How EnergySignal processes personal data, on what legal basis, and the rights you hold under the GDPR.
The controller of your personal data is EnergySignal s.r.o., IČO [●], registered in the Commercial Register kept by the Municipal Court in Prague, File No. C [●], with its registered seat at Na Folimance 2155/15, Vinohrady, 120 00 Praha 2, Czech Republic. You can reach us at info@energysignal.io for any privacy matter.
We keep collection narrow. Depending on how you interact with us, we process:
Contact correspondence. If you email or call us: your name, contact details, and the content of the exchange. Purpose: responding and managing the business relationship. Legal basis: our legitimate interest in communicating with our contacts and managing our business relationships, or steps taken prior to entering into a contract.
Business contacts received from partners. In the course of our brokerage business we may receive the name, role, and business contact details of counterparty personnel from our business partners and introducers. Purpose: making introductions and managing the resulting relationships. Legal basis: our legitimate interest in conducting our brokerage business. Where we receive your details from a partner in this way, we direct you to this policy when we first contact you.
Access requests and acceptance records. If you request model access under our Terms and Conditions of Model Access: first name, last name, email address, the terms version you accepted, a timestamp, and the IP address from which the acceptance was sent. Purpose: granting access and evidencing acceptance of the terms. Legal basis: performance of a contract and our legitimate interest in establishing, exercising, and defending legal claims.
Authenticated access data. When you sign in to a protected area: your email address and sign-in events, processed through our access-control provider. Purpose: security and ensuring each person sees only what they are authorised to see. Legal basis: our legitimate interest in network and information security, and performance of a contract.
Model feedback. If you send a note through a model's feedback panel: your name, your message, and the model settings at the time of sending, together with your verified access identity. Purpose: responding to your question and developing the engagement. Legal basis: performance of a contract and our legitimate interest in improving our services.
Technical data. Our hosting infrastructure processes IP addresses and request logs for delivery and security. Purpose: operating and protecting the site. Legal basis: our legitimate interest in network and information security.
Providing your data with an access request is a contractual requirement. Without it, we cannot grant access. Everything else you provide voluntarily.
We do not run advertising or marketing trackers, we do not sell or share personal data for marketing, and we do not use analytics cookies. We do not make automated decisions with legal effect about you.
The public site sets no tracking cookies. Three narrow exceptions exist: a preference stored on your own device, solely at your request, to remember your dark or light theme choice (never transmitted to us); strictly necessary authentication cookies set by our access-control provider when you sign in to a protected area; and strictly necessary security cookies set by our infrastructure provider (Cloudflare) to protect the site against abuse and to distinguish automated from human traffic. Under § 89(3) of Act No. 127/2005 Sb., on electronic communications, storage that is strictly necessary or provided solely at your explicit request does not require consent, so no cookie banner is shown.
We use a small number of infrastructure providers acting as processors: Cloudflare, Inc. for hosting, content delivery, access control, and storage of access and acceptance records, and Google Ireland Limited (Google Workspace) for business email. Web fonts are self-hosted: loading a page does not transmit your IP address to any third-party font provider.
Some of our providers are established in, or route data through, the United States. Where personal data leaves the European Economic Area, it is protected by recognised safeguards: the EU-US Data Privacy Framework where the recipient is certified under it, and standard contractual clauses otherwise or in addition. You can request a copy of the relevant safeguards at info@energysignal.io.
Correspondence is kept for the duration of the relationship and up to four years after our last contact, unless a longer period is needed for legal claims. Acceptance records are kept for the duration of the engagement and for the limitation periods applicable to legal claims, generally three to ten years under Czech law. Access and security logs are kept on short rotation, typically no longer than 90 days. Records we must keep under accounting and tax law are retained for the statutory periods, generally five to ten years. When data is no longer needed, it is deleted.
Under the GDPR you can request access to your data, rectification, erasure, restriction of processing, and portability, and you can object to processing based on our legitimate interests. Write to info@energysignal.io. We respond within one month; for complex requests we may extend this by a further two months and will tell you if so. You also have the right to lodge a complaint with the Czech supervisory authority, the Úřad pro ochranu osobních údajů (uoou.gov.cz), or with the supervisory authority of your habitual residence.
If this policy changes, the new version is published here with an updated effective date. Material changes affecting active counterparties are notified directly.