New since 1 August: consumption points with a bidirectional meter are billed on net metering.See what changed ›
Legal

Data protection

1. Our approach

Data protection is the foundation of the Gridea service. We apply data protection by design and by default (GDPR Art. 25) — collecting only the data needed to provide the service and protecting it throughout its lifecycle.

2. Technical and organisational measures

  • Encryption of data in transit (TLS) and at rest.
  • Role-based access control and multi-factor authentication.
  • Regular backups and recovery procedures.
  • Logging and traceability to detect potential incidents.

3. Data location and sub-processors

Data is kept within the European Economic Area. We use carefully selected sub-processors (cloud, email and analytics services) with whom we have signed data-processing agreements (GDPR Art. 28).

4. Data breaches

In the event of a personal-data breach we notify the Estonian Data Protection Inspectorate within 72 hours and, where necessary, the affected users, as required by GDPR.

5. Data-processing agreements (DPA)

For business clients acting as a controller, we offer a separate data-processing agreement. To obtain one, write to: support@gridea.io.

6. Contact

For data-protection questions, contact: support@gridea.io.

This document is available in Estonian, English and Russian. In case of any discrepancy or translation error, the Estonian version prevails.