energycontrol.ai
energycontrol.ai
  • Home
  • Case Studies
  • Savings calculator
  • Become a Partner
  • BLOG
  • Terms and Conditions
  • More
    • Home
    • Case Studies
    • Savings calculator
    • Become a Partner
    • BLOG
    • Terms and Conditions

  • Home
  • Case Studies
  • Savings calculator
  • Become a Partner
  • BLOG
  • Terms and Conditions

Terms & conditions

Welcome to energycontrol.ai

Effective Date: 13 July 2026


These Terms and Conditions apply to all quotations, orders, sales, installations and related services provided by Energy Control AI LTD ("Energy Control AI", "we", "our" or "us") to the customer ("Customer", "you" or "your"). By accepting a quotation, issuing a purchase order or otherwise placing an order with Energy Control AI LTD, you agree to these Terms and Conditions.


1. Quotations

1.1 All quotations are valid for 30 days from the date of issue unless otherwise stated.

1.2 Quotations are based upon the information available at the time of preparation. Should site conditions or customer requirements differ materially from those disclosed, Energy Control AI LTD reserves the right to amend the quotation accordingly.

1.3 A quotation does not constitute a binding contract until accepted by the Customer and acknowledged by Energy Control AI LTD.

2. Orders

2.1 Orders may be placed by signing a quotation, issuing a purchase order or confirming acceptance in writing.

2.2 Once accepted, orders may not be cancelled without the written agreement of Energy Control AI LTD. Any costs already incurred may be charged to the Customer.

3. Pricing

3.1 All prices are quoted exclusive of VAT unless expressly stated otherwise.

3.2 VAT shall be charged at the prevailing rate.

3.3 Prices are based on the agreed scope of work. Any additional work requested by the Customer may be charged separately.

4. Payment Terms

4.1 A deposit equal to 50% of the total order value is payable upon acceptance of the order.

4.2 No equipment will be ordered, reserved or scheduled for installation until the deposit has been received.

4.3 The remaining 50% of the order value becomes due within 24 hours of completion of the installation.

4.4 Energy Control AI LTD reserves the right to charge statutory interest and recovery costs on overdue invoices in accordance with the Late Payment of Commercial Debts (Interest) Act 1998.

5. Delivery and Installation

5.1 Delivery dates and installation dates are estimates only and are subject to product availability and site readiness.

5.2 Energy Control AI LTD shall use reasonable endeavours to meet agreed dates but shall not be liable for delays caused by manufacturers, suppliers, shipping providers, customer availability or events beyond our reasonable control.

5.3 The Customer shall provide safe access to the installation site and ensure that all necessary permissions are in place.

6. Ownership of Goods

6.1 Title to all goods supplied shall remain with Energy Control AI LTD until payment has been received in full.

6.2 Risk in the goods passes to the Customer upon delivery or installation.

7. Software and SaaS Services

7.1 Certain products supplied by Energy Control AI LTD include access to software, cloud services, analytics, firmware updates and other Software-as-a-Service ("SaaS") functionality provided by measurable.energy.

7.2 Energy Control AI LTD acts solely as an authorised reseller and installer of measurable.energy products and services.

7.3 Energy Control AI LTD does not own, operate, host or control the measurable.energy SaaS platform.

7.4 The Customer acknowledges that all SaaS functionality, cloud services, data processing, software availability, analytics, software updates, cybersecurity, uptime, service levels and ongoing operation of the measurable.energy platform are the sole responsibility of measurable.energy.

7.5 Use of the measurable.energy platform is subject to measurable.energy's own Terms and Conditions and associated policies, which form the governing agreement between the Customer and measurable.energy in respect of those services.

7.6 Energy Control AI LTD accepts no liability for interruption, modification, suspension, withdrawal or failure of any SaaS or cloud-based services provided by measurable.energy.

7.7 Any warranty, support or service relating specifically to the measurable.energy software platform shall be provided by measurable.energy in accordance with its published policies.

8. Product Warranty

8.1 Hardware products supplied by Energy Control AI LTD are covered by the manufacturer's warranty where applicable.

8.2 Energy Control AI LTD will provide reasonable assistance in facilitating warranty claims but does not provide additional warranties beyond those expressly stated by the manufacturer.

9. Customer Responsibilities

The Customer agrees to:

·  provide accurate site information;

·  provide suitable electrical and network infrastructure where required;

·  allow reasonable access for installation and commissioning;

·  operate the equipment in accordance with the manufacturer's instructions;

·  ensure only authorised persons interfere with installed equipment.


10. Limitation of Liability

10.1 Energy Control AI LTD shall not be liable for indirect, consequential or economic losses including loss of profits, business interruption, loss of revenue or anticipated savings.

10.2 Our total liability arising from any contract shall not exceed the total amount paid by the Customer under that contract.

10.3 Nothing in these Terms excludes liability which cannot legally be excluded under English law.

11. Right to Assign

11. 1 Energy Control AI LTD reserves it’s right to assign or re-assign it’s rights and obligations in respect of this agreement.

11.2 The Customer shall not have the right to assign or re-assign it’s rights and obligations in respect of this agreement unless agreed in writing by Energy Control AI LTD.

12. Force Majeure

Energy Control AI LTD shall not be liable for delays or failures caused by circumstances beyond its reasonable control, including but not limited to supplier shortages, transport disruption, industrial action, fire, flood, pandemic, government action or failure of telecommunications or cloud services.

13. Data Protection

Where personal data is processed, each party shall comply with applicable UK data protection legislation.

14. Governing Law

These Terms and Conditions shall be governed by the laws of England and Wales.

Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales.

15. Measurable.energy SaaS Terms & Conditions

Customers using measurable.energy software and cloud services are also subject to measurable.energy's own Terms and Conditions and related policies, as updated from time to time by measurable.energy. The current measurable.energy Terms and Conditions are available at: https://measurable.energy/policies/terms-and-conditions and as of July 2026 are as ser out below:-

Schedule 1 – Data Processing Addendum

The purpose of this Data Processing Addendum (“DPA”) is to set out the additional terms, requirements and conditions on which the Customer (and its Nominated Customer(s)) and Supplier will process Personal Data in connection with the terms of the Contract, including any Order Form(s), as entered into between them, and to which this DPA is attached and duly incorporated.

For the purposes of this DPA the terms controller, processor, data subject, personal data, personal data breach and processing shall have the meaning given to them in the EU GDPR and/or the UK GPDR, as applicable. 

This DPA contains the mandatory clauses required by Article 28(3) of the retained EU law version of the General Data Protection Regulation ((EU) 2016/679)) for contracts between controllers and processors and the General Data Protection Regulation ((EU) 2016/679))

1.  Definitions and Interpretation

Purposes: the services to be provided by the Supplier to the Customer as described in the Contract and any other purpose specifically identified in Part 2 of Exhibit 1. 

Captured Data: has the meaning given in the Contract.

Captured Datapool: has the meaning given in the Contract.

Commissioner: the Information Commissioner (see Article 4(A3), UK GDPR and section 114, DPA 2018).

EEA: the European Economic Area.

Records: has the meaning given in paragraph 10.1. 

1.1.  This DPA is subject to the terms of the Contract and is incorporated into the Contract. Interpretations and defined terms set forth in the Contract apply to the interpretation of this DPA. 

1.2.  The Exhibits form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.

1.3.  A reference to writing or written includes email.

1.4.  In the case of conflict or ambiguity between:

(a)  any provision contained in the body of this DPA and any provision contained in the Exhibit, the provision in the body of this DPA will prevail; and

(b)  any of the provisions of this DPA and the provisions of the Contract, the provisions of this DPA will prevail.

2.  Roles of the Parties, Personal Data types and processing purposes

2.1.  The parties have determined that, for the purposes of Applicable Data Protection Laws:

(a)  the Supplier is an independent Controller in respect of the Personal Data and processing activities set out in Part 1 of Exhibit 1; 

(b)  the Supplier shall process the Personal Data set out in Part 2 of Exhibit 1 as a Processor, on behalf of the Customer, in respect of the processing activities set out in Part 2 of Exhibit 1; and 

(c)  the Customer and its authorised Nominated Customer(s) are either independent or joint Controllers in respect of the Personal Data and processing activities relating to the Captured Datapool.

2.2.  The Customer and the Supplier agree and acknowledge that for the purpose of the Applicable Data Protection Laws and for the purpose of carrying out the Contract and the processing activities set out in Part 2 of Exhibit 1:

(a)  the Customer is the Controller and the Supplier is the Processor.

(b)  the Customer retains control of the Personal Data and remains responsible for its compliance obligations under the Applicable Data Protection Laws, including but not limited to, providing any required notices and obtaining any required consents, and any obligations set out in the Contract, and for the written processing instructions it gives to the Supplier. 

(c)  Part 2 of Exhibit 1 describes the subject matter, duration, nature and purpose of the processing and the Personal Data categories and Data Subject types in respect of which the Supplier may process the Personal Data to fulfil the Purposes, in accordance with clauses 3 to 10 of this DPA. The Customer warrants and represents that the Supplier's expected use of the Personal Data for the Purposes and as specifically instructed by the Customer will comply with the Applicable Data Protection Laws.

2.3.  The parties acknowledge and represent that with respect to Personal Data set out in Part 1 of Exhibit 1 herein, for which each party acts as Controller but which is not under the joint controllership of the parties, each party undertakes to comply with the Applicable Data Protection Laws in respect of their processing of such Personal Data as a Controller. For the purposes of this clause 2.4, each party shall:

(a)  process the Personal Data in compliance with its obligations under the Applicable Data Protection Laws and not do anything to cause the other party to be in breach of such laws;

(b)  only provide Personal Data to each other to the extent necessary to perform their respective obligations under the Contract; and

(c)  be responsible for their own compliance with Articles 13 and 14 of the EU and the UK GDPR in respect of the processing of Personal Data for the purposes set out in Exhibit 1 of this DPA.

2.4.  Customer shall take all reasonable measures to ensure that any authorised Nominated Customer(s) that has access to Personal Data pursuant to clause 4 of the Contract is subject to a written undertaking as to compliance with clause 2.4 of this DPA. 

2.5.  Notwithstanding clauses 2.4 and 2.5, in the event that Customer and/or any of its authorised Nominated Customer(s) process(es) Personal Data in connection with the Services described in clause 4 of the Contract, the Customer is responsible for and represents to the Supplier that it has validly entered into either an:

(a)  intra-group personal data sharing and transfer agreement with its subsidiaries, affiliates and/or any undertakings affiliated to it, that governs the access to and use of the data in the Nominated Customer Account(s) by any Nominated Customer(s); or 

(b)  a data sharing agreement (either as separate controllers, joint controllers, or even controller to processor) that governs the access to and use of the data in the Nominated Customer Account(s) by any Nominated Customer(s).

3.  Supplier’s Obligations

3.1.  The Supplier will only process the Personal Data to the extent, and in such a manner, as is necessary for the Purpose, or in accordance with the Customer's written instructions. The Supplier will not process the Personal Data for any other purpose or in a way that does not comply with this DPA or the Applicable Data Protection Laws. The Supplier must promptly notify the Customer if, in its opinion, the Customer's instructions do not comply with the Applicable Data Protection Laws.

3.2.  The Supplier must comply promptly with any Customer written instructions concerning the processing of Personal Data requiring the Supplier to amend, transfer, delete or otherwise process the Personal Data, or to stop, mitigate or remedy any unauthorised processing.

3.3.  The Supplier will maintain the confidentiality of the Personal Data and will not disclose the Personal Data to third-parties unless the Customer or this DPA specifically authorises the disclosure, or as required by domestic or EU law, court or regulator (including the Commissioner). If a domestic or EU law, court or regulator (including the Commissioner) requires the Supplier to process or disclose the Personal Data to a third-party, the Supplier must first inform the Customer of such legal or regulatory requirement and give the Customer an opportunity to object or challenge the requirement, unless the domestic or EU law prohibits the giving of such notice.

3.4.  The Supplier will reasonably assist the Customer, with costs to be reasonably agreed between the parties, with meeting the Customer's compliance obligations under the Applicable Data Protection Laws, taking into account the nature of the Supplier's processing and the information available to the Supplier under the Applicable Data Protection Laws.

4.  Supplier’s Employees

4.1.  The Supplier will ensure that all of its employees:

(a)  are informed of the confidential nature of the Personal Data and are bound by written confidentiality obligations and use restrictions in respect of the Personal Data;

(b)  have undertaken training on the Applicable Data Protection Laws and how it relates to their handling of the Personal Data and how it applies to their particular duties; and

(c)  are aware both of the Supplier's duties and their personal duties and obligations under the Applicable Data Protection Laws and this DPA.

5.  Security

5.1.  The Supplier must at all times implement appropriate technical and organisational measures against accidental, unauthorised or unlawful processing, access, copying, modification, reproduction, display or distribution of the Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Personal Data.

5.2.  Without prejudice to the generality of paragraph 5.1 the Supplier shall, in relation to the Personal Data implement the technical and organisational measures set out in Part 1 of Exhibit 2.

5.3.  In entering into this DPA the Customer acknowledges their controllership of the Personal Data set out in Part 2 of Exhibit 1 and shall also implement and maintain, at its cost and expense, the technical and organisational measures prescribed by Applicable Data Protection Laws, as well as those recommended by the Supplier as set out in Part 2 of Exhibit 2 to this DPA. 

6.  Personal Data Breach

6.1.  The Supplier upon awareness of a Personal Data Breach as defined in Applicable Data Protection Laws, and in any event without undue delay shall notify the Customer in writing concerning any Personal Data Breach.

6.2.  Where the Supplier becomes aware of a Personal Data Breach it will, without undue delay, also provide the Customer with the following written information:

(a)  reasonable description of the breach, as known at the time of notification, including, if possible, the approximate number of both Data Subjects and the Personal Data records concerned; and

(b)  a description of the measures taken or proposed to be taken to address the breach including measures to mitigate its possible adverse effects. 

6.3.  Immediately following any accidental, unauthorised or unlawful Personal Data processing or Personal Data Breach, the parties will co-ordinate with each other to investigate the matter. Further, the Supplier will reasonably co-operate with the Customer at no additional cost to the Customer, in the Customer's handling of the matter. 

6.4.  The Supplier will not inform any third-party of any accidental, unauthorised or unlawful processing of all or part of the Personal Data and/or a Personal Data Breach without first obtaining the Customer's written consent, except when required to do so by domestic or EU law.

6.5.  The Supplier will assist, at their own expense, the performance of the obligations under paragraph 6.1 to paragraph 6.3 unless the matter arose from the Customer's specific written instructions, negligence, wilful default or breach of this DPA, in which case the Customer will cover all reasonable expenses. 

7.  Transfers of personal data

7.1.  The Supplier (and any subcontractor) must not transfer or otherwise process the Personal Data outside the UK or the EEA, without prior written authorisation of the Customer. In the event Supplier seeks to transfer Personal Data outside of the UK or the EEA, it shall ensure that all such transfers are effected in accordance with Applicable Data Protection Laws.

8.  Complaints, data subject requests and third-party rights

8.1.  The Supplier must, at no additional cost to the Customer, take such technical and organisational measures as may be appropriate, and promptly provide such information to the Customer as the Customer may reasonably require, to enable the Customer to comply with:

(a)  the rights of Data Subjects under the Applicable Data Protection Laws, including, but not limited to, subject access rights, the rights to rectify, port and erase personal data, object to the processing and automated processing of personal data, and restrict the processing of personal data; and

(b)  information or assessment notices served on the Customer by the Commissioner or other relevant regulators under the Applicable Data Protection Laws.

8.2.  The Supplier must notify the Customer immediately in writing if it receives any complaint, notice or communication that relates directly or indirectly to the processing of the Personal Data or to either party's compliance with the Applicable Data Protection Laws.

8.3.  The Supplier must notify the Customer within five (5) working days if it receives a request from a Data Subject for access to their Personal Data or to exercise any of their other rights under the Applicable Data Protection Laws.

8.4.  The Supplier will give the Customer, at no additional cost to the Customer, its full co-operation and assistance in responding to any complaint, notice, communication or Data Subject request.

8.5.  The Supplier must not disclose the Personal Data to any Data Subject or to a third-party other than in accordance with the Customer's written instructions, or as required by domestic or EU law. 

9.  Data return and destruction

9.1.  Subject to clause 4.8 of the Contract, at the Customer's request, the Supplier will give the Customer, or a third-party nominated in writing by the Customer, a copy of or access to all or part of the Personal Data in its possession or control in the format and on the media reasonably specified by the Customer.

9.2.  The Supplier will securely delete or destroy or, if directed in writing by the Customer, return and not retain, all or any of the Personal Data related to this DPA in its possession or control, except for one copy that it may retain and use six (6) years for record keeping and system improvement purposes only.

9.3.  If any law, regulation, or government or regulatory body requires the Supplier to retain any documents, materials or Personal Data that the Supplier would otherwise be required to return or destroy, it will notify the Customer in writing of that retention requirement, giving details of the documents, materials or Personal Data that it must retain, the legal basis for such retention, and establishing a specific timeline for deletion or destruction once the retention requirement ends.

10.  Records

10.1.  The Supplier will keep up-to-date records regarding any processing of the Personal Data, including but not limited to, the access, control and security of the Personal Data, the processing purposes, categories of processing, and a general description of the technical and organisational security measures referred to in paragraph 5.1 (Records).

Exhibit 1 – Part 1 – Supplier Controllership Personal Data

11.  Scope

11.1.  Customer contact information containing any Personal Data required to enter into, administer, and to perform the invoicing for the Contract.

11.2.  The Customer’s Personal Data, including of Nominated Customer(s) required for the analysis and creation of the accounts for the authorised persons to access the Supplier’s platform, and for the provision of the Services.

11.3.  Records regarding the support provided to Customer staff who may contact the Supplier for assistance.

12.  Nature

12.1.  The processing is the collection, storage, and access, for the administration of the Contract and provision of the Services.

13.  Purpose of Processing

13.1.  Necessary processing for the performance of the Contract between the Supplier and the Customer, to provide the Services, and any required support related to the Services.

14.  Duration of Processing

14.1.  The processing will be for the duration of the Subscription Term, or the duration of the Nominated Customer Account(s) Service for the Personal Data processed under clause 4 of the Contract, with the understanding that Personal Data may be retained for six (6) years upon expiry, termination, or cessation of the Subscription Term or Nominated Customer Account(s) Services for the purposes of Supplier’s records due to either accounting, legal, compliance and company monitoring requirements.

15.  Categories of Personal Data

15.1.  Names, contact details (including emails and telephone numbers), addresses, and employment position.

16.  Categories of Data Subjects

16.1.  Customer employees, staff and personnel.

17.  Approved Subcontractors

Name

Location

Processing Activity

HubSpot Inc (HubSpot)

United Kingdom, EU Data Centres, international transfers in accordance with Data Protection Legislation

CRM and Customer Success case management

Xero Limited (Xero)

EU Data Centres, international transfers in accordance with Data Protection Legislation

Invoicing and Accounting

Cin7 Americas, Inc (Cin7)

EU Data Centres, international transfers in accordance with Data Protection Legislation

Order Management

DHL

International data processing

Shipping

DPD

International data processing

Shipping

Exhibit 1 – Part 2 – Customer Controllership Personal Data

18.  Scope

18.1.  Power consumption data collected via supplier provided Hardware that are connected to the internet. This data is collected and accessible to the Customer on the Supplier information platform, which allows the Customer certain access rights and for the manipulation of labelling datasets.

18.2.  Any Personal Data inserted or provided via the Supplier platform, and forms part of the Captured Data.

19.  Nature

19.1.  The processing of Personal Data required in providing the Contract Service for the Customer as inserted during the term of servicing the contract and communicating with the Customer and their employees, contractors, staff, authorised representatives and personnel as is required.

20.  Purpose of Processing

20.1.  The details required for use of the Service, including support Services, provided under the contract.

21.  Duration of Processing

21.1.  The processing will be for the duration of the Subscription Term, or the duration of the Nominated Customer Account(s) Service and following twenty four (24) months.

22.  Categories of Personal Data

22.1.  Names, contact details, nominated employee emails for the formation of Supplier platform accounts, Customer inputted Personal Data, SSO provided details from Customer records, IP addresses of Supplier devices, IP addresses of Customer devices used to access the Supplier platform, Wi-Fi Network Information used by Supplier Hardware to connect to the network (including unique identifiers of customer networking equipment).

23.  Categories of Data Subjects

23.1.  Customer designated end users, employees, staff and personnel.

24.  Approved Subcontractors

Name

Location

Processing Activity

Google Inc (Google Cloud)

United Kingdom, EU Data Centres

Cloud hosting supplier (with no logical access to data)

Amazon Inc (AWS)

United Kingdom, EU Data Centres

Software and Cloud hosting supplier (with no logical access to data)

MongoDB

United Kingdom, EU Data Centres

Machine learning and configuration monitoring, hosting and maintenance.

Exhibit 2 – Part 1 – Supplier Security Measures

25.  Supplier Security Measures

25.1.  Firewall and protection of the Supplier’s domain and all subdomains by Cloudflare.

25.2.  Firewall and protection of the Supplier’s servers and databases by Google Cloud Platform and Amazon Web Services.

25.3.  Multi-factor authentication (MFA) or Single Sign On (SSO) password protection for all services.

25.4.  User management and identification for all services by the Supplier’s team.

25.5.  Hardware cryptography on Hardware for all data sent to and from the Supplier to provide the Service.

25.6.  Ongoing security and vulnerability testing.

25.7.  Accreditation to Cyber Essentials Plus and IoT Cyber Assurance Level 2.

Exhibit 2 – Part 2 – Recommended Security Measures

26.  Recommended Security Measures to be Implemented by Customer

26.1.  Secure IoT specific Wi-Fi network with specific list of devices allowed to access network using MAC addresses or similar process.

26.2.  Change passwords immediately when passwords are suspected to be compromised.

26.3.  Do not save passwords within browsers.

26.4.  Do not leave Software open after use (i.e. close browser).

26.5.  Do not use the Software on public access devices.

Schedule 2 – Nominated Customer Account Service

1.  Nominated Customer Account Access and Capabilities within the Software

1.1.  When using the Captured Data Service, the Nominated Customer, and the Customer, dependent on individual end user permissions set by Customer administrators, will have access to the Captured Datapool and the capabilities listed below:

(a)  Access and export energy performance, energy cost, safety events and carbon emissions Reports;

(b)  Control of Units;

(c)  Management of Units, including updating configurations;

(d)  Enable, disable and adjust manual and automated schedules;

(e)  Enable and disable automated energy reduction features;

(f)  Receive notifications, inclusive of safety events;

(g)  Set power limits for Units;

(h)  Manage, add or remove profiles for users;

(i)  Edit Unit groups;

(j)  Access asset reporting;

(k)  Access occupancy reporting;

(l)  Setup API calls; and

(m) Other such access and usage capabilities which may be updated from time to time.

  • Privacy Policy
  • Cookies Policy
  • Data Processing Policy
  • About Us
  • Contact Us

energycontrol.ai

Copyright © 2026 energycontrol.ai - All Rights Reserved.

This website uses cookies.

We use cookies to analyse website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

DeclineAccept