Governance
Privacy Policy
This notice explains what personal data PUEpredict processes when you use the platform, why we process it, and the rights you have under the UK GDPR and the Data Protection Act 2018.
Version 1.0 · Last updated 1 September 2026 · PUEpredict Limited (in formation), United Kingdom
1. Who we are
PUEpredict Limited (in formation) is the controller of the account and contact data described below. Where we process facility telemetry and operational records on behalf of a customer organisation, that customer is the controller and we act as processor under the Data Processing Addendum.
Privacy enquiries and data subject requests: privacy@puepredict.co.uk.
2. Personal data we process
- Account data — name, work email address, tenancy role, and the timestamp of your most recent sign-in.
- Authentication data — a password verifier (a salted hash; we never store or receive your password in readable form) and session tokens.
- Usage and audit data — which reports you generated or exported, and which recommendations you accepted, deferred or rejected, retained as an audit trail because compliance output must be attributable.
- Operational data — facility names, locations, IT load, cooling configuration and telemetry readings. This is normally organisational rather than personal data, but it is treated with the same controls.
We do not process special category data, we do not use automated decision-making that has a legal effect on you, and we do not run advertising or profiling.
3. Lawful bases
- Contract — creating and operating your tenancy, authenticating you, and producing the dashboards and compliance output you have subscribed to.
- Legitimate interests — securing the service, preventing abuse, maintaining audit trails, and improving model accuracy using aggregated, non-identifying measures. Peer benchmarking is opt-in and only ever reports cohort statistics where at least five sites contribute.
- Consent — optional analytics and interface-preference storage, and any marketing email. Consent can be withdrawn at any time on the cookies page.
- Legal obligation — retaining records we are required to keep, for example to support ESOS, SECR or CCA evidence trails.
4. Sub-processors and hosting
Platform data is hosted on managed cloud infrastructure in the United Kingdom or European Economic Area. We use a small number of sub-processors for hosting, database and authentication services, transactional email (account confirmation, password reset and team invitations), and error monitoring. The current list, with locations and safeguards, is maintained in the Data Processing Addendum and customers are notified before a new sub-processor is engaged.
Where a transfer outside the UK is unavoidable, it is made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses together with a transfer risk assessment.
5. Retention
- Account and profile records: for the life of the tenancy, then deleted within 30 days of termination.
- Telemetry readings: retained for the contracted period (12 months on Enterprise) then aggregated to daily means.
- Generated compliance reports and export records: six years, because they evidence statutory submissions.
- Security and access logs: 12 months.
6. Security
Access is enforced in the database itself: every table applies row-level security scoped to your tenancy, so one operator can never read another operator's facilities, readings or reports regardless of what a browser requests. Roles are held separately from profile records and evaluated server-side. Traffic is encrypted in transit with TLS, data is encrypted at rest, passwords are stored only as salted hashes, and privileged operations re-verify the caller's role on the server.
7. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where consent is the basis. Requests are answered within one month. If we act as processor for your employer, we will refer your request to them and assist them in answering it.
You may complain to the Information Commissioner's Office (ico.org.uk). We would ask for the chance to resolve the matter first.
8. Changes
Material changes are notified to tenancy Operations Leads by email at least 30 days before they take effect. The version and date at the top of this page always reflect the current notice.
