Effective: Aug 30, 2018
Enel X North America Inc is committed to maintaining compliance with applicable laws governing data privacy and data security, and ensuring that its customers can have complete confidence in Enel X North America as a trusted partner. General Data Protection Regulation (GDPR) effective May 25, 2018 covers the collection, storage, use, and processing of personal data of EEA residents. For the purpose of EU data protection legislation, the data controller is Enel X North America, Inc. of One Marina Park Drive, Suite 400, Boston, Massachusetts 02210.
- We define your personally identifiable information (PII) as your:
- First Name
- Last Name
- Email Address
- Phone Number
- User Name
- The data elements listed above are the only personal data elements that we store. We also store data related to the organization that contracted with us and that you work for. For example, corporate address, energy consumption, energy monitoring devices and utility account data. We do not consider these elements as PII.
- We collect and store your PII only to perform the service that we are contracted to do.
- Enel X North America has an Information Security Policy and process to protect your PII. Part of this Policy is to make sure we notify you of any security breaches.
- Enel X North America will never sell your PII. We will not transfer your PII to any third party without disclosing to whom and why.
- Enel X North America will cooperate with you regarding your rights to access, correct, delete, and opt-out preferences. You can do so by contacting: email@example.com.
- Enel X North America will maintain our certification under the EU-US Privacy Shield.
- Enel X North America Data Privacy Officer is accountable for making sure everything stated here is truthful and up-to-date. You can reach our Data Privacy Officer by first emailing: firstname.lastname@example.org.
Personal Data processed for the purposes set out above will be kept in compliance with the principles of proportionality and necessity, and in any case until the purposes of the processing have been pursued.
Information Collected Automatically and Cookies
Enel X North America’s website(s) collect certain information about you automatically, including the domain that referred you to our website, the type of browser and computer operating system you use, navigational information, time and date of visit, Internet Protocol (IP) addresses, and cookies (as described in more detail below).
What are cookies?
A cookie is a small file that attaches to a computer or web browser when accessing or viewing a website. We use both session cookies and persistent cookies. Session cookies are used during a single website visit and are automatically deleted from your computer when you close your browser. Persistent cookies are used to track website activity over a longer period, and remain on your browser or computer until either you choose to delete them or they expire.
Enel X North America uses persistent cookies in several places on our website so we can pre-populate forms to improve your ease of use. For example, the information provided during a brochure download is captured so that you do not need to enter it again when requesting additional documents. Enel X North America may also use persistent cookies to collect analytical information about how visitors use our website. For example, we may measure website usage, access to online services, and the level of interest in particular products. We use this information to improve our service and provide a better experience for visitors to our website.
When we post videos, third parties may use local shared objects, known as “Flash Cookies,” to store your preferences for volume control or to personalize certain video features. Flash Cookies are different from browser Cookies because of the amount and type of data and how the data is stored.
Do I have to accept cookies?
Cookie management tools provided by your browser will not remove Flash Cookies. To learn how to manage privacy and storage settings for Flash Cookies, click here: https://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html.
Further information about cookies, including how to see what cookies have been set on your computer or mobile device and how to manage and delete them, visit www.allaboutcookies.org and www.youronlinechoices.com/uk.
Accessing, Updating, and Deleting Information
You may request access, corrections, or deletions of your information by contacting email@example.com. We will use commercially reasonable efforts to honor your request. For your protection, we may only implement requests with respect to the personal data associated with the particular email address that you use to send us your request, and we may need to verify your identity before implementing your request. Please note that if you request deletion of your information, we may be required by law to keep such information and not delete it (or to keep this information for a certain time, in which case we will comply with your deletion request only after we have fulfilled such requirements). When we delete any information, it will be deleted from the active database, but may remain in our archives. We may also retain your information for fraud or similar purposes.
Enel X North America Solutions: Information Collection and Use
In order for you to use or access a Solution, you must expressly consent to Enel X North America’s access to certain information in order to provide you with the applicable Solution. Enel X North America may collect information from the Solution meters installed on your site. If you received our Solution through a utility company (“Utility”), we may receive information from your Utility. If you received our Solution through one of our distributors or resellers, including but not limited to, one of our affiliates that market our Solution, we may receive information from such party. In addition, we collect any information which you provide to us directly. Information collected through the foregoing methods includes your customer contact information, financial information, account information, customer metadata, energy costs, energy behavioral analytics information, and energy usage and performance data.
Our website also makes use of Remarketing with Google Analytics, Google Display Network Impression Reporting, Google Analytics Demographics and Interest Reporting, and DoubleClick Campaign Manager integration. Enel X North America and third party vendors, such as Google, may use first-party cookies (such as the Google Analytics cookies) and third party cookies (such as the DoubleClick cookie) together to (i) inform, optimize, and serve ads based on your past visits to our website and (ii) report how your ad impressions, uses of ad services, and interactions with the foregoing are related to your visits to the website. In addition, Enel X North America may utilize Google Analytics data, including but not limited to, geographic, demographic, and interest reporting information to recognize and understand user preferences; make improvements to our website, products, and services; and for other business purposes that will allow us to better serve you. You may prevent your data from being collected and used by Google Analytics by opting out through the use of the Google Analytics Opt-out Browser Add-on available at: tools.google.com/dlpage/gaoptout.
In addition, we use “Pixel Tags” (also referred to as clear gifs, web beacons, or web bugs). Pixel Tags are tiny graphic images with a unique identifier, similar in function to Cookies, that are used to track online movements of Web users. In contrast to Cookies, which are stored on a user’s computer hard drive, Pixel Tags are embedded invisibly in web pages. Pixel Tags also allow us to send e-mail messages in a format users can read, and they tell us whether e-mails have been opened to ensure that we are sending only messages that are of interest to our users.
Enel X North America Websites: Information Collected When Voluntarily Provided
Registration forms on our website require you to provide accurate business contact information, which helps us deliver high quality service. This may include your name, postal address, email address, telephone number, username, password and demographic information. With your consent, we will send you marketing emails from us and any co-sponsors of a webinar or other event. Information that you provide may be used to send you information about our company, the co-sponsor companies, and the products and services, special offers, and newsletters of our company and the co-sponsor companies which may be of interest to your business. To view or modify information previously submitted, or to opt out of receiving future marketing communications via email, click the unsubscribe link provided at the bottom of the email communication you receive. Please be aware, that even if you opt out of marketing emails, we may still provide to you administrative and operational emails regarding the Enel X North America website and the Solutions. We may also collect information from you at other points on our website that state that information is being collected.
We often receive testimonials and comments from users who have had positive experiences with our Solutions and services. We occasionally publish such content on our website, emails, and other marketing material. When we publish this content, we obtain the user’s consent prior to posting the user’s information along with the testimonial.
Information Collected from Third Party Companies
We may receive information and/or Anonymous Data (defined below) about you from third party companies. We may add this information to the information we have already collected from you.
In general, information collected by Enel X North America may be used for the following purposes:
- Communicating with you concerning our Solutions and services;
- Responding to questions or requests you submit;
- Enabling us to fulfill any contractual obligation owed to you;
- Providing our Solutions and services, including our Solutions and services provided in conjunction with Utilities (as defined below);
- Improving our website, Solutions and services;
- Analyzing and optimizing any Enel X North America website;
- As necessary or appropriate to: (a) to comply with applicable laws; (b) to comply with lawful requests and legal process, including to respond to requests from public and government authorities to meet national security or law enforcement requirements ; (c) to enforce our Policy; and (d) to protect our rights, privacy, safety or property, and/or that of you or others;
- Notifying you about changes to our Solutions and services and sending you offerings of products and services in which you may be interested; and
- Sending you marketing emails as described in the “Information Disclosures” section below.
We may anonymize your information by excluding information (such as your name) that makes the data personally identifiable to you (“Anonymous Data”). We use this Anonymous Data, in part, to analyze request and usage patterns so that we may enhance our services. We reserve the right to use Anonymous Data for any purpose and disclose Anonymous Data to third parties in our sole discretion.
We disclose information to third party entities in the following ways or circumstances:
- When we have your consent – you acknowledge that Enel X North America does not control or have responsibility for the manner in which such third parties use or further disclose your information;
- To our subsidiaries and affiliated companies;
- To third party businesses or persons who act as our service providers, including but not limited to, Utilities and providers who process information on our behalf;
- For our Energy Procurement Services we distribute contact, facility, usage information to enable transactions to be consummated on our site (such as at the end of an auction). We will not sell, rent, loan, trade or otherwise offer your personal information to third parties except to enable business you choose to transact.
International Data Transfer
E.U. – U.S. Privacy Shield
As described in the Privacy Shield Principles, Enel X North America is accountable for personal data that it receives and subsequently transfers to third parties. If third parties that process personal data on our behalf do so in a manner that does not comply with the Privacy Shield Principles, we are accountable, unless we prove that we are not responsible for the event giving rise to the damage.
In compliance with the Privacy Shield Principles, Enel X North America commits to resolve complaints about our collection or use of your personal data. European Union individuals with inquiries or complaints regarding our Privacy Shield policy should first contact us at: firstname.lastname@example.org or (617) 692-2629.
Enel X North America commits to cooperate with the panel established by the EU Data Protection Authorities (DPAs) and comply with the advice given by the panel with regard to personal data transferred from the EU. Please contact us to be directed to the relevant DPA contacts.
As further explained in the Privacy Shield Principles, binding arbitration will also be made available to you in order to address residual complaints not resolved by any other means. Enel X North America is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).
Third Party Privacy Policies
Use by Children
We do not intentionally gather information from visitors who are under the age of 13. If a child under 13 submits information to Enel X North America and we learn that the information is the information of a child under 13, we will attempt to delete the information as soon as possible. If you believe that we might have any information from a child under 13, please contact us at email@example.com.
The data presented herein is for informational purposes only. Some of the data set forth herein is derived in whole or in part from third party sources. As a result, Enel X North America, Inc., on behalf of itself, and its affiliates and subsidiaries (“Enel X North America”) disclaims all representations and warranties as to the accuracy and completeness of said data.
We seek to use reasonable organizational, technical and administrative measures to protect personal data within our organization. Unfortunately, no transmission or storage system can be guaranteed to be completely secure, and transmission of information via the internet is not completely secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us of the problem by contacting us using the details in the "Contact" section below.
Privacy Notice within the meaning of art. 13 of EU Regulation 2016/679 ("GDPR")
1. DATA CONTROLLER
1.1. When you subscribe to the various services or to gain access to the aforementioned, you will be given the names of any further Data Controllers or Data Processors.
2. DATA PROTECTION OFFICER (DPO)
1.2. The Data Controller has appointed a Data Protection Officer (DPO) who can be contacted at the following email address : firstname.lastname@example.org
3. PURPOSE AND METHOD OF PROCESSING
3.1. Enel will process the personal information you provide us or which has been legitimately collected by the Controller (“Personal Data”). The following Personal Data in particular will be processed:
3.1.1. Contact information: name, surname, email address, telephone number and content of the message sent by you and other Personal Data that you may have provided during the communication. We will process this Personal Data in the case in which you make enquiries, request information or send us communications of any type. You send us this Personal Data at the moment in which you contact us. The processing of this Personal Data is necessary for us to provide a response to the communications received from you or to the requests that you have made. The provision of any further Personal Data by you is completely voluntary.
3.1.2. Navigation data: the IT and electronic communications systems and software procedures put in place to allow the Website to function, will, in the course of their normal work, collect certain data (e.g. access date and time, pages visited, name of the Internet Service Provider and Internet Protocol (IP) address you use to access the internet, the internet address from which you connect to our Website, etc.), the transmission of which is implicit in the use of web communications protocols or is pertinent to effective management or optimisation of the data or email sending system.
3.3. Please be informed that this Personal Data will be processed manually and/or using IT or electronic support.
4. PURPOSES AND LEGAL BASES OF PROCESSING
4.1. Enel will process your Personal Data for very specific purposes and only if there is a specific legal basis provided for under applicable personal data protection and privacy legislation. Specifically, Enel will process your Personal Data only when one or more of the following legal requirements has been met:
- you have freely given your specific, informed, unambiguous and affirmative consent to the processing of said data;
- the processing is necessary to the performance of a contract to which you are a party or to take pre-contractual measures at your request;
- or the purposes of the pursuit of Enel’s legitimate interests;
- Enel has a legal obligation to process said Personal Data.
4.2. The following table lists the purposes for which your Personal Data can be processed by the Controller and the legal bases for said processing.
Purpose of Processing
To allow you to use all of the Website’s functionalities
Performance of a contract
To check that the Website is functioning correctly.
Performance of a contract
To establish responsibility in the case of cyber crime that has caused damage to the Website; the detection, prevention, mitigation or verification of fraudulent or illegal activities relating to the services provided on the Website; the performance of security controls required under law.
To respond to a query or a request from the Data Subject
Implementation of pre-contractual measures adopted at the request of the Data Subject
4.3. The provision of your Personal Data is necessary in all instances in which processing is a legal requirement or necessary to the performance of a contract to which you are a party or to the implementation of pre-contractual measures adopted at your request. Any refusal on your behalf may make it impossible for Enel to perform the task for which your Personal Data has been collected.
4.4. The provision of your Personal Data, however, is voluntary for any further purposes and failure to give your consent in such cases will have no effect on the completion of the contract. The obligatory or optional nature of the provision of data will be specified at the moment of its collection.
5. PERSONAL DATA RECIPIENTS
5.1. Your Personal Data may be made accessible for the abovementioned purposes, to:
a) employees and staff of the Controller who, for that purpose, have been tasked with data processing, or to Enel Group companies in the European Union for the implementation of organisational, administrative, financial and accounting activities.
b) to third party companies or other subjects to which the Controller outsources work required to allow the Website to function, in their role as external data processors.
6. TRANSFER OF PERSONAL DATA
6.1. Your Personal Data will be processed in United States and in the European Union.
7. PERIOD FOR WHICH YOUR DATA WILL BE Stored
7.1. Personal Data processed for the purposes described above will be stored in compliance with the principles of proportionality and necessity, and, in all cases, until the purposes of the processing have been completed.
8. RIGHTS OF THE DATA SUBJECT
8.1. Under articles 15 – 21 of EU Regulation 2016/679 (GDPR), you have the right in relation to the Personal Data you provide:
a) To access and request a copy;
b) To request rectification;
c) To request erasure;
d) To obtain restriction of data processing;
e) To object to the processing;
f) To receive in a commonly-used structured form readable on an automatic device and to transmit without impediment said data to another Data Controller in the case that this is technically feasible.
8.2. Please be informed that you have the right to object at any time to the processing of Personal Data relating to you that is carried out in the pursuit of Enel’s legitimate interests.
8.3. When you object to the processing of your Personal Data as per article 8.2, the Controller will refrain from further processing your Personal Data, except where convincing legitimate reasons for continuing with the processing have been established or for the verification, exercising or defence of a right in a court of law.
8.4. For further information relating to your Personal Data, you can contact Enel’s Personal Data Protection Officer at this email address email@example.com It is essential to insert the following subject line “Privacy” also.
8.5. Please note that you have the right to make a complaint to the relevant Personal Data protection authority.