1. Introduction
CertiMinuz Ltd ("we", "us", "our") is committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, process, and protect your personal data when you use our services, visit our website, or interact with us.
We are registered as a data controller with the Information Commissioner's Office (ICO) under registration number ZA123456. Our registered office is located at 25 Canary Wharf, London E14 5AB, United Kingdom.
2. Information We Collect
2.1 Personal Information
We may collect the following types of personal information:
- Contact Information: Name, address, phone number, email address
- Account Information: Customer account number, billing preferences, payment details
- Energy Usage Data: Meter readings, consumption patterns, smart meter data
- Financial Information: Bank account details, payment history, credit information
- Technical Information: IP address, browser type, device information, website usage data
- Communication Records: Records of calls, emails, and other communications with us
2.2 Sensitive Information
We may collect sensitive personal information in specific circumstances:
- Health information (if you qualify for Priority Services Register)
- Financial information (for vulnerability assessments and support schemes)
- Criminal convictions (for debt recovery purposes, where applicable)
3. How We Collect Information
We collect personal information through various channels:
- Direct Collection: When you apply for our services, contact us, or use our website
- Automatic Collection: Through smart meters, website cookies, and usage analytics
- Third Parties: From credit reference agencies, comparison websites, and previous energy suppliers
- Public Sources: From publicly available databases and registers
4. How We Use Your Information
4.1 Primary Purposes
We use your personal information for the following purposes:
- Providing electricity and gas supply services
- Processing applications and setting up customer accounts
- Billing and payment processing
- Customer service and support
- Managing your account and preferences
- Compliance with legal and regulatory obligations
4.2 Secondary Purposes
We may also use your information for:
- Improving our services and developing new products
- Marketing and promotional communications (where consented)
- Fraud prevention and security purposes
- Statistical analysis and reporting
- Debt management and recovery
- Research and development
5. Legal Basis for Processing
We process your personal information under the following legal bases:
- Contract: To perform our energy supply contract with you
- Legal Obligation: To comply with energy regulations and other legal requirements
- Legitimate Interest: For business operations, fraud prevention, and service improvement
- Consent: For marketing communications and non-essential cookies
- Vital Interest: In emergency situations or for Priority Services Register requirements
6. Information Sharing
6.1 When We Share Information
We may share your personal information in the following circumstances:
- Service Providers: With trusted third parties who help us deliver our services
- Regulatory Bodies: With Ofgem, network operators, and other regulatory authorities
- Legal Requirements: When required by law, court order, or government authority
- Emergency Services: In cases of emergency or safety concerns
- Business Partners: With your consent, for joint services or promotions
6.2 Third-Party Service Providers
We work with carefully selected third parties, including:
- Billing and payment processing companies
- Customer service providers and call centers
- IT support and cloud hosting services
- Marketing and communications agencies
- Credit reference agencies
- Debt collection agencies
7. Data Retention
We retain your personal information for as long as necessary to:
- Provide our services to you
- Comply with legal and regulatory requirements
- Resolve disputes and enforce our agreements
- Maintain accurate financial and business records
Specific retention periods include:
- Customer records: 7 years after account closure
- Billing information: 6 years for tax purposes
- Marketing consents: Until withdrawn or 3 years of inactivity
- Website analytics: 26 months maximum
8. Your Rights
Under UK data protection law, you have the following rights:
8.1 Right of Access
You can request a copy of the personal information we hold about you.
8.2 Right to Rectification
You can ask us to correct inaccurate or incomplete personal information.
8.3 Right to Erasure
You can request deletion of your personal information in certain circumstances.
8.4 Right to Restrict Processing
You can ask us to limit how we use your personal information.
8.5 Right to Data Portability
You can request your personal information in a structured, machine-readable format.
8.6 Right to Object
You can object to processing based on legitimate interests or for direct marketing.
8.7 Rights Related to Automated Decision Making
You have rights regarding automated decision-making and profiling.
9. Cookies and Online Technologies
Our website uses cookies and similar technologies to:
- Ensure the website functions properly
- Remember your preferences and settings
- Analyze website usage and performance
- Provide personalized content and advertisements
You can control cookie settings through your browser or our cookie preference center. For more details, see our Cookie Policy.
10. Security Measures
We implement appropriate technical and organizational measures to protect your personal information:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and employee training
- Secure data centers and backup systems
- Incident response and breach notification procedures
11. International Transfers
We primarily process your personal information within the UK. If we transfer data outside the UK, we ensure appropriate safeguards are in place, including:
- Adequacy decisions by the UK government
- Standard contractual clauses
- Binding corporate rules
- Approved certification schemes
12. Children's Privacy
Our services are not directed at children under 18. We do not knowingly collect personal information from children without parental consent. If you believe we have collected information about a child, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of significant changes by:
- Posting the updated policy on our website
- Sending you an email notification
- Including a notice with your next bill
14. Contact Information
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:
15. Complaints
If you're not satisfied with how we handle your personal information, you can make a complaint to the Information Commissioner's Office (ICO):