Privacy Policy
Who we are
Ductly is a business energy broking service operated by Ductly Ltd, a company registered in England and Wales (company number 17192912), registered office 71-75 Shelton Street, Covent Garden, London WC2H 9JQ. When we refer to "we", "us", or "our" in this policy, we mean Ductly Ltd, the data controller for the personal data described below. We are registered with the Information Commissioner's Office (registration ZC137221). Contact us via our contact page.
What data we collect
When you request a quote through our website, we collect:
- Your name, email address, phone number, and business name
- Your business postcode
- A copy of your energy bill (if you choose to upload one)
- Information extracted from that bill: your supplier, contract end date, unit rates, and consumption data
If you accept analytics cookies, we also collect standard web analytics data (pages visited, browser type, referring URL). This is not collected unless you accept analytics cookies. See our Cookie Policy for detail.
How we use your data
We use your data to prepare and present energy quotes relevant to your business, contact you about those quotes by phone or email, comply with our regulatory obligations as an energy broker, and improve our website and service.
Our legal bases for processing are:
- Legitimate interests: preparing and presenting quotes, contacting you about them, and operating our brokerage service. You can object to processing based on legitimate interests at any time.
- Consent: for setting non-essential analytics cookies. You may withdraw consent at any time using the cookie banner or your browser settings.
- Legal obligation: keeping records we are required to keep as an energy broker.
To exercise any right or raise a query, use our contact page.
Who we share your data with
We share your data with energy suppliers and our aggregation partner (Tritility) solely for the purpose of obtaining and presenting quotes to you. Once we pass your data to a supplier or to Tritility, they process it as independent data controllers under their own privacy policies, and your rights also apply to them directly. We do not sell your data. We do not share it with any other third parties unless required by law.
How long we keep your data
We retain your data for up to 3 years from the date of your last interaction with us, after which it is securely deleted. Uploaded bill files are retained for the same period. Where we are required to keep certain records for longer to meet a legal or regulatory obligation, we retain only what is necessary for that purpose.
Your rights
Under UK GDPR you have the right to access, correct, or delete your personal data; to object to or restrict processing; to data portability; and to object to processing based on our legitimate interests. To exercise any of these rights, contact us. You also have the right to lodge a complaint with the ICO at ico.org.uk.
International transfers
Your data is stored within the EU (see Security below). Where any processor we use transfers data outside the UK or EEA, we ensure an appropriate safeguard is in place, such as the UK International Data Transfer Agreement or equivalent standard contractual clauses.
Security
Your data is stored securely on Supabase infrastructure hosted within the EU. Access is restricted to authorised Ductly staff only.
Changes to this policy
We may update this policy from time to time. The date at the top of this page reflects the most recent revision.
