1. Who controls your data
The controller of personal data collected through this website and related early-access communications is Kamil Janiszewski, a sole proprietorship registered in Poland, NIP/VAT ID PL7262504188. You can contact the controller at privacy@gridpassport.com.
We have not appointed a Data Protection Officer because the current website and early-access activity do not require one. Privacy requests should be sent to the contact address above.
2. What this policy covers
This policy applies to GridPassport.com, the founding member application flow, Energy Brief subscriptions, contact emails and product research communications connected with GridPassport. It does not cover third-party websites, device manufacturers, energy suppliers or installers that may have their own privacy notices.
If GridPassport later launches a production app, hardware service, installer portal or connected energy product, that product may need an additional or updated privacy notice before it starts processing broader operational energy data.
3. Personal data we may collect
Depending on how you use the website, we may collect the following categories of personal data:
- Contact details, such as name, email address, company name and country.
- Early-access application details, such as your role, home energy setup, installed devices, tariff context and product needs.
- Energy Brief preferences, such as the selected countries or the location and PV system settings needed to prepare the requested email.
- Communications you send to us, including questions, feedback and support requests.
- Normal security and request data processed by our hosting, CDN and anti-abuse controls, such as an IP address, request headers, timestamp and whether a request passed a bot check. The form limiter stores keyed hashes and aggregate counters rather than raw IP addresses, email addresses, challenge tokens or form payloads.
- Optional Energy Brief engagement data, such as an approximate email open, a link click, a usefulness response, message identifier, timestamp, IP address and mail-client request data.
- Website resource data, such as HTTP request metadata that may be processed when Google-hosted fonts or other Google services are loaded.
- Consent and preference records, where we ask for optional marketing, research or cookie consent.
We normally collect this data directly from you. If someone recommends you as a potential early user or partner, we may receive basic contact context from that person or from publicly available professional sources. We do not intentionally collect special category data, such as health, biometric, political or religious data, and you should not include that type of information in forms or emails.
We do not ask for browser geolocation when you subscribe and we do not create a cross-site device fingerprint. A Solar Forecast location and coordinates are stored only when you provide or select them for that forecast. Raw IP and proxy headers are not copied into the Energy Brief or certification lead notification.
Providing personal data is voluntary. If you do not provide contact or application details, we may not be able to respond, evaluate early-access fit, deliver a requested Energy Brief or continue the conversation.
4. Why we use personal data and legal bases
5. Cookies and analytics
The current website is designed as a static marketing site and should not require non-essential cookies to work. It may load Google-hosted resources such as fonts, and this can disclose normal technical request data to Google. If we add Google Analytics, Google Tag Manager, advertising pixels, heatmaps or similar non-essential tracking, we will use consent controls where required.
Where a consent management platform is active, it will provide the current service-level cookie, vendor and preference details. The CMP should be treated as the live cookie layer, while this policy explains the broader privacy position.
If you separately enable Energy Brief engagement analytics, a message-specific image request may record an approximate open and message links may pass through a GridPassport redirect that records the click before opening the requested page. An open does not prove that a person read the message: privacy features, image proxies and security scanners can load images or links automatically. We therefore treat deliberate clicks and usefulness feedback as stronger signals. The optional setting is not required to receive the Energy Brief and can be withdrawn by contacting privacy@gridpassport.com. Clicking an explicit “Useful” or “Needs work” response records the feedback you chose to send.
6. How long we keep data
We keep personal data only for as long as it is needed for the purposes described above. As a baseline, contact and founding member data may be kept for up to 24 months after the last meaningful interaction. An unconfirmed Energy Brief request expires after 24 hours and never enters the active delivery list. Confirmed subscription data is kept until you unsubscribe, withdraw consent or the service is discontinued, subject to a minimal suppression record where needed to honour an opt-out. Sent-message and optional engagement records are normally kept for up to 24 months so we can measure whether the requested emails remain useful. Aggregate form-security counters are kept on a rolling 31-day basis; ordinary infrastructure logs are normally kept for up to 12 months unless security or legal needs require longer.
7. Sharing data with suppliers
Personal data may be handled by the controller, the website hosting infrastructure, Cloudflare Turnstile for bot and abuse detection, a transactional email provider, the internal GridPassport mailbox that receives confirmed signup notifications, a GridPassport-operated Mautic instance used for contact and subscription records, and Google services. The intended Google setup for email, documents and related communications includes Google Workspace, Gmail, Google Drive, Google Fonts and Google analytics or tag services if they are enabled with appropriate consent controls. Google and Cloudflare may process personal data as processors or independent controllers depending on the service and configuration.
We do not sell personal data. If another hosting, form, analytics, CRM or communications provider is added, we will update this policy or the consent management platform where required before relying on that provider for personal data processing. We may also disclose data if required by law, a court, a competent authority or to protect legal claims.
8. International transfers
Google, Cloudflare and email services may involve processing outside the European Economic Area or the United Kingdom. Where that happens, we rely on the transfer mechanisms made available for the relevant service, such as adequacy decisions, the EU-US Data Privacy Framework where applicable, standard contractual clauses or equivalent safeguards required by data protection law.
9. Your rights
If GDPR or similar data protection law applies to you, you may have the right to access, correct, delete, restrict, object to or receive a portable copy of your personal data. You can object to processing based on legitimate interests, and you can object to direct marketing at any time. Where processing is based on consent, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise these rights, contact privacy@gridpassport.com. We may need to verify your identity before fulfilling a request. We aim to respond within one month, unless the request is complex or the law allows a longer period.
You also have the right to lodge a complaint with a supervisory authority. In Poland, the competent authority is the President of the Personal Data Protection Office, Urząd Ochrony Danych Osobowych, ul. Stanisława Moniuszki 1A, 00-014 Warsaw, Poland, uodo.gov.pl.
10. Automated decision-making
We do not use personal data from this website for solely automated decisions that produce legal or similarly significant effects. We may manually review early-access applications to decide who is a good fit for the first GridPassport research or pilot conversations.
11. Security
We use reasonable technical and organizational measures to protect personal data. No internet service can be guaranteed to be perfectly secure, so we design data collection around minimization: collecting less data lowers the risk.
12. Children
GridPassport is not intended for children and we do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy as GridPassport moves from early product research to a commercial product. The latest version will always be posted on this page with the updated date.