Privacy Policy

Data controller: HeatLoop OÜ, registry code 17562021, Mätta tn 3, Lagedi alevik, Rae vald, 75303 Harju maakond, Estonia. Contact for privacy matters: info@heatloop.com

This notice explains how HeatLoop OÜ processes personal data in accordance with the EU General Data Protection Regulation (GDPR), articles 12–14.

What we process and why

Website and application usage. When you use this website or our application we process account data (name, email address, hashed authentication data) and technical logs (IP address, browser details, timestamps). Legal basis: performance of a contract with you (account features) and our legitimate interest in operating and securing the service (logs). Retention: account lifetime plus up to 1 year; technical logs up to 1 year.

Business contacts. We process the work contact details and correspondence of our clients’ and partners’ representatives for ordinary B2B communication and contract management. Legal basis: legitimate interest. Retention: duration of the business relationship plus 3 years.

Energy metering data (Estfeed Datahub). As an energy service provider we retrieve metering point technical data and electricity consumption data (hourly / 15-minute resolution) of our clients’ buildings from Elering’s Estfeed Datahub, strictly on the basis of an authorization the client grants in the Estfeed customer portal. See the dedicated section below (in Estonian and English).

Accounting. Invoice and payment data is processed to fulfil our legal accounting obligations and retained for 7 years as required by the Estonian Accounting Act.

Energy metering data — Estfeed Datahub

Our service is directed at companies (building owners and managers). Metering data of legal persons is not personal data; where a metering point relates to an identifiable natural person, we treat the data as personal data and this policy applies in full.

  • What: metering point technical data and consumption time series (hourly / 15-minute), up to 12 months retroactively and ongoing data during the validity of the authorization.
  • Source: Elering AS Estfeed Datahub, only under an authorization granted by the client in the Estfeed customer portal (valid up to 3 years, revocable at any time).
  • Purposes: analysing the building’s electricity consumption and dimensioning our heat-reusing computing equipment, planning equipment operation and consumption, and service billing.
  • Legal basis: performance of the contract with the client; our legitimate interest in operating the service.
  • Recipients: our group company CSW Energy OÜ (registry code 17500385) only where the client has ordered electricity supply or flexibility services; no other recipients.
  • Retention: validity of the authorization plus the end of the billing period; as part of accounting records, 7 years.
  • No automated decision-making within the meaning of GDPR article 22 takes place.

Eesti keeles: Töötleme hoonete mõõtepunktide tehnilisi andmeid ja elektritarbimise mõõteandmeid (tunni/15-minuti resolutsioonis) Eleringi Estfeed Datahubist üksnes kliendi poolt Estfeed kliendiportaalis antud volituse alusel (kehtivus kuni 3 aastat, igal ajal tagasivõetav; tagasiulatuvalt kuni 12 kuud). Eesmärgid: hoone elektritarbimise analüüs ja seadmete võimsuse dimensioneerimine, seadmete töö ja tarbimise planeerimine ning teenusega seotud arveldus. Õiguslik alus: kliendilepingu täitmine ja õigustatud huvi. Andmeid edastame kontserni ettevõttele CSW Energy OÜ üksnes juhul, kui klient on tellinud elektritarne või paindlikkusteenuse. Säilitame andmeid volituse kehtivuse aja ja arveldusperioodi lõpuni; arveldusdokumentide koosseisus 7 aastat. Automatiseeritud otsuseid ei tehta.

Where your data is processed

All personal data is processed within the European Economic Area (hosting in an EEA data centre in Stockholm). We do not transfer personal data outside the EEA.

Cookies

Where necessary, this website uses cookies to store information about a visitor’s preferences and session in order to operate the service (e.g. authentication). We do not use third-party advertising cookies.

Security

Data is transmitted over encrypted connections (TLS), access is role-based and logged, API credentials are stored securely, and backups are kept within the EEA. In the event of a personal data breach we follow our incident response procedure, including notification of the Estonian Data Protection Inspectorate within 72 hours where required (GDPR article 33).

Your rights

You have the right to request access to, rectification or erasure of your personal data, restriction of processing, data portability, and to object to processing based on legitimate interest. Application users can export and delete their data in the application self-service. To exercise your rights, email info@heatloop.com — we respond within one month. You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).

Changes to this policy

This policy is effective as of 11 August 2026. We may update it from time to time; material changes will be announced on this page.

Contact

For any questions regarding this policy or our data processing, contact info@heatloop.com.