Square1 Energy Limited considers the protection and security of your data to be of paramount importance. We never sell personal data, and we carry out all processing operations in strict compliance with the UK General Data Protection Regulation ("GDPR"). We take your privacy very seriously and will process your data responsibly and lawfully.
What information do we collect about you?
Whenever you visit our site, we collect anonymous data about the way you use our website. We also collect personal data if you decide to apply for any products or services, a quote or contact us through our 'contact us' forms. The data we collect falls into the following categories:
• Information you give us.
• Information we collect about you.
Information you give us and how we use it:
We will process your personal information under the legal ground 'performance of a contract' for supply of your energy and will take the necessary pre-contractual steps requested by you prior to entering into that Contract.
• Tulo Energy sign up process When you begin the quote process on our website, we ask for your postcode, full address and energy consumption data. We store this information for two years in line with energy industry licence requirements. If you proceed to sign-up, then we collect the information we ask you to input (e.g., name, email address etc.). If you do not complete the sign-up process within 7 days, we will delete this data from our records.
Information we collect about you and how we use it:
We process your information for our own legitimate interests. This is where we use your personal information for our normal business purposes where the benefits of doing so are not outweighed by your fundamental rights or freedoms. You have a right to object to this type of processing. See 'What rights do you have over your personal information?'
• Website usage data When you visit our website we store the name of your internet service provider, the website from which you visited us from, the parts of our site you visit, the date and duration of your visit, and information from the device (device type, operating system, screen resolution, language, country you are located in, and web browser type) you used during your visit. We process this usage data to facilitate your access to our services (e.g., to adjust our services to the device you are using), and to recognise and stop any misuse. We also process usage data in an anonymised form for statistical purposes and to improve our site.
• Website Analytics We use programs such as Google Analytics and Lotame to help us find out: o How many people visit our websites.
- Which pages and parts are most popular.
- How long people spend in each area
- What information people are searching for.
- Browser types
- Operating systems
- Referring sites that sent you to us
- The date and time of a visit.
- See where people click on a webpage.
- Follow mouse patterns.
- And track non-sensitive text that people might type into the site.
We also use third-party analytics services like Hotjar, which is similar to Google Analytics. Where Google Analytics identifies overall trends in people's browsing habits, Hotjar helps us work out 'why' those trends exist. For example, why everybody is suddenly visiting a certain page. It allows us to:
• Advertising We use tools such as Doubleclick to place Powershop ads on other websites you may visit. These tools may set cookies to track the performance of our advertising campaigns and allow us to tailor the advertising you might be interested in.
We also use products like Google Analytics Advertising, including remarketing with Google Analytics, Google Display Network Impression Reporting. These products help us understand what ads work best so we can more effectively promote our products and services to you.
We also use Google Adometry to track the way you interact with our ads before you come to our website. This helps us to work out which ads are relevant to you and which ones aren't. We use a unique identifier to track how successful our advertising is, and this is done on an anonymous basis. We do not use your personal information.
Information we collect from third parties about you
We collect personal information about you from third parties such as energy comparison websites or brokers where you sign up to our products or services through their website or contact centres. They will be governed by their own privacy policies, and we recommend you review them.
Where you have chosen to contact us via social media such as Facebook or Twitter, we will use the contact information you have provided to answer your questions and the information will continue to be stored on Facebook or Twitter in line with their deletion periods. You should review Facebook and Twitter's privacy policies to find out more.
How we share your personal information
We may pass information about you to our agents and service providers for the purposes set out in this privacy notice for the following purposes:
• Agents acting on our behalf to carry out profiling, modelling and analysis, market and customer research, statistical analysis to help improve the way we provide our services and the products that we can make available to you. These agents include creative agencies, professional user experience testing agencies and search engine optimisation agents. We do not provide personal information to these agents.
• Our processors and sub-processors for the development and testing of our IT systems, diagnosing and implementing bug fixes, and diagnosing and dealing with incidents.
Whenever your personal data is passed to an external data processor, your information is managed to the same high standard as it is by us. In accordance with the data protection laws, we only work with data processors that offer security guarantees and we take reasonable measures to ensure their compliance. The data processor is only allowed to process personal data in line with our specific instructions and for no other purpose than it was originally intended.
We take your privacy seriously and do everything we can to protect your personal data. Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data being transmitted to the website and app, however once we have received the information, we will do all we can to keep your data secure.
Whenever you input your details on this website you do so via our secure servers. These use what's known as Secure Socket Layer encryption, a leading security standard in the e-commerce industry. Some of this website may not be encrypted because there's no need. However, the moment you submit any personal information as part of the quote and apply process or register to manage your account online, you will be on secure pages.
We also train our staff to protect your personal details and check your identity whenever you contact us. You should always keep your password and account details secure and always remember to log out of your account and close your browser window when you've finished. This helps to ensure that no one else can access your personal data.
Credit Reference Agencies
We may share your information with credit reference agencies. All Credit Reference Agencies adhere to the Credit Reference Agency Information Notice (CRAIN) which was developed by various credit reference agencies and the ICO to ensure how and why they use and share personal data, as well as the type of data they hold, where it comes from, and the legalities of how it is handled. It’s important you understand this so please read the CRAIN – https://www.transunion.co.uk/legal/privacy-centre/pc-credit-reference
When do we pass your information outside the UK?
We do not pass your information outside the United Kingdom.
What rights do you have over your personal information?
• Information: You are entitled to know a range of information about your personal information such as what we collect about you, how we use it, who we share it with, what legal grounds we rely on, how to exercise your rights etc.
• Access: You are entitled to know what personal information we hold about you at any time. (If you write to, email, or phone us and ask to see this information, it is known as a 'Subject Access Request' or 'SAR'. When we receive your request, we will send you a form to fill in, along with identity checks. If you do not return the form and/or answer our phone calls to verify you have made this request, we will not be able to deal with your request.
• Data Portability: You can request the personal information you provide to us in a commonly used and machine-readable format. We already allow you to access some of your information online, but if you need other information you can contact us.
• Accuracy/Rectification: You can check that the personal information that we hold is accurate, or to let us know of any changes to your personal information. We always try to ensure that the information that we hold is accurate, up to date and relevant. We'll be more than happy to make changes or to correct any inaccuracies.
• Deleting/Erasure: You can ask us to delete some or all your personal information in certain circumstances (e.g., we no longer need it), and we are obliged to delete it. We can refuse to delete that information if those circumstances don't apply.
• Restriction on use: You can ask us to temporarily stop using the personal information in the following circumstances: o where you think your personal information is not accurate, we will temporarily stop using it until we have verified the accuracy of it, if we cannot resolve the accuracy of it straight away;
- where you have objected to our use of the personal information (in circumstances where it was necessary for the performance of a public interest task or for our legitimate interests as a business), and we are considering whether our legitimate interests as a business override your rights to object to our use of it;
- when processing is unlawful, and you don't want us to erase it, and request restriction instead; or
- if we no longer need the personal information but you want it to establish, exercise or defend a legal claim.
If we have legitimately shared the personal information in question to third parties, we must inform them about the restriction on the processing of the personal information, unless it is impossible or involves disproportionate effort to do so. We must also inform them when we decide to lift a restriction on processing.
• Right to object to processing based on our 'legitimate interests' as a business: If we rely on the legal grounds that we have a legitimate right as a business to use your personal information (as opposed to any other legal ground) then you have a right to object to us using your personal information for these purposes. You can exercise your right to object by emailing or contacting us via our website.
• Right not to be subjected to automated decision-making: You have the right not to be subject to a decision based solely on automated processing which produces legal effects or similarly significantly affects you, except where we do so for the purposes of your energy supply, it is authorised by law, or you consent to it. In those circumstances you are entitled to at least contest any such decision and obtain a review. Our systems do not have automated processing that fulfil these criteria.
• Complain: If you think we are using or processing your personal information in a way that is not consistent with this privacy notice or with the law, you can lodge a complaint with the Information Commissioner's Office. Contact details are available at https://ico.org.uk/concerns/. We would always prefer you to contact us first though, to see if we can answer your concerns.
- Emailing email@example.com
- Writing to us at Data Protection Officer, Tulo Energy, 71 Graham Road, Malvern, England, WR14 2JS
You can exercise any of these rights by contacting us as set out below under 'Who is your data controller?'.
Who is your data controller?
You also have the right to ask us to delete or correct any information we hold about you that is inaccurate.
Duration of Processing
We will store your data for the time periods listed in the table below All other data as specified above will be retained for as long as is necessary for the purpose(s) for which we originally collected it. We may also retain information as required by law.
Personal information processed
Incomplete account sign-up by site visitor