ELECTRICAL ONE LTD (“we”, “us”) is the data controller for personal data processed through Electrical1. This policy explains what we collect, why, and your rights under the UK GDPR and CCPA.
Data we collect
- Account data — email, hashed password, plan, billing identifiers.
- Audit inputs — your typed messages, uploaded photos of meters / fuse boxes / appliances, monthly kWh figures.
- Outputs — diagnostic charts, hazard overlays, Audit Reels generated for you.
- Operational data — IP address, device class, log timestamps, error reports.
- Payment data — handled by Stripe; we store only the customer identifier and last four digits.
How we use it
- To run audits and generate outputs you requested.
- To bill your subscription and prevent fraud.
- To improve product quality using aggregated, anonymous statistics.
- To respond to support tickets you open.
- To meet legal obligations.
We do not use your individual audit inputs to train general-purpose AI models. We do not sell your personal data.
Legal bases (UK GDPR)
- Contract — to deliver the audit you purchased.
- Legitimate interests — security, fraud prevention, product improvement.
- Consent — optional marketing emails.
- Legal obligation — bookkeeping, tax, lawful requests.
Sub-processors we use
- Stripe Payments Europe Ltd — card processing (PCI-DSS Level 1).
- PayPal (Europe) S.à r.l. et Cie, S.C.A. — PayPal / Pay-later (PCI-DSS Level 1).
- Creem — Merchant-of-Record processing for select markets (PCI-DSS Level 1).
- Vercel Inc. — application hosting and edge delivery (US / EU regions, encrypted at rest).
- Supabase Inc. — auth and database (EU region by default).
- Transactional email provider (DPA on file).
- Error monitoring — IP truncated, no PII in stack traces.
We sign Data Processing Addenda with each sub-processor and review them annually. None of our payment sub-processors are authorised to use your data for marketing.
Retention
- Account data — kept while the account is active, plus 12 months after closure.
- Audit inputs and outputs — retained for 90 days unless you delete them earlier from the dashboard.
- Billing records — 6 years (UK statutory).
Your rights
You have the right to:
- Access a copy of your data.
- Correct inaccurate data.
- Erase your account (we will retain billing records as required by law).
- Object to or restrict processing.
- Port your data to another provider.
- Withdraw consent for marketing at any time.
CCPA residents have equivalent rights, including the right to opt out of any future sale or share (we currently sell and share none).
Email support@electrical1pro.com with the subject “Data Request”. You can complain to the UK ICO at ico.org.uk.
International transfers
Some sub-processors are based in the United States. We rely on UK IDTA / EU SCCs and additional technical safeguards (encryption, access controls) for any transfer outside the UK or EEA.
Children
Electrical1 is not intended for users under 18. We do not knowingly collect data from children.
Contact
Data controller: ELECTRICAL ONE LTD, 9 Meadow Close, Sutton, SM1 3LP. Email support@electrical1pro.com.