Privacy Notice

Last updated: [Date of publication]

This notice explains how [Legal entity name] ("we", "us") handles personal data in the Zero2NetZero service, as required by UK data protection law (UK GDPR and the Data Protection Act 2018). It is written for account holders, their team members, and people whose details are entered into the service, such as supplier contacts.

Who is responsible

For account and usage data we are the controller. For personal data your organisation enters about other people — most notably supplier contact names and email addresses, and any personal data appearing in uploaded documents — your organisation is the controller and we process it on their instructions.

[If registered with the ICO, state the registration number here.]

What we collect

  • Account data: your email address, password (stored as a secure hash by our authentication provider) and role within your company.
  • Company data: your organisation’s Companies House record (a public source) — name, number, registered address, incorporation date and SIC codes — plus the profile figures you enter (employees, turnover, balance sheet) and an optional logo.
  • Emissions and energy data, reduction plans, and generated disclosure documents.
  • Uploaded documents such as utility bills and invoices, which may incidentally contain personal data.
  • Supplier engagement data: contact names and email addresses your team enters, and the responses suppliers submit through secure links.
  • Copilot conversations: the questions you ask and the answers given.
  • Audit records: who did what and when, kept so figures remain defensible.

Why we process it (legal bases)

  • To provide the service you signed up for — performance of a contract.
  • To keep an audit trail supporting your regulatory disclosures — legitimate interests and, where applicable, legal obligation.
  • To secure the service and prevent misuse — legitimate interests.
  • To contact suppliers at your instruction — performed as processor on your organisation’s behalf.

AI processing

Two features send content to third-party AI providers: document extraction (the content of bills you upload) and the Copilot assistant (your questions, together with summary figures from your company’s data needed to answer them). Providers process this to return results to you; [confirm the contractual position — e.g. API data is not used to train their models].

Who we share it with

  • Supabase — database, authentication and file storage.
  • Vercel — application hosting.
  • Anthropic and OpenAI — AI processing described above.
  • Companies House — a public data source we read from; we do not send them your data.
  • No personal data is sold, and none is shared for advertising.
  • [Confirm data processing agreements and the location/transfer safeguards for each provider — e.g. UK/EU hosting regions, International Data Transfer Agreements or UK Addendum for US providers.]

How long we keep it

Company data is kept for as long as the account is active. Emissions records and audit trails use soft deletion so that published disclosures remain reproducible — deleted entries are retained, marked as deleted, for the retention period of [X years] and then removed. On account closure we delete personal data within [X days], except where law requires longer retention.

Cookies

The application sets only strictly necessary cookies: the authentication session cookies needed to keep you signed in. No advertising or third-party analytics cookies are set, so no consent banner is shown. [Update this section before adding any analytics.]

Security

Data is isolated per company at database level (row-level security), transmitted over TLS, and access within a company is role-based and controlled by your admins. Supplier response links are single-purpose tokens with expiry, and only a hash of each token is stored.

Your rights

You have the rights UK GDPR provides: access, rectification, erasure, restriction, portability and objection. To exercise them, contact [contact email address]. Where we act as processor (for example, supplier contact details), we will refer or support the request with the controlling organisation.

You can complain to the Information Commissioner’s Office (ico.org.uk) — though we would welcome the chance to resolve any concern first.

Contact

[Legal entity name], [registered office address], [contact email address]. This notice was last updated on the date shown above; substantive changes will be flagged in the application.