Purpose limitation
Information is collected and used for stated website, account, support and contracted service purposes.

Hotels & HospitalityGuest comfort and estate performance
Office BuildingsOccupancy-led performance
Retail & MallsTrading-hours intelligence
UniversitiesCampus-wide energy decisions
Wellness CentresWater, humidity and comfort
Residential CommunitiesHomes and shared infrastructure
Airports & TerminalsContinuous terminal operations
Data CentresCooling, power and resilience
Utilities & District EnergyGeneration, storage and demand
Ports & LogisticsCargo-linked energy operations
ManufacturingProduction-linked intelligence
Food & Cold ChainTemperature-assured optimisationENERGE TWIN separates personal information from operational evidence and applies controls according to purpose, sensitivity, customer instructions and applicable data protection law.
Information is collected and used for stated website, account, support and contracted service purposes.
Roles, organisation scope and property permissions limit who can view or manage information.
Retention follows purpose and obligation, with routes for applicable individual rights.
CEBS Worldwide generally acts as controller for information collected through the public website, assessment enquiries and direct account administration. For customer workspace data, CEBS Worldwide may act as a processor on the customer's documented instructions.
The applicable agreement identifies the parties, processing purpose, data categories and responsibilities for a contracted deployment.
Data requirements should be defined against the intended monitoring, modelling, support or reporting outcome. Personal data should not be collected merely because a source system makes it available.
Customers and users should keep submitted account and operational context accurate and notify the relevant administrator when information changes.
Personal data may be used to respond to enquiries, administer accounts, deliver contracted services, provide support, secure the service and meet legal obligations. Under UK and EU law, the lawful basis depends on the relationship and may include contract, legitimate interests, legal obligation or consent. Where legitimate interests are used, CEBS Worldwide considers necessity, proportionality and the individual's interests and rights.
Consent is requested where required and may be withdrawn without affecting processing already carried out lawfully. Singapore users will be informed of the purposes for collection, use or disclosure and the likely consequences of withdrawing consent.
Most ENERGE TWIN evidence concerns buildings, equipment, energy, weather, tariffs and operating conditions. Operational data may become personal data where it identifies or can reasonably be linked to an individual.
Where occupancy or user activity is used, the deployment should prefer aggregated, proportionate information and document its purpose.
CEBS Worldwide may use hosting, communications, security, support and other service providers to operate ENERGE TWIN. Providers should receive only the access needed for their service and be subject to appropriate contractual and security requirements.
Relevant subprocessor information is confirmed for contracted deployments.
Where an applicable US state privacy law covers the processing, residents may request access to or confirmation of personal data, correction, deletion and a portable copy, subject to verification and legal exceptions. Applicable state law may also provide rights to opt out of targeted advertising, sale, certain profiling or to limit particular uses of sensitive personal data, and to appeal a denied request.
CEBS Worldwide does not sell personal information submitted through ENERGE TWIN and does not use it for cross-context behavioural advertising. It will honour recognised opt-out preference signals where required. Exercising a privacy right will not result in unlawful discrimination. An authorised agent may submit a request where applicable law permits and authority can be verified.
Where the UK GDPR or EU GDPR applies, individuals may have rights to be informed, access, rectification, erasure, restriction, portability, objection and safeguards concerning solely automated decisions. Requests are normally answered within one month, subject to permitted extensions, identity checks and exemptions.
Individuals may complain to the UK Information Commissioner's Office or the competent EEA supervisory authority. You are encouraged to contact CEBS Worldwide first so the concern can be investigated, but doing so does not limit the right to complain to a regulator.
Where Singapore's Personal Data Protection Act applies, CEBS Worldwide follows the consent, purpose limitation, notification, accuracy, protection, retention limitation, transfer limitation, access and correction, breach notification and accountability obligations, subject to statutory exceptions.
Individuals may request access to personal data under CEBS Worldwide's possession or control and information about its use or disclosure during the applicable period, request correction, or withdraw consent with reasonable notice. A privacy contact performs the functions required of a data protection officer; requests may be submitted through the contact route below.
Where personal data is transferred across jurisdictions, the transfer is documented and protected using an applicable adequacy decision or regulation, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or another lawful mechanism. Transfer risk or data-protection assessments and supplementary safeguards are used where required.
For Singapore transfers, contractual or other legally recognised measures are used to provide a standard of protection comparable to the PDPA. Hosting locations and relevant safeguards are confirmed for contracted environments and may be requested through the contact form.
Retention depends on the processing purpose, account lifecycle, contractual requirements, security needs and legal obligations. Information should be deleted, anonymised or returned when it is no longer required, subject to necessary records and backup cycles.
A fixed period does not apply to every data category. Customer-specific periods are documented where required.
Depending on applicable law and the processing context, individuals may have rights to access, correct, erase, restrict or object to processing, request portability or withdraw consent.
Where CEBS Worldwide processes information for a customer, a request may need to be referred to that customer as controller. Identity may be verified before a request is fulfilled.
Requests may be submitted through the ENERGE TWIN contact form without creating a new account. CEBS Worldwide will acknowledge, assess and answer requests within the period required by the applicable law and explain any refusal, extension or available appeal route.
ENERGE TWIN is a business service and is not directed to children. CEBS Worldwide does not knowingly collect personal data from children through the public enquiry journey or use children's data for targeted advertising or sale. If such information is received unintentionally, contact the team so it can be assessed and deleted where appropriate.
Sensitive or special-category data should not be submitted unless it is necessary, authorised and supported by an applicable legal condition and safeguards.
ENERGE TWIN may derive or model operational findings from property evidence. Evidence status and assumptions should remain visible so users can understand the basis of an output.
The service is designed for governed human review and is not intended to make solely automated decisions that produce legal or similarly significant effects about individuals.
Suspected loss, unauthorised access or disclosure is contained, documented and assessed through the security incident process. Where required, a notifiable UK or EU breach is reported to the competent authority without undue delay and, where feasible, within 72 hours; affected people are informed without undue delay when the required high-risk threshold is met.
Singapore breaches are assessed for significant harm or significant scale and notified to the PDPC and affected individuals as soon as practicable where required. US notices follow the timing, content and recipient requirements of the applicable federal or state law.
Data categories, sources, integrations, residency, retention and user roles can differ by customer and property. These details should be confirmed during implementation and recorded in the applicable agreement or governance documentation.
Privacy questions and requests can be submitted through the ENERGE TWIN contact form. Include enough information to identify the relevant account or enquiry, but do not send passwords or unnecessary sensitive information.
The applicable controller, purposes, categories, location, retention and safeguards are confirmed for each customer engagement rather than assumed from a generic website statement.
Speak with our team about the website, platform or your assurance requirements.
Contact the ENERGE TWIN team