ENSEK GENERAL PRIVACY NOTICE (2026-07-30 V4.0)
This document is our privacy notice with respect to personal data we process concerning client and marketing contacts, office and website visitors, users of our products and services, and customers of our clients.
2. WHO ARE THE DATA SUBJECTS THIS NOTICE IS ADDRESSED TO?
2.1 Data Subjects As Controller
2.2 Data Subjects As Processor
3. WHAT THIS THIS PRIVACY NOTICE ABOUT?
4. WHAT CATEGORIES OF PERSONAL DATA DO WE PROCESS?
4.1 Client, Marketing & Other Contacts
4.4 System Users / Client User Agents
4.5 As Controller - Client Customer Enquiries and Complaints
4.6 As Processor - Client Customers & Complainants
5. HOW DO WE OBTAIN YOUR DATA?
6. WHAT IS OUR LAWFUL BASIS FOR PROCESSING YOUR DATA??
7. WHAT PURPOSES DO WE PROCESS YOUR DATA FOR?
8. WHO DO WE SHARE YOUR DATA WITH?
9. WHERE DO WE KEEP YOUR DATA?
10. HOW LONG DO WE KEEP YOUR DATA FOR?
1. INTRODUCTION
1.1 Publisher
This is a privacy notice published by ENSEK Ltd.
We are a company registered in England and Wales (part of the UK), with company number 07167027 and registered office at Hounds Gate, 30-34 Hounds Gate, Nottingham, England, NG1 7AB. This is also our postal address and head office.
Our website is at https://ensek.com/.
We have a data protection officer, who can be contacted at dataprotection@ensek.co.uk.
We are registered with the UK Information Commissioner's Office with registered number ZA058283.
1.2 Data Subjects
This privacy notice is for those categories of data subjects who are not covered by our other privacy notices.
It is addressed in particular to the categories listed in Section 2 below.
1.3 Data Subjects As Processor
Note that we are controller in some cases and processor in others.
We process personal data on behalf of other businesses and organisations as part of our cloud and other services.
Those clients may contract direct with us, or we may partner with a third party reseller to resell our products and services of their clients, in which case we would be a sub-processor.
References in this notice to our "clients" include controllers we directly contract with as processor and controllers for whom we are a sub-processor (e.g. clients of our reseller partners).
Your rights as data subject should be exercised against the client, who will contact us if we need to be involved or support.
1.4 Other Notices
This notice does not cover our data subjects in the following capacities: (a) employees; (b) job candidates; (c) job applicants; and (d) contractors.
We have a privacy notice for employees, which is published internally only.
We have a privacy notice for job candidates and job applicants, which is published internally and published on our website.
We have a privacy notice for our contractors and their workers, which is published internally and published on our website.
If you are an individual who is using any home energy management app directly under an arrangement with us, then a separate published privacy policy applies to that app and is published in that app.
1.5 Any Questions?
If you have any questions, please contact our Data Protection Officer through the contact details above in this notice.
2. WHO ARE THE DATA SUBJECTS THIS NOTICE IS ADDRESSED TO?
2.1 Data Subjects As Controller
These are our data subjects for the purposes of this notice where we are acting as controller.
|
Contacts - Marketing & Enquiries |
|
|
Contacts - Clients |
Individuals who are contacts for our clients (or of any client of a reseller partner). |
|
Contacts - Other |
|
|
Visitors |
|
|
Client Customers |
|
|
Client Complainants |
|
|
Client User Agents |
|
2.2 Data Subjects As Processor
These are data subjects for the purposes of this notice where we are acting as processor. The controllers noted below should issue or publish their own privacy notices to you in this respect.
|
Client Customers |
|
|
Client Complainants |
|
|
Client Broker Contacts |
Individuals who are contacts of energy or other brokers or intermediaries who work with out clients, whose contact details are recorded in our SaaS systems. |
|
Client Users / Agents |
Individuals who are employed or engaged by our clients to use our SaaS systems on behalf of those clients; such as where they have a user account in our SaaS systems. |
3. WHAT THIS THIS PRIVACY NOTICE ABOUT?
3.1 Scope
This privacy notice explains what personal data we hold about you, how we collect it, how we use it, who we share it with, and what your rights are.
We are required to notify you of this information, under data protection laws.
Set out below are some general points to note before reading further.
3.2 What is the applicable law?
This document is a privacy notice is published primarily to comply with Article 13 and Article 14 of the UK GDPR, as updated by the UK Data (Use And Access) Act 2025.
You can find out more information through the useful links section of this document.
3.3 What is our commitment as controller?
This sub-section sets out our commitments where we are controller of your data.
We are ultimately responsible for the processing of your data.
We are committed to complying with our legal obligations as controller of your personal data, and to transparency about what we use your data for.
Our legal obligations are principally set out in: (a) the UK GDPR; (b) the Data Protection Act 2018 (supplements the UK GDPR); and (c) the Data (Use And Access) Act 2025.
We comply with the data protection principles in the UK GDPR when gathering and using personal data.
We seek to ensure that our collection and processing of your personal data is proportionate.
We will inform you of any material changes to our processing of your personal data through updates to this policy.
3.4 What is our commitment as processor?
This sub-section sets out our commitments where we are a processor or sub-processor of your personal data.
A processor of your data is the person who is processing data on behalf of the controller.
We are committed to complying with our legal obligations as processor of your personal data, and to transparency about our processing of your personal data.
Our legal obligations are set out in: (a) the UK GDPR; (b) the Data Protection Act 2018 (supplements the UK GDPR); and (c) the Data (Use And Access) Act 2025.
Our main obligations are to keep your data secure, and only to process it in accordance with the instructions or permissions of the controller (e.g. our clients).
4. WHAT CATEGORIES OF PERSONAL DATA DO WE PROCESS?
This section lists the key categories of personal data we may process relating to you.
4.1 Client, Marketing & Other Contacts
This is the key personal data we may record about you if you are a contact for a client or other business or organisation.
|
Name |
Your name. |
|
Organisation |
|
|
Role |
Your role or job title within the business you work for or in relation to the business you are representing. |
|
Email Address |
|
|
Phone |
Your telephone number supplied to us, and/or any public telephone number published by any company or organisation you represent. |
|
Relationship |
Your relationship with us, such as whether you are a client, potential sales opportunity, supplier, visitor or other. |
|
Web Forms |
The contents of any website forms you complete and submit,. |
|
Emails |
The contents of all emails which we exchange with you. |
|
Messages |
The contents of all messages and chats we exchange with you. |
|
Calls & Meetings |
|
|
Communications |
Records and minutes of all communications, meeting, enquiries, complaints, feedback and responses exchanged between us. |
|
Consents |
Records of your consents to receive any newsletters or other messages from us. |
|
Feedback |
Any feedback you provide concerning us or our products and services. |
4.2 Office Visitors
This is the key personal data that we may record about you if you visit our offices.
|
Name |
Your name. |
|
Organisation |
The organisation you represent. |
|
Entry & Exit Times |
|
|
Purpose of Visit |
The purpose of your visit and who you are meeting with. |
|
CCTV |
|
|
Access Card Detials |
Records of any access card assigned to you. |
|
Access Card Photograph |
We may take and use a photograph of you for card access. |
4.3 Website Visitors
This is key personal data we may record about you if you are a general visitor to our website, but it will normally be held anonymously.
|
Website Usage Information |
|
4.4 System Users / Client User Agents
This is key personal data we may record about you if you are a user of any of our products or systems or given access to any files or folders in our systems. This includes data subjects who are client customers, client complainants, client brokers, and client user agents.
|
Name |
Your name. |
|
Organisation |
|
|
Role |
Your role within the business you work for or in relation to the business you are representing. |
|
Email Address |
Your email address, which will normally be a work email. |
|
Account |
Details of any user account granted to you, including log-in details, for any of our products, environments or systems. |
|
Access Permissions |
Details of any access permissions and sharing links granted to you in respect of any of our products, environments, systems, files or folders. |
|
Access Logs |
Logs of your access to and use of your systems and files, and activities in those systems or with those files; including when you logged in and out; API calls; what activities you carried out, and what files you viewed, downloaded and edited. |
|
Product Usage Information |
|
|
Task Audit Information |
If you are given user rights to effect any changes or actions in our products or other systems, then we may record and store audit information that links you to the activities and tasks you undertook in our products and systems. |
|
Product Testing |
|
|
General Feedback |
Records of any feedback you provided in connection with our products and systems, including as recorded through meetings, video calls, and other communications and messages; and any shared with us by our clients. |
4.5 As Controller - Client Customer Enquiries and Complaints
This is key personal data we may record about you if you are a customer or other individual making a call to our clients (such as an enquiry or complaint by email, chat, telephone or other method).
|
Core Details: |
|
|
Name |
Your name. |
|
Call Details: |
|
|
Account Link |
A number or other identifier to link to a customer's account with our products and systems. |
|
Date of Call |
Date & timestamp of contact call to client. |
|
Category |
Category of query; e.g., tariff enquiry, problem with bill, moving home etc. |
|
Reason for Call |
What was the reason for the call? |
|
Handle Time |
Agent handle time |
|
Complaint? |
Was the contact logged as a complaint? |
|
Quality Metrics |
Quality metrics, e.g. CSAT, FCR, or other markers of successful resolution |
|
Channel |
Contact channel (chat/phone/email/other) |
|
Full Transcripts |
Transcript (with sensitive info redacted), and including agent responses. |
|
AI Reason Analysis |
AI analysis of the call to give a view as to why the call happened. |
4.6 As Processor - Client Customers & Complainants
This is key personal data we may record about you as processor for our clients.
|
Name |
Your name. |
|
Contact Data |
Your address and contact details, including address of any energy supply or to which any home energy management services are provided. |
|
Vulnerability Data |
Data relating to any vulnerabilities at your home that need to be accounted for, such as under the UK Priority Services Register. |
|
Contract Data |
Data relating to any contract with our client, such as a contract for the supply of electricity or gas, and any moves. |
|
Device Data |
Data relating to meters, electric vehicles, solar panels, batteries, inverters and home devices. |
|
Consumption and Export Data |
Data relating to consumption, charging, export and generation associated with your devices. |
|
Billing & Payment Data |
Data relating to billing, charges, statements, payments and debt (and associated litigation and repayments) relating to you. |
|
Calls, Contacts and Complaints |
Data relating to calls, contacts and complaints you make to a client, and any subject access requests you make to a client. |
|
Industry |
Data relating to industry related activities relating to you connected with the clients, such as change of energy supplier or submission of meter readings. |
5. HOW DO WE OBTAIN YOUR DATA?
This section sets out how we obtain your data, including from you and other sources.
|
From Forms You Complete |
We obtain it from forms you complete, including any general enquiries, sales, media contacts, demo requests forms on our website, any newsletter sign-up, any surveys or interviews your participate in, and any testing web pages you participate in. |
|
From Your Documents |
From files and documents you provide to us, and emails and messages you send, and from your public LinkedIn account. |
|
From Conversation With You |
We obtain it from conversation with you, which may include phone calls and video calls, emails, and instant messaging. |
|
From Your Devices |
From your energy devices (such as meters, batteries, inverters, electric vehicles) that you enable to be connected to our SaaS systems. |
|
From Your Web Browser and Email Client |
|
|
From Our SaaS Systems |
|
|
From Our Back Office Systems |
Where you are provided with a link to any back office system, file sharing service or other resource of ENSEK, that system may monitor and log your access, viewing, downloading or other use of that resource. |
|
From Our Clients |
From our clients, either through: (a) user agent input into our SaaS system user interfaces; (b) from file uploads and sharing; (c) from data supplied through calls to APIs to our SaaS systems. |
|
From Integrations |
From integrations we host on behalf of our clients with third party systems, such as energy industry systems, payment processors, smart meter systems, home and business premises device connectivity services, and electric vehicle manufacturers. |
|
From Our Own Research |
From research we do of publicly available data, including through internet searches or AI searches. |
6. WHAT IS OUR LAWFUL BASIS FOR PROCESSING YOUR DATA??
To be able to process your data we need to have a lawful basis for doing so under the law.
This section sets out the types of lawful basis we use, and the next section gives some specific (non-exhaustive) examples against each purpose of use.
|
Sales |
To enter into or perform a contract for the supply of services with you or the business or organisation you represent. |
|
Legal Obligation |
To comply with a legal obligation or exercise a legal right. |
|
Our Legitimate Interests |
|
|
Special Category Data |
|
|
Security |
|
|
Intragroup data |
We may process your data for the purposes intra-group data transfers for group administration purposes. |
|
Your Interests |
|
|
Your Consent |
|
|
Our Clients |
Where we are acting as processor, the lawful basis will be a matter for our clients, but is typically processing in connection with the supply of electricity or gas to you, or in connection with their resale of our home and EV energy management and optimisation services to you. |
7. WHAT PURPOSES DO WE PROCESS YOUR DATA FOR?
This part sets out the key purposes we use your data for and the associated lawful basis.
|
PURPOSE |
DESCRIPTION |
EXAMPLES |
LAWFUL BASIS |
|---|---|---|---|
|
Audits |
To carry out audits of our business and to enable third parties to audit our business and controls, including audits under ISO 27001 & ISO 27701, audits under the UK Smart Energy Code and other industry codes, and SOC (Service Organisation Controls) audits. |
Providing evidence (which may include your personal data) to demonstrate the operation of ENSEK's policies and controls in the business (such as performance reviews, access logs). |
Legitimate Interest = To operate our business to a good standard and provide assurance of this to clients and other third parties we deal with. |
|
Client SaaS Services |
To provide our SaaS products and services to our clients, and the processing of your personal data that is inherently part of those services. |
|
Legitimate Interest = Providing our products and services to our clients, who will define their own lawful basis to you. |
|
Client Relations Management |
To manage our relationship with our clients. |
|
|
|
Enquiry Follow-Up |
To follow-up on enquiries or requests you made, including any follow-up sales processes. |
|
|
|
Marketing |
To market our products to you or to the business or organisation you represent or work for. |
|
|
|
Newsletter |
Where you have signed-up, we will use your data to send to our regular newsletter until you ask us to stop. |
Client update newsletters. |
|
|
Security Monitoring |
|
|
|
|
Visit & Event Management |
To manage your visits with us and your attendance at any events with us. |
|
|
|
System Management |
|
|
|
|
Product & Services Improvement |
|
Our main products are SaaS products, which are accessed by our clients using a web user interface. The quality of that user interface determines how well and efficiently our clients and their staff are able to use our products. We therefore, as with a web site, we seek to capture information about how our SaaS products and their interfaces are used by our staff, which we then use to consider and improve the design of our products and the user guidance we provide. |
Legitimate interest = To be able to improve our products. Contract - To be able to deliver SaaS products that meet the standards expected by our clients in their contracts with us. |
|
Website Improvement |
To assess the use of our website and improve it so that it is visited and used more, and has better rankings in search engines, and provides a better outcome for our visitors |
Capturing how many unique visitors there are and how often they are visiting and which parts of the site are used most. |
Legitimate Interest = To be able to promote and grow our business through an effective and relevant website. |
8. WHO DO WE SHARE YOUR DATA WITH?
This section details who we may share your information with. We will normally share in confidence unless the law requires otherwise
8.1 Auditors
We may share your personal data with any third party that is auditing our business and controls, including our security measures and operational controls, for the purposes of evidence, but only to the extent reasonably required for such evidence.
It will be shared securely, and under a non-disclosure agreement; and is shared normally to the auditors secure evidence repository.
They use it as ENSEK's sub-processor, to provide audit services to ENSEK.
They may retain this in archive for up to 7 years, as evidence of the audit services provided.
8.2 Cloud System Providers
We may share your data with our systems providers, through putting your data into any cloud systems that we procure, as part of their hosting of those systems; but they are not expected to access or use it, except for technical support purposes; and your data otherwise resides on and is processed in those systems as part of their cloud service, and is encrypted at rest.
They will receive it as ENSEK's sub-processor.
They will retain data in the system according to our retention policy.
8.3 Our Clients
We may share any feedback information, support ticket information, and information concerning your use of our systems with your employer / the company you work for, for the purposes of assessing our software and performance, and audit, logging and investigation purposes.
They will receive it as a controller, and not our processor.
They will retain data in the system according to their retention policy.
9. WHERE DO WE KEEP YOUR DATA?
9.1 Introduction
Your data is kept in the systems referred to below.
Some useful links are provided at the end of this privacy notice.
We no longer keep any paper records and all of your data is created, stored, and retained electronically.
9.2 General Aim
We aim to store and process your data in data centres in the UK or European Economic Area.
Exceptionally your data may be processed in the USA or other countries, and in such case we follow EU and UK rules for data transfers.
We accesses these systems from networks and staff located in the UK, and from contractors located in the UK and EEA.
9.3 Marketing and Client CRM
We host our website and manage our marketing and customer relationship database, contacts, enquiries and forms in a CRM service (currently Hubspot)
9.4 Office Systems
We use a range of internal office systems, applications, and cloud services for a range of internal business data processing needs, including: (a) file storage; (b) file sharing; (c) databases; (d) email; (e) messaging; (f) document creation and editing; (g) software development; (h) work task management; (i) reporting; and (j) chats.
Your personal data may appear in these systems in various forms as appropriate for use connected with the purposes for which we are processing your data.
We specify the UK or EEA for hosting where possible.
9.5 SaaS Systems
If you are a client data subject (such as a user agent, client customer, or broker contact), your personal data will be stored and processed in our SaaS products and as part of our client services; such as our Ignition Energy Orchestration Platform, and our Flex Home Energy Management product, and their associated databases.
These are hosted in Amazon Web Services and Google Cloud in the UK and EEA.
9.6 SaaS Product Analytics
We may capture data about your use of our SaaS products in the databases of those products or in other analytics cloud services we use (such as Data Dog, Full Story and Useberry).
We aim to hold that data in pseudo-anonymised form were practicable; such as by hashing identifiers.
10. HOW LONG DO WE KEEP YOUR DATA FOR?
This section covers our retention policy.
10.1 General Principle
Subject to the following cases, we will only use your data for as long as it is required for the purposes for which it is processed, and we will only hold your data for as long as: (a) we need it for the purposes for which it is processed; (b) we need it as an evidence archive for legal claims purposes (for which we set a 7 year time period for retention from when our other purposes of use end).
10.2 CCTV
Landlord CCTV recordings are held for 30 days.
We hold CCTV recordings from internal secure areas for 3 months.
If a recording is needed for evidence in relation to an incident that has happened, we may hold the data for as long as may be reasonably required for that incident, but no more than 7 years.
10.3 Clients
Where we are processor we will use and hold your data according to the instructions of our clients / controllers and their data retention policies.
11. HOW DO WE KEEP YOUR DATA SECURE?
This section covers our security measures.
11.1 General Principle
We have appropriate security measures in place to prevent personal information from being accidentally lost, or used or accessed in an unauthorised way.
In particular we have the following measures to keep your data secure.
11.2 ISO 27001
We are certified to and aim to keep certified to ISO 27001:2022, which requires us to have a security management system, and to maintain a range of security controls.
11.3 ISO 27701
We are also certified to and aim to keep certified to ISO 27701:2019, which requires us to have a privacy information management system, and to maintain a range of privacy controls.
11.4 SOC Audit
We have our security controls audited independently by an auditor under the SOC (service organisation controls) audit standards.
11.5 Industry Audit
We are subject to some security assessment checks under UK Industry codes such as the Smart Energy Code and the Retail Energy Code.
11.6 Data Breach
We have procedures in place to deal with any suspected data security or privacy breach affecting your data.
We will notify you and any applicable regulator of a suspected data security or privacy breach where we are legally required to do so.
11.7 Other Measures and Controls
The above standards and audits require and examine all our security and privacy measures and controls, which we have in place to protect against unauthorised use, access to, change to, or disclosure of your data, against viruses and other malicious software, and against unauthorised access to our equipment, offices, networks, cloud systems, and databases.
These measures and controls cover areas such as office access controls, equipment log-in, cloud system log-in and associated roles and permissions, network and access monitoring, staff training, management, staff background checks, usage monitoring, anti-virus and other protective software and devices, and data segregation and encryption.
11.8 System Providers
Individual system providers listed in this document have their own separate security and privacy controls with respect to your data in their systems, and we consider these prior to using those systems.
11.9 Cloud First
We operate on a "cloud first" basis, which means that your data is stored in secure and reputable cloud systems, rather than at any offices of ours.
11.10 Access Controls
We limit access to your personal information to those who have a genuine business need to know it.
11.11 Proportionate and Confidentially
Those processing your information will do so only in an authorised and proportionate manner and are subject to a duty of confidentiality.
11.12 Supplier On-Boarding Process
Where your data is processed for us by a supplier (such as in a cloud system we procure), we have a supplier on-boarding process that assesses where your data is held and the security and privacy compliance measures of the supplier.
We aim to use cloud service providers who store your data in data centres in the UK or European Economic Area; but occasionally also the USA and other countries following EU and UK rules for data transfers.
12. WHAT ARE YOUR RIGHTS?
This section covers your rights in relation to our processing of your data.
|
Introduction |
|
|
Our Service Providers |
|
|
Right to be informed |
|
|
Right to withdraw consent |
If any processing is based on your consent, you have the right to withdraw it at any time. Just email using our contact details in this document. |
|
Right to stop direct marketing |
You have the right to stop direct marketing at any time. |
|
Right to a copy |
|
|
Right to a correction |
You have the right to request correction of your data (a right to rectification). |
|
Right to erasure |
|
|
Right to restriction |
|
|
Right to object to legitimate interests |
|
|
Automated Decision Making |
If we are making important decisions about using a compute, without any human involvement, then you can ask us to stop, subject to conditions. |
|
Right to complain |
|
13. USEFUL LINKS
|
Contains updates to Data Protection laws in the UK. |
|
|
Contains additional rules to support the UK GDPR. |
|
|
The UK's version of the European General Data Protection Act. |
|
|
Legal limitation periods for bringing a claim in court. |
|
|
The Privacy and Electronic Communications (EC Directive) Regulations 2003 which cover direct marketing and use of cookies. |
|
|
The Network and Information Systems Regulations 2018 which apply security requirements to operators of important cloud services. |
|
|
Our principal SaaS product and application for home energy management and optimisation; previously branded Zoa. |
|
|
Our principal SaaS product in which energy customer personal data is processed, which may also be referred to as the Energy Orchestration Platform. |
|
|
Page for making a complaint to the UK Information Commission. |
|
|
ICO page on the rights of data subjects under UK law. |
|
|
International security controls standard. |
|
|
International personal data management controls standard. |
|
|
Auditing standard for auditing of security and operational controls. |
|
|
An online database system ENSEK use for ad-hoc database purposes, such as storing user feedback. |
|
|
A hosting platform we use to host and run some of our products. |
|
|
A third party cloud service used to monitor our SaaS products and their performance and availability, which includes monitoring of API calls. |
|
|
A cloud service used to generate user interface usage analytics, and record and document how user interfaces are used; used by us to improve and develop our products. |
|
|
A hosting platform we use to host and run some of our products. |
|
|
Our back office business applications and cloud tools for email, messaging, calling, and file creation, storage and editing. |
|
|
A third party cloud service we use to host our websites, and carry out our marketing and client relationship management processing. |
|
|
Our back office business applications and cloud tools for email, messaging, calling, and file creation, storage and editing. |
|
|
IT service desk ticketing system for incident management and access requests and other business process management. |
|
|
An internal and external messaging and teams management system, similar to Microsoft Teams. |
|
|
A third party cloud service we use to test user interface designs for our products with users, and to obtain user surveys and feedback; used by us to improve and develop our products. |