How Solar Ireland collects, uses, and protects your personal data in compliance with GDPR and Irish data protection law.
Your data is protected by GDPR-compliant processes and AES-256 encryption
We never sell, rent, or trade your personal data to anyone - ever
You have 9 enforceable rights including access, erasure, and portability
All data is stored within the EU/EEA and accessed only by authorised personnel
Solar Ireland ("we", "us", or "our") is a SEAI-registered solar panel installation company operating across all 32 counties of Ireland. We are committed to protecting your privacy and ensuring that any personal data we collect is processed lawfully, fairly, and transparently in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, how long we keep it, and your rights in relation to your data. It applies to all interactions you have with us, including our website solarirelandgroup.ie, our county-specific landing pages, WhatsApp Business, email, phone calls, in-person surveys, and any other communication channels through which you share information with us.
By using our services or providing us with your personal data, you acknowledge that you have read and agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this privacy policy, please do not provide us with your personal information and discontinue use of our services.
When you request a quote, book a survey, or engage our services, we may collect the following personal information to provide you with an accurate and efficient service:
When you visit our website, certain technical information is collected automatically through cookies and similar technologies to help us improve your experience and maintain site security:
We do not routinely collect special category data (such as health data, racial or ethnic origin, religious beliefs, or political opinions). In rare cases where such data may be relevant to your installation (for example, if you mention a disability requiring specific accessibility accommodations), we will only process it with your explicit written consent and under strict confidentiality protocols.
We use your personal data for specific, legitimate purposes. Here is a detailed breakdown of how your information is used across our business operations:
Providing Quotes & Solar Installation Services
We use your contact details, property information, and energy usage data to prepare accurate solar installation quotes, conduct site surveys, design your system, schedule installation dates, and manage your project from initial enquiry through to commissioning and handover.
SEAI Grant Applications & Compliance
Your property details, MPRN, and BER rating are submitted to the Sustainable Energy Authority of Ireland (SEAI) to process your grant application. We coordinate with ESB Networks for grid connection notifications and ensure all work complies with NSAI standards.
Post-Installation Support & Warranty
We retain your installation records, system specifications, and contact details to provide ongoing warranty support, handle maintenance enquiries, and process any guarantee claims that may arise during the warranty period.
Marketing Communications (Consent-Based Only)
With your explicit consent only, we may send you information about new services, seasonal promotions, solar energy news, or policy updates affecting your solar investment via email or WhatsApp. You can withdraw consent at any time using the unsubscribe link in any communication or by contacting us directly.
AI Bill Analyser
When you use our AI Bill Analyser, the bill you upload is read to produce your estimate and is then deleted. It is not retained and is not used to train any model. We do keep an anonymous record of what the bill showed: the county, the supplier, the unit rate and standing charge, the annual usage and the day/night split, and the month. That record holds no name, email, phone number, address, Eircode or MPRN, carries no link to your enquiry, and is stored with the month only rather than a date and time, so it cannot be matched back to you. We use it to understand what Irish households actually pay and use, and to publish aggregate research. Because it identifies nobody, it is not personal data under GDPR.
Service Improvement & Analytics
We analyse anonymised website usage data, customer feedback, and service delivery metrics to improve our website experience, streamline our operations, develop new products, and enhance overall customer satisfaction.
Legal, Regulatory & Financial Compliance
We process your data as necessary to comply with Irish tax law, financial regulations, SEAI reporting requirements, insurance obligations, health and safety standards, and to resolve disputes or enforce contractual terms.
Under GDPR, every processing activity must have a valid legal basis. We process your personal data under one or more of the following legal grounds, depending on the specific purpose:
Consent
When you explicitly opt in - for example, ticking a box to receive marketing emails, agreeing to optional cookie categories, or consenting to smart meter data sharing. You can withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Contractual Necessity
When processing is necessary to deliver the service you have requested - such as installing solar panels on your property, submitting a grant application on your behalf, or communicating with you about your active project. Without this data, we cannot provide our services.
Legitimate Interest
When processing serves a genuine business interest that does not override your rights and freedoms - such as website analytics, fraud prevention, service quality monitoring, and direct marketing to existing customers where you have not opted out.
Legal Obligation
When processing is required by law - such as retaining financial records for 7 years under Irish tax law, reporting to SEAI for grant compliance, responding to valid legal requests from authorities, or maintaining insurance documentation as required by our professional indemnity policies.
We treat your data with the utmost confidentiality. We may share your personal data with the following categories of third parties only when necessary to deliver our services or comply with legal obligations. We do not sell, rent, or trade your personal data for marketing purposes.
SEAI (Sustainable Energy Authority of Ireland)
Processing your SEAI grant application, verifying our installer registration, and submitting compliance reports as required by the grant scheme terms and conditions.
ESB Networks
Submitting NC6 grid connection notifications, registering for the Clean Export Guarantee (CEG) tariff, and coordinating smart meter installation or data sharing with your consent.
Insurance Providers
Supporting public liability and professional indemnity insurance claims, providing installation documentation for policy compliance, and maintaining records as required by our insurers.
Subcontractors & Specialist Partners
Engaging RECI-registered electricians, scaffolding contractors, roofing specialists, and BER assessors who are contractually bound to process your data only for the specific installation task and to delete it upon completion.
Financial Institutions
Processing payments, issuing invoices, managing grant refund disbursements, and maintaining financial records as required by Irish tax law and Revenue Commissioners.
Legal & Regulatory Bodies
Responding to lawful requests from the Data Protection Commission, Revenue Commissioners, SEAI compliance teams, or other regulatory authorities with proper jurisdiction.
We never sell your personal data - period.
Solar Ireland does not sell, rent, trade, or otherwise monetise your personal information. All third-party data sharing is strictly limited to what is necessary to deliver our solar installation services, comply with legal obligations, and protect your warranty. Every subcontractor and partner is bound by written data processing agreements that enforce GDPR compliance.
Under GDPR, you have powerful rights over your personal data. We are committed to making it easy for you to exercise these rights:
Right of Access (Art. 15)
Request a complete copy of all personal data we hold about you, including how it was collected, who it was shared with, and retention periods. Provided within 30 days.
Right to Rectification (Art. 16)
Request corrections to any inaccurate, incomplete, or outdated personal data. We will update your records within 21 days and confirm in writing.
Right to Erasure (Art. 17)
Request deletion of your personal data where we no longer have a legal basis to retain it. We will comply unless legally obligated to retain the data.
Right to Data Portability (Art. 20)
Request your data in a structured, machine-readable format (CSV, JSON, or XML) so you can transfer it to another service provider.
Right to Object (Art. 21)
Object to processing based on legitimate interests at any time. We will stop processing unless we have compelling grounds to continue.
Right to Withdraw Consent (Art. 7)
Withdraw consent for marketing or optional data processing at any time. This does not affect the lawfulness of prior processing.
Right to Restrict Processing (Art. 18)
Request that we limit how we use your data while a dispute is being resolved or accuracy is contested.
Right to Lodge a Complaint (Art. 77)
Complain to the Data Protection Commission (DPC) at dataprotection.ie or +353 21 431 0700 if you believe your data has been mishandled.
Automated Decision-Making (Art. 22)
You have the right not to be subject to decisions based solely on automated processing. We do not currently use such processes.
How to Exercise Your Rights
Contact our Data Protection Officer at sales@solarirelandgroup.ie. We acknowledge requests within 5 working days and respond substantively within 30 days. Complex requests may take up to 90 days with advance notice. We may ask for identification to verify your identity before processing your request.
We follow a data minimisation approach and retain your personal data only for as long as necessary. Here are our standard retention periods:
Financial & Tax Records
Required by Irish tax law (Taxes Consolidation Act 1997) and Revenue Commissioners.
Installation & Warranty Records
Product warranty coverage, insurance claims, BER compliance, and SEAI installer audit requirements.
Marketing Consent Records
Retained while consent is active. Removed 3 years after last confirmed opt-in.
Website Analytics Data
Google Analytics 4 default retention for anonymised, aggregated data.
Communication Records
Customer service quality assurance, dispute resolution, and regulatory compliance.
CCTV / Security Footage
Physical security. Automatically overwritten unless retained for incident investigation.
When the retention period expires, data is securely deleted using industry-standard methods or irreversibly anonymised. You may request earlier deletion subject to legal and contractual obligations.
We implement a multi-layered security programme to protect your personal data:
Encryption in Transit
TLS 1.3 encryption for all website and API traffic. HSTS with one-year max-age.
Encryption at Rest
AES-256 encryption for sensitive data including payment details and ID documents.
EU/EEA Data Residency
All data stored and processed within the EU/EEA. No transfers outside the EU.
Access Controls
Role-based access with multi-factor authentication for administrative accounts. All access logged and auditable.
Vulnerability Management
Regular penetration testing, vulnerability scanning, and code reviews. Critical patches applied within 72 hours.
Staff Training
Mandatory GDPR training upon joining and annually thereafter for all employees and contractors.
Incident Response
Documented breach response plan. DPC notified within 72 hours. Affected individuals informed without undue delay.
Third-Party Security
All processors contractually required to maintain equivalent standards. Due diligence assessments before engagement.
If you become aware of any potential security vulnerability, contact us immediately at sales@solarirelandgroup.ie.
Our services integrate with these third-party platforms. Each is independently responsible for their own GDPR compliance:
Google Analytics 4
Website analytics. IP anonymised, data sharing for ads disabled, 14-month retention.
Privacy: policies.google.com/privacy
WhatsApp Business (Meta)
Customer communication. Processed under EU Standard Contractual Clauses.
Privacy: whatsapp.com/legal/privacy-policy
ESB Networks
Grid connection notifications, CEG registration, smart meter integration.
Privacy: esbnetworks.ie
SEAI
Grant applications, BER assessments, installer compliance.
Privacy: seai.ie
Vercel (Hosting)
Website hosting on EU-region servers. SOC 2 Type II compliant.
Privacy: vercel.com/legal/privacy-policy
We do not control these third parties' privacy practices and encourage you to review their individual privacy policies. Contact us if you have concerns about any third-party processing.
Our website and services are exclusively directed at adults aged 18 and over. We do not knowingly collect, process, or store personal data from individuals under the age of 18. If we become aware that we have inadvertently collected data from a child under 18, we will securely delete it from all systems including backups within 14 days.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us at sales@solarirelandgroup.ie and we will take prompt action.
We may update this Privacy Policy to reflect changes in our business practices, data protection legislation, new services, or for operational reasons. We are committed to keeping you informed about how your data is protected.
When we make material changes, we will update the "Last updated" date at the top of this page, display a prominent notice on our homepage for at least 30 days, and where appropriate, send you an email or WhatsApp notification. Your continued use of our services after changes constitutes acceptance of the updated terms. We encourage you to review this policy periodically.
If you have any questions, concerns, or requests about this Privacy Policy or how we handle your personal data, we would love to hear from you. Our team will respond promptly to all enquiries.
For data protection-specific enquiries or to exercise your GDPR rights, contact our Data Protection Officer directly. We acknowledge all data protection enquiries within 5 working days and provide a substantive response within 30 days.