New since 1 August: consumption points with a bidirectional meter are billed on net metering.See what changed ›
Legal

Privacy Policy

This privacy policy describes how Gridea OÜ (hereinafter "Gridea" or "we") processes personal data and electricity data in providing the Gridea portal and related services. Gridea OÜ is the data controller of this data within the meaning of the General Data Protection Regulation (GDPR). The policy applies both to portal users and to persons who have granted Gridea an access right to their data in the e-elering portal.

1. What data we process

  • Account data — name, email address, role in the portal, associated company, password hash, and the time and version of acceptance of the terms of use.
  • Electricity data from Elering's data hub — metering point data (EIC code, address, technical parameters) and consumption and production data at hourly or 15-minute resolution. For a private individual customer, consumption data is personal data.
  • Customer relationship data — company name and registry code, validity of access rights and authorisations, and subscription and billing data.
  • Technical data — log records of logins and significant operations (including IP address and time of the operation) for security and auditing purposes.
  • Cookies — we use only cookies strictly necessary for the operation of the service; the cookie policy describes them in more detail.

2. Processing of electricity data on the basis of an Elering access right

We process data from Elering's data hub solely on the basis of a valid access right granted by the customer to Gridea OÜ in the e-elering portal, and only for the duration of that access right. The processing purpose registered with the access right in Elering is consumption monitoring and analysis; we do not use this data for any other purpose.

  • The access right grants only the right to view and download data. It does not give Gridea the right to conclude or amend contracts or to perform any other actions on the customer's behalf.
  • We use the data for service features: displaying and analysing consumption, comparing and optimising network tariffs, detecting anomalies, forecasts, and reports.
  • The access right can be revoked at any time in the e-elering portal (the "My roles and rights" section). Upon revocation we stop loading new data immediately; revocation does not affect the lawfulness of processing that took place before it.
  • After the access right ends, we retain data already loaded in order to display the service history; at the customer's request we delete it (see "Your rights").

3. Purposes and legal bases of processing

  • Providing the service — account management, portal features, reports, and notifications. Basis: performance of a contract (GDPR Art. 6(1)(b)).
  • Electricity data analysis — processing of data from Elering's data hub to the extent described in the previous section. Basis: the access right/consent granted in e-elering (GDPR Art. 6(1)(a)); for a business customer, also performance of a contract.
  • Security — prevention of misuse, logging, and investigation of incidents. Basis: legitimate interest (GDPR Art. 6(1)(f)).
  • Legal obligations — accounting and tax records. Basis: a legal obligation (GDPR Art. 6(1)(c)).

We do not sell data to third parties, do not use it for marketing profiling, and do not make decisions based solely on automated processing that would have legal consequences for the customer.

4. To whom we disclose data

To provide the service we use data processors with whom data processing agreements have been concluded:

  • database and infrastructure service (Supabase);
  • application hosting (Vercel);
  • sending of emails (Resend).

Where data is transferred outside the European Economic Area, this takes place on the basis of applicable safeguards (e.g. the European Commission's standard data protection clauses or an adequacy decision). If your company's energy portfolio is managed in the portal by a service partner of your choice, they can see your metering point data within the scope of their role. We disclose data to authorities only on a legal basis.

5. Retention

  • Account data: until the account is deleted; thereafter we delete or anonymise it within a reasonable time.
  • Electricity data: for the duration of the service; after the access right ends we delete it at the customer's request.
  • Accounting source documents: 7 years (the Accounting Act).
  • Security logs: generally up to 12 months.

6. Your rights

You have the right to:

  • access the data processed about you;
  • request the correction of inaccurate data;
  • request the erasure of data (the "right to be forgotten");
  • restrict processing and object to processing;
  • receive the data in a portable form (data portability);
  • withdraw consent at any time — in the e-elering portal or by writing to support@gridea.io.

We respond to requests within one month at the latest. If you consider that your rights have been violated, you have the right to contact the Data Protection Inspectorate (www.aki.ee) or the courts.

7. Security

We use appropriate technical and organisational safeguards: encrypted data transmission (HTTPS), role-based access restriction, password hashing, security logs, and regular backups. We notify the supervisory authority and affected persons of any personal data breach in accordance with the procedure laid down by law.

8. Changes

We may update the privacy policy; the date of the current version is shown in the document header. We will notify you of significant changes in the portal or by email.

9. Contact

For data protection questions, write to: support@gridea.io · Gridea OÜ (reg. no. 17165308) · www.gridea.io

This document is available in Estonian, English and Russian. In case of any discrepancy or translation error, the Estonian version prevails.