Data Protection
Home » Data Protection
Last updated: 13-July-2026
Zentiq Energy is committed to handling personal information responsibly, lawfully and securely.
This page explains the principles we follow when collecting, using, storing, sharing and protecting personal information across our website, franchise activities, technology platform, partner network and battery-related services.
It should be read together with our Privacy Policy and Cookie Policy.
1. About Zentiq Energy
For the purposes of this Data Protection Statement, “Zentiq Energy”, “we”, “us” and “our” refer to:
Legal company name: Zentiq Energy
Registered office: 20–22 Wenlock Road, London, England, N1 7GU
Email: info@zentiqenergy.com
Telephone: 0044 0207 0461830
Depending on the service or business relationship, Zentiq Energy may act as:
- A data controller
- A joint controller
- A data processor
- A service provider acting on behalf of another organisation
The role we perform will depend on who decides why and how the personal information is processed.
2. Our Data Protection Principles
Zentiq Energy aims to process personal information in accordance with the following principles.
Lawfulness, Fairness and Transparency
We aim to use personal information lawfully, fairly and in a way that people can understand.
Where required, we explain:
- What information we collect
- Why we collect it
- How it will be used
- Who it may be shared with
- How long it may be retained
- What rights may apply
Purpose Limitation
We aim to collect personal information for clear and legitimate purposes.
We should not use personal information for a new and incompatible purpose without first considering whether another lawful basis or additional notice is required.
Data Minimisation
We aim to collect only the information reasonably needed for the relevant purpose.
For example, a general enquiry should not require the same level of personal or financial information as a formal franchise application.
Accuracy
We aim to keep personal information accurate and up to date where reasonably possible.
People may contact us to correct information that is inaccurate or incomplete.
Storage Limitation
We aim to keep personal information only for as long as it is reasonably needed.
Retention periods may depend on:
- The type of information
- The reason it was collected
- Contractual requirements
- Legal and regulatory duties
- Accounting and tax rules
- Potential disputes or claims
- Operational and security needs
Integrity and Confidentiality
We aim to protect personal information against unauthorised access, misuse, accidental loss, destruction or damage.
The security measures used should be appropriate to the nature and sensitivity of the information and the risks involved.
Accountability
Zentiq Energy is responsible for its use of personal information and should be able to demonstrate the steps taken to support compliance.
The ICO describes accountability as taking responsibility for data protection and keeping suitable measures and records to demonstrate compliance.
3. Information Covered by This Statement
This statement may apply to information relating to:
- Website visitors
- Customers
- Franchise applicants
- Franchisees
- White-label partners
- Workshops and technicians
- Platform users
- Fleet operators
- Dealers
- Auction businesses
- Insurance and assessment partners
- Job applicants
- Employees and contractors
- Suppliers
- Business contacts
- Vehicle owners
- People named in reports, certificates or service records
The information may include:
- Names
- Contact details
- Business details
- Application information
- Account information
- Payment and transaction records
- Communication records
- Job application information
- Technical support records
- Website usage data
- Vehicle information
- Battery diagnostic information
- Reports and certificates
Vehicle or battery information may become personal information where it can be linked to an identifiable person.
4. Data Protection by Design
Zentiq Energy aims to consider privacy and data protection when introducing or changing:
- Website forms
- Franchise processes
- Platform features
- Reporting tools
- Certificates
- Customer databases
- Partner systems
- Marketing systems
- Recruitment processes
- Data-sharing arrangements
- New services and technologies
This means considering privacy at the planning stage rather than only after a system has been launched.
Data protection by design and by default requires organisations to build suitable safeguards into systems and business practices from the beginning and throughout the lifecycle of the processing.
Where appropriate, we may consider:
- What information is genuinely needed
- Who should have access
- How long the information should be retained
- Whether information can be anonymised or pseudonymised
- How people will be informed
- Whether a privacy risk assessment is needed
- How information will be protected
- How information can be deleted or corrected
5. Technical and Organisational Measures
Zentiq Energy aims to use technical and organisational measures that are proportionate to the risks involved.
Depending on the system and the information processed, these measures may include:
- User access controls
- Strong passwords
- Multi-factor authentication
- Role-based permissions
- Secure hosting
- Encryption where appropriate
- Regular software updates
- Malware protection
- System monitoring
- Secure backups
- Controlled data exports
- Confidentiality obligations
- Staff guidance
- Supplier checks
- Incident-response procedures
- Data-retention schedules
- Access reviews
- Secure disposal methods
The exact measures may vary according to the type of system, service, user and data involved.
No security measure can completely remove every risk. However, reasonable steps should be taken to reduce the likelihood and effect of unauthorised access, loss or misuse.
The ICO advises organisations to assess risk and use suitable organisational, physical and technical measures rather than relying on a single security control.
6. Access to Personal Information
Access to personal information should be limited to people who need it for an authorised business purpose.
Depending on the system, access may be given to:
- Authorised Zentiq Energy personnel
- Approved service providers
- Franchisees
- White-label partners
- Workshop personnel
- Technical support providers
- Professional advisers
- Other approved business partners
Access should be appropriate to the person’s role.
Users must not:
- Share login details
- Access information without a business reason
- Copy or export information without approval
- Use personal information for personal purposes
- Disclose information to unauthorised people
- Attempt to bypass security controls
Access may be removed or restricted when:
- A role changes
- A business relationship ends
- A user no longer requires access
- A security concern arises
- Terms of use are breached
7. Franchise and Partner Responsibilities
Franchisees, white-label partners, workshops and other authorised partners may handle personal information relating to customers, employees, vehicles and battery reports.
Depending on the arrangement, the partner may act as:
- An independent data controller
- A joint controller
- A processor acting for Zentiq Energy
- A controller using Zentiq systems
The applicable agreement should explain the responsibilities of each party.
Partners are expected to:
- Follow applicable data protection laws
- Use information only for authorised purposes
- Restrict access to authorised personnel
- Protect account credentials
- Keep information accurate
- Follow approved retention and deletion processes
- Report suspected data incidents promptly
- Respect individual rights
- Use Zentiq reports and systems properly
- Avoid unauthorised exports or disclosures
Zentiq Energy does not claim that every franchisee or partner is automatically compliant merely because they use Zentiq systems. Each independent business remains responsible for its own legal obligations where it acts as a controller.
8. Data Sharing
Personal information may be shared where there is a lawful and legitimate reason.
This may include sharing with:
- Franchisees
- White-label partners
- Workshops
- Fleet operators
- Dealers
- Auction or insurance partners
- Technology providers
- Cloud and hosting providers
- Payment providers
- Professional advisers
- Regulators
- Courts or law-enforcement bodies
- Business buyers or investors, where appropriate
Before personal information is shared, we may consider:
- Why the information is needed
- Whether the recipient is authorised
- Whether the information can be limited
- Whether a contract is required
- Whether appropriate safeguards are in place
- Whether the individual has been informed
- Whether international transfer rules apply
Where a supplier processes information on our behalf, suitable contractual arrangements should be used where required.
9. Processor and Supplier Management
Zentiq Energy may use external providers for services such as:
- Website hosting
- Cloud storage
- Customer relationship management
- Analytics
- Payment processing
- Platform infrastructure
- Support systems
- Recruitment
- Marketing
- Document management
Before using a provider, we may review matters such as:
- The services provided
- The information involved
- Security arrangements
- Location of processing
- Subcontractors
- Retention arrangements
- Incident procedures
- Contractual protections
Where required, the agreement should define:
- The subject and duration of processing
- The nature and purpose of processing
- The types of personal information
- The categories of individuals involved
- Confidentiality obligations
- Security requirements
- Subprocessor controls
- Deletion or return of information
- Audit and assistance obligations
Both controllers and processors have responsibilities to maintain appropriate security. Depending on the risks, measures may include encryption, resilience, restoration capability and regular testing.
10. International Data Transfers
Zentiq Energy may work with users, suppliers, franchisees and partners in different countries.
Personal information may therefore be stored in or accessed from another country.
Where international transfer rules apply, we aim to use an appropriate legal transfer mechanism.
This may include:
- An adequacy decision
- The UK International Data Transfer Agreement
- The UK Addendum to approved contractual clauses
- Standard Contractual Clauses
- Another legally recognised safeguard
The Privacy Policy provides further information about international transfers.
11. Retention and Secure Disposal
Zentiq Energy aims to avoid keeping personal information indefinitely.
Retention periods should be based on:
- Business need
- Legal duties
- Contractual requirements
- Industry practice
- Tax and accounting rules
- Complaint and claim periods
- Security needs
When information is no longer required, it may be:
- Deleted
- Securely destroyed
- Anonymised
- Archived where legally justified
- Returned to the relevant organisation
The method used should be appropriate to the format and sensitivity of the information.
12. Personal Data Breaches
A personal data breach may include:
- Information sent to the wrong person
- Loss or theft of a device
- Unauthorised account access
- Malware or ransomware
- Accidental deletion
- Loss of availability
- Improper disclosure
- Unauthorised alteration
- Lost documents
- Compromised login details
Suspected breaches should be reported promptly to the appropriate Zentiq Energy contact.
Zentiq Energy may then:
- Contain the incident
- Protect affected systems
- Investigate what happened
- Assess the information involved
- Evaluate the potential risk to individuals
- Document the incident
- Notify affected organisations
- Notify individuals where required
- Report the breach to a supervisory authority where legally required
- Review controls to reduce the risk of recurrence
Franchisees, partners and service providers should not delay reporting an incident while trying to investigate it alone.
13. Individual Rights
Depending on the applicable law, individuals may have rights relating to their personal information.
These may include the right to:
- Request access
- Request correction
- Request deletion
- Request restricted processing
- Object to certain processing
- Withdraw consent
- Request data portability
- Raise concerns about automated decisions
- Complain to a supervisory authority
Requests should be passed promptly to the appropriate privacy contact.
Identity checks may be required before information is disclosed or changed.
Rights are not always absolute and may be subject to legal conditions or exemptions.
14. Training and Awareness
People who handle personal information should understand their responsibilities.
Where appropriate, Zentiq Energy may provide or require guidance covering:
- Secure handling of personal information
- Password and account security
- Phishing and suspicious messages
- Confidentiality
- Data sharing
- Retention
- Incident reporting
- Use of customer and vehicle information
- Responding to rights requests
- Use of platform and reporting tools
Training requirements may vary according to the person’s role and level of access.
15. Records and Governance
Where appropriate, Zentiq Energy may maintain records such as:
- Processing activity records
- Retention schedules
- Supplier information
- Data-processing agreements
- Access records
- Consent records
- Incident logs
- Rights-request records
- Privacy notices
- Risk assessments
- Training records
- Policy reviews
These records help support accountability and business continuity.
16. Privacy Risk Assessments
A privacy or data protection impact assessment may be considered where a proposed activity could create a higher risk to individuals.
Examples may include:
- Large-scale monitoring
- New profiling or automated assessment
- Sensitive information
- New tracking technology
- Large partner databases
- International data-sharing systems
- New platform functions
- Combining information from several sources
The assessment may consider:
- The purpose of the activity
- Whether the processing is necessary
- The people affected
- Possible privacy risks
- Security controls
- Alternative approaches
- Whether specialist advice is needed
17. Vehicle and Battery Data
Zentiq Energy may process technical vehicle and battery information through its diagnostic, reporting or platform services.
This may include:
- Vehicle identifiers
- Mileage
- Battery condition
- Fault codes
- State of health
- State of charge
- Test results
- Technician observations
- Repair recommendations
- Certificate details
Technical information should be treated as personal information where it can reasonably be linked to an identifiable customer, account holder, vehicle owner or driver.
Where possible, aggregated or anonymised battery information may be used to:
- Improve reporting
- Understand battery trends
- Develop technical benchmarks
- Improve services
- Support research and business analysis
Anonymised information should not be presented in a way that identifies an individual.
18. Automated Tools and Assessments
Zentiq systems may use software calculations, diagnostic rules or automated processes to support battery assessments and reporting.
Automated outputs may assist technicians, partners or business users, but they may not be suitable as the only basis for a decision that has a significant effect on a person.
Where appropriate:
- Results should be reviewed by a suitably qualified person
- The limitations of the report should be explained
- Incorrect source information should be corrected
- People should be able to raise questions
- Human judgment should remain part of important decisions
19. Monitoring and Review
Data protection arrangements should be reviewed periodically and when significant changes occur.
A review may be needed when:
- A new service is launched
- A new country is entered
- A new supplier is appointed
- A new platform feature is introduced
- A security incident occurs
- A legal requirement changes
- A new category of information is collected
- A partner relationship changes
- A new marketing or analytics tool is introduced
Updates may be made to policies, contracts, security measures, training or retention periods where necessary.
20. Complaints and Concerns
Questions or concerns about data protection should be sent to:
Zentiq Energy
Legal company name: Zentiq Energy
Registered office: 20–22 Wenlock Road, London, England, N1 7GU
Email: info@zentiqenergy.com
Telephone: 0044 0207 0461830
Individuals may also have the right to complain to the relevant supervisory authority.
In the United Kingdom, this is the Information Commissioner’s Office.
21. Changes to This Statement
Zentiq Energy may update this Data Protection Statement to reflect changes in:
- Law
- Technology
- Services
- Business structure
- Partner relationships
- Security arrangements
- Platform functions
- International operations
The updated version will be published on this page with a revised date.
