Privacy Policy
Last updated: 11 June 2026
This Privacy Policy explains how Fyxo Limited ("FYXO", "we", "us") — a private company limited by shares registered in Ireland (CRO 813642), with its registered office at 4 Kirkpatrick House, Spencer Dock, Dublin, D01 DY86, Ireland — collects, uses, and shares personal data when you use our website and Service.
This policy applies to users in the European Economic Area (EEA) and the United Kingdom. FYXO is the data controller of your personal data for the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Data we collect
We collect only what we need to run the Service:
| Category | Examples | Source |
|---|---|---|
| Account | Email, name, country, password hash, session tokens | You |
| Subscription | Plan tier, billing email, payment status, last 4 digits of card | Stripe |
| Connected Assets | Device type, manufacturer, ID, state-of-charge, temperature, charging status, control mode | Third-Party Providers, you |
| Energy & schedule | Charge plans, dispatch decisions, savings calculations, electricity tariff details | Generated by Service |
| Usage / audit | Login events, write actions (including via AI assistants), IP-derived country, OAuth scopes granted | Generated by Service |
| Communications | Support emails, partner enquiries, contact-form messages | You |
We do not collect special-category data (e.g. health, biometric, religious) and we do not knowingly collect data from anyone under 18.
2. Purposes and lawful bases
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Provide the Service, run your account, optimise your assets, calculate savings | Performance of a contract |
| Process payments, prevent fraud, comply with tax law | Performance of a contract; legal obligation |
| Send service emails (write notifications, security alerts, billing) | Performance of a contract; legitimate interests in keeping you informed about your account |
| Audit logs, abuse prevention, geofencing, rate limiting | Legitimate interests in operating a secure Service and meeting our security obligations |
| Improve the Service (aggregated, non-identifying) | Legitimate interests in improving our products |
| Marketing emails (only if you opt in) | Consent |
3. Sub-processors and recipients
We share your personal data with the following sub-processors strictly to operate the Service:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| Vercel | Web hosting, edge CDN, serverless functions | EU edge with US controller |
| Stripe | Subscription billing, payment processing | Ireland (EU customers), UK |
| Resend | Transactional email delivery | EU/US |
| Zoho Mail | Customer support email inbox | EU |
| ENTSO-E Transparency Platform | Wholesale electricity price data (no PII shared) | EU |
| Open-Meteo, Electricity Maps | Weather and carbon intensity data (no PII shared) | EU |
| Anthropic, Cursor, other AI providers | Only if you authorise them via MCP — they receive only the data you allow through OAuth scopes | Varies (US) |
| Device providers (Tesla, Ohme, myenergi, Easee, Wallbox, Shelly, Tapo, SwitchBot, Tuya, etc.) | Only providers you connect — for sending control signals and reading device state | Varies |
We are not responsible for the privacy practices of Third-Party Providers you choose to integrate. Please review their policies before connecting.
4. International transfers
Personal data is primarily stored in the EU (Frankfurt). Where a sub-processor transfers data outside the EEA/UK (for example to a US-based vendor like Vercel for edge serving, or to an AI assistant you authorise), the transfer is covered by Standard Contractual Clauses or another approved transfer mechanism under GDPR/UK GDPR.
5. Retention
| Data | Retention |
|---|---|
| Account data | For as long as your Account is active, then up to 12 months after closure (or longer if legally required) |
| Billing records | 7 years (Irish tax law requirement) |
| Activity / audit log | 90 days |
| MCP safety logs (rate limits, denials, power drift) | 7 days |
| Revoked OAuth tokens | 30 days after revocation |
| OAuth authorisation codes | 1 day |
| Marketing email logs | Until you withdraw consent, then deleted within 30 days |
6. Your rights
Under GDPR and UK GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data (subject to legal retention obligations such as tax records);
- restrict or object to certain processing, including processing based on legitimate interests;
- data portability — receive your data in a structured, machine-readable format;
- withdraw any consent you have given, at any time, without affecting prior lawful processing;
- not be subject to a decision based solely on automated processing that produces significant legal effects — note that our dispatch decisions are advisory and reversible by you at any time;
- lodge a complaint with a supervisory authority:
- Ireland: Data Protection Commission (DPC) — dataprotection.ie
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
To exercise any right, email kgma@fyxo.io. We will respond within one calendar month (extendable by two months for complex requests, with notification).
7. Security
We use industry-standard safeguards including TLS in transit, encryption at rest (Supabase), row-level security policies, OAuth 2.0 with PKCE, refresh-token rotation, rate limiting, audit logging, and geofencing of write operations.
No system is perfectly secure. If you discover a vulnerability, please email kgma@fyxo.io.
8. Automated decisions
FYXO uses automated algorithms (including rules-based and AI-assisted) to generate charging schedules and recommendations. These decisions do not produce legal effects or similarly significant effects on you, and you can review, override, or stop them at any time from the Portal.
9. Cookies
See our Cookie Policy.
10. Changes to this Policy
If we make material changes, we will notify Account holders by email at least 14 days before the change takes effect, and update the "Last updated" date above.
11. Contact
Data protection contact: kgma@fyxo.io
Postal: Fyxo Limited, 4 Kirkpatrick House, Spencer Dock, Dublin, D01 DY86, Ireland.
FYXO is not required to appoint a Data Protection Officer under GDPR Art. 37 at this stage. The contact above is our designated privacy contact.