Privacy Policy

How we collect, use, and protect your personal information

Last updated: 24/10/2025

At EnerWise, we are committed to protecting your privacy and maintaining the security of your personal information. This policy explains how we collect, use, and safeguard your data.

Information We May Collect

Personal Information

  • • Name and contact details (email, phone, address)
  • • Property information and energy usage data
  • • Account credentials and preferences
  • • Communication history with our team

Technical Information

  • • IP address and device information
  • • Browser type and version
  • • Website usage patterns and analytics

For detailed information about cookies and tracking technologies, please see our Cookie Policy.

Business Information (Installers)

  • • Company details and registration information
  • • Qualifications, certifications, and insurance details
  • • Service areas and specialisations
  • • Financial information for payments

How We May Use Your Information

For Homeowners

  • • Provide energy savings calculations
  • • Match you with suitable installers
  • • Facilitate communication between parties
  • • Process payments and manage projects
  • • Send relevant updates and offers

For Installers

  • • Verify qualifications and credentials
  • • Match you with suitable projects
  • • Process payments and commissions
  • • Provide business support services
  • • Send industry updates and opportunities

Information We May Share

With Your Consent

We may share your information with:

  • • Installers to facilitate quotes and projects
  • • Payment processors for secure transactions
  • • Service providers who assist our operations
  • • Regulatory bodies when required by law

Legal Requirements

We may disclose information when required by law, to protect our rights, or to prevent fraud or harm.

Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.

Data Security

Protection Measures

  • • Encryption of data in transit and at rest
  • • Secure hosting with industry-standard security
  • • Regular security audits and updates
  • • Access controls and authentication
  • • Employee training on data protection

Data Retention

We retain your information for specific periods based on the type of data and its purpose:

  • • Account data: Retained for the duration of your account plus 7 years for legal compliance
  • • Project data: Retained for 7 years after project completion for warranty and legal purposes
  • • Communication records: Retained for 3 years after last contact
  • • Marketing data: Retained until you withdraw consent or for 2 years of inactivity
  • • Analytics data: Anonymised after 26 months

You may request deletion of your data subject to legal obligations and legitimate business interests.

Your Rights

Access and Control

  • • Access your personal information
  • • Correct inaccurate data
  • • Request deletion of your data
  • • Object to processing of your data

Communication Preferences

  • • Opt out of marketing communications
  • • Choose how we contact you
  • • Update your preferences anytime
  • • Unsubscribe from emails

Data Processing Consent Types

When you create an account with EnerWise, you'll be asked to provide consent for different types of data processing. Here's what each consent type means:

Essential Data Processing

Required for service functionality. This includes processing your name, email, and account type to create and maintain your account, authenticate you, and provide core platform features. This consent is mandatory and cannot be withdrawn as it's necessary for the service to work.

Marketing Communications

Optional promotional content. This allows us to send you marketing emails about new features, promotions, renewable energy updates, and special offers. You can unsubscribe at any time and change this preference in your account settings.

Analytics & Usage Data

Optional platform improvement. This allows us to collect usage analytics including page views, feature usage, and performance data to help improve the platform, fix bugs, and enhance user experience. This data is anonymised and aggregated.

Service Communications

Optional important updates. This allows us to send you important service updates, security notifications, account-related communications, and system maintenance notices. These are typically essential for account security and service continuity.

Managing Your Consent

You can change your consent preferences at any time in your account settings. Withdrawing consent for optional services will not affect your ability to use the core platform features. Essential data processing consent cannot be withdrawn as it's required for the service to function.

Third-Party Services We May Use

Services We May Use

  • • Analytics providers for website usage insights (anonymised data only)
  • • Payment processors for secure transactions (payment details, transaction records)
  • • Cloud hosting providers for data storage and authentication (account and project data)
  • • Email service providers for communications (contact details, communication content)
  • • Security and performance services (IP addresses, request logs)
  • • Error monitoring services (technical error data, no personal information)

All third-party services are bound by data processing agreements that help protect your data according to GDPR standards.

Website Analytics and User Experience

We use analytics tools like Microsoft Clarity to capture how you use and interact with our website through behavioral metrics, heatmaps, and session recordings. This helps us improve our products and services by understanding user behavior and optimising the platform experience.

Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of features and online activity. We use this information for site optimisation, fraud prevention, security purposes, and to improve our advertising effectiveness.

For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.

External Links

Our website may contain links to external sites. We are not responsible for the privacy practices of these sites.

GDPR Compliance

Lawful Basis for Processing

  • • Contract performance: Processing necessary to provide our services
  • • Legitimate interests: Business operations, security, and platform improvement
  • • Consent: Marketing communications and optional analytics
  • • Legal obligation: Compliance with UK and EU regulations

Data Subject Rights

Under GDPR, you have the right to:

  • • Access your personal data (data portability)
  • • Rectify inaccurate or incomplete data
  • • Erase your data (right to be forgotten)
  • • Restrict processing of your data
  • • Object to processing based on legitimate interests
  • • Withdraw consent at any time

To exercise these rights, contact us at info@getenerwise.co.uk. We aim to respond within 30 days.

Data Protection Officer

For data protection queries, contact our Data Protection Officer at info@getenerwise.co.uk or write to us at our registered address.

Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe we may have collected such information, please contact us immediately.

Changes to This Policy

We may update this privacy policy from time to time. We may notify you of any material changes by:

  • • Posting the updated policy on our website
  • • Sending you an email notification
  • • Displaying a notice on our platform

Your continued use of our services after changes become effective may constitute acceptance of the updated policy.