Broadsight Labs Ltd.
Version 2.0 · Effective date: 6 September 2026 · Supersedes the policy dated July 2026
Broadsight Labs Ltd. ("Broadsight Labs", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This policy explains what personal data we collect, why we collect it, what we do with it, who we share it with, how long we keep it, and the rights you have under the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018 ("DPA 2018") and the Privacy and Electronic Communications (EC Directive) Regulations 2003 ("PECR"), each as amended by the Data (Use and Access) Act 2025.
Please read it alongside our Terms of Service, which govern the use of our products and services.
Contents
- About us and how to contact us
- The services this policy covers
- Our role: when we are a controller and when we are a processor
- The personal data we collect and why
- 4.1 Visitors to our websites
- 4.2 Enquiries, demonstrations and marketing
- 4.3 Broadsight Energy platform accounts
- 4.4 Broadsight Mobile
- 4.5 Metering equipment and telemetry
- 4.6 Support portal, documentation and status page
- 4.7 Security monitoring, audit trails and logs
- 4.8 Customer Data we process on behalf of our customers
- 4.9 Suppliers, partners and business contacts
- Lawful bases we rely on
- Cookies and similar technologies
- Google Analytics
- Who we share personal data with
- International transfers
- How long we keep personal data
- How we protect personal data
- Your rights
- Complaints
- Automated decision-making and profiling
- Children
- Third-party websites and services
- Changes to this policy
- Annex A – Cookies and local storage
- Annex B – Sub-processors and other recipients
1. About us and how to contact us
Broadsight Labs Ltd. is a company registered in England and Wales with company number 17126211. Our registered office is at 1 Tower House, Tower Centre, Hoddesdon, Hertfordshire, EN11 8UR, United Kingdom. We are registered with the Information Commissioner's Office ("ICO") as a data controller under registration reference ZC194002.
We have appointed a Data Protection Officer ("DPO"). If you have any questions about this policy or about how we handle personal data, or if you want to exercise any of your rights, please contact us:
| Data Protection Officer | [email protected] |
| General enquiries | [email protected] |
| Security and vulnerability reports | [email protected] (see also https://broadsightlabs.co.uk/.well-known/security.txt) |
| Telephone | +44 (0)204 538 5011 |
| Post | Data Protection Officer, Broadsight Labs Ltd., 1 Tower House, Tower Centre, Hoddesdon, Hertfordshire, EN11 8UR, United Kingdom |
2. The services this policy covers
This policy applies to the following (together, the "Services"):
| Service | Description |
|---|---|
| Corporate website | https://broadsightlabs.co.uk, including its contact and demonstration request form. |
| Product website | https://broadsight.energy, the public website for the Broadsight Energy platform. |
| Broadsight Energy platform (the "Platform") | The unified energy management platform at https://app.broadsight.energy (and any other domain on which we make it available, including customer-branded domains), used for planning, testing, monitoring and analysing temporary and permanent power installations. |
| Broadsight Mobile (the "App") | Our native technician app for iOS and Android (listed in the app stores as "Broadsight"), which is a companion to the Platform. |
| Metering Equipment and telemetry | Power meters, generator monitoring equipment, cellular routers and gateways, and the connectivity and data-ingest services that feed measurements into the Platform. |
| Support system | Our customer support portal and knowledge base, which are provided using Atlassian Jira Service Management and Confluence at https://broadsightlabs.atlassian.net, and our service status page at https://broadsightlabs.statuspage.io. |
Where we make the Platform available under a customer's own branding or domain name, this policy still applies to our processing.
3. Our role: when we are a controller and when we are a processor
Data protection law distinguishes between a controller (who decides why and how personal data is processed) and a processor (who processes personal data on a controller's instructions). We act in both capacities:
We are the controller of personal data relating to:
- visitors to our websites, and the cookies and analytics described in sections 6 and 7;
- people who contact us, request a demonstration or trial, or receive marketing from us;
- people who use our support portal, knowledge base or status page;
- the account, access and security data we hold about anyone who signs in to the Platform or the App (for example authentication events, session records, audit trails and security logs). We determine the purposes of this processing to meet our own security, integrity and legal obligations;
- device and notification data generated by the App itself (for example push-notification tokens and app-version information);
- our billing, contract and business records; and
- our suppliers, partners and other business contacts.
We are a processor for Customer Data: the information that our customers (the organisations that hold a licence to use the Platform, "Customers") and their authorised users put into the Platform and the App. This includes the names and contact details of a Customer's own clients and site contacts, project and site records, personnel assignments and invitations, inspection and test records, electronic signatures, photographs, work orders, meter readings, and any technician location data that a Customer chooses to enable. For this data, the Customer is the controller and we process it only in accordance with our Terms of Service and the Data Processing Addendum they contain (Schedule 1 of the Terms of Service).
If you use the Platform or the App as a member of a Customer's organisation, your organisation is responsible for telling you how it uses the Customer Data it holds about you and for responding to requests relating to that data. We will help our Customers do so.
4. The personal data we collect and why
We do not knowingly collect special category data (for example data about health, ethnicity, religion, trade-union membership or biometric data used to identify someone) or data about criminal convictions through the Services, and our Customers must not upload it (see the Terms of Service). Where the App offers Face ID, Touch ID or fingerprint unlock, the biometric check is carried out entirely by your device's operating system; we never receive your biometric data, only a yes or no result.
4.1 Visitors to our websites
When you visit https://broadsightlabs.co.uk or https://broadsight.energy we collect:
- Technical data sent by your browser: IP address, browser type and version, operating system, referring page, the pages you visit and the time and date of your visit. Our websites and the Platform are delivered through Cloudflare, which processes this data at its network edge to route traffic, balance load, defend against attacks and enforce our web application firewall rules.
- Analytics data through Google Analytics 4, only if you accept analytics cookies in the cookie banner. See section 7.
- Cookie and local storage preferences so that we remember your choice. See Annex A.
We use this data to run and secure our websites, understand how they are used and improve them. Our lawful bases are our legitimate interests in operating, securing and improving our websites and, for analytics on the websites, your consent.
4.2 Enquiries, demonstrations and marketing
If you use the contact form on our websites, email or telephone us, or ask for a demonstration or product trial, we collect your name, email address, company name (optional), telephone number (if you give it), your message and any other information you choose to provide. The contact form is protected by rate limiting and by Cloudflare Turnstile (a bot-detection service that does not require you to solve a puzzle), so your IP address is processed when you submit it. Form submissions are relayed to our mailbox through Mailgun, our email delivery provider.
We use this data to respond to you, arrange demonstrations and trials, prepare proposals and agreements, and manage our relationship with you. If you are a representative of a business, we may also send you information about our products and services that we think will be of interest to you. You can opt out at any time by using the unsubscribe link in any marketing email or by contacting us. We do not send marketing to individual (non-business) subscribers without their consent, and we do not sell or rent personal data to anyone.
Our lawful bases are our legitimate interests in responding to enquiries and promoting our business to other businesses, taking steps at your request before entering into a contract, and, where we ask for it, your consent.
4.3 Broadsight Energy platform accounts
Accounts on the Platform are created by us or by a Customer's administrator, or are provisioned automatically when you sign in through a Customer's single sign-on provider or through a Microsoft Entra External ID sign-up. We collect and hold:
- Identity and contact data: name, email address, organisation, role and permissions, project memberships and invitations, and, if you are invited to a project, the email address the invitation was sent to.
- Authentication data: for local accounts, a one-way hash of your password (Argon2id) and an encrypted authenticator (TOTP) secret and hashed one-time recovery codes for the two-factor authentication we require; for single sign-on accounts, the identifiers your identity provider sends us (for example a Microsoft Entra object ID or SAML NameID). We never see or store your identity-provider password.
- Session and security data: session cookies, CSRF tokens, the date and time of your last sign-in together with the IP address and country it came from, failed sign-in attempts and any temporary lock-out, and the events described in section 4.7. The IP country is derived by Cloudflare from your IP address.
- Preferences: your light/dark theme choice and cookie preference.
- Usage data: the pages and features you use, the actions you take (for example creating a project, editing a device or generating a report) and the time of those actions, as recorded in the Platform's activity logs, work-order activity logs and audit trails.
- Content you create: anything you enter into the Platform is Customer Data (section 4.8), including electronic signatures you draw with the signature pad (stored as an image together with your name, role and the time of signing) and photographs you upload.
- Emails we send you: for example password-reset links, project invitations, report share notifications, alert notifications and work-order assignments. We keep a record of the recipient, subject line, attachment names, delivery provider and delivery outcome of each email we send, but not the body of the message.
- Analytics data through Google Analytics 4 (page views and coarse account context: your user role, administrator tier and organisation identifier), unless you decline analytics cookies. See section 7.
Maps in the Platform are provided by Google Maps Platform. When a page containing a map loads, your browser requests map tiles and scripts directly from Google, which will process your IP address and the map area you view under Google's privacy policy. Address look-ups you type into the Platform are sent to Google's Places API from our servers (not from your browser) and postcode look-ups are sent to postcodes.io; only the text you type is sent.
Where you are a member of a Customer organisation, we hold your account data on behalf of that Customer to provide its tenancy, and we process the authentication, session and security data as controller for the purposes of securing the Platform, preventing and detecting misuse and meeting our contractual and legal obligations. Our lawful bases are the performance of our contract with the Customer, our legitimate interests in securing and operating the Platform, and compliance with our legal obligations.
4.4 Broadsight Mobile
The App is a companion to the Platform and is only usable with a Platform account. In addition to the data described in section 4.3, the App involves the following:
- Sign-in and device tokens. You sign in through your device's system browser using the same methods as the Platform. The App then receives a long-lived access token and a rotating refresh token, which are stored in your device's secure keychain or keystore and can be protected by the App's biometric lock. On our servers we keep only a one-way hash of each token together with the device name you enter (for example "Jane's iPhone"), the device platform, the app's user-agent string, the IP address from which the token was issued, and when it was last used, so that you and your administrators can see and revoke signed-in devices. Tokens are revoked automatically if your password is changed or reset or your account is deactivated.
- Push notifications. If you allow notifications, the App registers a push token with our servers together with a random installation identifier, the platform (iOS or Android), the app version and your device language, and your notification preferences. Notifications are delivered through Apple Push Notification service (for iOS) and Google Firebase Cloud Messaging (for Android). Notification payloads contain only identifiers and generic titles (for example "New work order assigned"); site names, customer names and readings are fetched by the App after you open the notification and are not sent through Apple or Google.
- Camera and photo library. With your permission, the App uses your camera and photo library so that you can attach photographs of equipment and site conditions to work orders and test records. Photographs are Customer Data. Take care not to photograph people unnecessarily; your organisation is responsible for ensuring that any images of people are collected lawfully.
- Biometric unlock. With your permission, the App uses Face ID, Touch ID or fingerprint recognition to unlock the App and to confirm your identity before you sign a record. This is performed by your device; we never receive biometric data.
- Location. The App requests "while using the app" location permission only, never "always". Your location is used in two ways, both of which are under your control:
- Pinning a job to where you are. When you tap "use my current position" while raising a work order, the App reads your location once and stores it against that work order as the job location.
- On-shift positioning. Where your organisation has enabled this feature and you switch the "on shift" toggle on, the App periodically shares your position with your organisation so that dispatchers can find the nearest technician. The toggle is off by default, switches itself off automatically after a set period, shows a persistent system indicator while it is on, and lets you see your own location history. Your organisation, as controller, is responsible for assessing the impact of this monitoring on you and for telling you how it is used. We process this data only as your organisation's processor.
- Offline data. So that you can work without mobile coverage, the App keeps a local copy of the work orders, inspection and test records, photographs and signatures relevant to you in a database on your device, and queues your changes until connectivity returns. This data is protected by your device's operating-system encryption and the App's lock, and is removed when you sign out. Keep your device secured with a passcode and report a lost or stolen device to your administrator promptly.
- Maps. The App uses the native Google Maps software development kit. Map tiles are requested from Google, which processes your IP address and the map area you view under Google's privacy policy.
- Diagnostics. The App does not currently send crash or usage reports to us or to any third party; error details are written to your device only. Apple and Google may provide us with aggregated, anonymous crash and installation statistics under their own policies. We will update this policy before enabling any crash-reporting service.
- App stores. Downloading the App from the App Store or Google Play involves Apple or Google processing your data under their own privacy policies.
Our lawful bases are the same as for the Platform (section 4.3). Where the App asks for a device permission, we rely on that permission to access the relevant device feature and on the lawful bases in section 4.3 for the resulting processing.
4.5 Metering equipment and telemetry
The Platform receives measurements from power meters, generator monitoring equipment and similar devices ("Metering Equipment"), typically Shelly Pro 3EM energy meters and Modbus power meters connected through Teltonika cellular routers, over MQTT or over our HTTPS ingest service. Each device sends:
- a device identifier, timestamps and per-phase and per-circuit electrical measurements (power, voltage, current, apparent power, power factor, frequency and energy counters);
- device configuration and network data: the GPS position of the router or device, the mobile network operator it is connected to, and its public (WAN) IP address; and
- the time and source IP address of each authenticated ingest request, which we record against the device's access token.
Within the Platform, devices are given friendly names and site locations or addresses and are assigned to Customers, customers of Customers, projects and device groups.
This data is about equipment and electrical loads rather than people, and in most cases it is not personal data. It can become personal data when it relates to an identifiable individual, for example where equipment is installed at a named person's premises or is combined with personnel records. We treat all telemetry and device data as Customer Data and process it as our Customers' processor. Where we supply cellular connectivity for Metering Equipment, we and our connectivity provider process SIM identifiers, connection records and data usage to provide and manage that connectivity.
We may also create aggregated and anonymised statistics from telemetry (for example fleet-wide load profiles or the accuracy of energy estimates) that cannot identify any individual or Customer. We use these to operate, benchmark and improve the Services.
4.6 Support portal, documentation and status page
Our support portal is provided using Atlassian Jira Service Management at https://broadsightlabs.atlassian.net/servicedesk/customer/portal/35, and our knowledge base using Atlassian Confluence. You do not need an account to raise a request. When you raise a request we collect your name, email address, organisation, the request type, the details you provide, any attachments or screenshots, and correspondence about the request. We also link requests to your Customer account where relevant. We use this data to provide support, to investigate and fix problems, to improve our products and to keep records of the support we have provided. Please do not include passwords, authentication codes or other secrets in support requests.
Our service status page is provided using Atlassian Statuspage at https://broadsightlabs.statuspage.io. If you subscribe to updates we (through Atlassian) collect the email address, Slack workspace or Microsoft Teams webhook you use to subscribe. The subscription form is protected by Google reCAPTCHA. You can unsubscribe at any time using the link in any status email or the subscription manager on the page.
Atlassian's own cookies and tracking notice applies to the pages it hosts, and its cookie banner will be shown to you there.
Our lawful bases are the performance of our contract with the Customer, our legitimate interests in providing support and communicating service status, and, for status subscriptions, your consent.
4.7 Security monitoring, audit trails and logs
We monitor the Services to keep them secure, detect and investigate misuse or attacks, and meet our obligations under our Information Security Policy (POL-IT-002), our Cyber Essentials certification and our contracts with Customers. This involves:
- Edge security (Cloudflare). All traffic to our websites and the Platform passes through Cloudflare's network, which operates our DNS, tunnels, load balancing, web application firewall, bot management and Turnstile human-verification challenge. Cloudflare processes IP addresses, request headers, TLS details and similar metadata, and may set security cookies (Annex A). Local sign-in and password-reset requests on the Platform must pass a Turnstile check.
- Platform audit trail. The Platform records every sign-in attempt (successful or not), sign-out, lock-out and two-factor event, together with the account involved, the sign-in method, the source IP address and country, the browser user-agent string and the reason for any failure. It also records administrative changes (for example creating or modifying users, roles, permissions and settings, with the previous and new values), outbound email metadata (recipient, subject, attachment names, provider and outcome; never the message body) and the acting user and IP address. Global administrators can search and export this audit trail.
- Security information and event management (SIEM). Authentication events, administrative changes, email events and application errors (which can include the client IP address of a failed request) are forwarded in real time to our security monitoring platform, hosted in the United Kingdom or the European Union, for correlation, alerting and investigation.
- Application telemetry and diagnostics. Our servers keep operational logs of requests, errors and performance so that we can diagnose faults and keep the Services running.
We rely on our legitimate interests in ensuring network and information security, preventing fraud and misuse, and protecting our Customers and their data (which the UK GDPR recognises as a legitimate interest), on the performance of our contracts, and on compliance with our legal obligations. Where security data is needed to detect, investigate or prevent crime, or to respond to a request from a public authority, we may also rely on the "recognised legitimate interests" basis introduced by the Data (Use and Access) Act 2025.
4.8 Customer Data we process on behalf of our customers
When a Customer or its users use the Platform or the App, they enter information that may include personal data about:
- the Customer's own clients and site contacts (names, email addresses, telephone numbers, notes);
- the Customer's staff, contractors and freelancers (project roles such as project manager, senior person, authoriser, inspector or technician; work-order assignments; on-shift location where enabled);
- signatories and recipients of inspection, test and danger reports (names, roles, organisations, email addresses and electronic signatures); and
- anyone who appears in photographs or free-text notes uploaded to the Platform.
The Platform can also send emails on a Customer's instruction to addresses the Customer specifies (for example project invitations, shared reports, danger reports and work-order documents), can send alert notifications to email addresses and webhook URLs the Customer configures, and can create public "share links" for reports that anyone with the link can open until the link expires or is revoked. We carry out these actions only on the Customer's instructions.
The Customer is the controller of Customer Data. We process it only to provide the Services in accordance with our Terms of Service and the Data Processing Addendum, and we do not use it for our own purposes other than as anonymised, aggregated statistics (section 4.5) or as required by law. If you have questions about Customer Data that relates to you, please contact the organisation that entered it; we will assist that organisation as its processor.
4.9 Suppliers, partners and business contacts
If you work for one of our suppliers, partners, professional advisers or other business contacts we collect your name, job title, employer, business contact details and correspondence, and use them to manage our relationship, to obtain goods and services, and to meet our legal and accounting obligations. Our lawful bases are the performance of our contract with your organisation, our legitimate interests in running our business, and compliance with our legal obligations.
If you apply for a job with us we will give you a separate privacy notice for recruitment.
5. Lawful bases we rely on
| Purpose | Lawful basis (UK GDPR Article 6) |
|---|---|
| Operating, securing and improving our websites | Legitimate interests |
| Website analytics (Google Analytics) | Consent (websites); PECR statistical-purposes exception and legitimate interests with a right to object (Platform) – see section 7 |
| Responding to enquiries, demonstrations and trials | Legitimate interests; steps at your request before entering into a contract |
| Business-to-business marketing | Legitimate interests (with the right to opt out at any time); consent where we ask for it |
| Providing the Platform, the App, Metering Equipment and connectivity to Customers | Performance of our contract with the Customer (we act as processor for Customer Data) |
| Account administration, authentication and session management | Performance of contract; legitimate interests |
| Security monitoring, audit trails, SIEM, fraud and abuse prevention | Legitimate interests (network and information security); legal obligation; recognised legitimate interests where crime prevention or public-authority requests are involved |
| Push notifications and App device management | Performance of contract; legitimate interests |
| Support portal, knowledge base and status page | Performance of contract; legitimate interests; consent (status subscriptions) |
| Billing, accounting, tax and corporate records | Legal obligation; performance of contract |
| Establishing, exercising or defending legal claims; complying with court orders and regulatory requests | Legitimate interests; legal obligation |
| Aggregated, anonymised service statistics | Legitimate interests (the output is not personal data) |
Where we rely on legitimate interests we have balanced those interests against your rights and interests. You can ask us for more information about that assessment, and you can object to processing based on legitimate interests (section 12).
6. Cookies and similar technologies
Cookies are small files placed on your device by a website. We also use browser local storage, which works in a similar way. We use them for three purposes:
- Strictly necessary: to sign you in, keep you signed in, protect forms against cross-site request forgery, complete single sign-on and two-factor authentication flows, complete the App's sign-in hand-off, remember your cookie choice and defend the Services against automated attacks. These are essential to provide the Services you have asked for and do not require your consent.
- Preferences: to remember your light/dark theme. This is stored in your browser only and is not sent to us for tracking.
- Analytics: Google Analytics cookies, described in section 7.
Full details of each cookie, who sets it, what it does and how long it lasts are in Annex A. Pages hosted by Atlassian (our support portal, knowledge base and status page) use Atlassian's cookies under Atlassian's own notice.
You can control cookies through your browser settings, including blocking or deleting them, although blocking strictly necessary cookies will stop the Platform working. You can change your analytics choice at any time as described in section 7.
7. Google Analytics
We use Google Analytics 4, provided by Google LLC and Google Ireland Limited, to understand how our websites and the Platform are used so that we can improve them. Google Analytics uses first-party cookies (_ga and _ga_<property>) to distinguish visitors and sessions, and sends Google information about the pages you view, the device and browser you use, approximate location derived from your IP address, and the time of your visit. Google states that Google Analytics 4 does not log or store IP addresses.
We use Google Analytics for statistical purposes only, to measure and improve our own Services, with Google's standard configuration. We have not enabled Google Signals, advertising features, remarketing or audience sharing, and Google Analytics is not linked to any Google advertising account. Google retains event-level data for two months (its standard setting) and keeps the aggregated reports we use for longer. Under Google's standard data-sharing settings, Google may also use the data it collects to maintain and improve its own products and services, as described at https://policies.google.com/technologies/partner-sites. On the Platform we also set three coarse "user properties" so that we can see how different kinds of user use the product: your user role (for example standard user or administrator), your administrator tier, and a numeric organisation identifier. We do not send your name, email address or any content you create to Google Analytics.
How consent works
- On our websites (broadsightlabs.co.uk and broadsight.energy) Google Analytics loads only after you click "Accept" in the cookie banner. If you click "Decline" or make no choice, it is not loaded. Your choice is remembered in your browser's local storage.
- On the Platform (app.broadsight.energy) Google Analytics is switched on by default, and you are shown a banner the first time you visit that lets you decline it. If you decline, the analytics script is stopped immediately, its cookies are deleted, and we remember your choice in a cookie for 12 months so that the script is never loaded again on that browser. We rely on the exception in regulation 6 of PECR (as amended by the Data (Use and Access) Act 2025) for the collection of statistical information about how a service is used in order to improve it, which requires us to give you clear information and a simple, free way to object; this banner and this section are how we do that. For the associated processing of personal data we rely on our legitimate interests in understanding and improving the Platform, and you have the right to object at any time.
You can change your mind at any time. On the websites, clear your browser's site data for the site to see the banner again. On the Platform, delete the bs_cookie_consent cookie for app.broadsight.energy to see the banner again, or contact us. You can also install Google's browser add-on, which prevents Google Analytics from collecting data in that browser: https://tools.google.com/dlpage/gaoptout. Google's own privacy policy is at https://policies.google.com/privacy and its description of how it uses data from sites that use its services is at https://policies.google.com/technologies/partner-sites.
8. Who we share personal data with
We share personal data only where necessary, with:
- Service providers (processors and sub-processors) who host and support the Services, deliver our email, provide analytics, maps, push notifications, identity services, support tooling, connectivity and security monitoring. Each is bound by a written contract that requires it to process personal data only on our instructions and to protect it appropriately. The current list is in Annex B, and Customers receive advance notice of changes under the Data Processing Addendum.
- Our Customers, where we process Customer Data as their processor, and, for Authorised Users, the organisation that administers your account (for example your sign-in history and signed-in devices are visible to your administrators).
- Identity providers you choose to sign in with (Microsoft Entra ID, Microsoft Entra External ID or a Customer's SAML identity provider), which receive the information needed to authenticate you.
- Recipients that Customers instruct us to send data to: email recipients, webhook endpoints and holders of report share links.
- Professional advisers, including lawyers, accountants, auditors and insurers.
- Regulators, law enforcement, courts and other public authorities where we are required to by law, or where necessary to protect our rights, our Customers or the public.
- A purchaser or prospective purchaser of our business or assets, or a successor in the event of a merger, reorganisation or insolvency, subject to appropriate confidentiality obligations.
We do not sell personal data, and we do not share it with third parties for their own marketing.
9. International transfers
We are based in the United Kingdom. The Platform and its database are hosted in the United Kingdom, and all backups and redundant copies of Platform data are stored in the United Kingdom or the European Union. Some of our service providers are based in, or provide support and transient processing (for example analytics, push notifications, support tooling and edge security) from, the United States or other countries outside the UK. Whenever personal data leaves the UK we make sure it is protected by one of the safeguards recognised under Chapter V of the UK GDPR:
- Adequacy regulations: transfers to the European Economic Area, and to organisations in the United States that are certified under the UK Extension to the EU-US Data Privacy Framework ("DPF"), are covered by UK adequacy regulations. Cloudflare, DigitalOcean, Google, Microsoft, Apple, Atlassian and Backblaze are certified under the DPF at the date of this policy.
- Appropriate safeguards: where no adequacy regulation applies we use the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, supported by a transfer risk assessment and technical measures such as encryption in transit and at rest.
Annex B sets out the country in which each provider processes data and the safeguard we rely on. You can ask the DPO for a copy of the relevant safeguard.
10. How long we keep personal data
We keep personal data only for as long as we need it for the purposes described above, and then delete or anonymise it. Our main retention periods are:
| Data | Retention |
|---|---|
| Website and Platform analytics (Google Analytics event-level data) | Two months (Google's standard setting); aggregated reports are kept for longer |
| Cookie/analytics choice | 12 months (Platform cookie); until you clear site data (websites) |
| Contact-form enquiries and demonstration requests | 24 months after our last contact with you, unless you become a Customer |
| Marketing preferences and opt-outs | For as long as needed to honour your opt-out |
| Platform and App account data | For the duration of the Customer's subscription and for 90 days after it ends (the export and deletion period in our Terms of Service), unless the Customer or the account holder asks us to delete it sooner |
| Customer Data (including telemetry, records, photographs and signatures) | As above; deleted or returned within 90 days after the subscription ends, at the Customer's choice, save for copies in backups |
| Platform audit trail (sign-in events, email metadata, administrative changes) | 90 days by default (configurable by us between 1 day and 10 years to meet Customer or legal requirements) |
| Security (SIEM) logs and Cloudflare security events | Up to 12 months |
| Server and application diagnostic logs | Up to 30 days |
| Database backups | 14 days (rolling); backups are then overwritten |
| Password-reset links | 60 minutes, or until used |
| App sign-in tokens | Access tokens 30 days, refresh tokens 90 days; revoked immediately on sign-out, password change or deactivation |
| App push tokens and preferences | Until you sign out of the device, uninstall the App or the token is reported invalid by Apple or Google |
| App idempotency records (protect against duplicate submissions) | About 24 hours |
| Report share links | Until the expiry date set by the Customer, or until revoked |
| Support requests and correspondence | 3 years after the request is closed |
| Status page subscriptions | Until you unsubscribe |
| Contracts, invoices, accounting and tax records | 6 years after the end of the financial year to which they relate, as required by the Companies Act 2006 and HMRC |
| Records relating to a legal claim or regulatory investigation | Until the matter is concluded and any appeal period has expired |
Where data is held in backups it is deleted when the backup cycle completes. Anonymised, aggregated statistics may be kept indefinitely.
11. How we protect personal data
We take the security of personal data seriously. Broadsight Labs holds Cyber Essentials certification, and our security programme is governed by our Information Security Policy (POL-IT-002), which is the top-level document of our information security management system and cyber governance framework. It is an internal document; Customers may request a summary of its controls under a non-disclosure agreement.
Measures we apply include:
- encryption of data in transit (TLS 1.2 or higher everywhere, including between the Platform and its database) and at rest (including encrypted storage, encrypted two-factor authentication secrets and encrypted alert-channel credentials);
- passwords hashed with Argon2id, mandatory two-factor authentication for password-based accounts, single sign-on support, and hashed, revocable tokens for the App and for Metering Equipment;
- role-based access control, per-organisation tenancy isolation, licence-based feature control and least-privilege access for our staff;
- a Cloudflare web application firewall, bot management, DDoS protection and rate limiting in front of every Service, with our servers not exposed directly to the internet;
- hardened containers, security headers and content security policies, input validation and parameterised database queries;
- centralised audit logging and security monitoring (section 4.7), regular independent penetration testing, dependency and vulnerability management, and a coordinated vulnerability disclosure process (https://broadsightlabs.co.uk/.well-known/security.txt);
- twice-daily backups held in the United Kingdom or the European Union, tested restoration and an incident response process; and
- staff confidentiality obligations and security training.
No system can be guaranteed to be completely secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms we will notify the ICO within 72 hours as the law requires and, where the risk is high, tell you without undue delay. Where we are a processor we will notify the affected Customer without undue delay so that it can meet its own obligations. If you believe you have found a security vulnerability in any of our Services, please tell us at [email protected].
12. Your rights
Under the UK GDPR you have the following rights in relation to personal data we hold about you as controller:
- Access: to be told whether we are processing your personal data and, if so, to receive a copy of it together with information about how we use it.
- Rectification: to have inaccurate personal data corrected and incomplete data completed.
- Erasure: to have your personal data deleted in certain circumstances, for example where it is no longer needed for the purpose it was collected for.
- Restriction: to have the processing of your personal data restricted in certain circumstances, for example while a dispute about its accuracy is resolved.
- Portability: to receive personal data you have provided to us, which we process by automated means on the basis of consent or contract, in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.
- Objection: to object at any time to processing based on our legitimate interests, and to object at any time to direct marketing, in which case we will stop.
- Withdrawal of consent: where we rely on your consent, to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Automated decisions: not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. We do not make such decisions (section 14).
To exercise any of these rights, contact the DPO at [email protected] or by post (section 1). We may need to verify your identity before we act on a request, and we may ask you to clarify the scope of a request; the law permits us to carry out searches that are reasonable and proportionate. We will respond within one month, which we may extend by up to two further months for complex or numerous requests, in which case we will tell you. We will not charge a fee unless a request is manifestly unfounded or excessive.
Where we hold your personal data as a processor for one of our Customers (section 3), we will pass your request to that Customer and help it respond. If you are an Authorised User, your organisation's administrators can also update your account details, change your role and revoke your access and signed-in devices directly in the Platform.
13. Complaints
If you are unhappy with how we have handled your personal data, or with how we have dealt with a request, you have the right to complain to us. Under the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025, we must make it easy for you to complain, acknowledge your complaint within 30 days of receiving it, and respond without undue delay after considering it and taking appropriate steps.
You can complain by:
- emailing the DPO at [email protected] with the subject line "Data protection complaint"; or
- writing to the DPO at our registered office (section 1).
Please tell us what the complaint is about, when it happened and what outcome you would like. We will acknowledge your complaint within 30 days, investigate it and reply to you with our conclusions and any action we are taking.
You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office, at any time:
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · Telephone 0303 123 1113 · https://ico.org.uk/make-a-complaint/
We would appreciate the chance to deal with your concerns before you approach the ICO, but you are not required to contact us first.
14. Automated decision-making and profiling
We do not make decisions about you based solely on automated processing that have legal or similarly significant effects on you. The Platform does evaluate equipment data automatically (for example alert rules that compare meter readings with thresholds, or portable appliance test results calculated from the values a technician enters), but these decisions concern equipment and electrical installations, not individuals, and are always reviewed by the people who configure and use them.
We do not carry out profiling of individuals. The Google Analytics user properties described in section 7 are used only to produce aggregated statistics.
15. Children
Our Services are designed for businesses and are not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact the DPO and we will delete it.
16. Third-party websites and services
Our Services contain links to third-party websites and services, including the identity providers you may sign in with, Google Maps, Apple's App Store, Google Play, Atlassian-hosted pages and the manufacturers of Metering Equipment. We are not responsible for the privacy practices of third parties, and this policy does not apply to them. We encourage you to read their privacy notices.
17. Changes to this policy
We review this policy at least annually and update it when our Services or the law change. We will publish the updated policy on our websites with a new effective date and, where a change is significant, we will notify Customers by email or through the Platform and, where the law requires it, seek fresh consent. Earlier versions are available from the DPO on request.
Annex A – Cookies and local storage
Strictly necessary (no consent required)
| Name | Set by | Where | Purpose | Duration |
|---|---|---|---|---|
ems_session | Broadsight Labs | Platform | Signed session cookie that keeps you signed in and carries your anti-forgery (CSRF) token. HttpOnly, Secure, SameSite=Lax. | Expires after 1 hour of inactivity and, in any event, 12 hours after sign-in |
ems_mfa_pending | Broadsight Labs | Platform | Short-lived signed token used between password entry and two-factor verification. | A few minutes |
ems_entra_state | Broadsight Labs | Platform | Signed state for Microsoft Entra sign-in, protecting against forged sign-in responses. | 5 minutes |
| SAML request state cookie | Broadsight Labs | Platform | Signed state for SAML single sign-on requests. | A few minutes |
app_authz | Broadsight Labs | Platform | Signed record of a pending Broadsight Mobile sign-in while you authenticate in the browser. | A few minutes |
bs_cookie_consent | Broadsight Labs | Platform | Remembers whether you accepted or declined analytics cookies. | 12 months |
bsl-cookie-consent (local storage) | Broadsight Labs | Websites | Remembers whether you accepted or declined analytics cookies. | Until cleared |
| Theme preference (local storage) | Broadsight Labs | Platform | Remembers your light/dark theme choice on this device. | Until cleared |
__cf_bm, cf_clearance, __cfruid, _cfuvid | Cloudflare | Websites and Platform | Bot management, security challenges (Turnstile) and load balancing. See https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/ | Up to 1 year (cf_clearance); others 30 minutes to session |
Analytics (websites: consent; Platform: PECR statistical-purposes exception with right to object)
| Name | Set by | Where | Purpose | Duration |
|---|---|---|---|---|
_ga | Google Analytics | Websites and Platform | Distinguishes visitors. | 2 years |
_ga_<property id> | Google Analytics | Websites and Platform | Maintains session state and page-view counts. | 2 years |
Third-party pages: our support portal, knowledge base and status page are hosted by Atlassian, which sets its own cookies under the Atlassian Cookies and Tracking Notice (https://www.atlassian.com/legal/cookies). The status page subscription form uses Google reCAPTCHA, which is subject to Google's privacy policy and terms.
Annex B – Sub-processors and other recipients
| Provider | Service | Data processed | Location of processing | Transfer safeguard |
|---|---|---|---|---|
| Cloudflare, Inc. (San Francisco, USA) | DNS, Cloudflare Tunnel, load balancing, web application firewall, bot management, Turnstile, edge logging, R2 object storage for uploaded images, branding assets and generated reports | Website and Platform traffic metadata (IP address, headers), security events, uploaded files and generated documents | Global edge network for transient request processing; stored files in the European Union | UK Extension to the EU-US DPF; Cloudflare Data Processing Addendum |
| DigitalOcean, LLC (New York, USA) | Cloud hosting of the Platform, its database and supporting infrastructure | All Platform data | United Kingdom | UK Extension to the EU-US DPF; DigitalOcean Data Processing Agreement |
| Backblaze, Inc. (San Mateo, USA) | Off-site database backups | All Platform data (backup copies) | European Union | UK Extension to the EU-US DPF; Backblaze Data Processing Addendum |
| Google LLC (Mountain View, USA) and Google Ireland Limited (Dublin, Ireland) | Google Analytics 4; Google Maps Platform (Maps JavaScript API, Places API, Maps SDKs for Android and iOS); Firebase Cloud Messaging; reCAPTCHA (status page) | Analytics data (section 7); IP address and map areas viewed; address text typed into look-ups; push tokens and notification payloads | United States, EU and other Google locations | UK Extension to the EU-US DPF; Google Ads Data Processing Terms / Google Cloud Data Processing Addendum |
| Apple Inc. (Cupertino, USA) and Apple Distribution International Ltd (Cork, Ireland) | Apple Push Notification service; App Store distribution | Push tokens and notification payloads; App download and aggregated diagnostics | United States and Ireland | UK Extension to the EU-US DPF; Apple Developer Program terms |
| Microsoft Corporation (Redmond, USA) and Microsoft Ireland Operations Ltd (Dublin, Ireland) | Microsoft Entra ID and Entra External ID (sign-in); Microsoft 365 (our business email and documents) | Sign-in identifiers and tokens; business correspondence | EU Data Boundary and United States | UK Extension to the EU-US DPF; Microsoft Products and Services Data Protection Addendum |
| Mailgun Technologies, Inc. (a Sinch company) (San Antonio, USA) | Transactional email delivery for the Platform and website contact form | Email addresses, subject lines and message content of emails we send; contact-form submissions | European Union (Mailgun EU region) | Mailgun Data Processing Addendum with data stored in the EU; UK Addendum to the EU Standard Contractual Clauses for any access from outside the UK and EU |
| Atlassian Pty Ltd (Sydney, Australia) and Atlassian, Inc. (San Francisco, USA) | Jira Service Management (support portal), Confluence (knowledge base), Statuspage (service status) | Support requests and correspondence; status subscriptions | European Union and United States | UK Extension to the EU-US DPF (Atlassian, Inc.); Atlassian Data Processing Addendum |
| Ideal Postcodes Ltd (postcodes.io) (London, UK) | Postcode look-up | Postcode text entered | United Kingdom | Not required (UK) |
| Mobile network operators and IoT connectivity providers (United Kingdom) | SIM management and mobile data for Metering Equipment | SIM identifiers, connection records, data usage, device IP addresses | United Kingdom | Not required (UK) |
| Our accountants, payment providers, banks and insurers | Billing, payments, accounting and insurance | Billing contact details and transaction data | United Kingdom | Not required (UK) |
The Platform also retrieves public, non-personal data from the National Energy System Operator Carbon Intensity API and from Elexon (BMRS) for carbon and grid-mix analysis; no personal data is sent to these services.
Customers are notified of changes to this list in accordance with the Data Processing Addendum in our Terms of Service.