This policy and any other documents referred to within sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Under the General Data Protection Regulations (GDPR) you have a number of rights and this policy outlines them. For further information on your rights under the new data protection regulations please visit the ICO website.
Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
For the purpose of the GDPR, the data controller is Sandal Plc whose registered office is Claremont House, Deans Court, Bicester, Oxon OX26 6BW.
Our main contact address is Unit 5, Harold Close, The Pinnacles, Harlow, Essex, CM19 5TH.
This policy covers all users who use the Energenie website.
The Energenie website is operated by Sandal PLC. We are committed to protecting your privacy when you are using our online services. To protect your privacy, we apply eleven principles which you can read about below.
During payment process, we ask for personal information which both identifies you and enables us to communicate with you. We will retain this information for a period of 6 years for a number of purposes such as HMRC auditing, customer support and warrantee, and complaint handling.
To help us prevent fraud, please be aware that we may make searches about you at credit reference agencies for the purpose of verifying your identity. These agencies will supply us with information, including information from the Electoral Register. The fact that we have requested an identity check is recorded by these agencies, though be assured that the searches will not be seen or used by lenders to assess your ability to obtain credit.
Please also note that we may cross reference the information you provide us with data from a specialist anti-fraud third party with a view to stopping fraudulent transactions before they occur.
Energenie do not disclose buyers' information to third parties other than when order details are processed as part of the order fulfilment. In this case, the third party will not disclose any of the details to any other third party.
We use a third party provider, Zendesk, to manage our interactions with you when you contact us via e-mail (using our firstname.lastname@example.org, email@example.com, or firstname.lastname@example.org), the contact form on our website, or via social media. Messages will be stored by Zendesk for 6 years to enable us to help monitor and improve customer satisfaction. It will not be shared with any other organisations. You can find out about Zendesk and GDPR compliance at their website here https://www.zendesk.co.uk/company/customers-partners/eu-data-protection/
If you e-mail a member of our staff directly we use Mimecast to process e-mail traffic to us. Transport Layer Security (TLS) is used to encrypt and protect email traffic. If your email service does not support TLS, you should be aware that any emails we send or receive may not be protected in transit.
We will also monitor any emails sent to us, including file attachments, for viruses or malicious software. Please be aware that you have a responsibility to ensure that any email you send is within the bounds of the law.
When you call us we collect Calling Line Identification (CLI) information. We use this information to help improve its efficiency and effectiveness. This data is stored for 7 days in the system and then replaced.
We use a third party provider, Zendesk, to supply and support our LiveChat service, which we use to handle customer enquiries in real time.
If you use the LiveChat service we will collect your name (optional), email address and the contents of your LiveChat session. This information will be retained for six years and will not be shared with any other organisations.
You can request a transcript of your LiveChat session if you provide your email address at the start of your session or when prompted at the end.
Like many websites https://energenie4u.co.uk uses a third party service, Google Analytics, to collect anonymous standard internet log information and details of visitor behaviour patterns. We do this to find out things such as the number of visitors to the various parts of the site. You can find out more about Google Analytics and how the data we collect through this service is protected here https://support.google.com/analytics/answer/6004245?hl=en
Our website search feature does not use any 3rd party software and stores only the searched phrase, along with the date it was searched for. It does not store any user-specific data.
Energenie does not undertake any form of automatic decision making with respect to the personal identifiable data we collect.
Where you have given your consent, we will use the information you provide only for the following purposes:
You have the right to ask for a copy of your personal information free of charge (unless the request is excessive, repetitive or manifestly unfounded). Under statutory regulations we have up to 1 month to provide your information.
Sandal Plc uses a third party service to help maintain the security and performance of the Energenie website. To deliver this service the hosting server processes the IP addresses of visitors to the Energenie website. We have taken appropriate measures to ensure that your personal information is not unlawfully processed. Energenie uses industry standard practices to safeguard the confidentiality of your personal identifiable information, including firewalls and SSL. Energenie treats data as an asset that must be protected against loss and unauthorized access. However, no information transferred over the Internet or wireless network can be guaranteed to be completely secure. We employ many different security techniques to protect such data from unauthorised access by users inside and outside the company.
We will not transfer your personal information outside of the European Economic Area (EEA) unless required for operation and support purposes, (Zendesk only) and where it is we have a specific data sharing agreement in place to ensure protection of your data.
For general information regarding cookies, please visit http://en.wikipedia.org/wiki/HTTP_cookie
Our website creates multiple essential cookies on your machine which contain session and state information, (e.g. keeps track of the contents of your shopping cart, stores your delivery addresses if the address book is used, and stores your details if you select the 'Remember Me' Option. A number of non essential cookies are also stored which contain anonymous data (see google analytics section of this policy). Our website requires cookies to be enabled in the web browser and in any third party security programs to allow tasks such as registering, logging in, buying items or accessing accounts. Please be aware that should cookies be disabled or blocked by third party software, many of our website's features will be impaired or unavailable.
Data collected by this site is used to:
Full details of all cookies used by the Energenie site are given in our cookie info page here Cookies Info
The Energenie website is not intended for children and we ask that no-one under the age of 13 submits personal information to us or uses the site without supervision of a parent or guardian.
The GDPR gives you the right to have the data we hold on you deleted under certain circumstances such as where:
Instances where the right to erasure does not apply includes (but not limited to):
The GDPR gives you the right to have the personal data we hold on you, or our selected partners to which we have provided information to, to be rectified if it is inaccurate or incomplete.
The GDPR gives you the right to 'block' or suppress processing of personal data. In such cases Sandal Plc will continue to store your personal data but not process it further.
Should you wish to obtain and reuse your personal data which we hold we will provided it in a standard readable format (e.g. MS Office)
You have the right to object processing of your information where:
Please use the form below to get in touch