Volt Éire Installer Data Processing Terms
Version installer-data-processing-2026-10-01 · Effective 01/10/2026
1. Roles
- 1.1These terms form part of the Volt Éire Installer Network Agreement and meet the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Terms defined in the GDPR have the same meaning here.
- 1.2Volteire Limited ("Volt Éire", "we") is the controller of the Customer personal data it makes available to you through the Portal or otherwise for a Job ("Customer Data"). When you process Customer Data to carry out a Job, you (the "Installer") act as our processor.
- 1.3You are a separate controller only for personal data you must keep to meet your own legal obligations as a Registered Electrical Contractor, employer or taxpayer, such as your copies of completion certificates and test records. You must not use Customer Data for any other purpose. If you do, you become a controller for that processing and are responsible for it.
2. Details of the processing
- 2.1Subject matter and purpose: carrying out EV charger installations, surveys, call-backs and related certification and grant paperwork for Customers.
- 2.2Duration: for each Job, from when it is allocated to you until you have completed it and the call-back period in the SOP has ended.
- 2.3Nature: viewing, recording, storing, using and deleting Customer Data, and completing forms and certificates with it.
- 2.4Categories of data subjects: Customers and members of their household who appear in photographs or videos, or who are present at a Job.
- 2.5Categories of personal data: name, address and Eircode, phone number, email address, MPRN, property photographs and videos, details of the electrical installation and charger, SEAI grant references and dates, and access notes.
- 2.6No special category data is intended to be processed. If you come across any, do not record it.
3. Your obligations as processor
- 3.1Instructions: you will process Customer Data only on our documented instructions, which are this agreement, the SOP and the Job details, unless the law requires otherwise. In that case you will tell us before processing unless the law prohibits it. You will tell us immediately if you believe an instruction breaks data protection law.
- 3.2Confidentiality: you will make sure that everyone who processes Customer Data for you is bound by a duty of confidentiality and sees only what they need for the Job.
- 3.3Security: you will take appropriate technical and organisational measures under Article 32 GDPR. At a minimum: protect devices used for Jobs with a PIN, password or biometric lock; keep operating systems updated; do not share Portal log-ins; do not leave paperwork or devices unattended in vehicles; and use the Portal rather than personal messaging or email to hold Customer photographs and videos.
- 3.4Sub-processors: you will not engage another person or company to process Customer Data without our prior written authorisation. We give general authorisation for mainstream business email and cloud storage providers hosted in the European Economic Area. You will impose the same data protection obligations on any sub-processor, and you remain liable for it.
- 3.5International transfers: you will not transfer Customer Data outside the European Economic Area without our prior written consent and a transfer mechanism that meets Chapter V of the GDPR.
- 3.6Data subject rights: you will tell us within 2 Business Days if you receive a request from a Customer about their personal data, and will not respond to it yourself unless we ask you to. You will help us respond within the legal time limits.
- 3.7Personal data breaches: you will tell us without undue delay, and in any case within 24 hours of becoming aware of it, of any personal data breach affecting Customer Data, including a lost or stolen device. You will give us the information we need to assess and report the breach, and follow our reasonable instructions to contain it.
- 3.8Assistance: you will help us, taking into account the nature of the processing, to meet our obligations on security, breach notification, data protection impact assessments and prior consultation under Articles 32 to 36 GDPR.
- 3.9Deletion: within 30 days of completing a Job, you will delete any Customer Data you hold outside the Portal, except records you must keep by law as a separate controller. You will confirm deletion on request. When the Installer Network Agreement ends, you will delete or return all Customer Data as we direct.
- 3.10Audit: you will make available the information we reasonably need to show compliance with these terms, and allow and contribute to audits and inspections by us or an auditor we appoint, on reasonable notice.
4. Our obligations
- 4.1We will make available to you only the Customer Data needed to carry out each Job. We are responsible for having a lawful basis for sharing it with you and for telling Customers about it in our privacy notice.
5. Liability
- 5.1You will indemnify us against fines, claims, losses and reasonable costs arising from your breach of these terms or of data protection law, to the extent the law allows. The limits on our liability in the Installer Network Agreement apply to these terms.