Personal Data Protection
Last modified: 16 March 2023
Who is the data controller?
Otovo Limited, a company registered in England with number 14031127, whose registered office is at 167-169 Great Portland street, 5th Floor, London, W1W 5PF (“Otovo”), is the data controller of the data collected through the Platform.
Purposes and legal basis for processing
All the personal data collected through the Platform may be processed on following legal basis:
- Contract:This covers carrying out our contractual duties and exercising our contractual responsibilities, as well as our need to estimate the solar potential at an address, for the purpose of entering into a contract with you regarding purchase and/or subscription of domestic solar and/or battery energy storage installation(s) (and any related installation services) (the “Agreement”).
- Consent: You have given specific consent to processing your data. Generally we rely on consent as a legal basis for processing your personal data to send emails concerning the estimated solar potential at your relevant address, and personalised communication on subsidies, product benefits, special offers and Otovo’s other products and services. You have the right to withdraw consent to us sending you this information at any time by sending an email to email@example.com.
- Legal obligation: Processing necessary to comply with our legal and regulatory obligations.
- Legitimate Interests: Processing necessary for our or a third party’s legitimate interests. Your data will not be processed on this basis if our or a third party’s interests are overridden by your own interests, rights and freedoms.
Personal data we process about you
When you check the solar potential of your roof, we collect your home address, and email address from you if you have provided your consent for this purpose. We may also ask for additional data in order to calculate an estimate of your electricity consumption for the purpose of providing adapted installations sizes. The purpose is to be able to provide an estimate for the installation of solar cells on your roof, as well as to managing your customer relationship and completing the delivery. The email address is used to communicate with you in the form of personal follow-up, newsletters and any other communication on Otovo’s products and services that you may be interested in. If you do not wish to receive newsletters, you may opt out here.
We collect and store data about the address for which you are estimating the solar potential, such as azimuth, slope of your roof, area and roof height, in order to make an estimate of the energy potential from solar cells on your roof, as well as a price calculation. We save this information for analysis, so that we can make calculations better in the future.
If you would like to proceed with an estimate, we will ask for your name, phone number and email address so that we can contact you to clarify any doubt and, if appropriate, send you a formal offer. All the information requested is necessary for entering into the Agreement. If you fail, or refuse, to provide this information, Otovo will not be able to enter into a contract with you.
If you accept the offer, we may send your name, telephone number and the contractual document to one of our partners for digital signatures, such as Scrive, who will act as a data processor.
In the case where this information is required, we may also ask for your personal ID number. If so, the purpose will be to complete applications where this information is necessary and/or to perform a credit check of you to evaluate your credit worthiness and ability to fulfil your obligations under the Agreement. Your personal ID number will be stored encrypted.
How long will we retain your personal data?
The period that we will retain your personal data depends on the purpose for which it was obtained. If your data is used for several purposes requiring different retention periods we will apply the longest one.
Personal data processed on the basis of your consent, will be retained until you withdraw your consent, or request the erasure or objection of your data.
Personal data processed for the performance of the Agreement, will be retained during the whole relevant contractual relationship.
Personal data processed under Otovo’s legitimate interests, will be retained as long as Otovo needs to comply/achieve them.
Once these periods have ended or your request to erase your personal data has been fulfilled, we will only retain your personal data duly blocked for the periods required by law. This means they may not be processed, for any other purpose than to make it available to courts or competent public authorities, to comply with any liability arising from the processing and only during its limitation period. Once this period has expired, the data will be destroyed.
With whom can we share your personal data?
If you have chosen to switch electricity providers to one of our partners, in connection with ordering a solar system, we will send your contact information to your chosen electricity provider so that they can contact you.
We may share your information with data processors in the field of energy consumption in order to ask for your electricity consumption for the purpose of providing adapted installations sizes.
After Otovo has planned your installation in detail, we share your contact information, address and project data with our installer.
When connecting your installation to the electrical grid, we share your contact information and information about the solar panel installation with your electrical grid owner.
Once the installation is operational and connected to the network, production data from your inverter will be shared with the manufacturer of the inverter for analysis and potential troubleshooting. These data say nothing about your residential energy use in general, only whether the sun shines on your installation.
The production data from the installation will also be collected by Otovo. This information is used for analysis and potential troubleshooting. The data serves as the basis for the statistics found on My Page and in the Otovo apps.
Otovo may use production data associated with addresses to improve calculation models, both internally and in collaboration with other entities in the solar power industry, and share these publically. When sharing the data, it will be rendered anonymous to the greatest extent possible, but location is an important element in the analysis of production data.
Your personal data may be shared with data processors providing services to Otovo. Otovo will ensure that all of them comply with the current data protection legislation by signing a data processing agreement pursuant to art. 28 of the General Data Protection Regulation.
We may share your personal data, including your personal ID number, with credit reference agencies. In these cases we will supply your personal information to credit reference agencies, who will give us information about you, such as your financial history. More information about how our credit reference agency, TransUnion, operates and handles data, can be found here.
We use Google service and Google Advertising service, notably to serve you personalized and non-personalized ads, provided that you accept targeting cookies and scripts. We may share personal data, such as name, email and phone number, with Google. This allows us to better target our ads. To learn more about how Google uses your data, please refer to Google’s Privacy & Terms site
We may share personal data where it is otherwise allowed under the law where necessary to protect our or a third party’s legitimate interests, where required to comply with our obligations to regulators or law enforcement agencies or where we have obtained your prior consent to do so.
Chat and email
When you communicate with us via email at one of our support or sales email addresses, or the web chat feature at the website, the exchange of messages is saved so that we can best serve you over time. Both chat messages and emails are saved in Hubspot.
We currently use MailChimp for sending out our newsletter. In connection with this, your email address will be saved together with information like which product you showed interest in and what region you live in. If you opt out of the newsletter, the service will still have your email address in its system to prevent you from becoming re-enrolled. Any other data will be deleted.
These companies act as data processors.
In order to be able to improve our software, we log exceptions and errors that occur on our website, and on the apps. These error events, along with data associated with the state the system was in when it failed, are collected by an external service. We currently use Sentry for this. The information is stored for 90 days.
Data Storage and Back-Up Systems
The website and Otovo apps use several Otovo services on the back end. These services run exclusively in the cloud and therefore use multiple third party systems. Servers, databases and data storage provided by Amazon and Heroku, which is a service provider on top of the Amazon platform, owned by Salesforce. We use data centres in Europe, if possible, primarily in Ireland and Germany.
Automatic SMS and emails
We use Mailgun for sending out automatic emails, and Twilio for both emails and SMS. For example, this could be information on changes regarding the installation, etc. The services store metadata for tracking and troubleshooting.
For internal communications we use Slack. Our back-end systems send updates to this service in connection with events related to customer behaviour. Among other things, these updates may contain name, address and contact information.
For email and file storage we use Google G Suite. See “Password Routines” below, for how we manage access to these services.
The above mentioned companies act as data processors.
Access To Sensitive Data
Where our systems handle sensitive data, these are only accessible to Otovo’s developers and other employees with a justified need for access. Encryption codes, which among other things are used for the storage of sensitive data, are only accessible to Otovo’s developers. All machines used in development, and that may have copies of data from production systems, have an encrypted file system.
All data communication with external partners is encrypted.
All Otovo employees are required to use two-factor authentication when logging in to Otovo’s systems, as well as password-protected telephones and devices. All external collaboration partners (installers, etc.) who have access to Otovo’s systems use personal accounts with access only to relevant parts of the system.
You may request us at any time for access, copy, rectification, restriction or deletion of the personal data we store about you, such request should be addressed to Otovo by written request to our business address or by email to firstname.lastname@example.org, providing some proof of your identity (e.g. a photocopy of your ID card or passport). Under certain circumstances you may also object to processing as well as exercise your right to data portability.
Changes To The Privacy Protection Declaration
We will keep your privacy protection declaration updated as the service offer changes. At the top of the page, you will find a date stamp for when we last updated the content. If we make any major changes that affect registered customers, you will be notified of this by email.
You have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK regulator for data protection issues ( www.ico.org.uk). Otovo has its own privacy representative who can be contacted by emailing email@example.com.