1. Introduction

CeraNova Energy Ltd (“CeraNova”, “we”, “us”, “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you visit www.ceranovaenergy.com (the “Site”), request a quotation, place an order, or otherwise interact with us.

We process personal data in accordance with the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (“PECR”).

2. Who We Are (Data Controller)

CeraNova Energy Ltd is the data controller responsible for your personal data.

• Company name: CeraNova Energy Ltd
• Company number: 05603998 (England & Wales)
• VAT number: 494063672
• RDCO approval number: 47120426
• ICO registration number: ZC133443
• Registered office: Second Floor, Berkeley Square House, Berkeley Square, Mayfair, London, W1J 6BD
• Privacy contact: privacy@ceranovaenergy.com
• General contact: info@ceranovaenergy.co.uk | 020 3773 0125

Privacy queries are handled by our Compliance Officer at the privacy@ inboxabove. We are not required to appoint a statutory Data Protection Officer under Article 37 UK GDPR and have not done so; instead, all data protection matters are managed by our Compliance function. Our internal Data Protection Policy is maintained at CEN-POL-002.

3. The Personal Data We Collect

3.1 Data You Provide Directly
When you submit a quote request, contact form, credit application, or order through the Site (or via email or telephone), we collect:

• Identity data: full name, job title, business name
• Contact data: business address, delivery postcode, email address, telephone number
• Order data: fuel type, volume, tanker type, delivery instructions, delivery site details
• Financial data: bank or card details where required to complete a transaction (collected by our payment processor)
• Credit data: trade references and credit application information where credit terms are sought
• Communications data: messages and correspondence with our team

3.2 Data Collected Automatically
When you browse the Site, our servers and analytics tools may automatically collect:

• Technical data: IP address, browser type and version, operating system, device identifiers, time zone
• Usage data: pages viewed, time on page, navigation paths, referring URL, date and time of access
• Cookie data: see our Cookie Policy (CEN-WEB-003) for full details

3.3 Data From Third-Party Sources
We may receive personal data from third parties where lawful – including credit reference agencies (for credit checks before extending credit terms), Companies House and HMRC (publicly available business data), AML and sanctions screening providers, and marketing partners where you have consented to be contacted.

4. How and Why We Use Your Personal Data

Under the UK GDPR we must have a lawful basis under Article 6 for each use of your personal data. The table below sets out the purposes for which we process personal data and our lawful basis.

PurposePersonal data usedLawful basis (UK GDPR)
Respond to enquiries and provide quotationsIdentity, contact, orderArticle 6(1)(b) – pre-contractual steps at your request
Perform our contract and arrange fuel supplyIdentity, contact, orderArticle 6(1)(b) – performance of contract
KYC, RDCO due diligence, AML checksIdentity, contact, credit, screening resultArticle 6(1)(c) – legal obligation (Excise Notice 192 / HCOS; MLR 2017)
Recover overdue debtsIdentity, contact, financial, credit
Article 6(1)(b) and 6(1)(f) – legitimate interests
Send electronic marketingIdentity, contactArticle 6(1)(a) consent OR PECR Reg 22(3) soft opt-in
Improve our website and servicesTechnical, usage, cookieArticle 6(1)(f) – legitimate interests; consent for non-essential
Comply with regulatory and legal obligationsAs applicableArticle 6(1)(c) – legal obligation

You can withdraw consent or opt out of marketing at any time via any unsubscribe link or by emailing privacy@ceranovaenergy.com.

5. Automated Decision-Making

We do not use solely automated decision-making (including profiling) that produces legal or similarly significant effects. Pricing is generated by our quoting platform but every order is reviewed by a human trader before acceptance.

6. Who We Share Your Personal Data With

We share personal data only where necessary and with appropriate safeguards. Recipients fall into the following categories:

• Approved fuel suppliers and terminal operators – to fulfil your order
• Third-party haulage and tanker operators – to deliver fuel to your nominated site
• Payment processors and acquiring banks – to process payment transactions
• Credit reference agencies and trade credit insurers – for credit assessment
• Debt collection agencies, solicitors and enforcement agents – where an account is overdue
• HM Revenue & Customs – for RDCO returns, VAT, and tax compliance
• Regulators and law enforcement – where we are legally required to disclose
• IT, hosting, CRM and email service providers – acting as data processors on our written instructions
• Professional advisers – accountants, auditors, lawyers and insurers under confidentiality obligations
• A buyer or successor – in the event of a sale, merger, or restructuring

7. International Transfers

Personal data is primarily stored and processed within the UK and the EEA. Where any service provider is located outside the UK or EEA, we ensure that an appropriate safeguard under Article 46 UK GDPR is in place, typically an adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

8. How Long We Keep Personal Data

We keep personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, tax, or regulatory requirements:

• Customer due diligence records: 6 years from end of customer relationship (Excise Notice 192; HCOS; MLR 2017 reg. 40)
• VAT and accounting records: 6 years (Schedule 11, Value Added Tax Act 1994)
• Contract and order records: 6 years from end of contract (Limitation Act 1980)
• Marketing data: until you opt out, plus a suppression record indefinitely
• Website analytics data: typically 14 months in aggregated form
• Quote-only enquiries that do not convert: 24 months from last contact

9. Your Rights

Under the UK GDPR, you have the following rights in relation to your personal data:

• Right of access – to obtain a copy of the personal data we hold about you
• Right to rectification – to have inaccurate or incomplete data corrected
• Right to erasure – the “right to be forgotten” in certain circumstances
• Right to restrict processing – to limit how we use your data
• Right to data portability – to receive your data in a structured, machine-readable format
• Right to object – including to direct marketing and to processing based on legitimate interests
• Rights related to automated decision-making – see section 5
• Right to withdraw consent – at any time, where we rely on your consent

To exercise any of these rights, please email privacy@ceranovaenergy.com or write to our registered office. We will respond within one calendar month per Article 12 UK GDPR. We may need to verify your identity before processing your request.

10. How to Complain

If you have any concerns about how we handle your personal data, please contact us first at privacy@ceranovaenergy.com so we can investigate and respond.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO):

• ICO, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
• Helpline: 0303 123 1113
• Website: ico.org.uk

11. Security

We use appropriate technical and organisational measures to safeguard personal data, including encrypted transmission (TLS), access controls, role-based permissions, secure cloud hosting, regular backups, malware protection, and quarterly cybersecurity penetration testing. Our staff receive data protection training and are bound by confidentiality obligations.
No method of internet transmission or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

12. Cookies

Our website uses cookies and similar tracking technologies. For full details, including the cookies we use, the lawful basis for each, and how to manage your preferences please see our Cookie Policy (CEN-WEB-003).

13. Third-Party Links

Our website may contain links to third-party websites and services (for example LinkedIn). We are not responsible for the privacy practices of those third parties.

14. Children

Our website and services are intended for businesses and adult professionals. We do not knowingly collect personal data from anyone under the age of 18.

15. Changes to This Policy

We may update this Privacy Policy from time to time. The version and effective date are recorded in the cover block above. We will post the latest version on our website and, where changes are material, notify you by email.

16. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: privacy@ceranovaenergy.com
Post: Data Protection, CeraNova Energy Ltd, Second Floor, Berkeley Square House, Berkeley Square, Mayfair, London, W1J 6BD
Telephone: 020 3773 0125