Skip to content

Solar Analytics Consumer Data Right Policy

The Consumer Data Right (CDR) gives you control over the data you share with companies. In the energy sector, this is often referred to as Open Energy. It’s a secure way for you to send your data to companies with your full consent, knowledge and control, enabling you to get products, services and advice that are tailored to your needs. This Consumer Data Right (CDR) Policy (the Policy) explains how Solar Analytics can collect, use, hold and disclose your data that you consent to sharing with us. This ensures transparency and trust between all parties. It also ensures the quality, integrity and security of your personal information under applicable CDR legislation and Privacy Laws.

Please refer to our Privacy Policy on our website for information on how we manage your personal information.

To unlock the full capabilities of Solar Analytics monitoring and personalised insights, we give you the option to share data from your energy retailers with us. This can include:

  • Customer Details - such as individual or organisation’s name, address and contact details
  • Service Point and Usage Details - such as NMI (National Meter Identifier) and energy usage readings
  • Distributed Energy Resource (DER) Details - such as DER make, model and capacity
  • Energy Account Details - such as account number, electricity/gas contract and concessions
  • Invoice and Billing Details - such as invoice issue and due dates, usage and once-off charges, payment amounts and method

With your consent we may collect, store and use your CDR data to:

  • Help you visualise your energy consumption and provide personalised insights to optimise your energy usage;
  • Find the best electricity plan for your solar home;
  • And know when to invest in your solar home, for example buying a battery, upgrading you solar system or installing a new efficient hot water system.

We also analyse and use de-identified, statistical data to:

  • Help us improve our product features and services and customer experience.

De-identified data is CDR data that is not able to be associated with your identity. Solar Analytics removes all directed and indirect identifiers about you to ensure the data cannot be linked to you and your identity cannot be revealed. We do not require your consent to use de-identified CDR Data.

Solar Analytics does not disclose your CDR data to any third parties.

Solar Analytics develops and maintains its own software for use with energy data collected under the CDR Rules. All data is stored and processed on Amazon Web Services (AWS) Australian infrastructure.

When enabling a Solar Analytics feature or service that requires your CDR Data, you will be asked to provide your consent. Consent will only last for a maximum of 12 months at which point it will automatically expire. You can withdraw your consent at any time either via your Solar Analytics dashboard or that of your data holder.

Section titled “Consequence of withdrawing consent or letting it expire”

Should your consent expire or be withdrawn, all personally identifiable CDR Data will be deleted. We will contact you before your consent expires and encourage you to renew your consent. Failing to do so will cause all your CDR Data to be deleted, and associated Solar Analytics features to be disabled. In this event, we may not be able to restore all your historical data when you provide consent again in the future, therefore the accuracy or availability of our insights will be limited.

What if my Solar Analytics subscription expires, or I choose not to renew?

Section titled “What if my Solar Analytics subscription expires, or I choose not to renew?”

We will automatically revoke your consent(s) and all of your CDR derived data 30 days after your subscription ends.

What type of events will you receive a notification for?

Section titled “What type of events will you receive a notification for?”

In the event of a data breach (such as an unauthorised party accessing your CDR Data), we will notify you as soon as practical. This is so you can take action to mitigate any potential damage or loss caused by the data breach.

If this occurs, we will:

  • Contain the data breach to prevent any further leak of personal information;
  • Investigate the data breach by gathering the facts and taking action to reduce any risk of harm;
  • Notify the Commissioner if the breach is an ‘eligible data breach’ under the Notifiable Data Breach scheme;
  • And review the incident and improve our processes, policies and controls to prevent future breaches.

If you have a complaint about how your personal information is being handled please contact us at any time via:

Please include the following information with your complaint:

  • Your name
  • Your contact details
  • Your site name and/or site ID
  • The details of your complaint

Once we receive your complaint, we will acknowledge it as quickly as possible and let you know if any further information is needed to resolve your complaint.

We will assess whether the complaint can be addressed immediately, investigate if more details are required, determine the most appropriate remedy and communicate the proposed remedy to the complainant.

We aim to resolve complaints as quickly as possible, but some complaints take longer to resolve than others. If your complaint has taken longer than five (5) business days to resolve we will send you a progress update, including an updated timeframe as to when you can reasonably expect a response.

Raising your issue with our Complaints Officer does not limit you from raising your issue at any time with external disputes schemes or relevant regulators.

Under the Privacy Act you may complain to the Office of the Australian Information Commissioner (OAIC) about the way we handle your personal information. Please note the OAIC requires any complaint must first be made to the respondent organisation. Australian law allows 30 days for the respondent organisation to deal with the complaint before any complaint is made to the OAIC. The Commissioner can be contacted at:

Office of Australian Information Commissioner
GPO Box 5218 Sydney NSW 2001
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
http://www.oaic.gov.au