ESOS IQ

Source-backed ESOS account intelligence

PRIVACY INFORMATION

How ESOS IQ uses personal information

The account, support and product-measurement data flows used by ESOS IQ—separate from the published organisation evidence you research.

Version privacy-policy-2026-08-28 · Effective 28 August 2026

Account creation is temporarily unavailable.

Public evidence search and support remain available while the required controller contact and governing terms are completed.

1. Controller and contact

Christopher Rae is identified as the individual controller for ESOS IQ.

The controller contact and governing terms must be configured before account creation can proceed. Public evidence search remains available.

You can also use the privacy support route. Do not include passwords, authentication codes or unnecessary confidential information.

2. Information used

Public visitors

  • A short-lived, pseudonymous security subject may be used for rate limiting.
  • Limited server-side events record that a page or search journey was used and whether results existed. Search words are not sent to PostHog.
  • Standard hosting and security logs may include IP address, request metadata, device/browser information and timestamps.

Verified account users

  • Email, verification and authentication records.
  • Pseudonymous user/account identifiers, access basis, membership, permissions and versioned policy acceptance.
  • Research purpose, selected energy theme and optional starting query.
  • Saved views, tracked organisations, alerts, comparisons, exports, Evidence case activity and account-security actions.

Support and feedback

  • Email, category, affected page, message, account identifier when signed in, status, timestamps and the privacy version acknowledged.
  • If you explicitly ask for a reply to feedback, the contact details and permission supplied for that response. This is not consent to general marketing.

3. Why information is used

Provide the requested service

To create and secure a verified account, deliver the selected Explore — Free, Professional or Team access, preserve governed work and respond to account or support requests.

Protect and improve ESOS IQ

To prevent misuse, enforce access boundaries, diagnose failures, recover data and measure whether core first-user journeys deliver value.

Reply when you ask

Optional feedback/contact permission is used only for the requested follow-up and can be withdrawn through support.

Meet legal duties

To respond to valid rights requests, security incidents, legal claims or duties applying to the configured operator.

ESOS IQ does not use account behaviour to infer purchasing intent, build advertising profiles or make solely automated decisions with legal or similarly significant effects.

4. Processors and data flows

ProviderCurrent role
SupabasePostgreSQL database, row-level access controls, authentication and authentication-email orchestration.
VercelApplication hosting, delivery, runtime execution, security and operational logs.
ResendTransactional support and service email delivery when active; no marketing campaign is authorised.
PostHog EULimited server-side product events with pseudonymous identifiers, no search text, browser autocapture, replay or person profiles.
GitHubPrivate source control, deployment workflow records and encrypted recovery artifacts only when the corresponding workflow completes.
StripeSecure Checkout, subscription, invoice, payment and billing management if live purchasing opens. Explore creates no Stripe customer, card, charge or subscription.

Providers may process data in locations described by their current terms and safeguards. Current transfer information can be requested through the privacy support route. Personal information is disclosed only where needed for these services, security, legal obligations or a properly notified future business transfer.

5. Cookies, local storage and analytics

Supabase authentication uses strictly necessary browser storage/cookies to keep a signed-in session secure. ESOS IQ does not currently load a browser PostHog library, set an analytics cookie, run session replay, autocapture behaviour or use advertising pixels. The guided tour uses product state, not cross-site tracking.

If optional browser analytics or marketing technology is proposed later, it must remain off until the notice and consent behaviour are reviewed and updated.

6. Account acceptance, feedback and marketing are separate

Signup requires acceptance of the versioned Terms and acknowledgement of this privacy information. It does not contain a marketing checkbox. Support processing is limited to investigating and replying to the submitted request. Optional feedback contact permission, when shown, applies only to that follow-up. ESOS IQ does not currently send marketing email.

7. Retention, backups and deletion

  • Account and governed workspace data: retained while the account is open, then deleted or restricted through the process in the Deletion Policy.
  • Policy, entitlement, security and governance audit: retained where needed to prove acceptance, protect access, investigate abuse or establish legal claims; it is not used for marketing.
  • Support and optional feedback: retained only while needed to resolve, follow up and evidence the request, then deleted or de-identified under the configured retention schedule.
  • PostHog events and provider logs: governed by the applicable project/provider retention settings and minimised to the stated operational purpose.
  • Database backups: backup and restore evidence is monitored separately; no recovery claim is made unless the corresponding run completed successfully.

Retention is limited using the purpose-based criteria above and the configured provider schedules. A deletion request may not remove information that must be retained for security, a legal claim or another legal duty; retained use is restricted to that purpose.

8. Your rights and complaints

Depending on the purpose and applicable law, you may request access, correction, deletion, restriction, objection or portability, and may withdraw consent where consent is used. Identity may need to be verified before protected data is disclosed or changed.

Use Privacy or account closure. You may also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.

9. Security, incidents and changes

Email verification, server-side access checks, rate limits, restricted service credentials, workspace isolation and database row-level security protect account data. No internet service can guarantee absolute security; report a suspected issue through Security concern.

The version and effective date identify the notice acknowledged at signup. Material changes will be presented clearly and fresh acceptance or consent requested where required. This notice will be updated before browser analytics, marketing, a new operator or changed processors are introduced.