Simpli Green LTD

Our Terms & Policies

Policy Name: Data Protection Policy



Document ID: #2610

Version Number: #0.1

Published: 08/06/2026

This Data Protection Policy explains how Simpli Green Ltd collects, uses, stores, protects and disposes of personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and all other applicable privacy legislation.

Simpli Green Ltd is committed to protecting the privacy of our customers, employees, suppliers, contractors, business partners and website users. We recognise that safeguarding personal information is fundamental to maintaining trust and delivering our services responsibly.

Simpli Green Ltd is a company registered in England and Wales (Company No: 13044379) with our registered office at:

Chambers Business Centre, Chapel Road, Oldham, OL8 4QQ

Questions regarding this policy should be directed to: hello@simpligreen.energy or by calling 03300 941 785.

1. Policy Statement

Simpli Green Ltd is committed to processing personal information fairly, lawfully, securely and transparently.

We recognise that personal information belongs to the individual, not to the organisation processing it. Every employee has a duty to ensure personal information is protected against unauthorised access, disclosure, alteration, loss or destruction.

This policy establishes the minimum standards expected throughout the business and forms part of our wider governance, cyber security and compliance framework.

2. Purpose of this Policy

The purpose of this policy is to ensure that Simpli Green Ltd:

2.1 Complies with UK GDPR and the Data Protection Act 2018.

2.2 Protects the rights and freedoms of individuals whose personal information we process.

2.3 Maintains appropriate technical and organisational security measures.

2.4 Ensures employees understand their responsibilities when handling personal information.

2.5 Reduces the risk of data breaches, cyber attacks and accidental disclosure.

2.6 Maintains customer confidence by handling personal information responsibly.

3. Scope

This policy applies to everyone working for or on behalf of Simpli Green Ltd including:

3.1 Directors.

3.2 Permanent employees.

3.3 Temporary employees.

3.4 Agency workers.

3.5 Apprentices.

3.6 Contractors and subcontractors.

3.7 Consultants.

3.8 Suppliers processing data on our behalf.

3.9 Anyone granted access to Company information systems.

This policy applies regardless of whether personal information is stored electronically, on paper, within cloud services, customer portals, CRM systems, mobile devices or removable media.

4. Definitions

Personal Data
Any information relating to an identified or identifiable living individual.

Processing
Any operation performed on personal data including collection, recording, storage, organisation, consultation, sharing, transmission or deletion.

Data Subject
The individual whose personal information is processed.

Data Controller
The organisation determining why and how personal data is processed.

Data Processor
An organisation or individual processing personal data on behalf of the controller.

Special Category Data
Personal information requiring additional protection, including health data, racial or ethnic origin, religious beliefs, political opinions, biometric data, genetic data, sexual orientation and trade union membership.

Personal Data Breach
A security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

5. Data Protection Principles

Simpli Green Ltd adheres to the seven principles established by Article 5 of the UK GDPR.

5.1 Lawfulness, Fairness & Transparency
Personal information will always be processed lawfully, fairly and transparently.

5.2 Purpose Limitation
Personal data will only be collected for specified, explicit and legitimate purposes.

5.3 Data Minimisation
Only personal information that is genuinely necessary for business purposes will be collected.

5.4 Accuracy
Reasonable steps will be taken to ensure information remains accurate and up to date.

5.5 Storage Limitation
Personal information will not be retained for longer than necessary.

5.6 Integrity & Confidentiality
Appropriate technical and organisational security controls will protect personal information against unauthorised access, accidental loss, destruction or damage.

5.7 Accountability
Simpli Green Ltd accepts responsibility for demonstrating compliance with all applicable data protection legislation.

6. Roles & Responsibilities

Protecting personal information is the responsibility of everyone working for or on behalf of Simpli Green Ltd.

6.1 Company Directors

6.1.1 Ensure adequate resources are available to comply with data protection legislation.

6.1.2 Promote a culture of privacy and information security.

6.1.3 Review major data protection risks and incidents.

6.1.4 Ensure appropriate technical and organisational controls remain in place.

6.2 Managers

6.2.1 Ensure employees understand this policy.

6.2.2 Ensure only authorised persons access personal information.

6.2.3 Report suspected data breaches immediately.

6.2.4 Ensure information is stored securely within their departments.

6.3 Employees

6.3.1 Comply with this policy and all related procedures.

6.3.2 Protect personal information from unauthorised disclosure.

6.3.3 Report any suspected data breach immediately.

6.3.4 Complete mandatory data protection and cyber security training where required.

6.3.5 Use Company systems responsibly and securely.

7. Lawful Bases for Processing Personal Data

Simpli Green Ltd will only process personal information where there is a valid lawful basis under UK GDPR.

7.1 Consent
Where an individual has freely given clear consent for a specific purpose.

7.2 Contract
Where processing is necessary to fulfil a contract or take steps prior to entering into a contract.

7.3 Legal Obligation
Where processing is necessary to comply with legal or regulatory requirements.

7.4 Vital Interests
Where processing is necessary to protect someone's life.

7.5 Public Task
Where processing is necessary for a task carried out in the public interest.

7.6 Legitimate Interests
Where processing is necessary for legitimate business purposes provided those interests do not override the rights and freedoms of the individual.

Before collecting personal information, Simpli Green Ltd will identify and document the lawful basis relied upon.

8. Categories of Personal Data We Process

Depending upon the services provided, Simpli Green Ltd may process the following categories of personal information.

8.1 Identity Data
Names, titles, dates of birth and identification details.

8.2 Contact Data
Addresses, telephone numbers and email addresses.

8.3 Customer Information
Property details, quotations, survey information, installation records and photographs.

8.4 Financial Information
Payment details, invoices, finance applications and transaction history.

8.5 Employment Information
Employee records, qualifications, training records, payroll and HR documentation.

8.6 Technical Information
IP addresses, browser information, website usage data, CRM activity logs and portal access logs.

8.7 Marketing Preferences
Communication preferences and consent records.

9. Special Category Data

Simpli Green Ltd will only process Special Category Data where absolutely necessary and where an appropriate lawful condition exists under UK GDPR.

Examples may include employee health information, occupational health records, accessibility requirements or information required to meet legal obligations.

9.1 Access to Special Category Data will be strictly limited.

9.2 Additional security controls will be applied wherever appropriate.

9.3 Processing will only occur where there is a lawful basis and an additional Article 9 condition.

10. Collection of Personal Information

Personal information may be collected directly from individuals or from authorised third parties where appropriate.

10.1 Website enquiry forms.

10.2 Telephone conversations.

10.3 Email correspondence.

10.4 Face-to-face appointments.

10.5 Customer surveys and assessments.

10.6 Installation records and project documentation.

10.7 Supplier and finance partners.

10.8 Recruitment processes.

Individuals will be informed why their information is being collected and how it will be used through our Privacy Policy and other privacy notices.

11. Data Accuracy

Simpli Green Ltd will take reasonable steps to ensure personal information remains accurate and up to date.

11.1 Individuals may request corrections to inaccurate information.

11.2 Employees should update records promptly when notified of changes.

11.3 Inaccurate or incomplete records will be corrected without unnecessary delay.

12. Individual Rights

Simpli Green Ltd respects the rights provided to individuals under UK GDPR.

12.1 Right to be Informed
Individuals have the right to understand how their personal information is used.

12.2 Right of Access
Individuals may request a copy of their personal information through a Subject Access Request.

12.3 Right to Rectification
Individuals may request inaccurate information be corrected.

12.4 Right to Erasure
Individuals may request deletion of personal information where legal grounds exist.

12.5 Right to Restrict Processing
Individuals may request processing be limited in certain circumstances.

12.6 Right to Data Portability
Individuals may request their personal information in a structured electronic format where applicable.

12.7 Right to Object
Individuals may object to certain processing activities, including direct marketing.

12.8 Rights relating to Automated Decision Making
Individuals have rights where decisions are made solely by automated processing.

Requests relating to these rights will be handled promptly and in accordance with statutory timescales.

13. Data Security

Simpli Green Ltd is committed to protecting all personal information against accidental loss, unauthorised access, disclosure, alteration, destruction and cyber attack.

Appropriate technical and organisational security measures will be implemented based upon the sensitivity of the information being processed and the risks presented.

13.1 Personal information shall only be accessible by authorised persons.

13.2 Systems processing personal information shall be protected by appropriate authentication controls.

13.3 Security controls will be reviewed regularly to ensure they remain effective.

13.4 Personal information shall be protected against accidental deletion, corruption or loss.

13.5 Security incidents must be reported immediately.

14. Access Control

Access to Company systems shall follow the principle of least privilege, ensuring employees only have access to information necessary to perform their duties.

14.1 Every user will have an individual account.

14.2 Shared accounts should be avoided wherever possible.

14.3 User permissions will be reviewed regularly.

14.4 Accounts belonging to leavers will be disabled immediately.

14.5 Administrator privileges will only be granted where operationally necessary.

14.6 Privileged accounts will be monitored and audited.

15. Password Management

Passwords remain one of the most important methods of protecting Company systems and personal information.

15.1 Passwords must be unique for every business system.

15.2 Passwords should be at least 14 characters long or use a secure passphrase.

15.3 Passwords must never be shared.

15.4 Passwords must not be written where unauthorised persons can access them.

15.5 Password managers approved by the Company are encouraged.

15.6 Default passwords must always be changed before systems enter production.

16. Multi-Factor Authentication (MFA)

Multi-Factor Authentication significantly reduces the risk of unauthorised access and will be enabled wherever supported.

16.1 MFA shall be enabled for Microsoft 365 accounts.

16.2 MFA shall be enabled for CRM platforms, customer portals and cloud services where available.

16.3 Administrative accounts must always be protected using MFA.

16.4 Authentication devices must be protected from unauthorised access.

17. Encryption

Encryption will be used wherever appropriate to protect sensitive Company and customer information.

17.1 Data transmitted across public networks should be encrypted.

17.2 Company laptops should use full-disk encryption.

17.3 Portable storage devices containing personal information should be encrypted.

17.4 Secure HTTPS connections shall be used for Company websites and portals.

18. Cloud Services & Microsoft 365

Simpli Green Ltd makes use of cloud-based business systems to improve collaboration and operational efficiency.

18.1 Cloud providers will be selected based upon their security credentials and compliance standards.

18.2 Access permissions will be reviewed regularly.

18.3 Microsoft 365 security features shall be utilised where appropriate.

18.4 Cloud data shall be backed up where appropriate.

18.5 Personal information must not be copied into unauthorised cloud storage services.

19. CRM & Customer Portal Security

Customer Relationship Management (CRM) systems and customer portals contain significant volumes of confidential information and require enhanced security.

19.1 Customer records shall only be viewed where required for legitimate business purposes.

19.2 User activity may be logged for security and auditing purposes.

19.3 Access permissions shall reflect employee job roles.

19.4 Customer portals shall use secure authentication and encrypted connections.

19.5 Security updates shall be applied promptly.

20. Mobile Devices & Remote Working

Employees working remotely or using mobile devices remain responsible for protecting Company information.

20.1 Devices should be protected using strong passwords or biometric authentication.

20.2 Devices must not be left unattended in public places.

20.3 Sensitive information should not be viewed where it may be overlooked by unauthorised persons.

20.4 Lost or stolen devices must be reported immediately.

20.5 Remote wipe functionality should be enabled where available.

21. Email & Physical Security

Email remains one of the highest cyber security risks faced by modern organisations. Employees must exercise caution whenever sending or receiving emails.

21.1 Verify recipients before sending personal information.

21.2 Suspicious emails must never be opened or responded to.

21.3 Personal information should only be sent securely.

21.4 Offices should operate a Clear Desk and Clear Screen policy wherever reasonably practicable.

21.5 Paper records containing personal information should be securely stored when not in use.

21.6 Visitors should not have unsupervised access to confidential information.

22. Sharing Personal Information

Simpli Green Ltd will only share personal information where there is a legitimate business need or a legal obligation to do so.

Before sharing personal information with another organisation, appropriate safeguards will be implemented to ensure the information remains secure.

22.1 Personal information will only be shared on a need-to-know basis.

22.2 Data sharing agreements will be implemented where appropriate.

22.3 Information will only be disclosed where a lawful basis exists.

22.4 Employees must never disclose customer information to unauthorised persons.

22.5 Requests from law enforcement or regulatory authorities will be handled in accordance with applicable legislation.

23. Third-Party Processors

Simpli Green Ltd works with carefully selected third-party service providers to support the delivery of our services.

Where third parties process personal information on our behalf, they must provide appropriate contractual and technical safeguards to protect that information.

23.1 Due diligence will be completed before appointing new processors.

23.2 Appropriate Data Processing Agreements (DPAs) will be maintained.

23.3 Third parties will only process information in accordance with our documented instructions.

23.4 Processor compliance may be reviewed periodically.

24. International Transfers

Personal information will only be transferred outside the United Kingdom where appropriate safeguards exist.

24.1 Transfers will only take place where permitted by UK GDPR.

24.2 Appropriate safeguards such as UK International Data Transfer Agreements or recognised adequacy decisions will be used where required.

24.3 Overseas processors will be assessed before any personal information is transferred.

25. Data Retention & Secure Disposal

Personal information will only be retained for as long as it is required to fulfil legal, contractual or operational obligations.

25.1 Retention periods will be documented where appropriate.

25.2 Personal information no longer required will be securely deleted or destroyed.

25.3 Paper records containing confidential information will be securely shredded or disposed of using approved confidential waste services.

25.4 Electronic media will be securely erased before disposal or reuse.

26. Backup & Disaster Recovery

Appropriate backup arrangements are maintained to ensure business continuity and minimise the risk of permanent data loss.

26.1 Business-critical systems will be backed up regularly.

26.2 Backup integrity will be tested periodically.

26.3 Backups containing personal information will be protected using appropriate security controls.

26.4 Disaster recovery procedures will be reviewed periodically.

27. Personal Data Breaches

Any suspected or confirmed personal data breach must be reported immediately to senior management.

27.1 Breaches will be investigated without delay.

27.2 Appropriate containment measures will be implemented immediately.

27.3 Risks to affected individuals will be assessed.

27.4 Where legally required, breaches will be reported to the Information Commissioner's Office (ICO) within the statutory timescales.

27.5 Affected individuals will be informed where there is a high risk to their rights and freedoms.

27.6 All breaches will be documented, regardless of whether notification is required.

28. Artificial Intelligence (AI) & Acceptable Use

Employees must exercise caution when using Artificial Intelligence (AI) tools and automated systems.

28.1 Confidential or personal information must not be entered into public AI platforms unless specifically authorised.

28.2 AI-generated information must be reviewed for accuracy before being relied upon.

28.3 AI must not be used in a way that breaches data protection legislation or customer confidentiality.

28.4 Employees remain responsible for decisions made using AI-assisted outputs.

29. Training & Awareness

All employees handling personal information are expected to maintain an appropriate level of knowledge regarding data protection and cyber security.

29.1 New employees will receive data protection awareness training during induction.

29.2 Refresher training will be provided periodically.

29.3 Additional training may be provided where legislation or Company systems change.

29.4 Completion of mandatory training may be monitored.

30. Monitoring & Auditing

Simpli Green Ltd will regularly review compliance with this policy through internal monitoring, audits and management reviews.

Where weaknesses or opportunities for improvement are identified, corrective actions will be implemented as part of our continual improvement programme.

31. Complaints

Individuals who have concerns regarding the handling of their personal information should contact Simpli Green Ltd in the first instance.

If an individual remains dissatisfied, they may have the right to lodge a complaint with the Information Commissioner's Office (ICO).

32. Policy Review

This Data Protection Policy will be reviewed at least annually, or sooner where legislation, regulatory guidance, Company systems or business operations change.

Employees will be notified of significant updates and may be required to complete additional training where appropriate.

Simpli Green Ltd is committed to continually improving its information governance, cyber security and privacy practices to protect the rights of customers, employees and all individuals whose personal information we process.

33. Information Classification & Handling

Simpli Green Ltd classifies information according to its sensitivity and the impact that unauthorised disclosure, alteration or loss could have upon customers, employees and the business.

All employees are responsible for ensuring information is classified, stored, transmitted and disposed of appropriately.

33.1 Public
Information approved for public release, including marketing materials, website content and published company information.

Handling Requirements

• May be freely shared.

• No special storage requirements.

• Must remain accurate and approved before publication.


33.2 Internal
Information intended for use within Simpli Green Ltd but not for public disclosure, including procedures, meeting notes and operational documents.

Handling Requirements

• Accessible only to authorised employees.

• Stored within approved Company systems.

• Must not be published externally without authorisation.


33.3 Confidential
Customer information, quotations, contracts, employee records, supplier agreements and commercially sensitive information.

Handling Requirements

• Access restricted to authorised personnel only.

• Encrypted when transmitted electronically where appropriate.

• Printed documents must be stored securely.

• Secure disposal is required when no longer needed.


33.4 Highly Confidential
Special Category Data, financial information, security credentials, encryption keys, authentication secrets and information that could cause significant harm if compromised.

Handling Requirements

• Strictly limited access on a need-to-know basis.

• Encryption required both at rest and during transmission wherever possible.

• Multi-Factor Authentication required where supported.

• All access should be auditable.

• Secure destruction required when retention periods expire.

34. Acceptable Handling Standards

34.1 Personal information must only be accessed where there is a legitimate business requirement.

34.2 Confidential documents must not be left unattended on desks, printers or meeting rooms.

34.3 Computers and mobile devices must be locked whenever left unattended.

34.4 USB storage devices should only be used where authorised and, wherever possible, encrypted.

34.5 Personal information must not be copied to personal devices or personal cloud storage.

34.6 Confidential information should not be discussed in public places where conversations may be overheard.

34.7 Printed documents containing personal information should only be printed where operationally necessary.

34.8 Confidential waste must always be disposed of using approved confidential waste disposal methods.

35. Compliance

Failure to comply with this policy may expose Simpli Green Ltd to regulatory penalties, financial loss, reputational damage and legal action.

Deliberate or negligent breaches of this policy may result in disciplinary action, up to and including dismissal, and where appropriate may be reported to the relevant regulatory or law enforcement authorities.

Every employee shares responsibility for protecting the confidentiality, integrity and availability of the information entrusted to Simpli Green Ltd.

36. Bring Your Own Device (BYOD)

Where employees are authorised to use personally owned devices for Company business, additional security controls shall apply to protect Company and customer information.

36.1 Personal devices must be protected using strong authentication.

36.2 Devices must have current operating system and security updates installed.

36.3 Company information must not be stored permanently on personal devices unless specifically authorised.

36.4 Lost or stolen devices containing Company information must be reported immediately.

36.5 The Company reserves the right to remove Company information from authorised devices where necessary.

37. Website Forms & Customer Portals

Simpli Green Ltd operates online enquiry forms, customer portals and digital services that process personal information.

37.1 All online services shall use encrypted HTTPS connections.

37.2 Access to customer portals shall require secure authentication.

37.3 Customer accounts shall only display information relevant to that individual.

37.4 Appropriate audit logging shall be maintained where reasonably practicable.

37.5 Online forms shall only request information genuinely required for the intended purpose.

38. CCTV & Video Recording

Where CCTV or video recording systems are used by Simpli Green Ltd, they shall operate in accordance with UK GDPR, the Data Protection Act 2018 and guidance issued by the Information Commissioner's Office.

38.1 CCTV shall only be used for legitimate business purposes such as security and crime prevention.

38.2 Appropriate signage shall be displayed where CCTV operates.

38.3 Access to recordings shall be restricted to authorised personnel.

38.4 Recordings shall be retained only for as long as necessary.

39. Compliance with Other Company Policies

This Data Protection Policy should be read alongside other Company policies, including but not limited to:

39.1 Privacy Policy

39.2 Information Security Policy

39.3 Acceptable Use Policy

39.4 Health & Safety Policy

39.5 Equality & Diversity Policy

39.6 Employee Handbook

40. Final Statement

Simpli Green Ltd is committed to maintaining the highest standards of information governance, cyber security and data protection. Every employee, contractor and supplier has a responsibility to protect the confidentiality, integrity and availability of the information entrusted to us.

Through continual improvement, staff training, investment in secure technologies and regular policy reviews, we aim to maintain full compliance with UK GDPR, the Data Protection Act 2018 and recognised industry best practice while delivering outstanding service to our customers.

© 2026 Next Phase Technology . All right reserved