Privacy Policy - Electric Load Orchestra

Last Updated: March 27, 2025

1. Introduction

Electric Load Orchestra ("we," "us," or "our"), a service provided by DaisyChain Energy, respects your right to privacy. We recognize the importance of protecting your personal information and are committed to processing it responsibly and in compliance with applicable laws.

This Privacy Policy describes how we collect, use, disclose, and safeguard your information when you use our platform, services, and website. It outlines the types of information we gather during our business relationship, how that information is used, and the choices you have regarding your personal data.

2. Information We Collect

2.1 Account Information

When you create an account with us, we collect personal information that identifies you and allows us to provide our services. This includes your email address (which serves as your username), your encrypted password, your first and last name, and optionally, your phone number. We also collect your physical address to help us understand the location of your service and for billing purposes.

2.2 Energy and Billing Data

To provide our core energy management services, we collect and process various types of energy-related information. This includes property and site information, meter identification data and readings, your energy consumption patterns, utility billing information, and apartment or unit identification numbers where applicable. This information is essential to delivering our service and providing you with insights about your energy usage.

2.3 Technical Information

Our system automatically records certain technical information when you interact with our platform. This information is primarily collected and processed by AWS Cognito as part of their authentication services to ensure secure access to your account. It includes authentication information, login timestamps, and your IP address (for security purposes). This data helps us maintain the security of your account and optimize your experience with our service.

2.4 Cookies and Local Storage

We use cookies and local storage technologies primarily for authentication purposes. Specifically, these technologies store AWS Cognito access tokens that keep you securely logged into our service. If our service incorporates mapping features through Mapbox or similar services, these third-party services may use their own cookies when you interact with these features within our platform.

3. How We Use Your Information

We use your information with care and only for specific, legitimate purposes related to providing and improving our services. Here's how we use the information we collect:

  • Service Provision: We use your account information to create and manage your user account, authenticate your identity when you log in, and provide you with access to our platform's features. This processing is necessary to fulfill our contractual obligations to you.

  • Energy Data Analysis: Your energy usage and billing data allows us to process, analyze, and display information about your energy consumption patterns. This helps you understand your usage and identify opportunities for efficiency improvements.

  • Service Communications: We use your contact information to communicate important updates about our service, notify you about changes to your account, and respond to your inquiries. These communications are an essential part of providing our service.

  • Customer Support: When you contact us with questions or concerns, we use your information to provide timely and effective support, resolving any issues you may encounter with our platform.

  • Service Improvement: We analyze aggregate usage patterns across our platform to identify trends, enhance our features, and develop new tools to better serve our customers' energy management needs.

  • Educational Content: Based on your energy usage patterns, we may provide personalized recommendations and educational resources about energy optimization and peak demand management. This helps you maximize the benefits of our service.

4. Legal Basis for Processing

We process your personal information based on the following legal grounds:

  • Contractual Necessity: To fulfill our contractual obligations to you as outlined in our Terms of Service

  • Legitimate Interests: To operate and improve our business and services in ways that do not override your privacy rights

  • Consent: Where required by law, we process certain data based on your explicit consent

  • Legal Compliance: To comply with applicable laws and regulations

5. Data Storage and Security

Protecting your personal information is a priority for Electric Load Orchestra. We implement appropriate technical and organizational safeguards designed to secure your data against unauthorized access or disclosure.

5.1 Data Storage

Your information is stored on secure cloud infrastructure provided by Amazon Web Services (AWS) and InfluxDB Cloud, industry-leading platforms that maintain robust security standards and compliance certifications.

5.2 Security Measures

We employ multiple layers of protection to safeguard your data:

  • Strong encryption for sensitive data at rest on our AWS RDS database

  • Secure SSH tunneling for all database connections

  • Industry-standard password hashing algorithms to protect your credentials

  • Strict access controls that limit data access to authorized personnel only

  • Regular security assessments to identify and address potential vulnerabilities

  • Nightly database backups stored securely to ensure data recovery if needed

While we implement these and other appropriate safeguards, please understand that no internet transmission or electronic storage system can guarantee absolute security. We continually evaluate and enhance our security practices to protect your information.

6. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy and to satisfy our legal and business requirements:

  • While you maintain an active account with us

  • As needed to provide our contracted services to you

  • As required to comply with applicable laws, resolve disputes, and enforce our agreements

We do not automatically delete your data when you stop using our service, as historical energy data provides valuable context for future analysis. If you close your account or wish to request deletion of your personal information, please contact us at privacy@daisychain.energy. We will respond to your request in accordance with applicable law and our data retention policies.

7. Data Sharing and Disclosure

7.1 Service Providers

We share your information with select third-party service providers who help us deliver and improve our services:

  • Amazon Web Services (AWS): For secure cloud hosting and database services

  • AWS Cognito: For secure user authentication and identity management

  • InfluxDB Cloud: For specialized time-series storage of energy consumption data

  • Mapbox: For mapping functionality within our platform when applicable

These service providers are bound by contractual obligations to handle your data securely and only for the purposes we specify. We do not allow our service providers to use your personal information for their own marketing or other purposes.

7.2 Legal Requirements

We may disclose your information when required by law, such as in response to a court order, subpoena, or other legal process. We may also share information to comply with regulatory requirements, protect our rights or property, prevent fraud, or ensure the safety of our users or the public.

7.3 Business Transfers

In the event that Electric Load Orchestra or DaisyChain Energy is acquired by or merged with another company, or in the case of a corporate reorganization, sale of assets, or bankruptcy, your personal information may be transferred as part of that transaction. We will notify you via email and/or prominent notice on our website if your information becomes subject to a different privacy policy.

We do not sell or rent your personal information to third parties for their marketing purposes, and we do not share your information except as described in this Privacy Policy.

8. Your Privacy Rights

We respect your control over your personal information and provide ways for you to access and manage your data.

8.1 Rights for All Users

As our customer, you have the right to:

  • Access Your Information: Request a copy of the personal information we maintain about you

  • Correct Your Information: Ask us to update or correct inaccurate or incomplete information in our records

  • Delete Your Information: Request deletion of your personal data, subject to certain exceptions such as legal obligations or outstanding contractual requirements

  • Opt Out of Communications: Choose not to receive promotional communications from us at any time

8.2 Rights for Connecticut Residents

Under the Connecticut Data Privacy Act (CTDPA), Connecticut residents have additional rights, including:

  • The right to confirm whether we are processing your personal data

  • The right to data portability in a readily usable format

  • The right to appeal a denial of a request to exercise your rights

To exercise any of these rights, please contact us at privacy@daisychain.energy. We will respond to your request within a reasonable timeframe, typically within 30 days. We may ask you to verify your identity before fulfilling your request to protect your privacy and security.

9. Children's Privacy

Our services are designed for and directed at individuals who are at least 18 years of age. We do not knowingly collect personal information from children under 18, as our services are intended for utility account holders and property owners or managers.

If we discover that we have inadvertently collected personal information from a child under 18, we will promptly take steps to delete that information from our systems. If you believe we might have collected information from a child under 18, please contact us immediately at privacy@daisychain.energy.

10. Data Breach Response

Protecting your data is a priority for us. In the unlikely event of a data breach that compromises your personal information, we will take prompt action to address the situation:

  • We will conduct a thorough investigation to understand the nature and scope of the breach

  • We will implement immediate security measures to contain the breach, including changing database passwords and SSH tunnel keys

  • We will notify affected users promptly in accordance with applicable law

  • We will work to identify and resolve any vulnerabilities that may have contributed to the breach

  • We will cooperate with relevant authorities as required by law

Our team regularly reviews and updates our security practices to help prevent unauthorized access to user information and to maintain the integrity of our systems.

11. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, services, or applicable laws and regulations. When we make material changes to this policy, we will:

  • Post the updated policy on our website with a revised "Last Updated" date

  • Provide notice through our service or by email for significant changes

  • Give you the opportunity to review the revised policy before continuing to use our services

Your continued use of Electric Load Orchestra after we post changes to this Privacy Policy means you accept the updated policy. We encourage you to review this Privacy Policy regularly to stay informed about how we protect your information.

12. Contact Us

We welcome your questions, concerns, and feedback about this Privacy Policy or our privacy practices. To contact us:

DaisyChain Energy

19 Morris Ave

Brooklyn, NY 11205

Email: privacy@daisychain.energy

We strive to respond to all inquiries within 30 days.