Privacy Policy
Introduction
We are Smart Merchant Energy Ltd, incorporated in England and Wales. Our registered office is at 252-262, Romford Road, London, England, E7 9HZ (Company number: [ 17171658 ]). In this notice, we refer to Smart Merchant Energy Ltd.
We are committed to protecting and respecting your privacy. This notice explains the basis on which we collect, use, store and share any personal data you provide to us, or that we obtain about you, whether through our website, over the phone, by email, or in the course of providing our services.
Please read this notice carefully. It should be read alongside any other privacy or fair processing notice we may give you on specific occasions, so that you are fully aware of how and why we use your data. This notice supplements those other notices and does not override them.
Our services are intended for businesses and business decision-makers. Our website is not directed at children and we do not knowingly collect data relating to children.
Contents
- Important information and who we are
- Changes to this privacy notice
- The personal data we collect about you
- How we collect your personal data
- How and why we use your personal data
- Marketing and your choices
- Who we share your personal data with
- Credit reference and fraud prevention agencies
- Call recording and monitoring
- Automated decision-making
- International transfers
- Data security
- How long we keep your personal data
- Your legal rights
- Cookies
- Glossary
1. Important information and who we are
1.1 Controller. Smart Merchant Energy Ltd is the controller responsible for your personal data collected through our website and in the course of providing our services.
1.2 Contact details. If you have questions about this notice, or wish to exercise any of your rights, you can reach us at:
| Legal entity | Smart Merchant Energy Ltd |
| Contact | 252-262, Romford Road, London, England, E7 9HZ |
| info@smartmerchantenergy.com | |
| Postal address | 252-262, Romford Road, London, England, E7 9HZ |
| Telephone | +004407552826909 |
1.3 Complaints. You have the right to complain at any time to the ICO, the UK supervisory authority for data protection matters (ico.org.uk). We would appreciate the opportunity to address your concerns first, so please contact us before approaching the ICO.
1.4 Third-party links. Our website may contain links to third-party websites, plug-ins and applications. Following those links or enabling those connections may allow third parties to collect or share data about you. We do not control those sites and are not responsible for their privacy practices. We encourage you to read the privacy notice of every website you visit after leaving ours.
2. Changes to this privacy notice
We review this notice regularly to make sure it accurately reflects how we use your personal data, and we may update it from time to time. Any changes will be posted on this page, so please check back on your next visit.
It is important that the personal data we hold about you is accurate and current. Please tell us if any of your details change or need correcting.
3. Marketing and your choices
6.1 We may use your Identity, Contact, Technical, Usage and Profile Data to form a view of what products, services and offers may be relevant to you.
6.2 You will receive marketing communications from us if you have requested information from us, obtained a quote, or arranged products or services through us, and in each case have not opted out.
6.3 Third-party marketing. We will obtain your express opt-in consent before we share your personal data with any third party outside our group of companies for their own marketing purposes.
6.4 Opting out. You can ask us or any third party to stop sending you marketing messages at any time by using the unsubscribe link in any message, or by contacting us using the details in section 1.2. Opting out of marketing will not affect personal data we hold as a result of a product or service you have arranged, a contract, or another transaction.
4. Credit reference and fraud prevention agencies
In order to process an application, we may supply your personal information to credit reference agencies (“CRAs“), and they will give us information about you, such as your financial history. We do this to assess creditworthiness and product suitability, verify your identity, manage your account, trace and recover debts and prevent criminal activity.
We may continue to exchange information about you with CRAs on an ongoing basis, including information about settled accounts and any debts not fully repaid on time. CRAs will share your information with other organisations. The identities of the CRAs, and the ways in which they use and share personal information, are explained in more detail in the Credit Reference Agency Information Notice (CRAIN), which is available on each CRA’s website.
5. Call recording and monitoring
We record telephone calls made to and from our offices. It is in our legitimate interests to do so in order to:
- maintain and evidence the quality of our customer service;
- train and support our staff;
- confirm the details of any agreement made over the phone; and
- investigate and resolve any query or complaint we receive.
We may also transcribe calls and carry out sentiment analysis on them. We rely on our legitimate interests for this processing, as it helps us understand and improve the quality of our customer interactions and identify areas for service improvement. We do not use transcripts or sentiment analysis outputs to make legally binding decisions about you, and any decision informed by them will be subject to human review before any action is taken.
6. Automated decision-making
We do not currently make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing. If this changes, we will update this notice and inform you of your rights, including your right to obtain human intervention, to express your point of view and to contest the decision.
7. International transfers
11.1 Some of our external third parties are based outside the United Kingdom, so their processing of your personal data may involve a transfer of data outside the UK.
11.2 Whenever we transfer your personal data outside the UK, we make sure a similar degree of protection is given to it by ensuring at least one of the following safeguards is in place:
- we transfer to a country that has been deemed by the UK government to provide an adequate level of protection for personal data;
- we use specific contracts approved for use in the UK, such as the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, which give personal data the same protection it has in the UK; or
- we rely on another lawful transfer mechanism permitted under UK data protection law.
11.3 Please contact us using the details in section 1.2 if you would like more information about the specific mechanism we use when transferring your personal data outside the UK.
8. Data security
12.1 We have put in place appropriate technical and organisational security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. We limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and are subject to a duty of confidentiality.
12.2 We have procedures in place to deal with any suspected personal data breach, and will notify you and any applicable regulator where we are legally required to do so.
9. Your legal rights
14.1 Under data protection law, you have the following rights in relation to your personal data in certain circumstances:
- Request access to your personal data (commonly known as a “data subject access request”). This lets you receive a copy of the personal data we hold about you and check that we are processing it lawfully.
- Request correction of the personal data we hold about you. This lets you have any incomplete or inaccurate data corrected, although we may need to verify the accuracy of the new data you provide.
- Request erasure of your personal data. This lets you ask us to delete or remove personal data where there is no good reason for us to continue processing it. You can also ask us to delete data where you have successfully objected to processing, where we may have processed your information unlawfully, or where we are required to erase it to comply with the law. We may not always be able to comply with an erasure request for specific legal reasons, which we will explain to you at the time.
- Object to processing where we rely on a legitimate interest and there is something about your particular situation that makes you want to object on that ground. You also have an absolute right to object where we process your personal data for direct marketing purposes. In some cases we may demonstrate compelling legitimate grounds to continue processing that override your rights and freedoms.
- Request restriction of processing. This lets you ask us to suspend processing in the following situations: if you want us to establish the data’s accuracy; where our use of the data is unlawful but you do not want it erased; where you need us to hold the data even though we no longer require it, because you need it to establish, exercise or defend legal claims; or where you have objected to our use of the data and we are verifying whether we have overriding legitimate grounds.
- Request transfer of your personal data to you or to a third party. We will provide your personal data in a structured, commonly used, machine-readable format. This right only applies to automated information which you initially provided consent for us to use, or where we used the information to perform a contract with you.
- Withdraw consent at any time where we rely on consent to process your personal data. This will not affect the lawfulness of any processing carried out before you withdraw. If you withdraw your consent, we may not be able to provide certain products or services to you, and we will tell you if that is the case at the time.
14.2 To exercise any of these rights, please contact us at [EMAIL ADDRESS] or using the details in section 1.2.
14.3 No fee usually required. You will not have to pay a fee to access your personal data or to exercise any of your other rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive, or we may refuse to comply with the request in those circumstances.
14.4 What we may need from you. We may need to request specific information from you to help us confirm your identity before we act on a request. This is a security measure to make sure personal data is not disclosed to anyone who has no right to receive it. We may also contact you for further information to speed up our response.
14.5 Time limit to respond. We aim to respond to all legitimate requests within one month. It may occasionally take longer if your request is particularly complex or you have made a number of requests. In that case we will notify you and keep you updated.
10. Glossary
16.1 Lawful bases
- Legitimate interests means the interest of our business in conducting and managing it so that we can give you the best service and the most secure experience. We consider and balance any potential impact on you, both positive and negative, and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you, unless we have your consent or are otherwise required or permitted by law. You can obtain further information about how we assess our legitimate interests against any potential impact on you by contacting us.
- Performance of a contract means processing your data where it is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into such a contract.
- Comply with a legal or regulatory obligation means processing your personal data where it is necessary to comply with a legal or regulatory obligation to which we are subject.
16.2 Third parties
- Internal third parties — other companies within our group, where applicable, acting as joint controllers or processors and providing IT, system administration and reporting services.
- External third parties — service providers, professional advisers, regulators and authorities, energy suppliers, credit reference agencies, payment providers and marketing partners, as described in section 7.
This document is a template prepared for Smart Merchant Energy Ltd. Before publishing it, please complete all bracketed fields and have it reviewed by a qualified data protection or legal adviser to confirm it accurately reflects your actual processing activities.