according to our retention policy.

8.3 Our Clients

We may share any feedback information, support ticket information, and information concerning your use of our systems with your employer / the company you work for, for the purposes of assessing our software and performance, and audit, logging and investigation purposes.

They will receive it as a controller, and not our processor.

They will retain data in the system according to their retention policy.


9. WHERE DO WE KEEP YOUR DATA?

9.1 Introduction

Your data is kept in the systems referred to below.

Some useful links are provided at the end of this privacy notice.

We no longer keep any paper records and all of your data is created, stored, and retained electronically.

9.2 General Aim

We aim to store and process your data in data centres in the UK or European Economic Area.

Exceptionally your data may be processed in the USA or other countries, and in such case we follow EU and UK rules for data transfers.

We accesses these systems from networks and staff located in the UK, and from contractors located in the UK and EEA.

9.3 Marketing and Client CRM

We host our website and manage our marketing and customer relationship database, contacts, enquiries and forms in a CRM service (currently Hubspot)

9.4 Office Systems

We use a range of internal office systems, applications, and cloud services for a range of internal business data processing needs, including: (a) file storage; (b) file sharing; (c) databases; (d) email; (e) messaging; (f) document creation and editing; (g) software development; (h) work task management; (i) reporting; and (j) chats.

Your personal data may appear in these systems in various forms as appropriate for use connected with the purposes for which we are processing your data.

We specify the UK or EEA for hosting where possible.

9.5 SaaS Systems

If you are a client data subject (such as a user agent, client customer, or broker contact), your personal data will be stored and processed in our SaaS products and as part of our client services; such as our Ignition Energy Orchestration Platform, and our Flex Home Energy Management product, and their associated databases.

These are hosted in Amazon Web Services and Google Cloud in the UK and EEA.

9.6 SaaS Product Analytics

We may capture data about your use of our SaaS products in the databases of those products or in other analytics cloud services we use (such as Data Dog, Full Story and Useberry).

We aim to hold that data in pseudo-anonymised form were practicable; such as by hashing identifiers.


10. HOW LONG DO WE KEEP YOUR DATA FOR?

This section covers our retention policy.

10.1 General Principle

Subject to the following cases, we will only use your data for as long as it is required for the purposes for which it is processed, and we will only hold your data for as long as: (a) we need it for the purposes for which it is processed; (b) we need it as an evidence archive for legal claims purposes (for which we set a 7 year time period for retention from when our other purposes of use end).

10.2 CCTV

Landlord CCTV recordings are held for 30 days.

We hold CCTV recordings from internal secure areas for 3 months.

If a recording is needed for evidence in relation to an incident that has happened, we may hold the data for as long as may be reasonably required for that incident, but no more than 7 years.

10.3 Clients

Where we are processor we will use and hold your data according to the instructions of our clients / controllers and their data retention policies.


11. HOW DO WE KEEP YOUR DATA SECURE?

This section covers our security measures.

11.1 General Principle

We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way.

In particular we have the following measures to keep your data secure.

11.2 ISO 27001

We are certified to and aim to keep certified to ISO 27001:2022, which requires us to have a security management system, and to maintain a range of security controls.

11.3 ISO 27701

We are also certified to and aim to keep certified to ISO 27701:2019, which requires us to have a privacy information management system, and to maintain a range of privacy controls.

11.4 SOC Audit

We have our security controls audited independently by an auditor under the SOC (service organisation controls) audit standards.

11.5 Industry Audit

We are subject to some security assessment checks under UK Industry codes such as the Smart Energy Code and the Retail Energy Code.

11.6 Data Breach

We have procedures in place to deal with any suspected data security or privacy breach affecting your data.

We will notify you and any applicable regulator of a suspected data security or privacy breach where we are legally required to do so.

11.7 Other Measures and Controls

The above standards and audits require and examine all our security and privacy measures and controls, which we have in place to protect against unauthorised use, access to, change to, or disclosure of your data, against viruses and other malicious software, and against unauthorised access to our equipment, offices, networks, cloud systems, and databases.

These measures and controls cover areas such as office access controls, equipment log-in, cloud system log-in and associated roles and permissions, network and access monitoring, staff training, management, staff background checks, usage monitoring, anti-virus and other protective software and devices, and data segregation and encryption.

11.8 System Providers

Individual system providers listed in this document have their own separate security and privacy controls with respect to your data in their systems, and we consider these prior to using those systems.

11.9 Cloud First

We operate on a "cloud first" basis, which means that your data is stored in secure and reputable cloud systems, rather than at any offices of ours.

11.10 Access Controls

We limit access to your personal information to those who have a genuine business need to know it.

11.11 Proportionate and Confidentially

Those processing your information will do so only in an authorised and proportionate manner and are subject to a duty of confidentiality.

11.12 Supplier On-Boarding Process

Where your data is processed for us by a supplier (such as in a cloud system we procure), we have a supplier on-boarding process that assesses where your data is held and the security and privacy compliance measures of the supplier.

We aim to use cloud service providers who store your data in data centres in the UK or European Economic Area; but occasionally also the USA and other countries following EU and UK rules for data transfers.


12. WHAT ARE YOUR RIGHTS?

This section covers your rights in relation to our processing of your data.

Introduction

  • You have the following rights in relation to our processing of your personal data, but please note that these rights may be subject to conditions and exceptions set out in the law.
  • If you would like to exercise these rights, please contact our data protection officer.
  • If you are not sure, just email us using our contact details in this document.

Our Service Providers

  • If you ask for the following, we are obliged to pass this request down to the providers of the systems we use and anyone else we use to process your data, as needed.
  • See Article 19 of the UK GDPR.

Right to be informed

  • You have the right to be informed if your data is being used.
  • This document is how we are informing you.
  • See Article 13 and Article 14 of the UK GDPR.

Right to withdraw consent

If any processing is based on your consent, you have the right to withdraw it at any time. Just email using our contact details in this document.

Right to stop direct marketing

You have the right to stop direct marketing at any time.

Right to a copy

  • You have a right to an update of the information in this document.
  • You also have a right to a copy of the personal data we hold about you.
  • You have the right to ask for your data in a computer readable for, so that you can use it elsewhere.

Right to a correction

You have the right to request correction of your data (a right to rectification).

Right to erasure

  • You have the right to request erasure of your data (also known as the right to be forgotten).
  • However, there are a range of exceptions to this, which mean that we do not have to erase your data if there are good reasons for retaining a copy of it.

Right to restriction

  • You have the right to request that we stop using your data for some purposes.
  • There are conditions that apply.
  • This means that we might still hold your data, but we would be stopped from using it for certain purposes.

Right to object to legitimate interests

  • If the legal basis for our using your personal data is a "legitimate interest", or we are using your data to market to you, then you can object to the processing.
  • We must stop the processing, unless we can show that our interests should take precedence over yours.

Automated Decision Making

If we are making important decisions about using a compute, without any human involvement, then you can ask us to stop, subject to conditions.

Right to complain

  • We hope that we can resolve any query or complaint you have about our use of your personal data or your rights.
  • In any case, you have the right to complain to the Information Commissioner at any time.
  • Their details are - Information Commissioners Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF - Helpline number 0303 123 1113 - Website Complaints Page.

13. USEFUL LINKS

Law - UK - Privacy - Data (Use & Access) Act 2025

Contains updates to Data Protection laws in the UK.

Law - UK - Privacy - Data Protection Act 2018

Contains additional rules to support the UK GDPR.

Law - UK - Privacy - GDPR

The UK's version of the European General Data Protection Act.

Law - UK - Privacy - Legal Claims - Limitation Act 1980

Legal limitation periods for bringing a claim in court.

Law - UK - Privacy - PECR

The Privacy and Electronic Communications (EC Directive) Regulations 2003 which cover direct marketing and use of cookies.

Law - UK - Security - Cloud Services - NIS Regs

The Network and Information Systems Regulations 2018 which apply security requirements to operators of important cloud services.

Product - Energy Flexibility - Home Energy Management

Our principal SaaS product and application for home energy management and optimisation; previously branded Zoa.

Product - Ignition - Energy Customer Care & Billing

Our principal SaaS product in which energy customer personal data is processed, which may also be referred to as the Energy Orchestration Platform.

Regulator - UK - Privacy - ICO - Complaints Page

Page for making a complaint to the UK Information Commission.

Regulator - UK - Privacy - ICO - Data Subject Rights Page

ICO page on the rights of data subjects under UK law.

Standards - Global - ISO 27001 - Security

International security controls standard.

Standards - Global - ISO 27701 - Privacy

International personal data management controls standard.

Standards - Global - SOC - ISAE 3402

Auditing standard for auditing of security and operational controls.

System - Airtable

An online database system ENSEK use for ad-hoc database purposes, such as storing user feedback.

System - Amazon Web Services

A hosting platform we use to host and run some of our products.

System - Data Dog

A third party cloud service used to monitor our SaaS products and their performance and availability, which includes monitoring of API calls.

System - Full Story

A cloud service used to generate user interface usage analytics, and record and document how user interfaces are used; used by us to improve and develop our products.

System - Google Cloud

A hosting platform we use to host and run some of our products.

System - Google Workspace

Our back office business applications and cloud tools for email, messaging, calling, and file creation, storage and editing.

System - Hubspot - Website & CRM

A third party cloud service we use to host our websites, and carry out our marketing and client relationship management processing.

System - Microsoft 365 & SharePoint

Our back office business applications and cloud tools for email, messaging, calling, and file creation, storage and editing.

System - Service Now

IT service desk ticketing system for incident management and access requests and other business process management.

System - Slack

An internal and external messaging and teams management system, similar to Microsoft Teams.

System - Useberry

A third party cloud service we use to test user interface designs for our products with users, and to obtain user surveys and feedback; used by us to improve and develop our products.


END OF DOCUMENT