Karnot Energy Solutions Inc. ("Karnot", "we", "us", or "our") is a company registered in the Philippines with operations in the Philippines, the United Kingdom, the United States, and Canada. This Privacy Policy describes our practices regarding the collection, use, storage, and disclosure of personal data when you visit our website at karnot.com, use our services, or otherwise interact with us.
We process personal data in compliance with the Philippine Data Privacy Act of 2012 (Republic Act No. 10173) and its Implementing Rules and Regulations, the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and other applicable data protection legislation in the jurisdictions where we operate.
By accessing our website or providing personal data to us, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect
Information you provide directly
- Contact details — name, email address, telephone number, and postal address when you complete an enquiry form, request a consultation, or correspond with us.
- Business information — company name, job title, industry sector, and project requirements relevant to our energy solutions.
- Communications — the content of emails, messages, and other correspondence you send to us.
Information collected automatically
- Device and browser data — IP address, browser type and version, operating system, screen resolution, and language preferences.
- Usage data — pages visited, time spent on pages, referral source, click patterns, and navigation paths.
- Cookies and similar technologies — as described in the Cookies section below.
Information from third parties
We may receive personal data from third-party analytics providers, advertising platforms, referral partners, or publicly available sources, which we use to improve our services and understand our audience.
2. How We Use Your Information
We use personal data for the following purposes:
- Service delivery — to respond to enquiries, provide consultations, prepare proposals, and deliver our energy solutions.
- Communication — to send technical information, project updates, and respond to your requests.
- Marketing — with your consent, to send newsletters, industry updates, and information about our services. You may opt out at any time.
- Website improvement — to analyse usage patterns, diagnose technical issues, and enhance user experience.
- Legal compliance — to comply with applicable laws, regulations, and legal processes.
- Business operations — to manage our customer relationships, maintain records, and administer our business.
3. Legal Basis for Processing
Under the GDPR (applicable to our UK and EU customers) and the Philippine Data Privacy Act, we process personal data on the following legal bases:
- Consent — where you have given clear consent for us to process your personal data for a specific purpose, such as receiving marketing communications.
- Contractual necessity — where processing is necessary to perform a contract with you or to take pre-contractual steps at your request.
- Legitimate interests — where processing is necessary for our legitimate business interests, provided those interests are not overridden by your rights. This includes improving our services, securing our website, and understanding how our services are used.
- Legal obligation — where processing is necessary to comply with a legal or regulatory obligation.
4. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
- Service providers — third-party companies that perform services on our behalf, such as website hosting, email delivery, analytics, and customer relationship management. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
- Professional advisers — lawyers, accountants, and auditors where necessary for our business operations.
- Regulatory authorities — government agencies, law enforcement, or other authorities when required by law or to protect our legal rights.
- Business transfers — in connection with a merger, acquisition, reorganisation, or sale of assets, your data may be transferred to the relevant third party, subject to appropriate safeguards.
5. International Data Transfers
As a company operating in the Philippines, the United Kingdom, the United States, and Canada, your personal data may be transferred to and processed in countries outside your country of residence. These countries may have data protection laws that differ from those in your jurisdiction.
Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the UK Information Commissioner's Office or the European Commission.
- Transfers to countries recognised as providing an adequate level of data protection.
- Other legally recognised transfer mechanisms under applicable data protection law.
For transfers involving data of Philippine data subjects, we comply with the requirements of the National Privacy Commission regarding cross-border data transfers.
6. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.
- Enquiry data — retained for up to 3 years from your last interaction with us, unless you request earlier deletion.
- Customer data — retained for the duration of our business relationship and for up to 7 years thereafter for legal and regulatory compliance.
- Website analytics data — retained in anonymised or aggregated form for up to 26 months.
- Marketing consent records — retained for as long as you remain subscribed, plus 3 years after you unsubscribe for recordkeeping purposes.
When personal data is no longer required, we securely delete or anonymise it.
7. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data in certain circumstances.
- Right to restrict processing — request that we limit how we use your data.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format.
- Right to object — object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at contact@karnot.com. We will respond to your request within the timeframe required by applicable law (typically within one month for GDPR requests, or within 15 days for requests under the Philippine Data Privacy Act).
Complaints
If you are in the UK or EEA and believe your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority. In the UK, this is the Information Commissioner's Office (ICO). In the Philippines, you may file a complaint with the National Privacy Commission (NPC).
8. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your browsing experience, analyse website traffic, and understand how visitors interact with our site.
Types of cookies we use
- Essential cookies — required for the website to function properly. These cannot be disabled.
- Analytics cookies — help us understand how visitors use our website by collecting anonymised usage data (e.g., Google Analytics).
- Functional cookies — remember your preferences and settings to improve your experience.
- Marketing cookies — used to track visitors across websites and display relevant advertisements. These are only set with your consent.
Managing cookies
You can control and delete cookies through your browser settings. Please note that disabling certain cookies may affect website functionality. Most browsers allow you to refuse or delete cookies. The methods for doing so vary by browser; consult your browser's help documentation for instructions.
9. Children's Privacy
Our website and services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete that data as soon as reasonably practicable. If you believe we have collected data from a child, please contact us immediately at contact@karnot.com.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically to stay informed about how we protect your data.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us: