This policy describes how Compounding Energy Ltd (registered in England and Wales, company no. 17319227; registered office: Tanners Farm, Tanners Lane, Chalkhouse Green, Reading RG4 9AB) collects, uses, and protects personal data. We are the data controller for personal information you provide.
It covers this website and every Compounding Energy product, including CEAtlas, CEGridSight, CECadence, CompoundVision and CENovaSage. Where a product does something specific with your data, it is called out by name.
Account data — your email address, and any name, organisation or role you give us. Billing data — your plan, renewal dates, and the customer and payment identifiers our payment processor returns; we never see or store full card numbers. Work you save — sites, portfolios, studies and pipeline runs you choose to keep, stored against your account so they sync across your devices. Usage counters — counts of metered actions (site analyses, API calls, study credits) used to enforce plan limits. Product events — which features you open, with a session identifier, a truncated browser user-agent, and a one-way hashed IP address; we do not store raw IP addresses. Error reports — crash diagnostics (message, stack, page), which carry no identity.
Data you upload for analysis is treated as yours. In CEAtlas, met-mast and production CSVs uploaded for site calibration are processed in memory for the duration of that request only — used to compute the calibration factor and then discarded. They are never written to disk, logged, or retained. Portfolio and scenario data you save is held on encrypted storage, is never used to train or improve models, and is never shared with any third party.
We do not buy email lists. We do not run advertising or behavioural-targeting trackers. We do not sell or rent personal data, and we do not use your data for third-party advertising.
Contract — to provide paid services (account, billing, saved work, plan limits). Legitimate interests — to operate the free tier, keep the services secure, prevent abuse, and understand how the products are used; we balance these against your rights and you can object. Consent — for the waitlist and any optional product updates, which you can withdraw at any time. Legal obligation — to keep the transaction records UK tax law requires.
We use a small number of processors, each only for the purpose shown. This list is complete as at the effective date above.
We use no third-party error-monitoring service in production, and no third-party analytics beyond the cookieless website analytics described above — none at all inside the product applications themselves.
If you are a customer and we process personal data on your behalf, this is also the sub-processor list for our Data Processing Addendum, which commits us to emailing account holders at least 14 days before a new sub-processor begins processing personal data.
Our application infrastructure is hosted in the United Kingdom. Some providers above are US-based and may process limited operational data outside the UK and EEA. Where they do, transfers are made under the UK International Data Transfer Agreement or Standard Contractual Clauses, together with the additional safeguards in each provider's data processing terms.
The CEAtlas free trial gives full access to paid data, so we count what each trial uses: data volume, studies, API calls, and how many free trials an address has had. Those totals are stored against a salted one-way hash of your email address. The record holds no address, name or account link, but the hash is still personal data, because we can test whether a given address matches it.
We keep these counters for up to 60 days after last use, and — unlike everything else — an erasure request does not remove them. Being able to reset them on demand would remove the only limits on how much paid data a free trial can take and how often it can be restarted. We rely on our legitimate interest in preventing abuse (Art 6(1)(f)) and on Art 17(1)(c). You can object, and the counters are shown to you in a data export. Everything that identifies you — your address, account and activity records — is erased as normal, and being refused a second free trial never prevents you from subscribing.
If you are in the UK or EEA you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. California residents have equivalent rights under the CCPA.
If you hold a CEAtlas account you can exercise the main two yourself: a signed-in request to /api/dsr/export returns everything we hold for you, and /api/dsr/erase erases it. Two things deliberately survive that erasure, and both are listed in your export: the billing records the law requires us to keep, and the fair-use counters described above.
Otherwise, email privacy@compoundingenergy.com and we will respond within one month.
If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office at ico.org.uk.
We use first-party functional cookies and browser localStorage for strictly necessary purposes: keeping you signed in, remembering interface preferences, and a first-party session identifier. We load no third-party advertising or social-media trackers, and the website analytics we do use are cookieless. Because nothing we set is non-essential, no consent banner is required; if that ever changes we will ask first.
Access to paid data and account data is gated by signed tokens. IP addresses are stored only as one-way hashes. Payment card data never touches our servers. Stored data sits on encrypted volumes. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data, and we will tell you promptly if a breach affects you.
We may update this policy as our products evolve. We will notify account holders of material changes by email at least 14 days before they take effect. The version and effective date at the top show the current text.
Questions about this policy or your data? Email privacy@compoundingenergy.com.