Privacy Notice
Version 2026-09-25
How Ecoglow processes personal data in Ecoglow Hub, under the UK GDPR and the Data Protection Act 2018.
Who we are (controller)
Ecoglow [Ltd], [registered address], is the data controller. Contact our data protection lead at [dpo@ecoglow.uk.com]. ICO registration: [number].
Whose data we hold
- Staff and tradespeople: name, contact details, trade, schedule, attendance, invoices and performance.
- Residents and tenants: property address, works carried out, access arrangements and any issues raised. We avoid holding special-category data.
- People who use the system: name, email, permissions, and the activity records described below.
Activity and timing records
When you use Ecoglow Hub we record:
- Sign-in activity: when you sign in and out, and failed sign-in attempts. Our sign-in provider also records the device's IP address and browser type. For limiting repeated failed attempts we keep only a scrambled (hashed) form of the network address.
- Changes you make: the date and time of every change, who made it, what it was before and after, and any reason given. This audit trail is permanent and can't be edited.
- Work times: scheduled and confirmed attendance, visit dates and times, and job dates recorded by you or colleagues.
- Exports: when data is exported and by whom.
- Your acceptance of these terms: which version you accepted and when.
We use these records to keep the system and its data secure, to show who did what for financial and compliance purposes, to plan and pay for work, and to investigate problems or disputes. We do not track your location, record your screen or keystrokes, or make automated decisions about you from these records.
Why we process it and our lawful basis
- Contract and legitimate interests: delivering retrofit installations, scheduling, evidence, invoicing and payment, and keeping the system secure and accountable.
- Legal obligation: keeping compliance certificates and financial records.
- We don't use the data for marketing.
Who we share it with (processors)
We use vetted processors under data-processing agreements: Supabase (database and sign-in, London region), Vercel (application hosting) and Sentry (error monitoring, set not to collect personal data). We do not sell personal data.
International transfers
Main data is stored in the UK (London). Where a processor transfers data outside the UK, it is covered by the UK International Data Transfer Agreement or adequacy regulations. [Confirm per processor.]
How long we keep it
Operational records for the length of the programme plus [X] years; financial and compliance records for [6/7] years as the law requires; the audit trail and sign-in records for [X] years. Deleted records are archived and purged after [X].
How we protect it
Access is based on each person's permissions and enforced in the database; everyone signs in with two-factor authentication; data is encrypted in transit and at rest, with the most sensitive resident details encrypted separately; every change is recorded in a tamper-evident audit trail, with point-in-time backups.
Your rights
You can ask for access to your data, or for it to be corrected, erased, restricted or transferred, and you can object to processing. Contact [dpo@ecoglow.uk.com]; we reply within one month. You can also complain to the Information Commissioner's Office (ico.org.uk).