GDPR Compliance
Last updated: 9/23/2026
EnerMath is committed to ensuring the security and protection of the personal information that we process, and to provide a compliant and consistent approach to data protection. We have always had a robust and effective data protection program in place which complies with existing law and abides by the data protection principles.
1. Information Audit
We have performed a company-wide information audit to identify and assess what personal information we hold, where it comes from, how and why it is processed and if and to whom it is disclosed.
2. Policies and Procedures
We have revised our data protection policies and procedures to meet the requirements and standards of the GDPR and any relevant data protection laws, including:
- Data Breaches - Our breach procedures ensure that we have safeguards and measures in place to identify, assess, investigate and report any personal data breach at the earliest possible time.
- Data Retention & Erasure - We have updated our retention policy and schedule to ensure that we meet the "data minimization" and "storage limitation" principles and that personal information is stored, archived and destroyed compliantly and ethically.
- Subject Access Requests (SAR) - We have revised our SAR procedures to accommodate the revised 30-day timeframe for providing the requested information and for making this provision free of charge.
3. Legal Basis for Processing
We have reviewed all processing activities to identify the legal basis for processing and ensuring that each basis is appropriate for the activity it relates to. Where applicable, we also maintain records of our processing activities, ensuring that our obligations under Article 30 of the GDPR and Schedule 1 of the Data Protection Bill are met.
4. Privacy Notice/Policy
We have revised our Privacy Notice(s) to comply with the GDPR, ensuring that all individuals whose personal information we process have been informed of why we need it, how it is used, what their rights are, who the information is disclosed to and what safeguarding measures are in place to protect their information.
5. Contact Us
If you have any questions about our GDPR compliance, please contact our Data Protection Officer at [email protected].