GDPR Compliance
Last updated: May 10, 2026
Our Commitment to GDPR
Energy-whirl is committed to complying with the General Data Protection Regulation (GDPR) and UK data protection laws. This page outlines how we fulfill our obligations under GDPR.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Consent: When you provide explicit consent for specific processing activities
- Contract: When processing is necessary to fulfill our contractual obligations to you
- Legal Obligation: When we must process data to comply with legal requirements
- Legitimate Interests: When processing is necessary for our legitimate business interests, provided your rights and interests do not override those interests
Your Rights Under GDPR
As a data subject, you have the following rights:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee if your request is manifestly unfounded or excessive.
Right to Rectification
You have the right to request correction of any information you believe is inaccurate or incomplete.
Right to Erasure
You have the right to request deletion of your personal data under certain conditions.
Right to Restrict Processing
You have the right to request restriction of processing your personal data under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions.
Right to Data Portability
You have the right to request transfer of your data to another organization or directly to you, under certain conditions.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw your consent at any time.
How to Exercise Your Rights
To exercise any of your rights under GDPR, please contact us at:
Email: [email protected]
Address: 142 Kensington High Street, London W8 7RL, United Kingdom
We will respond to your request within one month. If your request is particularly complex, we may extend this period by two additional months, in which case we will inform you.
Data Protection Officer
We have appointed a Data Protection Officer who is responsible for overseeing our data protection strategy and implementation. You can contact our DPO at: [email protected]
International Data Transfers
We do not routinely transfer personal data outside the UK or European Economic Area. If we do so in the future, we will ensure appropriate safeguards are in place as required by GDPR.
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Client data: 7 years after service completion (in accordance with financial services regulations)
- Marketing data: Until consent is withdrawn or 3 years of inactivity
- Website analytics: 26 months
Children's Data
Our services are not directed at children under 18. We do not knowingly collect or process data from children. If we become aware that we have collected data from a child, we will delete it immediately.
Complaints
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
Website: https://energy-whirl.com
Phone: 0303 123 1113
Updates to This Statement
We may update this GDPR compliance statement from time to time to reflect changes in our practices or legal requirements. We will notify you of any significant changes.