Privacy policy

Last updated 13 September 2026.

This page says what personal data we collect, why, how long we keep it, and what your rights are. We collect as little as we can.

1. Who is responsible

The Energy Incident Register is the data controller. Contact: privacy@energyincidentregister.com or info@energyincidentregister.com.

2. What we collect and why

  1. Incident submissions. Your name, email address and role, plus the incident text. We use them to review the submission, ask follow-up questions, and tell you the outcome. Legal basis: our legitimate interest in running the register, and your consent when you submit. Submitter details are never published and are separated from the published entry by database access rules.
  2. Accounts. Email address, password (stored as a hash by Supabase), sign-in times, and your plan status. We use them to run your account and provide what you paid for. Legal basis: contract.
  3. Incident alerts. Email address, the page you signed up on, confirmation and unsubscribe times. We use them to send the alerts you asked for. Legal basis: consent. Every email has an unsubscribe link.
  4. Payments. Stripe collects your card details and billing address. We never see the full card number. We store the Stripe customer and subscription identifiers and your plan status. Legal basis: contract, and legal obligation for tax records.
  5. Correspondence. Emails you send us, so we can reply and keep a record. Legal basis: legitimate interest.
  6. Site analytics. We use Plausible, which does not use cookies and does not identify individuals. It records page views, referrers, country, device type, and events such as "alert signup" with no personal data attached. Legal basis: legitimate interest.
  7. Server logs. Netlify and Supabase keep short-lived technical logs (IP address, request, time) for security and reliability. Legal basis: legitimate interest.

3. What we do not do

4. Who we share data with

Only the providers we need to run the service, each under their own data protection terms: Supabase (database and accounts, hosted in the EU), Netlify (hosting and functions), Stripe (payments), Resend (email delivery), Plausible (analytics, EU hosted), and Anthropic (drafting and review of entries: the text of public sources, and for direct submissions the incident description and the submitter's stated role, never a name or an email address). We will disclose data if the law requires it.

5. International transfers

Some providers process data outside the UK and EU. Where they do, transfers rely on the UK and EU standard contractual clauses or an adequacy decision.

6. How long we keep data

7. Your rights

You can ask for a copy of your data, ask us to correct or delete it, object to or restrict processing, and withdraw consent at any time. Email privacy@energyincidentregister.com. We reply within 30 days. You can complain to the Information Commissioner's Office (ico.org.uk) if you are unhappy with our answer.

8. Security

Data is encrypted in transit and at rest. Database access is restricted by row level security so that private columns cannot be read through the public website. Administrative access requires a separate admin role. Secret keys are held in the hosting provider's environment settings, not in code.

9. Children

The service is for professionals. We do not knowingly collect data from anyone under 16.

10. Changes

We will update this page when our practices change and note the date at the top.