This Data Processing Addendum records the terms on which Compounding Energy Ltd (registered in England and Wales, company no. 17319227; registered office: Tanners Farm, Tanners Lane, Chalkhouse Green, Reading RG4 9AB) processes personal data on your behalf when you use our services. It is the standard DPA that applies to Desk and Enterprise subscriptions, and it is available to any customer.
This DPA forms part of the Terms of Service for customers whose use involves personal data. Enterprise customers may request a countersigned copy.
This DPA is between the customer named on the subscription account (you, the Customer) and Compounding Energy Ltd, a company registered in England and Wales under company number 17319227, registered office Tanners Farm, Tanners Lane, Chalkhouse Green, Reading RG4 9AB (Compounding Energy, we, us).
For the personal data described in clause 4, the Customer is the controller and Compounding Energy is the processor. Terms defined in the Terms of Service carry the same meaning here. Controller, processor, personal data, processing, data subject and personal data breach have the meanings given in the UK GDPR — that is, Regulation (EU) 2016/679 as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018, read with the Data Protection Act 2018.
Where we process personal data for our own purposes rather than yours — the billing and transaction records UK tax law requires us to keep, the cookieless analytics on our marketing website, and our own contact records — we act as controller in our own right. Our Privacy Policy, not this DPA, governs that processing.
Neither party is required to appoint a UK or EU representative under Article 27, and we are not obliged to appoint a data protection officer under Article 37. Data protection questions reach a named owner at privacy@compoundingenergy.com.
It is worth saying plainly, because it shapes everything below. Our services forecast wholesale electricity prices and dispatch for GB and European bidding zones. The data they ingest and publish is market and system data — day-ahead and imbalance prices, generation and demand, interconnector flows, unit and plant registries, outage notices, and weather — obtained from the public sources listed on the Licenses & Attribution page. That data describes markets, plants and networks, not identified or identifiable living individuals. It is not personal data, and this DPA does not apply to it.
Occasionally a fragment of personal data can sit inside a public market dataset — a named contact in a registry entry, for example. Where that happens we process it only as an incidental part of the source dataset, for the purposes in clause 3, and under the same security measures.
The personal data we process on your behalf is therefore limited to what is needed to run your account and keep the services secure: who your users are, how they authenticate, and what they use. Clause 4 describes it in full.
| Subject matter | Processing of personal data relating to the Customer's account holders and authorised users, so that Compounding Energy can provide the services described in the Terms of Service. |
|---|---|
| Duration | The term of the Customer's subscription, followed by the deletion and return process in clause 10 and the residual retention periods set out there and in the Privacy Policy. |
| Nature of the processing | Collection, recording, organisation, storage, retrieval, use, transmission, restriction and erasure, carried out by automated means on infrastructure operated by us and by the sub-processors identified in clause 6. |
| Purpose of the processing | Creating and administering accounts; authenticating users and issuing API keys; delivering forecasts, dispatch and accuracy data to authorised users; metering usage against plan limits; billing and subscription management; sending transactional email; detecting and preventing abuse; maintaining a security audit trail; and providing customer support. |
Data subjects — the Customer's account holders and the individual users the Customer authorises to use the services, including any technical, security or billing contacts the Customer gives us.
Categories of personal data:
The services are not designed to process special category data within Article 9 of the UK GDPR, or personal data relating to criminal convictions and offences within Article 10, and the Customer must not submit such data through them.
We give the Customer each of the commitments required by Article 28(3) of the UK GDPR. Lettered to match.
The Customer gives general written authorisation for us to engage sub-processors. Our current list is the one published under Who we share it with in the Privacy Policy — at the effective date of this DPA: Stripe (payment processing), Fly.io (application hosting and data storage, primary region London), Vercel (marketing-website hosting and cookieless analytics), Resend (transactional email), CARTO (base-map tiles), and Anthropic and Groq (the language models behind our in-product assistants). The list in the Privacy Policy is the authoritative and current one; the names here are a snapshot at this DPA's effective date, kept deliberately in one place rather than maintained twice.
Before a new sub-processor begins processing personal data on the Customer's behalf, we will notify account holders by email at least 14 days beforehand. The Customer may object within those 14 days on reasonable data protection grounds. We will work with the Customer in good faith to offer a change or a workaround; if we cannot, the Customer may terminate the affected subscription and we will refund the fees paid for the unused remainder of the then-current term. Where we must replace a sub-processor at short notice to keep the services secure or available, we will notify the Customer as soon as we reasonably can and the same objection right applies from that notice.
We engage each sub-processor under a written contract imposing data protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for the sub-processor's performance of its obligations.
We maintain appropriate technical and organisational measures under Article 32, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of the processing, and the risks to individuals. In summary:
We do not hold ISO/IEC 27001, SOC 2 or any equivalent third-party certification, and we make no claim to. We would rather say so here than let a procurement questionnaire assume otherwise. We will tell Desk and Enterprise customers if that position changes, and in the meantime we answer security questionnaires in writing under clause 11.
Our application infrastructure is hosted in the United Kingdom. Some of the sub-processors in clause 6 are US-based and may process limited operational data outside the UK and the EEA. Where they do, transfers are made under the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK International Data Transfer Addendum, together with the additional safeguards in each provider's data processing terms. The Customer instructs us to make those transfers for the purposes set out in clause 3.
We will not transfer personal data processed on the Customer's behalf to any other third country except on that basis, or on another lawful transfer mechanism, and any new recipient is a sub-processor change under clause 6.
We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal data we process on the Customer's behalf. Notice goes by email to the account holders and to any security contact the Customer has given us.
The notice will describe the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point for further information. Where we cannot provide all of that at once, we will provide it in phases without undue further delay.
As controller, the Customer decides whether a breach requires notification to the Information Commissioner under Article 33 or to data subjects under Article 34. We will not make those notifications on the Customer's behalf unless the Customer asks us to in writing, or the law requires it of us directly, and we will give the Customer reasonable assistance either way. We keep a record of breaches affecting the Customer's personal data and will make it available on request.
Within 30 days of termination or expiry of the subscription, the Customer may ask us to return a copy of the personal data we hold on its behalf. We will provide it in a commonly used, machine-readable format.
We will delete the personal data we process on the Customer's behalf from our production systems within 30 days of the later of termination and any such request, except where we are required to keep it by law or by the documented retention schedule in the Privacy Policy. At the effective date of this DPA that schedule means: billing and order records for seven years, as UK tax law requires; security audit logs for six months from the event; and usage logs and product events for 90 days from creation, after which they are deleted or aggregated. Anything retained under those exceptions stays subject to the security measures in clause 7, is not used for any other purpose, and is deleted at the end of the applicable period.
Where a customer has agreed a longer or shorter retention period in a signed order form, that period applies instead.
We will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 and this DPA. In the first instance we do that by responding in writing to a security and data protection questionnaire, within 30 days of receiving it.
If the questionnaire leaves matters genuinely unresolved, the Customer — or an independent auditor it appoints, who must not be a competitor of ours and must be bound by confidentiality obligations — may audit our processing once in any twelve-month period, on at least 30 days' written notice, during normal business hours, for no longer than is reasonably necessary, and in a way that does not disrupt the services or compromise the security or confidentiality of another customer's data. The Customer bears the cost of the audit, unless it reveals a material breach of this DPA by us, in which case we bear our own costs and the reasonable costs of the audit.
The Customer may audit more frequently where a supervisory authority requires it, or following a personal data breach affecting personal data we process on the Customer's behalf.
Audits do not extend to the premises or systems of our sub-processors, which we do not control; for those we will pass on the information and audit rights available to us under our own contracts with them. Because our infrastructure is operated by hosting sub-processors, on-site inspection of data-centre facilities is not something we are able to grant.
The limitations and exclusions of liability in the Terms of Service apply to this DPA. Liability under the Terms of Service and this DPA together is subject to a single aggregate cap, not to a separate cap for each. Nothing in this DPA limits or excludes liability that cannot be limited or excluded by law, restricts a data subject's rights under the UK GDPR, or affects a data subject's right to compensation under Article 82.
We may update this DPA as the services and the law change. We will notify account holders by email of material changes at least 14 days before they take effect, and the version and effective date at the top of this page always show the current text. Where a customer holds a countersigned copy, that copy governs until the parties agree a revision in writing.
This DPA forms part of the Terms of Service. If there is a conflict between this DPA and the Terms of Service about the processing of personal data, this DPA prevails. If there is a conflict between this DPA and the Privacy Policy, this DPA prevails for personal data we process on the Customer's behalf, and the Privacy Policy prevails for personal data we process as controller. A separately negotiated data processing agreement signed by both parties prevails over this page.
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, as set out in the Terms of Service.
To request a countersigned copy, or to ask anything about this document, email privacy@compoundingenergy.com.
Data Processing Addendum · Version 1.0 · Effective 28 August 2026
Compounding Energy Ltd, registered in England & Wales, company no. 17319227 · Registered office: Tanners Farm, Tanners Lane, Chalkhouse Green, Reading RG4 9AB