Privacy
Last updated 29 August 2026
Who this covers
This describes how [to supply: registered entity name] (“we”) handles information in the Copperloom platform. It applies to the people who sign in — the operations team and the staff of the organisations whose buildings are monitored.
The platform has no public sign-up. Every account is created by the operations team on behalf of an organisation, so we hold information about people because their employer asked us to.
What we hold
- Account details. Full name, User ID, email address and optionally a phone number. Passwords are never stored — only an Argon2id hash, which cannot be reversed to recover the password.
- Meter readings. Consumption figures read from the energy and water meters installed at the monitored sites, with the time of each reading. These describe a building, not a person.
- A record of actions. Significant changes — creating an organisation or a user, registering a meter, issuing or revoking an authority key — are written to an append-only audit log with who did them and when.
- Sign-in activity. Session records, failed sign-in counts and lockout state, kept so an account can be protected against password guessing.
What we do not do
There are no advertising or analytics trackers in this application. It loads no third-party scripts, sets no advertising cookies, and does not build a profile of you or sell information to anyone.
The only cookie the platform sets is the one that keeps you signed in. It is httpOnly, so no script can read it, and SameSite=Strict, so no other site can cause it to be sent. It is strictly necessary for the service to function.
Who it is shared with
- The certifying authority. Where a project is being certified, consumption figures for that project are made available to the authority through a key scoped to it. The key reaches that project and no other, and every request is recorded with its time and outcome. Personal details of your staff are not included.
- Meter manufacturers. We read from their systems to collect your readings. We do not send them information about you.
- Infrastructure providers. The platform runs on [to supply: hosting provider and region], and email is delivered through [to supply: email provider].
Beyond this we do not share information with anyone, except where we are legally required to.
Keeping organisations apart
Each organisation’s data is separated at the database level rather than only in application code, so a query made on behalf of one organisation cannot return another one’s rows. Within an organisation, people are granted specific projects and buildings, and every list, chart, report and download narrows to that grant.
How long it is kept
Meter readings are retained for [to supply: retention period for readings]. Account records are retained for [to supply: retention period after an account is closed]. Audit records are retained for [to supply: audit log retention period] because they exist to show what happened.
Your rights
You may ask what we hold about you, ask for it to be corrected, or ask for it to be deleted where we are not required to keep it. Because accounts belong to the organisation that asked for them, some requests are best made through your own organisation’s administrator.
These rights, and how disputes are resolved, are governed by [to supply: governing law and jurisdiction].
Contact
Write to [to supply: contact address for privacy requests]. We respond within [to supply: response window].