Privacy Policy

We are committed to protecting and respecting your privacy. This policy explains how we collect, process and keep your data safe.

Last updated: 21 September 2026

Version: 2.2.

This version replaces our 2024 Privacy Policy and versions 2.0 (17 August 2026) and 2.1 (8 September 2026), copies of which are available from us on request; it covers website visitors, platform users and homeowners in one document, moves cookies to a separate Cookie Policy, and adds our EU representative, data sources and automated-decision statements.

  1. Who we are and how to contact us

1.1 This is the Privacy Policy of Spruce Energy Limited (“Spruce”, “we”, “us”), a company registered in England and Wales (company no. 14742634) with its registered office at 126 Mildmay Road, London, N1 4NE, United Kingdom.

1.2 We comply with the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018 and, where we process personal data of people in the European Economic Area or on behalf of customers established there, Regulation (EU) 2016/679 (the “EU GDPR”) and applicable national law, including in the Republic of Ireland the Data Protection Acts 1988 to 2018.

1.3 Contact. Data protection queries and requests: dataprotection@spruce.eco, or by post to the registered office above. Our Data Protection Lead is Jo Saxby (CEO). Having assessed our processing against Article 37(1) of the UK GDPR and the EU GDPR, we are not required to designate a Data Protection Officer and have not done so; the Data Protection Lead is not a DPO within the meaning of Articles 37–39. We keep this under review.

1.4 Our representative in the EU (Article 27 EU GDPR). Because we offer our services in Ireland but are established only in the United Kingdom, we have appointed a representative in the European Union. If you are in the EU or EEA and have questions or concerns about your personal data, you may contact them:

Euverify Ltd (Ireland), Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork, T23 AT2P, Ireland · Email: gdpr@euverify.com

To submit a data subject access request, a deletion request or any other GDPR enquiry through our representative, you can use their secure portal at https://gdpr.euverify.com/verify/ca3ddd31-e7b1-42a4-99fe-03fd0487956c, which also lets you verify the appointment. Requests submitted through the portal are logged and tracked. You may equally contact us directly at dataprotection@spruce.eco.

1.5 Complaints. You may complain to us at dataprotection@spruce.eco. We will acknowledge your complaint within 30 days and respond without undue delay (section 164A of the Data Protection Act 2018). You also have the right to complain to a supervisory authority: in the UK, the Information Commissioner’s Office (ico.org.uk), which is expected to become the Information Commission under the Data (Use and Access) Act 2025; in Ireland, the Data Protection Commission (dataprotection.ie); or the authority where you live or work in the EEA. We would appreciate the chance to address your concerns first.

  1. Which part of this policy applies to you

This policy covers four situations. Please read the one that applies to you.

2.1 You visit our website or contact us — spruce.eco or any other Spruce website (a website visitor, prospective customer or business contact). Spruce is the Controller. Sections 3.1, 3.4, 3.5, 3.6 and 4 onwards apply. Cookies and similar technologies on our websites are covered separately in our Cookie Policy at spruce.eco/legal/cookies.

2.2 You use the Spruce platform (app.spruce.eco) as an employee or contractor of a business that subscribes to Spruce, or as a guest (for example a surveyor, electrician, installer, a manufacturer’s or merchant’s representative, or a homeowner) invited to a job. Spruce is the Controller of your account, login, support and usage data and, for subscriber staff, billing data (section 3.2). The job data entered into the platform belongs to the subscribing business. That business controls it unless a job concerns another business’s customer, in which case that other business controls it or the two control it together (section 2.3 explains how this works for homeowners). Spruce processes that data as the subscribing business’s Processor under our Data Processing Agreement (spruce.eco/legal/dpa), and as a sub-processor where that business is itself acting for another. Individual users are also subject to our User Terms of Use (spruce.eco/legal/user-terms).

2.3 You are a homeowner (or the occupier of a property, or someone who is buying it or about to move into it) whose details have been entered into Spruce by an installer, manufacturer, merchant or other business that uses Spruce. That business is the Controller of your personal data. Where more than one business is involved in your job (for example an installer and a manufacturer or merchant), either one of them controls your data or they control it together as joint controllers; the business you dealt with can tell you which, and where they are joint controllers you can exercise your rights against either of them. Spruce processes your data only on the instructions of the business whose Spruce account your job is in, under a Data Processing Agreement, to produce surveys, calculations, designs, proposals, quotations and related documents. For questions or requests about that data, contact the business you dealt with; if you contact us, we will pass your request within 3 working days (Monday to Friday excluding English public holidays) to the business whose Spruce account your job is in, which will pass it to the controller where that is a different business. If you are invited to view your job in the Spruce platform as a guest, we are the Controller of the login and account data you create for that purpose (section 2.2); your job information remains controlled by that business. Section 3.3 explains the anonymised data we create from property information on our customers’ instructions and then use for our own purposes; sections 5 (security) and 7 (transfers) also describe how your data is protected while we hold it.

When a customer stops using Spruce we delete its job data, including your details, from our production systems within 90 days unless the customer asks for it to be returned or instructs otherwise, and backup copies age out within a further 12 months after that deletion. If a legal claim relating to the Spruce service (for example about a design) is made or reasonably anticipated, or the law or a regulator requires it, we may keep the specific data needed, acting as an independent controller, and delete it within 30 days after the claim is concluded or can no longer be brought (or the legal requirement ends). We may also keep a de-identified copy of a job record (with names, contact details, full addresses, UPRNs, EPC or BER certificate numbers and other direct identifiers removed and location reduced to a broad area, keyed only by the customer’s job reference so that it can be linked back to your job only at the customer’s request or if a legal claim is made) for up to 6 years after the design was produced, so that we and the customer can respond to any dispute about it; we hold that copy as an independent controller. Where we hold your data as an independent controller in these ways, our lawful basis is our legitimate interest in establishing and defending legal claims, or our legal obligation where the law or a regulator requires the retention (section 3.5), we may share it with our professional advisers and insurers (section 6.1), and sections 1 (contact and complaints) and 4 (your rights) apply to it. Otherwise the rest of this policy does not apply to you.

2.4 Your details appear in someone else’s job — you are named in a job in Spruce (for example as the contact at an installer, merchant, distributor or manufacturer) but do not use the platform yourself. The business that entered your details is the Controller of them and Spruce processes them as that business’s Processor: contact that business with any questions, or contact us at dataprotection@spruce.eco and we will pass your request on within 3 working days. If we later keep part of a job record as our own controller, in the two limited cases described at the end of section 2.3, sections 1, 3.5, 4, 5, 6 and 7 apply to that data and you may exercise your rights against us directly. Otherwise the rest of this policy does not apply to you.

  1. The personal data we collect and why

3.1 Website visitors and business contacts. When you browse spruce.eco, book a demo, download content, subscribe to our newsletter or otherwise contact us, we collect: identity and contact data (name, business email, phone, company, job title); the content of your enquiry; technical data (IP address, browser and device type, referring site and campaign identifiers); and your marketing preferences. We also obtain business contact details of prospective customers from publicly available sources (such as company websites, professional networking sites and installer certification registers) and from business data providers, so that we can introduce Spruce to businesses we think may benefit from it. We use this data to respond to you, run and improve our website, understand where visitors come from, and send business-to-business marketing in accordance with section 3.5.

3.2 Platform users (Spruce as Controller). When you use app.spruce.eco we collect: identity and contact data (name, email (a business email for subscriber staff), phone, and business and billing address); organisation data (legal name, company number and VAT number where you give them at sign-up); account data (login credentials, role, preferences, settings, the organisation you belong to); transactional data (subscriptions purchased and payments made; Spruce does not itself store card or bank account details: card and direct debit details are collected and processed by our payment provider, Stripe (stripe.com/privacy), and customers paying by bank transfer pay from their own bank); technical data (IP address, browser, device and operating system); usage data (how you use the platform, collected through first-party product analytics); and support data (correspondence and feedback). We do not collect special category data, criminal offence data, dates of birth or gender.

3.3 Property information (Spruce as Processor, then anonymised data). Our customers (installers and the manufacturers, merchants and other businesses that work with them) enter information about homeowners’ properties (floorplans, dimensions, construction, heat-loss and other calculations, system designs, energy data and EPC data) to produce their designs, proposals and quotations. We process that information as our customer’s Processor. Under our terms with customers, we also create Anonymised Property Data: we remove names, contact details, full addresses, UPRNs, EPC or BER certificate numbers and other identifiers, reduce location to a broad area (no finer than a UK postcode sector or an Irish Eircode routing key, being the first three characters of an Eircode, which identify a routing area such as a Dublin postal district or, elsewhere in Ireland, a town and its surrounding area or a large part of a county, and never the full Eircode, which identifies an individual property), and generalise or suppress any unusual combination of attributes that could otherwise single out a property, so that no person or individual property can reasonably be identified. We may use Anonymised Property Data to analyse, benchmark, develop, train and improve our products, calculation methods and models. We treat it as anonymised information, not personal data; if any of it turned out to be reasonably identifiable we would stop using it, treat it as personal data and re-anonymise or delete it.

3.4 Where we get data about you. Most data comes directly from you, from the business you work for, or from the business that invited you into a job. As described in section 3.1, business contact details for outreach may come from public sources or business data providers. Payment status comes from Stripe. We do not buy consumer marketing lists.

3.5 Lawful bases. We rely on: contract (to provide the platform to you or your organisation and to support you); legal obligation (tax, accounting and regulatory requirements); legitimate interests (running, securing and improving our business and website; understanding how the platform is used; business-to-business marketing to relevant businesses; establishing and defending legal claims), always balanced against your rights; and consent where the law requires it (for example, certain cookies and some marketing), which you can withdraw at any time. Marketing emails are sent in accordance with the Privacy and Electronic Communications Regulations 2003 (UK) and S.I. No. 336/2011 (Ireland); every marketing email contains an unsubscribe link.

Responding to website enquiries and demo requests

Data: Identity, Contact, enquiry content, Technical
Lawful basis: Legitimate interest; contract (if you become a customer)
Retention: 24 months from last contact

Business-to-business marketing and outreach

Data: Identity, Contact, Marketing
Lawful basis: Legitimate interest; consent where required
Retention: Until opt-out, or 24 months of inactivity

Registering and operating your platform account (including guest accounts)

Data: Identity, Contact, Account
Lawful basis: Contract
Retention: Active account + 24 months (a guest account is inactive once your access to your last job ends)

Billing and payment administration

Data: Identity, Contact, Transactional
Lawful basis: Contract; legal obligation
Retention: 6 years from end of the financial year

Support and relationship management

Data: Identity, Contact, Support
Lawful basis: Contract; legitimate interest
Retention: Active account + 24 months

Platform administration, security and troubleshooting

Data: Technical, Usage
Lawful basis: Legitimate interest; legal obligation
Retention: Operational logs 90 days; error-diagnosis records 6 months; security and audit logs 12 months

Product analytics on the platform

Data: Usage (linked to your account)
Lawful basis: Legitimate interest
Retention: 60 days, then aggregated statistics only

These periods mirror our master retention schedule (our Information Classification & Handling Policy, which we provide to customers on request). If you have an active complaint with us, or we reasonably believe a legal claim is in prospect, we may retain relevant data for longer.

We use your personal data only for the purposes we collected it for, unless we reasonably consider we need it for a compatible purpose. If we need to use it for an unrelated purpose, we will tell you and explain the lawful basis.

3.6 Do you have to give us your data? To open and run an account or take payment we need the identity, contact and payment details we ask for; without them we cannot provide the service. Marketing preferences and any details we mark as optional are not required, and you can browse our website without giving us any data. Providing data to us is not a statutory requirement, although we need certain business details (such as a VAT number) to invoice correctly.

  1. Your rights

4.1 Under the UK GDPR and, where applicable, the EU GDPR you have the right to: be informed (this policy); access your personal data (we respond within one month); rectification; erasure where there is no good reason for continued processing; object to processing, including an absolute right to object to direct marketing; restrict processing in certain circumstances; and data portability for data you provided that we process by automated means under contract or consent. Where we rely on consent, you may withdraw it at any time.

4.2 To exercise any right, email dataprotection@spruce.eco. No fee applies unless a request is manifestly unfounded or excessive. We may need to verify your identity.

4.3 Deletion and backups. You may close your account at any time and ask us to delete your personal data. We action deletion promptly, subject to the retention periods in section 3. Data deleted from our production systems ages out of encrypted backups automatically within 12 months at the latest and is never restored to live systems except in a disaster-recovery event, in which case it is re-deleted within 7 days. The exception is our annual archive of financial and statutory business records (for example invoices), which we must keep for up to 6 years and which is never restored to live systems. Where a legal obligation requires us to keep specific data longer, we will tell you what we have kept and why, and delete it once that obligation ends.

4.4 Marketing opt-out. Use the unsubscribe link in any marketing message or email dataprotection@spruce.eco. Opting out does not affect data we process on other lawful bases.

  1. How we protect your data

We apply the controls described in our Information Security Management Policy (which we provide to customers on request), including: encryption in transit (TLS 1.2 or higher) and at rest (AES-256); hosting on DigitalOcean infrastructure within the UK and EEA (production systems in London; encrypted backups in Frankfurt); multi-factor authentication for our staff’s administrative and cloud-service access, and least-privilege access controls; separated production and test environments (staging and test use anonymised or synthetic data, not your data); annual penetration testing of our web application and API by an independent tester holding CREST individual certifications; Cyber Essentials certification (current certificate dated 17 April 2026, recertification due 17 April 2027); and staff confidentiality obligations and training. No transmission over the internet can be guaranteed completely secure; if you believe your interaction with us is no longer secure, please contact us.

  1. Who we share your data with

6.1 We share personal data only with: service providers processing on our behalf under written data processing terms, namely hosting and infrastructure, document rendering, payment processing, transactional email, error monitoring, product analytics, customer relationship management, outreach and email tools, and our business productivity tools (email, documents and internal operations). The current list of these providers, with their locations, is published at spruce.eco/legal/sub-processors (which covers both the platform Sub-processor List and our own service providers). Professional advisers (lawyers, insurers, accountants) where necessary; authorities where required by law; and prospective buyers or investors in the event of a business sale, reorganisation or financing, in which case your data remains protected consistently with this policy and you will be notified of any change of controller. We never sell your personal data.

6.2 Advertising partners on our website (Meta, LinkedIn, Google and Microsoft) and consent-based analytics tools (Microsoft Clarity, PostHog, Segment) receive data only where you have consented through Cookie Settings, as explained in the Cookie Policy; our cookieless website analytics (Fathom) runs without consent (section 3 of the Cookie Policy explains why we consider it falls outside the cookie consent rules), and you can object at any time. No advertising, retargeting or cross-site tracking technologies run on the Spruce platform (app.spruce.eco): the only analytics on the platform is our own product analytics, operated for us by PostHog and described in section 8, and no homeowner information is ever shared with advertising partners.

6.3 Our website may link to third-party sites; their privacy policies, not this one, govern what they collect.

  1. International transfers

7.1 Our primary systems are in the United Kingdom (London) and our backups are in the European Economic Area (Frankfurt). Transfers from the UK to the EEA are made under the UK’s adequacy regulations for EEA states; for people in the EEA, transfers to Spruce in the UK are covered by the European Commission’s adequacy decisions for the United Kingdom (in force to 27 December 2031).

7.2 Some named service providers store or process data in the United States, namely our transactional email provider, our error-monitoring provider (whose records may include limited details from the platform needed to diagnose an issue) and the providers of our internal email, documents and project-tracking tools, as recorded in the Sub-processor List. Our hosting provider (DigitalOcean), our document-rendering provider (Browserless), our product-analytics provider (PostHog) and our internal messaging tool store data in the United Kingdom or the EEA, but their support and administrative staff may access it from the United States under the same safeguards. Each such transfer is made under the EU-US Data Privacy Framework and its UK Extension, or Standard Contractual Clauses with the UK Addendum or International Data Transfer Agreement. You can ask for a copy of the safeguards we rely on, or details of where they are published, by emailing dataprotection@spruce.eco.

  1. Cookies and similar technologies

Our use of cookies and similar technologies on our websites is explained in our Cookie Policy at spruce.eco/legal/cookies, where you can also change your choices at any time via Cookie Settings. On the Spruce platform (app.spruce.eco), signed-in users’ sessions rely on strictly necessary technologies (authentication and security). We also use first-party product analytics (PostHog, EU-hosted) to understand performance, reliability and feature usage, so that we can run, support and improve the service. This analytics does not use cookies and stores nothing on your device: events are associated with your signed-in account and processed on the basis of our legitimate interests in operating and improving the platform. It is never used for advertising. To the extent the cookie rules apply to it at all, in the UK we consider this use falls within the statistical-purposes exception in the Privacy and Electronic Communications Regulations (as amended by the Data (Use and Access) Act 2025), which requires us to give you a simple way to object. You can object at any time by emailing dataprotection@spruce.eco and we will stop using data associated with your account for product analytics (the security, audit and system logs we keep to run the platform safely are unaffected).

  1. Automated decision-making

We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. The platform’s calculations and recommendations are tools for our customer’s professional judgement, not decisions about individuals.

  1. Age limit

The Spruce platform is a business tool and is not intended for children. You must be 18 or older to use Spruce, and we do not knowingly collect data relating to children.

  1. Changes to this policy

This page (spruce.eco/legal/privacy-policy) is the only current version of our Privacy Policy. We keep it under review and will post updates here, with the “last updated” date revised. Material changes will be notified to account holders by email. Previous versions are available from us on request (dataprotection@spruce.eco).

  1. Interpretation

“Including” means “including but not limited to”. Email addresses in this policy may be used only for their stated purpose. Our staff are not authorised to vary this policy by email; only a written update to this page may do so.