Privacy & Data Protection Policy

UK GDPR & Data Protection Act 2018 • Enev Networks Ltd

1. Introduction

Enev Networks Ltd ("Enev", "we", "us") is dedicated to protecting the privacy of EV drivers, fleet partners, and station hosts. This policy explains how we collect, store, process, and protect your information under the UK General Data Protection Regulation (UK GDPR).

2. Information We Collect

  • Ad-Hoc Charging Sessions: Masked payment card information (last 4 digits only), transaction reference numbers, timestamp, electricity dispensed (kWh), and fee breakdown. We never receive or store full 16-digit card numbers or CVV codes.
  • Copy Receipt Search: To retrieve VAT copy receipts, drivers provide their payment card's last 4 digits and transaction date. These inputs are used solely for record matching.
  • Registered Accounts & Fleets: Name, business email, contact phone number, vehicle registration number, and assigned RFID card identifiers.

3. Lawful Basis for Processing

We process your data on the following bases:

  • Contract Performance: To deliver EV charging electricity, process contactless payments, and issue statutory VAT invoices.
  • Legal Obligation: To comply with UK statutory regulations (The Public Charge Point Regulations 2023, SI 2023/1168) regarding 99% reliability reporting to the Secretary of State and OPSS.

4. Data Retention & Security

Financial ledger records and itemised receipts are retained in accordance with HMRC VAT statutory requirements (6 years). Sensitive hardware credentials and authentication tokens are encrypted at rest using industry-standard AES-256 and transmitted exclusively over HTTPS/WSS.

5. Contacting the Data Protection Officer

For questions or data subject access requests (DSARs), please email our Data Protection team at privacy@enev.energy.