This document is a working template prepared for GridOptic. It is pending review by a qualified solicitor and may change before public launch. Bracketed placeholders such as [COMPANY LEGAL NAME] must be completed before it is relied upon.
Legal · Data Protection
Last updated: 22 July 2026
This Privacy Policy explains how GridOptic collects, uses, shares, and protects personal data when you visit our website, create an account, or use our grid-intelligence platform and related services (together, the “Service”). It also explains your rights under the retained EU General Data Protection Regulation as it forms part of the law of England and Wales (“UK GDPR”) and the Data Protection Act 2018 (“DPA 2018”).
GridOptic is a business-to-business product. We process only a limited amount of personal data — principally the account and billing details of the professionals who use the Service. We do not build advertising profiles, and we do not sell personal data.
The Service is operated by GRIDOPTIC LTD, a company registered in England and Wales under company number 17350559, whose registered office is at Unit 720, Catalyst House, Centennial Avenue, Borehamwood, WD6 3SY, United Kingdom (trading as “GridOptic”, and referred to in this policy as “we”, “us”, or “our”).
For the purposes of UK GDPR and the DPA 2018, we are the data controller in respect of the personal data described in this policy. This means we are responsible for deciding how and why your personal data is processed.
If you have any questions about this policy or how we handle personal data, you can contact us at [email protected] or by writing to us at the registered office address above, marked for the attention of the Data Protection Contact.
We are not required by law to appoint a statutory Data Protection Officer. Where we have designated an individual as our data protection point of contact, their details are given above.
This policy applies to personal data we process about: (a) visitors to our website and marketing pages; (b) individuals who register for, subscribe to, or use the Service on behalf of a business; and (c) people who contact us with an enquiry or support request.
The Service aggregates and analyses publicly available data about the Great Britain electricity network. That grid data is not, in the overwhelming majority of cases, personal data, and its treatment is described separately in the section Public grid data we process so the distinction is clear.
Our website and the Service may contain links to third-party websites or resources. This policy does not apply to those third-party services, which have their own privacy notices.
We collect and process the following categories of personal data:
When you register for an account we collect your name, work email address, the name of the organisation you represent, your job role or title (where you provide it), and the credentials used to authenticate you (a hashed password, and/or identifiers from a single sign-on provider where you choose to sign in that way).
When you take out a paid subscription we collect billing details such as your billing name, business address, VAT number (where relevant), subscription plan, and a record of the transactions on your account. Payment card details are collected and processed directly by our payment processor, Stripe, and are never stored on our servers. We receive only limited information from Stripe, such as the last four digits of the card, card type, expiry, and the outcome of a transaction.
When you use the Service we automatically collect information about how you interact with it, including pages and features viewed, searches and queries you run within the platform, the sites and networks you analyse, session timestamps, referring pages, and diagnostic information. We also collect technical data such as your IP address, browser type and version, device and operating system information, and similar identifiers, primarily through server logs and application instrumentation.
If you contact us for support, submit an enquiry, or otherwise correspond with us, we keep a record of that correspondence and its contents.
Where you have asked to receive updates from us, or where we are otherwise permitted to contact you, we hold your contact preferences and a record of the marketing communications we have sent.
We do not intentionally collect any special category personal data (such as data revealing health, ethnicity, political opinions, or biometric data) and we ask that you do not submit such data to us through the Service.
A core function of the Service is to ingest, structure, and analyse data published by Distribution Network Operators, the National Energy System Operator (NESO), and government bodies — for example flexibility service requirements, network headroom, connection registers, and planning databases.
This grid data is published as open data and is overwhelmingly non-personal (it concerns physical assets, network locations, and commercial services rather than identifiable individuals). Where any such dataset does incidentally contain information relating to an identifiable individual, we process it only to provide the analytical function of the Service, we rely on our legitimate interests as the lawful basis (see below), and we handle it in accordance with this policy. We do not use publicly sourced grid data to market to, profile, or make decisions about individuals.
Under UK GDPR we must have a valid lawful basis for each processing activity. The bases we rely on are:
Direct marketing by electronic means is also subject to the Privacy and Electronic Communications Regulations (PECR). We send marketing emails only where PECR permits, and every marketing email contains an unsubscribe link.
We use personal data for the following purposes:
We do not use your personal data to carry out solely automated decision-making that produces legal or similarly significant effects on you.
We share personal data with carefully selected service providers who process it on our behalf under written contracts that meet the requirements of UK GDPR. Each processor may only use the data to provide services to us, and not for their own purposes. The categories of processor we use are:
We may also disclose personal data where required to do so by law, to enforce our agreements, to protect the rights, property, or safety of GridOptic, our users, or others, or in connection with a merger, acquisition, or sale of assets (in which case we will require the recipient to honour this policy).
A current, named list of our sub-processors is available on request from [email protected]. We do not sell your personal data.
We aim to keep personal data within the United Kingdom or the European Economic Area (EEA) where practicable. However, some of our processors (such as Stripe and certain infrastructure and analytics providers) may process personal data outside the UK or EEA.
Where personal data is transferred to a country that is not covered by UK ‘adequacy’ regulations, we ensure an appropriate safeguard is in place — typically the International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses together with the UK Addendum issued by the Information Commissioner’s Office — supplemented by additional measures where needed. You may request a copy of the relevant safeguard by contacting us.
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Our general retention periods are:
The exact periods above are set by us in line with operational and legal requirements. Where we no longer need personal data, we securely delete or irreversibly anonymise it.
Under UK GDPR and the DPA 2018 you have the following rights in respect of your personal data:
To exercise any of these rights, email [email protected]. We will respond within one month, though this can be extended by two further months for complex or numerous requests, in which case we will tell you. We may need to verify your identity before acting. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include: encryption of data in transit using TLS; hashing of stored passwords; role-based access controls and the principle of least privilege for access to production systems; network and application security controls; logging and monitoring; and regular review of our providers and practices.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office, and affected individuals where required, within the timescales set by law.
The Service is a business-to-business product intended for use by professionals. It is not directed at, or intended for use by, children, and we do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.
We may update this policy from time to time to reflect changes in our practices, technology, legal requirements, or the Service. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you by email or through a notice in the Service. We encourage you to review this policy periodically.
If you have any questions, concerns, or requests regarding this policy or our handling of your personal data, please contact us at [email protected] or by post at the registered office address in section 1. We take all concerns seriously and will do our best to resolve them.
You also have the right to lodge a complaint with the UK supervisory authority for data protection, the Information Commissioner’s Office (ICO), at ico.org.uk, by calling their helpline on 0303 123 1113, or by writing to Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would, however, appreciate the chance to address your concerns before you approach the ICO.