Data Collection & Handling Policy
1. Introduction
This Data Collection & Handling Policy explains how RAFT ENERGY LTD (“RAFT Energy”, “we”, “us”, or “our”) collects, uses, stores, and protects personal data in compliance with the UK General Data Protection Regulation (UK GDPR), the EU GDPR, and the Data Protection Act 2018.
We are committed to handling all personal information responsibly, lawfully, and transparently — both through our website and in the course of our business operations.
2. Who We Are
RAFT ENERGY LTD
Registered Office: 86–90 Paul Street, London, EC2A 4NE, United Kingdom
Jurisdiction: England & Wales
Contact: team@raftenergy.co.uk
RAFT Energy is the data controller responsible for determining how and why personal data is processed.
3. What Data We Collect
We collect and process personal data when you:
- Submit an enquiry or contact form on our website.
- Subscribe to our mailing list or download content.
- Attend one of our events or webinars.
- Engage with us for business or partnership opportunities.
Data we may collect includes:
- Name
- Email address
- Telephone number
- Company name and role
- Any optional message or information you provide
We also collect limited technical data through analytics tools (e.g. Google Analytics) to understand website performance, such as browser type, device, location, and pages visited.
4. How and Why We Use Personal Data
We use personal data for the following purposes:
- Responding to your enquiries and requests.
- Providing information about our products, services, or events.
- Sending newsletters, marketing, and updates (only where permitted).
- Conducting sales follow-ups and partner outreach.
- Analysing and improving website performance and user experience.
- Meeting legal, regulatory, and compliance obligations.
We never sell or rent your personal data.
5. Legal Basis for Processing
We process personal data under one or more of the following legal bases:
- Legitimate Interests: for business communications, analytics, and relationship management.
- Consent: for marketing emails or newsletters (you can withdraw consent at any time).
- Legal Obligations: to comply with laws, tax, or record-keeping requirements.
6. How We Store and Protect Your Data
We apply appropriate technical and organisational measures to protect data, including:
- Encrypted storage and password-protected systems.
- Access controls limited to authorised personnel.
- Secure transfer protocols for data exchange.
- Regular review of systems and permissions.
Personal data is stored within the UK or EEA, or with trusted third-party processors (e.g. Mailchimp, Google) under recognised safeguards such as Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy — including legal, accounting, or reporting requirements.
We may keep contact details for as long as you remain engaged with RAFT Energy or until you request deletion.
When data is no longer needed, it is securely deleted or anonymised.
8. Sharing and Disclosure
We may share personal data with trusted service providers who support our operations — such as:
- Email marketing (Mailchimp)
- Web hosting and analytics (Google)
- Event management or CRM tools
All such partners act as data processors under written agreements that ensure GDPR compliance.
We do not share personal data with unauthorised third parties.
9. International Transfers
Where data is transferred outside the UK/EEA (for example to US-based providers), we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs); or
- EU–US Data Privacy Framework participation.
10. Your Rights
You have the right to:
- Access and receive a copy of your data.
- Request correction or deletion of inaccurate data.
- Withdraw consent at any time.
- Object to or restrict processing.
- Lodge a complaint with the Information Commissioner’s Office (ICO): www.ico.org.uk.
To exercise your rights, please contact team@raftenergy.co.uk.
11. Cookies and Tracking
We use cookies and similar technologies to enhance user experience and analyse website traffic.
For full details, see our Cookie Policy.
12. Data Breaches
In the unlikely event of a personal data breach, RAFT Energy will:
- Assess the severity and scope immediately;
- Notify the ICO within 72 hours (if required); and
- Inform affected individuals without undue delay if there is a high risk to their rights or freedoms.
13. Data Protection Governance
RAFT Energy maintains internal procedures and staff awareness measures to ensure data is handled lawfully and securely.
We review this policy and our privacy practices regularly to ensure ongoing compliance.
14. Updates to This Policy
We may update this Policy to reflect legal changes or improvements to our data-protection practices.
The latest version will always be available on this page with the updated date shown above.
15. Contact
For questions about this Policy or our data-protection practices, please contact:
📧 team@raftenergy.co.uk