Who We Are
Caolú Consultants ("Caolú", "we", "us", or "our") is a company registered in the Republic of Ireland under Company Registration Number 783041. Our full company registration and contact details are available on our Contact page.
We operate the Caolú Irish Solar Edition — a field sales and solar quoting platform for SEAI-registered solar installers, accessible at app.caolu.ie and managed at account.caolu.ie. We also operate the yourhome.caolu.ie educational solar guide, which is reached by homeowners after completing a Lead Funnel questionnaire on a Caolú installer's website.
Caolú Consultants is the Data Controller under the GDPR for personal data collected through our platform. This means we determine the purposes and means by which your data is processed and are responsible for ensuring it is handled lawfully.
Where you use our platform to generate quotes for your own end customers (homeowners or businesses), you are the Data Controller for that customer data, and Caolú acts as your Data Processor. You are responsible for ensuring you have a lawful basis to collect and process your customers' personal information before entering it into our system.
What Personal Data We Collect
We collect only the personal data that is necessary to provide the Caolú platform. Below is a complete description of each category.
Account & Identity Data
- Full name — to identify you within your company account and to appear on generated quotes and proposals
- Email address — for account login, subscription management, and transactional communications
- Phone number — optional; provided at your discretion to allow managers or customers to contact you directly
- Password — stored as a one-way cryptographic hash (bcrypt). We never store or have access to your plaintext password
Professional & Business Data
- Company name, company registration number, and VAT number — displayed on quote documents sent to your end customers
- Company address, company phone, and company tagline — displayed on PDF proposals generated through the tool
- SEAI installer number and SEAI registration number — used to validate eligibility for the platform (restricted to SEAI-registered installers) and to auto-populate quote documents
- SEAI verification status and verification timestamps — the result of our automated cross-check against the public SEAI Solar PV Company register (
verified,pending,not_found,deregistered, ormanual_verified), the date the check was performed, and — where a manual review was required — the date that review was completed. These fields are stored on your profile and company record and are used solely to administer the eligibility verification process described below. - Bank name, IBAN, and BIC — entirely optional; if provided, these are used solely to populate the payment details section of your own PDF proposals sent to customers. They are never used by Caolú for payment processing and are never shared with third parties including Stripe.
Billing & Subscription Data
- Stripe customer ID and subscription ID — to manage your subscription lifecycle and open the Stripe billing portal
- Subscription status, tier, and seat limit — to control access to features appropriate to your plan
- Trial end date and billing period end date — to display accurate account information and send trial expiry reminders
- All card and payment details are handled exclusively by Stripe. We never see, store, or process card numbers, CVV codes, or bank account details used for payment.
Usage & Technical Data
- Session tokens stored in your browser's local storage — to keep you signed in between visits
- Login timestamps — recorded by our authentication provider (Supabase) for security purposes
- We intend to introduce anonymised, aggregated usage analytics (such as Plausible, a cookieless, privacy-first analytics tool) in the future. We will update this policy before doing so. Because it is cookieless and collects no personal identifiers, it does not set cookies or track you across sites.
Quote & Survey Data You Enter
Solar quotations you create through the tool — including customer energy usage profiles, roof survey data, equipment selections, and financial projections — are stored in your account. This data may relate to identifiable individuals (your end customers). As noted above, you are the Data Controller for this customer data, and you must ensure you have a lawful basis for collecting it. We process it solely to provide you with the service you have subscribed to.
This data may include, but is not limited to: customer name, email address, phone number, property address, Eircode, MPRN (Meter Point Reference Number), grant eligibility status, energy usage profile, and GDPR consent records. The MPRN is a unique property-level identifier used for SEAI grant applications and ESB Networks notification submissions (NC6/NC7). It is treated with the same care as other personal identifiers.
Where you have configured a webhook integration (available on Enterprise plan), certain customer and system data collected during the quoting process may be transmitted to a third-party endpoint — such as a CRM system — chosen and operated by you. Caolú transmits data to your configured webhook endpoint as a technical service only and does not control, store, or take responsibility for the receiving system. You, as the Data Controller, are solely responsible for the security, compliance, and lawful operation of your webhook endpoint, including ensuring any third-party system receiving personal data complies with GDPR and applicable Irish data protection law.
Sales Rep Performance Data (Teams & Enterprise plans)
Where a subscriber has a Teams or Enterprise plan and enables the Manager Dashboard, Caolú records structured behavioural data about each sales rep's use of the quoting tool. The purpose is to allow the subscriber's managers to oversee team performance. The data collected is limited to work-product metrics and does not include keystroke logging, screen capture, geolocation, or any observation of activity outside the Caolú platform.
The rep performance categories are:
- Session events: assessment opened, PDF generated, configuration saved, configuration reloaded, login, logout, session timeout
- Technical metadata per quote: system size (kWp), battery attach yes/no, EV charger yes/no, immersion diverter yes/no, orientation, county, estimated annual savings, SEAI grant eligibility
- Deal pipeline state: in progress / won / lost, and where applicable the categorised loss reason (price, competitor, timing, financial, planning, etc.)
- Assignment: which rep created which saved configuration
Where a subscriber is also the rep's employer, the subscriber is the Data Controller for the rep's performance data and carries the legal responsibility for notifying the rep that monitoring is in place. Caolú provides an employee notification template to subscribers for this purpose. Caolú acts as the Data Processor and applies the safeguards described in Section 9.1 (Manager Dashboard & Rep Performance Monitoring), including pseudonymisation by default and a 90-day retention ceiling on individual-level metrics.
Reps can see everything Caolú holds about them at any time via the "My Data & Privacy" screen in their profile dropdown, and can export their data as a JSON file.
Scheduling & Crew Data (Enterprise plan)
Where a subscriber uses the Schedule module to plan and manage installations after a deal is won, Caolú stores the operational data needed to run the job. As with quote & survey data, the subscriber is the Data Controller for any customer data within Schedule, and Caolú acts as Data Processor.
- Crew and resource records — crew or team name, the platform users assigned to a crew, skills, base county, and working hours. Where a subscriber adds external subcontractors as crews, the subscriber is responsible for informing those individuals under its own staff or contractor privacy notice.
- Booking records — job type, date and time, status and stage, the assigned crew or engineer, and the customer's first name and county shown on the dispatch board. Where the subscriber adds it, the customer's property address and approximate location are held in a separate, access-restricted record used only so the crew can attend; it is visible only to the subscriber's managers and the crew assigned to that job.
- Crew schedule links — a subscriber may generate a private, read-only, revocable web link for a crew or subcontractor that shows only that crew's upcoming jobs, including the customer's name, site address, Eircode, telephone number and job notes, so they can carry out the work. The link requires no login; the subscriber controls it and can revoke or regenerate it at any time.
- Milestone records — references for date-uncertain external steps such as ESB Networks connection, SEAI grant, and BER lodgement.
- Scheduling audit trail — an immutable record of who created, changed, or cancelled a booking, kept for accountability.
Schedule does not send any automated emails or text messages to your customers — notifications are shown in-app only. No third party receives this data. Customer personal data held in Schedule is scrubbed automatically when the related project is anonymised or erased.
Why We Collect It — Our Lawful Bases
Under GDPR Article 6, we must have a documented lawful basis for every type of personal data processing we carry out. We rely on the following:
Contract performance (Article 6(1)(b))
The majority of the data we process — your name, email address, company details, subscription data, and tool usage — is necessary to deliver the service you have subscribed to. Without this data we cannot create your account, generate quotes, manage your team, or provide billing. This is our primary lawful basis. Customer MPRN data collected during the quoting process is processed on the same basis, where required for SEAI grant application workflows or ESB Networks NC6/NC7 notification submissions. Where webhook integrations are configured by Enterprise subscribers, technical transmission of data to the subscriber's chosen endpoint is carried out on the basis of contract performance (delivery of the subscribed service feature). Where you use the Schedule module, processing your customers' appointment details to plan and deliver the installation they have contracted for is carried out on this same contract-performance basis; the scheduling and assignment of your own staff and crews relies on legitimate interests in operational and team management (Article 6(1)(f)).
Legitimate interests (Article 6(1)(f))
We process your SEAI installer number and professional registration details to verify that you meet our eligibility criteria (the platform is exclusively for SEAI-registered solar installers). Specifically, we carry out the following automated processing on account creation and on a nightly basis thereafter:
- Your SEAI installer number is cross-referenced against the public SEAI Solar PV Company register, which Caolú syncs nightly from the SEAI website.
- The result is stored as a verification status on your profile:
verified(number found and active),pending(number not yet found — 35-day grace period applies for new registrants),not_found(number not found after the grace period),deregistered(number previously verified but since removed from the register), ormanual_verified(confirmed directly by a member of the Caolú team). - Every check is logged in an audit table with a timestamp, the result, and the trigger (account creation, nightly sync, or manual review).
- If your status is
not_foundorderegistered, you will see an in-app notice and may be contacted at your registered email address. No automated account suspension or termination occurs — any action requires human review by a member of the Caolú team.
This processing does not constitute automated decision-making within the meaning of Article 22 GDPR — no decision producing legal or similarly significant effects is made automatically. All account-level decisions require human review. We have assessed this processing as proportionate to our legitimate interest in ensuring platform integrity, and as not overriding your rights or freedoms given the safeguards described above. We also rely on legitimate interests for basic platform security and fraud prevention.
We also rely on legitimate interests for the minimal hosting and personalisation processing involved in serving the yourhome.caolu.ie educational guide. The processing consists of standard CDN access logs (IP address and request metadata, recorded by Netlify as part of normal hosting operation) and a single internal API call from the page to our Supabase backend that retrieves the installer name to personalise the "Brought to you by …" line. We have assessed this processing as proportionate, as it is technically necessary to serve the page and to make the guide intelligible to the homeowner, and the only personal data involved is the visitor's IP address as a normal consequence of web hosting.
Legitimate interests for sales rep performance data (Teams & Enterprise plans)
Where a subscriber enables the Manager Dashboard, the lawful basis for the subscriber's processing of rep performance data is legitimate interest in team management. We, as Data Processor, rely on the subscriber's own legitimate-interest balancing test but also apply a conservative default posture at the platform level: pseudonymous rep cards by default, 90-day automated anonymisation of individual metrics, no automated scoring or evaluative labels, and full rep transparency via the in-app "My Data & Privacy" screen. These safeguards tip the balance in favour of legitimate interest for the subscriber's balancing test. Reps retain the right to object under Article 21 via the procedure described in Section 7, and objections are handled on a case-by-case basis with the subscriber.
Legal obligation (Article 6(1)(c))
We may retain or disclose certain data where required to comply with Irish company law, revenue obligations, or a lawful request from a competent regulatory authority or court.
Consent (Article 6(1)(a))
Where you choose to provide optional data such as your phone number or bank details, you do so voluntarily and can withdraw or remove this data at any time from your account settings. We will also seek explicit consent before introducing any analytics tracking or marketing communications.
How Long We Keep Your Data
We retain personal data only for as long as is necessary for the purpose for which it was collected, or as required by law. Our specific retention periods are as follows:
- Active accounts: All account data is retained and accessible for the full duration of your active subscription.
- Customer project records (saved quotes & assessments): Saved projects — including in-progress quotes — are retained for the full duration of your account and are not automatically deleted or anonymised. Solar enquiries frequently go quiet and reactivate months later, so a customer's project remains available for you to revisit or reopen at any time. Customer personal data within a project is removed only when you delete the project or when an erasure request is actioned. This data is never used to profile individuals.
- Individual rep performance metrics (Teams & Enterprise plans): Individual-level performance metrics visible in the Manager Dashboard are automatically anonymised after 90 days by a nightly scheduled job. Beyond 90 days, behavioural rows can no longer be attributed to a specific rep. Aggregate team-level statistics (which cannot be linked back to an individual) may be retained longer to support year-over-year trend reporting.
- Won and lost deal records: When a deal reaches "won" or "lost" status, its locked commercial values (quote total, system size, battery capacity) are retained for 7 years as commercial records in line with Irish Revenue requirements under the Taxes Consolidation Act 1997. These records are exempt from the 90-day individual anonymisation described above, but the rep name associated with a closed deal can be scrubbed on erasure request without removing the commercial figure.
- Schedule (installation planning) data: Bookings, crew assignments, and milestones follow the retention of the project they relate to. Any customer personal data held in Schedule — names, county, property address, and audit details — is scrubbed automatically when the related project is anonymised or erased, leaving only an anonymised operational record. Crew and job-type configuration is retained for the duration of your subscription and removed on company offboarding.
- After subscription cancellation: Your account and all associated data (including saved quotes) is retained for 30 days from the date of cancellation. This gives you the opportunity to export or retrieve anything you need. After 30 days, your personal profile data will be deleted or irreversibly anonymised, subject to the 7-year commercial-record exception above.
- Financial and transactional records: We may retain records of subscription transactions for up to 7 years to comply with Irish Revenue obligations under the Taxes Consolidation Act 1997. These records are kept in minimal form (transaction ID, amount, date, tier) and do not include card details.
- Security and authentication logs: Login records held by our authentication provider are retained for up to 90 days for security monitoring purposes.
- yourhome.caolu.ie hosting logs: Standard CDN access logs for the educational guide (containing IP address and request metadata) are retained by Netlify in line with their hosting log retention policy, which we treat as a service log rather than a profile of any individual. Caolú does not separately store, profile, or enrich this log data.
- Deleted invites and former team members: When a manager removes a team member or cancels an invite, their profile is unlinked from the company immediately. Their Supabase authentication account is retained for 30 days and then deleted.
- Company offboarding: When a subscriber offboards entirely, their complete dataset (live tables, saved configurations, deal status history, team goals, assessment events) is copied into a service-role-only cold storage schema and the live tables are cleared. Cold storage is retained for 10 years to cover the statute of limitations for Irish commercial disputes.
You may request deletion of your personal data at any time by contacting [email protected]. We will action erasure requests within 30 days, subject to any overriding legal retention obligations.
Who We Share Your Data With
We do not sell, rent, or trade your personal data. We share data only with trusted third-party service providers (Data Processors) who process it on our behalf, under contract, for specific purposes only.
The following table lists every sub-processor we use and why:
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase Privacy policy ↗ |
Database, authentication, file storage, and edge computing for the platform | All profile data, subscription data, quote data, session tokens | EU West (Ireland) — AWS eu-west-1 |
| Stripe Privacy policy ↗ |
Subscription billing, payment processing, and customer portal | Email address, subscription tier, Stripe customer ID. Card details are entered directly into Stripe and never pass through our servers. | EU (Stripe Ireland Limited) |
| Netlify Privacy policy ↗ |
Hosting and delivery of app.caolu.ie, account.caolu.ie and yourhome.caolu.ie | IP address and request metadata (standard web hosting logs). Marketing contact-form submissions (name, company, email, phone, message) are stored at rest in Netlify Forms. | EU CDN edge nodes |
| Cloudflare Privacy policy ↗ |
DNS management for caolu.ie, and cookieless, privacy-first web analytics for caolu.ie and for websites Caolú builds and hosts under the Websites & Leads Service | Aggregated, cookieless page-view measurements only — no cookies, no persistent identifiers, and no cross-site tracking of visitors. For DNS, domain configuration data only. | EU / global edge — transfers governed by Standard Contractual Clauses where applicable |
| Google Workspace Privacy policy ↗ |
Business email and calendar (Caolú internal use), including transactional and support correspondence | Email address and the content of email correspondence | EU / global — transfers governed by Standard Contractual Clauses and the EU-US Data Privacy Framework |
| HubSpot Privacy policy ↗ |
Customer relationship management (Caolú internal use): contact records, deal pipeline and sales activity | Name, email address, company name, subscription tier and deal status | EU data centre (Frankfurt) — transfers governed by Standard Contractual Clauses where applicable |
| Google Maps Platform Privacy policy ↗ |
Satellite imagery and geocoding for roof survey within the quoting tool | Property address entered during a roof survey session | Global (Google LLC) |
| Plausible Analytics (planned, EU-hosted) Privacy policy ↗ |
Cookieless, privacy-first usage analytics (not yet active — this policy will be updated before activation) | Aggregated, cookieless measurements only; no cookies, no personal identifiers, no cross-site tracking | EU-hosted |
| Installer-configured webhook endpoints (Enterprise plan) | Transmission of quotation and customer data to third-party CRM or business systems configured by the installer subscriber. Caolú acts as a technical conduit only — the installer is the Data Controller for this data flow. | Customer name, email, phone, property address, Eircode, MPRN, system specification, SEAI grant eligibility, GDPR consent record, rep and company identifiers | Determined by the installer subscriber. May be located inside or outside the EEA. The installer is responsible for ensuring appropriate transfer safeguards are in place where data is transmitted outside the EEA. |
| Anthropic PBC (Claude) Privacy policy ↗ |
AI-assisted software development tooling used internally by Caolú engineering to build, review and debug the Caolú platform. | Primarily source code, schema, configuration and technical documentation. Model training on Caolú data is disabled. | United States — data-processing terms for this tool are being formalised |
| Resend (Lead Funnel) Privacy policy ↗ |
Delivery of the transactional "Your Home Starter Pack" email to homeowners who complete a Lead Funnel questionnaire. These emails are not open- or click-tracked. | Homeowner name and email address, and the content of the Starter Pack email | Dispatched via Amazon SES (AWS eu-west-1, Dublin, Ireland) — transfers governed by Standard Contractual Clauses where applicable |
| Amazon Web Services (SES) Privacy policy ↗ |
Email transport used by Resend to dispatch transactional email | Same recipients and content as the Resend emails above | AWS eu-west-1 (Dublin, Ireland) — remains in the EEA |
| hCaptcha (Lead Funnel) Privacy policy ↗ |
Bot and abuse protection for the Lead Funnel questionnaire widget | Technical signals required for bot detection (such as IP address, browser/device metadata, and interaction data) | EU / United States — transfers governed by Standard Contractual Clauses where applicable |
Sub-Processor Change Procedure
We will provide all active subscribers with no less than fourteen (14) days' advance written notice via email before engaging any new sub-processor or replacing an existing sub-processor. Subscribers may object to the appointment of a new sub-processor on reasonable grounds relating to the protection of Personal Data within fourteen (14) days of receiving the notification. Where a subscriber objects and Caolú cannot reasonably accommodate the objection, either party may terminate the affected Services upon thirty (30) days' written notice without penalty.
AI-Assisted Development & Tooling
Caolú's engineering team uses an AI coding assistant — currently Anthropic's Claude, including the Claude Code command-line tool — to help build, review and debug the Caolú platform. Model training on our data is disabled. We are formalising the data-processing terms for this tool and will update this section accordingly. Questions may be directed to us via the Contact Us section.
International Data Transfers
We store and process your data primarily within the European Economic Area (EEA). Our primary infrastructure provider (Supabase) operates on AWS EU West servers located in Ireland. Our billing provider (Stripe) operates as Stripe Ireland Limited, an EU entity.
Google Maps Platform involves transfers of data to Google LLC in the United States. These transfers are carried out under Google's Standard Contractual Clauses (SCCs) approved by the European Commission, which provide an appropriate level of protection for your personal data. Our planned usage analytics (Plausible) is EU-hosted and cookieless, and does not involve a transfer of personal data outside the EEA.
Google Workspace (business email and calendar) involves transfers to Google LLC under the same Standard Contractual Clauses and the EU-US Data Privacy Framework. HubSpot (our CRM) stores our data in its EU (Frankfurt) data centre, with SCCs in place for any ancillary transfers; HubSpot's GDPR compliance is documented in its Data Processing Agreement, which we have in place.
Whenever your data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses or adequacy decisions, as required by Chapter V of the GDPR.
Webhook integrations (Enterprise plan): Where an Enterprise subscriber configures a webhook endpoint that transmits customer or quotation data to a system located outside the EEA, Caolú acts solely as a technical conduit. The subscriber, as Data Controller for that data flow, is solely responsible for ensuring that appropriate transfer safeguards — such as Standard Contractual Clauses or an adequacy decision — are in place for the destination system. Caolú does not assess, verify, or warrant the data protection compliance of subscriber-configured webhook endpoints.
Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights. You can exercise any of these rights by contacting us at [email protected]. We will respond within 30 days (or sooner where possible).
Self-service for sales reps (Teams & Enterprise plans): If you are a sales rep whose employer uses the Caolú Manager Dashboard, you can exercise your right of access (Article 15) and your right to data portability (Article 20) immediately and without contacting us — open your profile dropdown and click "My Data & Privacy". The screen shows your profile, your own performance metrics for the last 90 days, your deal pipeline status, and an access log of every time a manager has clicked "Reveal names" in the dashboard. You can export the whole file as JSON with one click. This is the fastest way to see exactly what Caolú holds about you.
You can request a copy of all personal data we hold about you, along with information about how we use it.
You can ask us to correct any inaccurate or incomplete personal data we hold about you.
You can request that we delete your personal data. We will comply unless we have an overriding legal obligation to retain it (e.g. tax records).
You can ask us to pause processing of your data in certain circumstances, such as while a complaint is being investigated.
You can request your personal data in a structured, machine-readable format (JSON or CSV) for transfer to another service.
You can object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling grounds that override your rights.
Where processing is based on your consent (e.g. optional fields, future analytics), you can withdraw consent at any time without affecting prior processing.
If you are unhappy with how we handle your data, you have the right to complain to the Data Protection Commission (Ireland's supervisory authority).
To contact Ireland's Data Protection Commission: www.dataprotection.ie — Lo Call: 1800 437 737.
Cookies & Local Storage
Our platform uses browser local storage (not traditional cookies) to maintain your login session. Specifically, when you sign in to account.caolu.ie or app.caolu.ie, your authentication session token is stored in your browser's local storage under the key caolu_sess. This is essential for keeping you signed in between pages and sessions.
This use of local storage is strictly necessary for the platform to function and does not require consent under the ePrivacy Regulations (SI No. 336 of 2011). No tracking or advertising cookies are used at present.
You can clear your local storage at any time through your browser settings, which will sign you out of the platform. This will not affect your account or subscription.
Where webhook integrations are used (Enterprise plan), data is transmitted server-side or via a direct network request from the application. No additional data is written to browser local storage or cookies as part of the webhook feature.
yourhome.caolu.ie: The homeowner-facing educational guide at yourhome.caolu.ie does not set any cookies and does not write to your browser's local storage. There is no analytics tracking, no advertising pixel, and no third-party tag on the page. If we change that in the future (for example to count anonymised section reads), we will update this policy and, where required, display a cookie consent notice before any tracking begins.
If we activate usage analytics (Plausible) in the future, we will update this policy first. Because it is cookieless and collects no personal identifiers, it does not set cookies or track you across sites.
How We Protect Your Data
We take the security of your personal data seriously and implement appropriate technical and organisational measures, including:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS).
- Encryption at rest: Your data is stored on Supabase, which encrypts all data at rest using AES-256.
- Password hashing: Passwords are stored as bcrypt hashes. We never store or transmit plaintext passwords.
- Access control: Row-Level Security (RLS) policies in our database ensure users can only access their own data. Team members can only access data belonging to their company.
- No card data: We never handle card numbers, CVV codes, or bank details used for payment. All payment data is processed directly by Stripe.
- EU-based infrastructure: Our primary database and authentication systems operate within Ireland (AWS eu-west-1), keeping your data within the EU.
- Minimal access: Only authorised Caolú personnel have administrative access to production systems, and only where necessary to provide support or maintain the service.
- Session management: Automated session timeout after 30 minutes of inactivity with re-authentication required. Users receive a visual warning at 25 minutes with the option to extend their session.
- Audit logging: Security-relevant events are logged including authentication, data access, configuration changes, session timeouts, and project status changes.
- Role-based database enforcement: Company-wide settings (brand, webhook, payment configuration) can only be modified by users with the manager or admin role, enforced at the database level via Row-Level Security policies.
For comprehensive details of our security measures, infrastructure, and compliance roadmap, visit our dedicated Security page.
Manager Dashboard & Rep Performance Monitoring
For Teams and Enterprise subscribers who enable the Manager Dashboard, Caolú applies a privacy-by-design posture to team performance visibility. The following controls operate automatically and cannot be disabled by managers:
- Pseudonymous by default. Rep cards in the Manager Dashboard display as "Rep A", "Rep B", "Rep C" etc. Real names do not appear unless a manager explicitly clicks "Reveal names" and confirms a consent dialog.
- Audit-logged identity reveals. Every click of "Reveal names" is recorded in the audit trail with the manager's identity, the period being viewed, and a timestamp. Reps can see these records themselves in their "My Data & Privacy" screen.
- Time-bounded reveals. After a reveal, real names auto-hide again after 30 minutes or when the manager closes the dashboard, whichever is sooner. The next dashboard session starts pseudonymous again.
- No automated scoring or evaluative labels. Caolú does not compute composite scores, tier labels, or automated performance judgements. Managers see raw numerical metrics (assessments, PDF rate, battery attach rate, average system size) and form their own opinions. Article 22 of the GDPR (automated individual decision-making) is not engaged because no automated decision is made.
- No in-app coaching notes. Caolú does not provide a free-text coaching-notes feature. Managers record coaching conversations in their own HR system. This keeps evaluative commentary out of Caolú's scope entirely.
- Team-level alerts only. Where the Manager Dashboard surfaces an "alert" (for example, low team battery attach rate), the alert is always about team-wide patterns and never names an individual rep.
- 90-day individual retention ceiling. Individual-level rep performance data is automatically anonymised after 90 days by a nightly scheduled job. After anonymisation, the data still contributes to team aggregates but cannot be linked back to a specific rep.
- Rep-facing "My Data & Privacy" screen. Every rep can open a first-class self-service view of everything Caolú holds about them — profile, metrics, pipeline status, access log of manager name-reveals, retention policy — and export it as JSON. This is built directly into the product.
- Rate limiting and access logging. Every call to the Manager Dashboard is scoped by server-side access controls that verify the caller is a manager of the same company before any data is returned.
We publish the full Manager Dashboard privacy architecture at our Security page. If you are a sales rep and have a concern about how your manager is using the dashboard, you can contact us at [email protected] and we will work with your employer (the Data Controller) to address the concern.
Breach Notification
In the event of a Personal Data Breach affecting subscriber or customer data:
- Caolú will notify affected subscribers within twenty-four (24) hours of confirmed breach detection
- Caolú will notify the Data Protection Commission within seventy-two (72) hours as required by GDPR Article 33
- Caolú will communicate the breach to affected Data Subjects without undue delay where required by GDPR Article 34
- Notification will include: nature and scope of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed to mitigate the breach
Data Processing Agreement
Where Caolú acts as a Data Processor on behalf of a subscriber (the Data Controller), the processing is governed by our Data Processing Agreement (DPA). The DPA sets out the obligations of each party regarding the processing of personal data, including: security measures, sub-processor management, breach notification procedures, audit rights, data deletion on termination, and liability. Enterprise subscribers may request a countersigned copy of the DPA by contacting [email protected].
Lead Funnel — Homeowner Enquiries
This section explains how we handle personal data collected through the Lead Funnel: a questionnaire widget that a Caolú installer embeds on their own website so that homeowners can make a solar enquiry. It is written first for homeowners who fill in the questionnaire, and then for the installers who receive those enquiries.
For Homeowners
What we collect. When you complete a Lead Funnel questionnaire, and only with your explicit consent, we collect:
- Your name, email address, phone number, address, and Eircode; and
- The self-reported answers you give about your property and energy use — for example your roof, household size, whether you have an EV or a heat pump, your electricity supplier, and the approximate age of your house.
Why we can use it (lawful basis). Our lawful basis is your consent, which you give by ticking the required checkbox in the questionnaire before you submit it. That checkbox refers you to this Privacy Policy. You can withdraw your consent at any time by contacting us (see Contact & Complaints), although that will not affect an installer who has already accepted your enquiry and become responsible for your data in their own right.
Who sees it. Your enquiry is shared only with the single installer whose website you filled the questionnaire in on. It is not broadcast to multiple installers and it is not sold. To protect you, your direct contact details (name, email, phone, address, and Eircode) are masked from the installer until they choose to accept your enquiry. The installer sees your property answers first, and only unlocks your contact details — by spending a lead credit — if they decide to follow up. If they accept, they may contact you about that solar enquiry only.
The Starter Pack. When you submit the questionnaire we email you an educational "Your Home Starter Pack". This email, and the information on yourhome.caolu.ie, are educational and indicative only — any figures are estimates and would be subject to a formal survey by an installer. We do not track whether you open the Starter Pack email or click links in it.
Browsing the yourhome.caolu.ie Guide
The Caolú educational guide at yourhome.caolu.ie is linked from the Starter Pack email and may also be linked from an installer's own website. Visiting the guide on its own — without filling in any questionnaire — does not require you to provide any personal information. We do not ask you to log in, we do not present any form on the page, we do not set tracking or advertising cookies, we do not run a marketing pixel, and we do not run web analytics on it at the time of writing.
What does happen when you visit follows from standard web hosting. Our content delivery network, Netlify, records standard request metadata (including your IP address) as part of normal CDN operation. A single internal API call is made from the page to our Supabase backend to look up the installer name so that we can personalise the "Brought to you by …" line at the top of the guide; that lookup also passes your IP address to Supabase's edge servers as a normal consequence of any HTTP request. Both providers are listed in Section 5 — Sub-Processors, and our lawful basis for this minimal processing is legitimate interests (technical operation and basic personalisation of the page). No persistent profile of you is created and the page does not write to your browser's local storage.
If we ever add visitor analytics or any other tracking to the guide — for example to count how many people read each section — we will update this Privacy Policy first and, where required by the ePrivacy Regulations, present a cookie consent notice before any tracking begins.
Retention & Sub-Processors
How long we keep it. Caolú holds your enquiry as a processor on behalf of the installer. If no installer accepts your enquiry, we retain it only for a limited period to allow the installer to review it, and then delete or anonymise it. Once an installer accepts your enquiry, that installer becomes responsible for how long they keep your data (see "For Installers" below). You can ask us to delete the enquiry we hold at any time.
Sub-processors used by the Lead Funnel. In addition to the providers listed in Section 5, the Lead Funnel relies on:
- Supabase — EU hosting and database for the enquiry (EU West, Ireland);
- Stripe — processing the installer's setup fee and credit payments (EU);
- Resend — sending the transactional "Your Home Starter Pack" email. These emails are not open- or click-tracked;
- hCaptcha — protecting the questionnaire from bots and abuse.
Your rights. As a homeowner you have the same GDPR rights set out in Section 7 — including access, rectification, erasure, restriction, portability, objection, and the right to withdraw consent — as well as the right to complain to the Data Protection Commission. To exercise any right in relation to the enquiry Caolú holds, contact us using the details in Contact & Complaints. If an installer has already accepted your enquiry, you may also need to contact that installer directly, as they are then a controller of your data in their own right.
For Installers
When you use the Lead Funnel, the data protection roles work as follows:
- Before you accept a lead, Caolú is the Data Processor: we capture the homeowner's enquiry (with the homeowner's consent) and transmit it to your inbox with contact details masked. This processing is governed by our Data Processing Agreement.
- When you accept a lead, you become the Data Controller of that homeowner's personal data. You are then responsible for handling it lawfully under the GDPR and the Irish Data Protection Act 2018.
As controller of an accepted lead, you must: contact the homeowner only on a lawful basis and only about the solar enquiry they made; not use their data for unrelated marketing or share it for unrelated purposes; give them any privacy information you are required to provide; honour their data subject rights; keep their data secure; and retain it only for as long as you have a lawful purpose. Your obligations as a controller are set out in full in the Lead Funnel section of our Terms of Service. Misuse of homeowner data is a breach of those Terms and may result in suspension of the Lead Funnel.
Websites We Build and Host (Websites & Leads Service)
Where Caolú designs, hosts and maintains an installer's website under the Websites & Leads Service (see Section 17 of our Terms), the same roles apply to any homeowner enquiry captured through that site's solar calculator: Caolú acts as the installer's Data Processor for the capture and transmission of the enquiry, and the installer is the Data Controller once they accept it. That processing is governed by our Data Processing Agreement. For general visitor measurement on the sites we host, we use Cloudflare's cookieless, privacy-first web analytics — it counts page views in aggregate and sets no cookies, uses no persistent identifiers, and does not track visitors across sites — together with standard hosting logs from our CDN. We do not build advertising profiles of a website's visitors.
Children
The Caolú platform is a professional business-to-business tool intended exclusively for use by SEAI-registered solar installers and their employed team members. It is not directed at or intended for use by anyone under the age of 18.
We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has provided us with personal data without appropriate consent, please contact us at [email protected] and we will take steps to delete that information promptly.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or applicable law. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Display a notice within the account management portal (account.caolu.ie) on your next login
- Send an email notification to all active subscribers if the changes are significant
Your continued use of the platform after changes take effect constitutes acceptance of the revised policy. If you do not agree with any changes, you have the right to close your account and request deletion of your data.
Contact Us & How to Complain
If you have any questions about this Privacy Policy, wish to exercise a data subject right, or have a concern about how we handle your data, please contact our data protection point of contact:
Data Protection — Caolú Consultants
CRO No. 783041 · Republic of Ireland · Company details
We will acknowledge your request within 3 working days and respond in full within 30 days. If your request is complex or you have submitted multiple requests, we may extend this period by a further two months, in which case we will notify you.
If you are not satisfied with our response, or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with the Data Protection Commission of Ireland, which is the relevant supervisory authority:
- Website: www.dataprotection.ie
- Phone (Lo Call): 1800 437 737
- International phone: +353 (0)761 104 800
- Email: [email protected]
- Post: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
You also have the right to lodge a complaint with the supervisory authority in the EU member state of your habitual residence or place of work, if that is somewhere other than Ireland. We would, however, appreciate the chance to address your concerns directly before you approach the Data Protection Commission, so please consider contacting us first.