Privacy Policy for EnergyPlus (United Kingdom)
We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how EnergyPlus (energyplus.co.uk) collects, uses, discloses, and safeguards your information in accordance with UK GDPR and the Data Protection Act 2018.
1) Who We Are & Scope
EnergyPlus (referred to as “EnergyPlus”, “we”, “us”, or “our”) operates the website energyplus.co.uk and provides energy-related information and services to customers and website visitors across the United Kingdom.
For the purposes of UK data protection laws, EnergyPlus is the controller of personal data processed via this website and related customer interactions, unless stated otherwise.
This policy applies to personal data collected online via our website and through our contact channels (for example, when you request a quote, sign up to newsletters, create an account, or contact support).
2) How to Contact Us
If you have questions about this Privacy Policy or how we handle your data, please contact us:
- Online: Contact page
- Address: EnergyPlus, United Kingdom (full postal details available upon request)
If applicable, we may appoint a Data Protection Lead responsible for privacy matters. You can reach our team using the details above.
3) What Data We Collect
We collect and process the following categories of personal data, depending on your interactions with us:
Identity & contact data
- Name, title, job title
- Postal address, email address, telephone number
- Company details (for business enquiries)
Account & interaction data
- Account credentials (if applicable; passwords stored using industry-standard hashing)
- Support messages, call notes, and communication preferences
- Form submissions (quotes, enquiries, surveys, feedback)
Technical & usage data
- Device information, browser type, IP address, approximate location
- Pages viewed, links clicked, session duration, referring/exit pages
- Cookie IDs and similar identifiers
Marketing & communications data
- Newsletter subscriptions and consent records
- Campaign interactions (opens, clicks) where permitted
Email alert subscription data
When you sign up to our free tariff alert service, we collect your email address and optionally your first name and postcode. We also record the date and source of your subscription and the exact consent wording you agreed to at the time, in line with UK GDPR requirements.
Special category data
We do not intentionally collect special category data (e.g., health, ethnicity) through this website. If such information is provided by you incidentally, we will only process it where a lawful basis applies and, where required, with your explicit consent.
Children
Our services are not directed to children and we do not knowingly collect data relating to children.
4) How We Collect Data
- Direct interactions: when you complete forms, request a quote, subscribe, or contact us.
- Automated technologies: through cookies, pixels, and analytics when you browse our site.
- Third parties: analytics providers, advertising networks, social media platforms, and business partners who may provide us with information consistent with this policy and applicable law.
5) Why We Use Your Data (Legal Bases)
We process personal data only when we have a lawful basis. Common purposes and legal bases include:
- To provide and improve our services, respond to enquiries, and manage customer relationships – performance of a contract or steps prior to entering into a contract; legitimate interests.
- To operate our website, diagnose issues, and keep it secure – legitimate interests and legal obligation (security and fraud prevention).
- To personalise content and measure site performance – legitimate interests and/or consent (for non-essential cookies).
- To send marketing communications – consent where required; legitimate interests for similar products/services to existing customers, with an easy opt-out.
- To comply with legal and regulatory obligations – legal obligation.
Where we rely on consent, you can withdraw it at any time using the links in our emails or by contacting us. Where we rely on legitimate interests, we balance our interests against your rights and expectations.
7) Marketing Preferences & Tariff Alerts
Email alert subscription
We operate a free tariff-alert email service. You can sign up on our website to receive notifications when energy tariff rates change, when new fixed deals become available, or when the Ofgem price cap is updated. This service is entirely optional and is independent of any quote or comparison you make on the site — we will never require you to subscribe in order to use our comparison tools.
When you subscribe, we collect your email address and optionally your first name and postcode. We record the date, source page, and exact wording of the consent shown to you at the time you opted in, in line with UK GDPR requirements. Subscription is always by an unticked opt-in checkbox or a standalone sign-up form.
What we send
Subscribers may receive:
- Price cap change notifications (Ofgem updates these quarterly)
- Alerts when significantly cheaper tariffs become available
- Energy-saving tips and seasonal guidance
- Solar export (SEG) rate changes for subscribers who have indicated they have solar panels
We aim to send no more than one email per week. We will never send promotional emails on behalf of third-party advertisers.
How to unsubscribe
You can unsubscribe at any time using:
- The unsubscribe link included in every email we send
- Our unsubscribe page
- Our Contact page
We will process unsubscribe requests immediately. We may retain your email address on a suppression list to ensure we do not accidentally email you again in the future.
Other marketing communications
Where you are an existing user and we communicate about similar products or services, we rely on legitimate interests as our legal basis, with an easy opt-out in every communication. We will not sell your personal data. We may use list suppression to respect your opt-out choices.
9) International Transfers
If personal data is transferred outside the UK, we implement safeguards such as UK-approved Standard Contractual Clauses, an adequacy decision, or other lawful mechanisms. We take steps to ensure your data receives an equivalent level of protection.
10) Data Retention
We keep personal data only for as long as necessary for the purposes described in this policy and to comply with legal, tax, or accounting requirements. Typical retention periods include:
- Enquiry records: up to 24 months after last interaction
- Customer account and contract data: for the contract term and up to 6 years thereafter
- Marketing preferences and consent records: for as long as you remain subscribed (plus a limited period for suppression evidence)
- Technical logs and security records: typically 12–24 months
We may anonymise data for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
11) How We Protect Your Data
We use administrative, technical, and organisational safeguards designed to protect personal data, including encryption in transit (HTTPS), access controls, secure configuration, regular monitoring, and staff awareness. While no method is 100% secure, we continually improve our security practices.
12) Your Privacy Rights
Under UK GDPR, you have rights which may include:
- Access: request a copy of your personal data
- Rectification: correct inaccurate or incomplete data
- Erasure: request deletion in certain circumstances
- Restriction: limit how we use your data
- Portability: obtain your data in a structured, commonly used format
- Object: to processing based on legitimate interests or to direct marketing
- Withdraw consent: where processing is based on consent
To exercise these rights, contact us via our Contact page. We may need to verify your identity. We aim to respond within one month, subject to lawful extensions for complex requests.
13) Children’s Privacy
Our services are intended for adults and business users. If you believe a child has provided us with personal data, please contact us so we can take appropriate action.
14) Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, technology, or our services. We will post the updated version here with a new “Last updated” date and, where appropriate, notify you through our website or email.
Last updated: 9 April 2026
15) Concerns & Complaints
If you have concerns, please contact us first so we can try to resolve them. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO): ico.org.uk or call 0303 123 1113.
Privacy FAQs
Do you sell my personal data?
No. We do not sell your personal data. We may share data with service providers under strict contracts to deliver our services.
How can I opt out of marketing emails?
Use the unsubscribe link in any email we send, visit our unsubscribe page, or contact us via our Contact page. We will process your request immediately and maintain a suppression list to ensure you are not emailed again.
How does the tariff alert subscription work?
You can sign up using the alert widgets on our website. We store your email address and optionally your first name and postcode in our secure database. We record the exact consent you gave and the date, as required under UK GDPR. You can unsubscribe at any time via the link in our emails or our unsubscribe page. We do not share your subscription data with third parties or use it to send advertising on behalf of other companies.
Can I access or delete my data?
Yes. You can request access to, correction of, or deletion of your data where applicable by contacting us. We may need to verify your identity.
Do you transfer data outside the UK?
Where necessary, we use approved safeguards such as UK Standard Contractual Clauses or rely on adequacy regulations to protect your data.
Have questions about your privacy?
Our team is here to help. We are committed to transparent data practices and your peace of mind.
This page is intended to provide clear information about how EnergyPlus handles personal data. It is not legal advice. For guidance on your specific circumstances, consult a qualified professional.