Privacy Policy
Last updated: 17 July 2026
1. Who we are
This Privacy Policy explains how Ecolyptus Limited (“ecolyptus”, “we”, “us” or “our”) collects, uses, shares and protects personal data. It applies to our website, our marketing activities, and our energy and sustainability management platform (the “Platform”).
Company: Ecolyptus Limited
Company number: 806284
Registered and operating address: 50 Clanbrassil Street, D08 Y5DC, Dublin, Ireland
Contact for privacy matters: info@ecolyptus.com
2. Who this policy covers
This policy applies to everyone whose personal data we handle, including:
- Visitors to our website and people who contact us or sign up to our marketing communications;
- Users of the Platform, including staff of our direct customers and of consultancies who use ecolyptus;
- Individuals whose data may appear within data processed through the Platform.
3. Our role: controller and processor
Data protection law distinguishes between a “controller” (who decides why and how data is processed) and a “processor” (who processes data on a controller’s behalf). ecolyptus acts in both capacities depending on the activity.
3.1 Where we are the controller
We are the controller for personal data relating to our website visitors, marketing contacts, prospective customers, and the account and billing details of our customers. This policy governs that processing.
3.2 Where we are the processor
For the data our customers load into or generate within the Platform (such as energy consumption, cost, emissions and related organisational data), we act as a processor. Our customer is the controller and decides how that data is used. Our processing of that data is governed by our Data Processing Agreement (DPA) with the customer.
3.3 White-label and multi-tier use
Many of our customers are energy and sustainability consultancies who use ecolyptus under their own brand and onboard their own end-clients. In these arrangements the consultancy (or its end-client) is the controller, and ecolyptus acts as processor, and where relevant as a sub-processor to the consultancy. Each consultancy is responsible for its own privacy notice to its end-clients. We make our DPA available to support these relationships along the full chain.
4. The personal data we collect
4.1 Website and marketing
- Contact and identity details you provide via forms (name, work email, company, job title, phone);
- Records of your communications and marketing preferences;
- Website usage data collected via cookies and Google Analytics (for example pages visited and device information).
4.2 Platform account users
- Account details such as name, work email, phone number, job title and role;
- Login credentials and authentication data;
- Usage logs relating to how the Platform is accessed and used.
4.3 Data processed within the Platform
The operational data in the Platform (energy, cost, emissions, revenue and related figures) is organisational data rather than personal data. Where any personal data is present within it, we process that data only as a processor on the controller’s instructions.
5. How we use personal data and our legal bases
As a controller, we rely on the following legal bases under the GDPR:
- Contract: to create and manage accounts, provide the Platform, and handle billing.
- Consent: to send marketing communications. We send marketing only to people who have opted in, and you can withdraw consent at any time.
- Legitimate interests: to operate, secure and improve our website and services, where not overridden by your rights.
- Legal obligation: to meet accounting, tax and other legal requirements.
6. Cookies and analytics
Our website uses cookies, including Google Analytics and HubSpot cookies, to understand usage and support our marketing. Where required by law, non-essential cookies are used only with your consent, which you can manage through our cookie preferences banner and any consent tools we provide.
7. Who we share data with (sub-processors)
We use trusted third-party providers to deliver our services. Each processes data on our behalf under appropriate contractual and security safeguards:
| Provider | Purpose | Location / transfer basis |
|---|---|---|
| Amazon Web Services | Back-end cloud hosting and storage of the Platform and all client data | EU region (Ireland). Data stored within the EU. |
| Vercel | Front-end application hosting and delivery | US / global – SCCs |
| Stripe | Payment and subscription processing | EU/US – Standard Contractual Clauses (SCCs) |
| HubSpot | CRM, marketing and customer communications | EU/US – SCCs |
| Google (Workspace & Analytics) | Business email, productivity and website analytics | EU/US – SCCs |
| Anthropic | Powers Lyptus AI. Data submitted to the copilot is sent to Anthropic to generate responses, under privacy-protected settings, and is not used to train models. | US – SCCs |
We will inform customers of any intended addition or change of sub-processor, giving a reasonable opportunity to object on legitimate data protection grounds. We may also disclose data where required by law, or in connection with a business sale or reorganisation, subject to appropriate protections.
8. Artificial intelligence (Lyptus AI)
Our AI copilot, Lyptus AI, is powered by Anthropic and processes data to generate insights for the user. We apply the following safeguards:
- Data you submit to the copilot is transmitted to Anthropic to generate responses; it is processed under privacy-protected settings and is not used to train AI models;
- Lyptus AI is used to assist users, not to make automated decisions producing legal or similarly significant effects on individuals;
- Human oversight remains with the user, who interprets and acts on the AI’s output;
- AI processing respects the same access controls and client data separation as the rest of the Platform.
9. Data separation in a multi-tenant platform
ecolyptus is a multi-tenant platform, meaning multiple customers use shared infrastructure. Each customer’s data is logically separated and access-controlled so that one customer (or consultancy and its end-clients) cannot access another’s data. Access is governed by authentication and role-based permissions.
10. Data ownership and confidentiality
Customers retain ownership of the data they load into or generate within the Platform. We do not claim ownership of that data and use it only to provide and support the Services, or as instructed by the customer. We treat customer data as confidential and restrict access to authorised personnel who need it to deliver the Services.
11. Aggregated and anonymised data
We do not use identifiable customer data to develop or benchmark our products. Where we use aggregated or fully anonymised data that cannot identify any customer, individual or organisation, we may do so to operate, secure and improve the Services.
12. International transfers and data residency
Platform data is stored within the EU (AWS, Ireland), including primary storage and backups. Certain providers that support delivery of the Service, such as Vercel (which hosts our front-end application) and Anthropic (which powers Lyptus AI), may process limited personal data outside the EU/EEA; where this occurs we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. Customers with specific data residency requirements can contact us to discuss them.
13. How long we keep data
- Account and Platform data: retained for the duration of the customer’s contract.
- After cancellation: a 30-day grace period to restore or export data, followed by permanent deletion within 90 days.
- Legal records: invoices and records required for tax and accounting retained for up to 6 years as required by Irish law.
- Marketing data: retained until you unsubscribe or withdraw consent.
Customers may request an export before leaving, or earlier deletion, subject to legal retention requirements.
14. How we protect data
We maintain appropriate technical and organisational security measures, including the following.
14.1 Encryption
Personal and customer data is encrypted in transit, and encrypted at rest within our cloud infrastructure.
14.2 Access control and authentication
Access is granted on a least-privilege, role-based basis and limited to authorised personnel, protected by authentication controls. Access is logged and reviewed.
14.3 Infrastructure and network security
The Platform back end and all client data are hosted with Amazon Web Services in the EU, and the front-end application is delivered via Vercel. We benefit from their physical, network and infrastructure security controls, complemented by our own configuration and monitoring.
14.4 Backups, resilience and disaster recovery
We maintain regular backups to protect against data loss and support service continuity.
14.5 Testing and monitoring
We monitor and log access and activity, and manage vulnerabilities.
14.6 People and processes
Personnel are bound by confidentiality obligations and receive data protection and security awareness guidance. We maintain internal policies governing the handling of personal and customer data.
15. Data breach notification
We maintain procedures to detect, investigate and respond to personal data breaches. Where we act as controller and a breach is likely to result in a risk to individuals, we will notify the Irish Data Protection Commission without undue delay and, where feasible, within 72 hours, and will inform affected individuals where required. Where we act as processor, we will notify the affected customer (controller) without undue delay so they can meet their own obligations.
16. Your rights
Under the GDPR you have the right to access your data, correct it, request erasure, restrict or object to processing, data portability, and to withdraw consent at any time.
- How to exercise them: contact us at info@ecolyptus.com. We may need to verify your identity before responding.
- Timeframe and cost: we respond within one month (extendable for complex requests), and requests are free unless manifestly unfounded or excessive.
- White-label chain: where we process data as a processor on a customer’s behalf, we will refer your request to the relevant controller (for example, the consultancy managing your account) and assist them in responding.
17. Keeping data accurate
We take reasonable steps to keep personal data accurate and up to date. Account users can update their details or ask us to correct inaccurate information.
18. Children
The Platform and our services are intended for business use and are not directed at children. We do not knowingly collect personal data from anyone under 18.
19. Changes to this policy
We may update this policy from time to time. The current version is always published on our website with its effective date. Where changes are significant, we will take reasonable steps to notify affected users, for example by email or an in-Platform notice.
20. Contact and complaints
For any privacy questions or to exercise your rights, contact us at info@ecolyptus.com or write to Ecolyptus Limited, 50 Clanbrassil Street, D08 Y5DC, Dublin, Ireland.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie), or your local supervisory authority.
Ecolyptus Limited
CRO: 806284
VAT: IE4568689EH
50 Clanbrassil Street, D08 Y5DC, Dublin, Ireland
Ph: +353 87 410 5486 E-mail: info@ecolyptus.com
Web: www.ecolyptus.com