[TBC]. Get it reviewed by a qualified Irish solicitor and confirm every placeholder before this platform goes live or processes real payments. Note also that DGB Energy Consultants is a registered business name (sole trader), not a limited company — the "liability" and "company" language in these drafts should be checked against that structure specifically, since a sole trader carries personal liability differently than a limited company would.Privacy Policy
Last updated: 10 August 2026 (draft)
This Privacy Policy explains how DGB Energy Consultants (trading as BER Direct, CRO business name no. 731435, registered office at 6 Joseph Terrace, Fairview, Dublin 3, D03 R9C6, Ireland) ("BER Direct", "we") collects, uses, and protects personal data when you use the BER Direct platform. We are the data controller for the personal data described below, in line with the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
1. What we collect
- Account data: name, email, phone number, password (stored hashed by our authentication provider, never in plain text).
- Property and booking data: property address, county, type, and details of assessment requests, quotes, and bookings.
- Assessor data: SEAI BER registration number, company name, counties covered, assessment types, and (if applicable) Stripe Connect account status.
- Messages: content of messages exchanged between a Homeowner and Assessor once a booking is made.
- Payment data: processed directly by Stripe. We receive confirmation that a payment succeeded and the amount, but your card number is never stored on or seen by BER Direct's own systems.
- Technical data: authentication session cookies (see our Cookie Policy).
2. Why we use it, and our legal basis
- To provide the service (matching, booking, messaging, payment) — necessary to perform our contract with you.
- To verify Assessor registration against the SEAI public register — our legitimate interest in trust and safety on the Platform.
- Transactional emails (new quote, quote accepted, payment receipt) — necessary to perform our contract with you; these are not marketing and do not require separate consent.
- To meet legal obligations, e.g. retaining payment records for tax purposes.
We do not currently send marketing emails. If that changes, we will ask for your consent first.
3. Who we share it with
We use the following processors to run the Platform. Each processes data only on our instructions, under a data processing agreement:
- Supabase — database hosting and authentication. Data region: [TBC — confirm the Supabase project's hosting region].
- Stripe — payment processing and Assessor payouts (Stripe Connect). Stripe may process data outside the EEA under its own safeguards (including Standard Contractual Clauses).
- Resend — sending transactional emails on our behalf.
We also share limited profile information (name, contact details) between a Homeowner and an Assessor once a booking is made between them, so the assessment can actually happen — this is necessary to perform that booking.
4. International transfers
Where a processor (e.g. Stripe or Resend) is based outside the European Economic Area, we rely on that processor's Standard Contractual Clauses or another lawful transfer mechanism recognised under GDPR.
5. How long we keep it
We keep account and booking data for as long as your account is active, and for a further period afterwards to meet legal/tax obligations and resolve any disputes — [TBC — a specific retention schedule should be defined and reviewed before launch]. You can ask us to delete your account at any time, subject to records we're legally required to keep.
6. Your rights
Under GDPR, you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- ask us to delete your data, subject to legal retention requirements;
- restrict or object to certain processing;
- receive your data in a portable format;
- lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie) if you believe we haven't handled your data properly.
To exercise any of these rights, contact us at [contact email — TBC].
7. Security
Data is encrypted in transit (HTTPS). Database access is controlled by row-level security policies scoped to your account role, so, for example, one Homeowner cannot read another Homeowner's bookings. Passwords are hashed by our authentication provider and never visible to BER Direct staff.
8. Children
BER Direct is not directed at, and should not be used by, anyone under 18.
9. Changes to this policy
We may update this policy from time to time; material changes will be flagged on the Platform.