Website, IHD and app privacy notice

The full name of our company is Green Energy Options Limited (“geo”, “we”, “us” or “our”). geo is registered in England & Wales under registration number 5783558. Our registered address is 3 St Mary’s Court, Main Street, Hardwick, Cambridge, CB23 7QS. You can contact us by writing to our Data Protection Officer at our registered address or by email at dpo@geotogether.com.

This Privacy Notice sets out how geo uses, processes and protects any information that you provide or data that is collected when you use the geo website, a geo In-Home Display product (the “IHD”) and/or a geo App (whether this is an app accessed via your phone or via the app website) (together the “Services”). geo is committed to ensuring that your privacy is protected. Should you be asked to provide certain information by which you can be identified (or other “personal data” as defined in the UK Data Protection Act 2018 and/or the UK GDPR) when using the Services, you can be assured that it will only be used as outlined in this Privacy Notice.

This policy may change from time to time. You should check this policy for updates or when notified to ensure that you understand and are happy with any changes. By using or continuing to use the Services, you agree to this policy as in force at the time of that use.

1. Purpose of this privacy notice

This Privacy Notice explains our approach where we act as an independent controller of any personal data that we might collect from you and the purposes for which we process your personal data. This Privacy Notice also sets out your rights in respect of our processing of your personal data.

When we talk about “personal data”, we mean any information which relates to an identified or identifiable living individual. An individual is ‘identified’ or ‘identifiable’ if they can be distinguished from other individuals.

Your Account Data (which we fully define below in What Personal Data We Collect) that you may enter using the App may include your name and contact details and would fall within the definition of personal data. Your Energy Use Data (which we also fully define below in What Personal Data We Collect) collected through the IHD will also fall within the definition of personal data – even though Energy Use Data, on its own, may not include any ‘real world’ identifiers (like your name and contact details).

This Privacy Notice is intended to assist you in making informed decisions when using our Services. Please take a moment to read and understand it.

Where your geo device has been provided to you by your energy supplier, your energy supplier will also process personal data as a separate controller in connection with the supply of energy and related services. Your energy supplier will provide its own privacy notice explaining how it processes your personal data.

This notice does not apply to personal data collected by third parties during your communications with those third parties or your use of their products or services (for example, where your IHD has been provided by your energy supplier and they have collected additional information as part of that process).

2. How to contact us

If you have any questions about this Privacy Notice or want to exercise your rights as a data subject set out in this Privacy Notice, you can contact us using the following methods:

On Site Contact us using our enquiry form on our website.
Email Send us an email at: dpo@geotogether.com
Post Write to us at: The Data Protection Officer, geo, 3 St. Mary’s Court, Main Street, Hardwick, Cambridge, CB23 7QS

 

 

3. What personal data we collect

In providing our Services, we may collect and process different types of personal data about you for different processing purposes. The types of personal data we collect depends on who you are and how you use the Services and includes the following:

Account Data Account username; email address; password; purchase/order details; home address; contact preferences; information added by a user via their account (e.g.  the number of bedrooms in the applicable property, how you heat your home, how many people live in your home).
Hardware Data The device type that our geo App is installed on (e.g. device identification numbers, type of device).

We also collect device related data in order to support the device and its services. This can include MAC address, IP Address, Timezone, Make or Model.

Usage Data We collect information on how you interact with our services, including: The duration of your usage; The pages you open and frequent; The time you spend on each page; Your exit points from the website or app; Your navigation journey through the website or app; How you arrived at the website or app; The pages you view; Your actions on specific pages or within the app (such as links you click on); Whether you access the website or app via a mobile device or laptop; Your web browser type; Demographic information (e.g., age range and gender); Usage patterns within the app, including time spent, interactions, and navigational pathways.
Geo Device Data Smart meter data including: gas consumption (in m3 and/or kWh, conversion factor and cost); Electricity consumption and export (in kWh and cost); Tariffs for energy; Sensor data (e.g. temperature and humidity) (if the system is equipped with these sensors); MPAN (Meter Point Administration Number); MPRN (Meter Point Reference Number); Schedules for specific energy appliances (e.g. heating or EV charging schedules, when a heating system or EV charger is paired with the relevant geo system); Live Power reading (in watts); Pre-payment information if applicable (electricity &/or gas credit /debt / balance); Carbon (kg) from gas energy usage (if supported by meter);

Where you have opted to receive the ‘Smart Metering Device Service’ from geo and you have provided your agreement to obtain this service, the energy consumption data listed above will be provided to geo from your Smart Meter on a half hourly basis.

Location Data Address, Postcode and/or Lat + Longitude if applicable to the service you have requested.
Purchase Data (when you buy a product or service from our Website) Name; telephone number; purchase/order details (what you are buying); home address; contact preferences; email address; shipment address; billing address.
Enquiry Data (including any enquiry form data and chat data) Name; email address; customer narrative submitted via online forms; online chat history.
Payment Data Your billing information, transaction and payment card or other payment method information, bank account and payment details; Billing address;

4. How we collect and receive personal data

We collect and receive personal data using different methods:

 

Personal data you provide to us We will collect the information directly from you, e.g. when you enter information into the Website or your IHD (in-home-device) and the App and when the Services are functioning and gathering your energy data.  We may also capture data from your geo Thermostat if you have one.  This may occur when you change your target temperature or when you direct a change of mode.

We also collect information when you are browsing the Website (please see our Cookies Policy for more information).

Data Provided via your In-Home-Device when you connect to your household wi-fi When you connect your IHD to your home wi-fi we will receive your ‘Account Data’ and ‘Geo Device Data’.

This is so that we can provide the energy data service to you, as requested by you when you use the geo IHD.

 

Personal data received from third parties We may receive personal data about you from third parties. Such third parties may include your energy supplier and third parties that provide technical services to us so that we can provide our Services.

Where we provide services that display or analyse smart meter consumption data, this data may be obtained from your smart meter via the national smart meter infrastructure operated by the Data Communications Company (“DCC”). We access this data using services provided by Procode Technology Limited, which interfaces with the smart meter network on our behalf.

This service uses the Smart Energy Code Party credentials and Party ID: Procode Technology Limited, Hutwood Court, Bournemouth Road, Eastleigh, SO53 3QB.

Freshdesk customer support portal We will use the information supplied by you in our customer support portal to help us resolve any product support queries that you may have.

5. Who we collect personal data about

We collect and process personal data from the following people:

Customers and Users If you buy or use our Services, we may collect and process your personal data in connection with the supply of goods or services to you.

 

 

6. How we use your personal data

We use your personal data for the purposes set out in this section. If we wish to make any changes to these purposes, or if we wish to use your personal data for any purpose that is not listed in this section, we will notify you using the contact details we hold for you:

Register and access your account Personal data used: Account Data, Hardware Data, Location Data;

Explanation: You will register your details with geo in order to gain access to certain features and functionality on a geo app and/or the IHD. We will use the information you provide to identify you when you log in to your account; so that we can administer and contact you about your account; so that we can link your system to your contact details and provide the most appropriate services to you.

To analyse your energy consumption data Personal data used: Geo Device Data

Explanation: When you select this as a service from geo, we will analyse your energy consumption data to generate energy insights and estimates about how energy may be used within your home (sometimes referred to as “energy disaggregation”). This analysis helps us provide you with information about your energy usage and improve our services.

To provide you with and/or show your energy consumption data and other energy related data on or via your device Personal data used: Geo Device Data

Explanation: We may display this information on your IHD and/or via a geo app.  This data may be correlated with input data that you have given, such as your energy tariff information or home temperature.  We may provide this information to you so that you can see how much energy you are using, what it may be costing you and how you can manage your energy usage (e.g. energy saving tips).

Develop our products Personal data used: Account Data, Hardware Data, Usage Data, Geo Device Data, Location Data

Explanation: We use this information to help us to monitor and improve our Services, to assist with the selection of future service lines and to train our personnel.

Develop our Services and make the App services better for our customers Personal data used: Account Data, Mobile Device Data, Usage Data

Explanation: We will also use the information to understand how you use our App so that we can improve it.

Answer your enquiries Personal data used: Account Data, Hardware Data, Location Data

Explanation: When you make an enquiry, we will collect this information, as well as any other personal data you volunteer, to enable us to respond to your enquiry.

To manage our relationship with you including notifying you of changes to the App or any Services Personal data used: Account Data

Explanation: We may use your personal data to inform you of any changes to our Services

Comply with our legal obligations and assist with the administration of our business Personal data used: Account Data, Hardware Data, Usage Data, Geo Device Data, Location Data

Explanation: We may use your personal data: (i) to comply with our legal obligations; (ii) to enforce our legal rights; (iii) to protect the rights of third parties; and (iv) in connection with a business transition such as a merger, reorganisation, acquisition by another company, or sale of any of our assets.

So that we can communicate with your smart meter in order to provide you with the Services Personal data used: Account Data

Explanation: We need to be able to communicate with your smart meter so that we can provide you with your energy information such as consumption information   – in order to do this, the geo devices will use your address to establish the smart meter link.

To provide you with our goods and services when you make a purchase Personal data used: Purchase Data; Payment Data.

Explanation: In order to make a purchase via the Website, we will need to obtain personal data from you so that we can take payment and send the goods to you and / or provide you with the services that you have requested;  we will not store your payment data.

Retaining and evaluating information on your recent visits to our website and how you move around different sections of our website for analytics purposes to understand how people use our website so that we can make it more intuitive or to check our website is working as intended Personal data used: Usage data;

Explanation: Your consent as gathered with reference to our ‘Cookies policy’ available on our website.

 

 

Marketing our services to customers who have enquired about our products or services as well as existing and former customers   Personal data used: Enquiry Data; Purchase Data.

Explanation: For our legitimate interests, i.e. to promote our business to newly enquiring, existing and former customers, to promote product trials and new products.

Customer support portal Personal data used: Enquiry data

Explanation: Customers who email us requesting support for their geo products, we will use the data provided in their email to provide support for their query.

Dealing with technical and hardware faults Personal data used: Account data

Explanation: Data used to identify faults or problems in our products or services and provide fixes. It may also be used to identify faults in other parts of the smart metering system (eg. identify faulty behaviour of non-geo components of the smart meter system).

Anonymisation Sometimes we turn personal data into anonymised information, which means it can no longer be used to identify you.

To do this, we follow the ICO’s Anonymisation Guidance and use safeguards like removing names or other identifiers, combining data, or replacing details with non‑identifying values.

Before anonymising, we reduce the amount of personal data we use and check the risk that anyone could reasonably re‑identify it. Once anonymised, we keep it only in a form where re‑identification isn’t reasonably possible for us or anyone else. We don’t try to re‑identify anonymised data, and we require the same from any partners who process it for us.

We use anonymised information to improve our services, carry out research, run statistical analysis, and develop new features. Because anonymised information can’t identify you, it isn’t considered personal data and isn’t covered by UK data protection law such as the UK Data Protection Act 2018 (and UK GDPR as defined therein) and the UK Data Use and Access Act.

 

 

7. Our legal basis for processing your data

We process your personal data only where we have a lawful basis under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.

7.1 Performance of a Contract (Article 6(1)(b) UK GDPR)
We will use your personal data where it is necessary for us to do so to perform our obligations in accordance with a relevant contract to which you are a party. This may be a contract that we have entered into with you such as the contract you agree when downloading a geo App. This will apply where you create and use a geo App account or purchase products or services directly from geo.

7.2 Legitimate Interests (Article 6(1)(f) UK GDPR)
We process your personal data where this is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Our legitimate interests include:
(a) operating, maintaining, and securing our Apps, platforms, and services;
(b) improving and developing our products and services;
(c) understanding how our services are used;
(d) providing customer support;
(e) preventing fraud and misuse;
(f) managing business reorganisations, mergers, or transfers;
(g) enforcing our contractual and legal rights; and
(h) protecting the rights, property, and safety of users and third parties.

We will use your personal data to send you updates (by email, text message, telephone or post) about our products and/or services, including exclusive offers, promotions or new products.
We may send you marketing communications where permitted under the Privacy and Electronic Communications Regulations (PECR). This will either be based on your consent, or where you are an existing customer and we are permitted to contact you under the ‘soft opt-in’ rules. You can opt out at any time. If we change our marketing approach in the future so that consent is needed, we will ask for this separately and clearly.
Where required under the Privacy and Electronic Communications Regulations 2003 (“PECR”), we will obtain your consent before sending electronic marketing communications. Where consent is not required, we rely on our legitimate interests.
You may opt out of receiving marketing communications at any time by:
• using the “unsubscribe” link in our emails;
• following the instructions in our messages; or
• contacting us directly.
Opting out will not affect service-related or legally required communications.

When we rely on “legitimate interests” as our legal basis for processing your personal data, we carefully consider whether our interests are balanced against your rights and freedoms. We carry out what is known as a legitimate interest assessment (LIA), which involves:

1. Identifying our legitimate interests – These include improving our services, understanding how our website and app are used, supporting customers, developing new features, and promoting our business to existing and potential users.
2. Assessing necessity – We only process the minimum amount of personal data needed to meet these objectives and only where the same purpose cannot reasonably be achieved by less intrusive means.
3. Balancing test – We consider the impact on your privacy and ensure that your interests and fundamental rights do not override our legitimate interests. Where appropriate, we apply safeguards such as data minimisation, pseudonymisation, opt-outs, and access controls.
We believe that this processing is proportionate, does not override your rights or cause undue harm, and is reasonably expected by our users.
We ensure that our processing is consistent with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.
You have the right to object to any processing we carry out on the basis of legitimate interests. For more information, or to raise an objection, please contact us at dpo@geotogether.com.

7.3 Compliance with Legal Obligations (Article 6(1)(c) UK GDPR)
We process your personal data where necessary to comply with our legal and regulatory obligations, including obligations arising under applicable energy, consumer, data protection, and regulatory regimes, court orders, or requests from competent authorities.

7.4 Permission to Access your Smart Meter Data via the DCC (where you are not using a ‘GEO’ device or where there is no IHD present)
To provide you with data services in scenarios where there is no Geo Device (but you may be utilising another supplier’s IHD), we need permission to access your smart meter data through the UK’s smart meter network, known as the Data Communications Company (DCC). This permission is provided by you at the time you set up your IHD.

Under the Smart Energy Code, we must obtain your appropriate permission before accessing your energy data. This means we must take reasonable steps to confirm that you are the person responsible for the property (for example, the bill payer or occupier) and that you have agreed to us accessing your smart meter data.
This permission allows us to securely access your energy consumption data through the DCC so your device (such as your phone when you have the app installed) can display your energy use and provide insights.
This industry permission is separate from data protection law. Once we have access to your data, we process it in accordance with UK data protection laws on the basis of our legitimate interests, as explained in this Privacy Notice.
We will not share your smart meter data with third parties unless you have agreed to this or we have another lawful basis to do so.
You can withdraw your permission at any time by contacting us at customerservices@geotogether.com. If you do, we will stop accessing your smart meter data via the DCC and you will no longer receive that element of the service.
Under Smart Energy Code requirements, your permission will remain valid for a limited period (typically up to 2 years), after which we will ask you to confirm it again.
To provide this element of our services to you, Procode Technology Limited, Hutwood Court, Bournemouth Road, Eastleigh, SO53 3QB acts as a data processor on our behalf for the purpose of accessing and transmitting smart meter data via the DCC infrastructure. Whilst we would prefer you contact us first you can also contact Procode’s Data Protection Officer by emailing Procodedpo@procode.email or writing to: Procode at Hutwood Court, Bournemouth Road, Eastleigh, SO53 3QB.Sharing personal data.

8. Sharing data

We only share personal data with others when we are legally permitted to do so. When we share personal data with others, we put contractual arrangements and security mechanisms in place to protect the personal data shared and to comply with our data protection, confidentiality and security standards and obligations. We will remain as the data controller in these scenarios.

When we share personal data, this may include identifiable data or, where possible, aggregated or pseudonymised data. Where we share data for analytics or research purposes, we aim to use data that does not directly identify you.

When processing your personal data, we may need to share it with third parties as set out in the table below. This list is non-exhaustive and there may be circumstances where we need to share personal data with other third parties.

Payment service providers, warehouses and delivery companies We may share your personal data with payment providers who help deliver our products and/or services to you, e.g. payment service providers for purchases made via the Website, warehouses and delivery companies, our banks
Third-party suppliers who provide applications/ functionality, data processing infrastructure or IT services We share personal data with third parties who support us in providing our Services and help provide, run and manage our internal IT systems. Such third parties may also include, for example, providers of information technology, cloud-based software-as-a-service providers, identity management,  hosting and management, data analysis, data back-up, security and storage services. The servers powering and facilitating that cloud infrastructure are located in secure data centres around the world, and personal data may be transferred to and stored in jurisdictions where our service providers operate. Where this involves transfers outside the UK, we apply appropriate safeguards in accordance with Articles 44–49 of the UK GDPR. We also share your personal data with third-party service providers to assist us with insight analytics and research.
Energy companies We may share personal data with your energy supplier where you have a contract with them for the supply of your home energy.

Your energy supplier acts as a separate data controller for the personal data it processes in connection with the supply of energy and related services.

Where you have enabled relevant features, we may share limited data with energy system operators (such as National Grid or similar organisations) to support services that help optimise energy usage. Where this involves identifiable or detailed household data, we will only do so with your consent.

Auditors, lawyers, accountants and other professional advisers We share personal data with professional services firms who advise and assist us in relation to the lawful and effective management of our organisation and in relation to any disputes we may become involved in.
Law enforcement or other government and regulatory agencies and bodies We share personal data with law enforcement or other government and regulatory agencies or other third parties as required by, and in accordance with, applicable law or regulation.
Another corporate entity in connection with a business transition If we are involved in a business transition such as a merger, reorganisation, acquisition by another company, or sale of any of our assets, we may share or transfer personal data to a third party. Any new owner of our business may continue to use your personal data in the same way(s) that we have used it, as specified in this Privacy Notice.
Other third parties Occasionally, we may receive requests from third parties with authority to obtain disclosure of personal data, such as to check that we are complying with applicable law and regulation, to investigate an alleged crime, or to establish, exercise or defend legal rights. We will only fulfil requests for personal data where we are permitted to do so in accordance with applicable law or regulation.

9. Transfers outside the UK and the European Economic Area ("EEA")

We may transfer, store, and process your personal data outside the UK and the EEA.

Where we do so, we ensure that appropriate safeguards are in place to protect your personal data in accordance with Articles 44 to 49 of the UK GDPR, including by relying on one or more of the following mechanisms:

(a) Adequacy Decisions

We may transfer personal data to countries or territories that have been recognised by the UK Government as providing an adequate level of protection for personal data.

(b) Approved Transfer Mechanisms

Where adequacy regulations do not apply, we may use one or more of the following safeguards:

  • the UK International Data Transfer Agreement (“IDTA”);
  • the UK Addendum to the EU Standard Contractual Clauses; or
  • other contractual safeguards approved by the Information Commissioner’s Office.

These agreements impose contractual obligations on recipients to protect personal data to UK GDPR standards.

(c) Transfer Risk Assessments and Supplementary Measures

Before making restricted transfers, we carry out a documented Transfer Risk Assessment to evaluate the level of protection in the recipient country.

Where necessary, we implement supplementary technical, organisational, and contractual measures to ensure an essentially equivalent level of protection.

(d) Onward Transfers

Where personal data is transferred onward by a recipient, we require equivalent safeguards to be applied to any subsequent transfers.

(e) Access to Safeguards

You may request further information about the safeguards we use, including copies of relevant transfer mechanisms, by contacting us using the details set out in this Privacy Notice.

10. How long we keep your personal data

In respect of personal data that we process in connection with the supply of our Services, we retain personal data only for as long as necessary for the purposes described in this Privacy Notice, including providing the Services, maintaining device functionality, responding to support queries, improving our products and services, and complying with legal or regulatory obligations. We may then destroy such files without further notice or liability.

Where we process personal data in connection with the registration and use of an account on our App or IHD, we may retain your personal data while your account is active and for up to 30 days from the date that the relevant account is terminated (and in compliance with our data protection obligations). We may then destroy such files without further notice or liability.

Where processing is based on your consent (for example, certain optional features or marketing where required under PECR), we will process your data until you withdraw that consent.  If you withdraw your consent, we will delete your data as soon as practicable and within 30 days of your request.

Different categories of data may be retained for different periods depending on legal, regulatory, and operational requirements (for example, transaction data may be retained longer to comply with financial or tax obligations).

11. Confidentially and security of your personal data

We are committed to keeping the personal data you provide to us securely and we have implemented information security policies, rules and technical measures to protect the personal data under our control from unauthorised access, improper use or disclosure, unauthorised modification and unlawful destruction or accidental loss. In addition, all our employees and data processors (i.e. those who process your personal data on our behalf) are obliged to respect the confidentiality of the personal data of all users of our Services.

12. Personal data of minors

Our Services are not intended for use by, or targeted at, minors (individuals under the age of 18) and we do not knowingly collect personal data of minors. However, this does not prevent minors from providing personal data to us. If we do collect personal data of minors, we will comply with all applicable laws and regulations relating to the processing of personal data of minors.

If you are under the age of 18, you must not use our App or purchase Services from us and you must not provide us with any personal information. If we discover that we are holding the personal data of a minor, we will delete that information as soon as possible. Please contact us if you have reason to believe that a minor may have submitted personal data to us (see the “How to contact us” section above).

13. Your rights as a data subject

You have certain rights in relation to the personal data we hold about you. These rights include the right: (i) to obtain copies of your personal data; (ii) to have your personal data corrected or deleted; (iii) to limit the way in which your personal data is used; (iv) to object to our use of your personal data; (v) to transfer your personal data; (vi) not to be subject to decisions based on automated processing (including profiling); and (vii) to complain to a supervisory authority.

If you would like to exercise any of these rights, please contact us using the details set out in the “How to Contact Us” section above.

 

Your right of access If you ask us, we will confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data (along with certain other details). If you require additional copies, we may charge a reasonable fee for producing those additional copies.
Your right to rectification If the personal data we hold about you is inaccurate or incomplete, you are entitled to have it rectified. If we have shared your personal data with others, we’ll let them know about the rectification where possible. If you ask us, where possible and lawful to do so, we will also tell you who we’ve shared your personal data with so that you can contact them.
Your right to erasure You can ask us to delete or remove your personal data in some circumstances, such as where we no longer need it or where you withdraw your consent (where applicable). If we have shared your personal data with others, we will let them know about the erasure where possible. If you ask us, where it is possible and lawful for us to do so, we will also tell you who we have shared your personal data with so that you can contact them directly.
Your right to restrict processing You can ask us to “block” or suppress the processing of your personal data in certain circumstances such as where you contest the accuracy of that personal data or you object to us processing it for a particular purpose. This may not mean that we will stop storing your personal data but, where we do keep it, we will tell you if we remove any restriction that we have placed on your personal data to stop us processing it further. If we’ve shared your personal data with others, we’ll let them know about the restriction where it is possible for us to do so. If you ask us, where it is possible and lawful for us to do so, we’ll also tell you who we’ve shared your personal data with so that you can contact them directly.
Your right to data portability You have the right, in certain circumstances, to obtain personal data you have provided to us (in a structured, commonly used and machine-readable format) and to reuse it elsewhere or to ask us to transfer it to your chosen third party.
Your right to object You can ask us to stop processing your personal data, and we will do so, if we are: (i) relying on our own or someone else’s legitimate interest to process your personal data, except if we can demonstrate compelling legal grounds for the processing; or (ii) processing your personal data for direct marketing purposes. This right is separate from any permissions you have provided under the smart meter framework.
Your rights in relation to automated decision-making and profiling You have the right not to be subject to a decision when it is based on automatic processing, including profiling, if it produces a legal effect or similarly significantly affects you, unless such profiling is necessary for the entering into, or the performance of, a contract between you and us.
Your right to withdraw consent If we rely on your consent (or explicit consent) as our legal basis for processing your personal data, you have the right to withdraw that consent at any time. You can exercise your right of withdrawal by contacting us using our contact details in the “How to Contact Us” section above or by using any other opt-out mechanism we may provide, such as an unsubscribe link in an email.
Your right to lodge a complaint with the supervisory authority If you have a concern about any aspect of our privacy practices, including the way we have handled your personal data, please contact us using the contact details provided in the “How to Contact Us” section above. You can also report any issues or complaints to the Information Commissioner’s Office (“ICO”). Contact details for the ICO can be found on its website at https://ico.org.uk.

 

Last reviewed: 24th October 2024