Understand what stays in your browser, what each form submits, why information is used, and which production privacy details still require approval.
Important publication status
An implementation-grounded privacy notice draft that has not completed legal approval
Before production collects personal information, the controller identity, contact address, lawful basis for each purpose, full retention schedule, processor locations and transfer safeguards must be supplied and approved by the operator and an appropriate reviewer. This page does not guess those missing facts.
Controller legal name
Not yet approved for publication
Controller or privacy contact address
Not yet supplied
Approved lawful-basis record
Pending controller and legal/privacy review
Full retention and deletion schedule
Pending owner approval and configuration
Privacy at a glance
You choose the purpose; one action does not silently expand into another
EnergyScope separates reading and tools, subscriptions and reminders, business enquiries and referrals, and contact, correction and complaint records.
Use without registration
Read public content, download files and use the three V1 tools without creating an account.
No automatic subscription or referral
Downloading a complaint template or using a calculator creates no newsletter, sales lead or partner permission.
Failure is not reported as success
If a database, email or external service fails, production does not claim the item was saved, sent or transferred.
No sale of contact lists
EnergyScope does not treat contact data as a list for sale. Any partner transfer requires a separate named disclosure and specific confirmation.
Information that currently stays in your browser
These features calculate or organise information in the browser. Using them alone does not send the inputs to EnergyScope's server:
Renewal-date calculation and a local `.ics` calendar file.
Quote usage, rates, fees, names, estimates and browser-generated PDF.
Complaint navigator answers, results and the editable AI prompt.
Glossary search, template copying and local downloads.
If you later request an email reminder, subscription, contact or business enquiry, only the fields in that separate form are submitted. Anything you choose to paste into third-party AI is governed by that service's policies.
Information we use
What each current form actually handles
These fields come from the current server validation and database models, rather than a vague statement that any information may be collected.
01
Energy-update subscription
Information
Email, language, selected business, home or market topics, confirmation and unsubscribe records.
Purpose
Send a 24-hour confirmation link and, only after double opt-in, selected-topic updates.
Boundary
Creates no business enquiry or partner referral. Newsletter withdrawal does not cancel an unrelated complaint or service request.
02
Renewal service reminder
Information
Email, electricity or gas, contract end date, language, and versioned six-, three- and one-month reminder status.
Purpose
Schedule the service prompts requested for the stated date; changing the date cancels unsent older versions.
Boundary
Marketing opt-in is fixed as false. A reminder is not consent for ongoing market promotion.
03
Business-energy enquiry
Information
Business name, postcode, sector, utilities, optional contract date or annual use, contact name, email or phone, preferred channel and language.
Purpose
Respond to the user-initiated contact request and retain the submitted snapshot and status.
Boundary
The first enquiry deliberately creates neither a subscription nor partner-referral permission.
04
Named partner referral
Information
Only separately disclosed fields, named partner, purpose, disclosure version, confirmation record and transfer evidence.
Purpose
Enter a manual handoff queue only after the readiness gate, partner approval and specific user confirmation all exist.
Boundary
Approved for manual handoff is not sent. Actual transfer has a separate time, method and evidence record.
05
Contact, correction and EnergyScope complaint
Information
Name, email, subject, message up to 5,000 characters, language, case type and handling status.
Purpose
Respond to general contact, a content correction or a complaint about EnergyScope.
Boundary
These cases stay outside sales. Supplier or broker disputes use separate guidance.
06
Security and abuse prevention
Information
A SHA-256 rate-limit key derived from IP plus purpose and a 15-minute window, scope, count and expiry; the host may also process network logs under its configuration.
Purpose
Limit automated or excessive submissions and protect forms and APIs.
Boundary
The MongoDB rate-limit bucket stores the hash rather than the raw IP in that record and is removed by TTL after the window.
07
Administrator sign-in and audit
Information
Google provider subject, administrator email, role and enabled state, plus important-operation summaries that should not contain full PII.
Purpose
Restrict back-office access and preserve accountability for publishing, settings, review and transfer operations.
Boundary
There is no public administrator registration and public users do not sign in with Google.
Lawful basis
Lawful basis must be decided purpose by purpose, not filled by a template
ICO guidance requires a valid lawful basis before each processing activity begins and for that basis to be explained in privacy information. Available rights also vary with the basis.
There is not yet an Article 6 mapping approved by the real controller. Production must not present the following implementation status as an approved lawful-basis decision.
Newsletter and direct marketing
The system uses double opt-in and withdrawal evidence. Final consent wording and PECR analysis await approval.
Requested renewal reminders, enquiries and support
Purposes and minimum fields are separated. The applicable contract or legitimate-interests basis must be decided by the controller against the real service relationship.
Abuse prevention, system security and audit
The technical need is documented. Any legitimate-interests assessment, legal obligation and retention exceptions still require formal review.
Named partner sharing
The product requires separate named confirmation. Lawful basis, controller roles and sharing documents must be approved partner by partner before enablement.
Recipients and transfers
Who may process information for EnergyScope
Recipients are limited to those needed for the website, database, sign-in, email, consented page analytics or a user-requested referral. Listing a provider does not claim its production contract, region or safeguards have completed review.
Current technical direction — provider review pending
Vercel
Website hosting and network-request processing. The production account, region, logs, DPA and subprocessors remain to be checked.
MongoDB Atlas
Contact, purpose, content and audit database. The production cluster region, backups and DPA remain to be checked.
Resend
Processes recipient email and delivery metadata only after the external-email gate is enabled. Without a key or sender, the app does not claim an email was sent.
Google OAuth
Used only for allowlisted administrator sign-in. Public users are not required to create a Google account.
Google Analytics 4
Measures public-page use only when production has a Measurement ID and a visitor explicitly accepts analytics. The Google tag does not load before consent, advertising features remain disabled, and the production account, retention, region, DPA and restricted-transfer assessment remain to be checked.
Partners
There is currently no named partner approved for public claim. Before a future handoff, the company, role, purpose, fields and remuneration relationship are shown and that confirmation recorded. A general privacy notice does not replace the case-specific disclosure.
Processing outside the UK and restricted transfers
Actual provider storage and support locations, whether they create a restricted transfer, and any adequacy or other safeguard have not completed production mapping. The real configuration and how to obtain safeguard copies must be recorded before launch.
Retention
One retention period does not fit every record
Purpose, complaints, permission evidence, audit, legal holds and deletion requests can need different treatment. Rights evidence must not be removed by an indiscriminate TTL.
Subscription confirmation token
Currently valid for 24 hours when created; only its hash is stored and an expired token is removed with MongoDB TTL.
Rate-limit bucket
Counts within a 15-minute window and stores a hashed request key; MongoDB TTL removes the bucket after the window.
Specific periods and deletion procedures still requiring approval before launch
Contacts, business enquiries and support, correction or complaint cases.
Subscriptions, suppression records and renewal reminders.
Permission or referral evidence, email outbox, activity and audit events.
Backups, legal holds, active disputes, statutory or accounting needs, and verified deletion procedures.
Security and minimisation
Technical controls reduce unnecessary information and false success claims
No system can promise absolute security. These are controls implemented in the current code, not a compliance certification.
Public forms use Zod field limits, a 32 KiB payload cap, honeypot, same-origin checks and a production shared-store rate limit.
Sensitive admin pages, APIs and mutations verify session, enabled state and role on the server.
Email action tokens are stored as hashes; outbox token payloads use AES-GCM with a key derived from a server secret.
Production database or email failure reports failure rather than falling back to demo; admin and CRM responses are private and no-store.
Secrets stay out of `NEXT_PUBLIC_*`, Git and audit summaries; audits should not contain full forms or provider payloads.
Public forms do not ask for health, ethnicity, politics, religion, trade-union membership, biometric, sex-life or sexual-orientation information, or criminal data. Do not place unnecessary sensitive data, passwords, full payment-card details, identity documents or signatures in free text.
Automated tools and AI
Current calculators, complaint rules and publication gates do not make solely automated decisions with legal or similarly significant effects on individuals. Estimates, navigation and lower-on-input labels organise information; they do not decide contracts, eligibility, liability, compensation or quotes.
AI may help create or translate drafts but is not human, legal or data-rights review. You edit and copy the complaint AI prompt in the browser. Information you choose to paste into third-party AI is not thereby received by EnergyScope, but it is governed by that third party.
Your rights
Your data-protection rights depend on the processing and lawful basis
Rights may include being informed, access, rectification, erasure, restriction, objection, portability and protection from solely automated significant decisions. Statutory exemptions or restrictions may apply.
Ask whether your information is processed and request a copy.
Correct inaccurate information or complete information that is incomplete.
Request erasure or restriction where the right applies.
Object to processing or request portability where the right applies.
Where processing relies on consent, withdraw it at any time without affecting earlier lawful processing.
Objecting to direct marketing
You may object at any time to personal information being used for direct marketing. Use the unsubscribe or preference link in a newsletter. This does not automatically cancel an unrelated service reminder, enquiry or complaint.
The formal production contact identity is not yet approved. The contact and correction page can currently be used for a privacy request, but this page is not a complete production notice until controller contact details are approved.
Essential cookies may be needed for preferences and administrator authentication. Google Analytics 4 is off by default and loads only when production is configured and you explicitly accept it. Having no cookies would not remove data-protection responsibilities.
Code and official guidance last checked: 3 October 2026. Some ICO guidance is being updated following the Data (Use and Access) Act; recheck it and complete legal/privacy review before production publication.