Privacy Policy

Our privacy policy and how we use your data

Last updated: 8 September 2026

1. Introduction

This Privacy Policy explains how Phy Energy ("Phy", "we", "us", "our") collects, uses, shares, and protects personal information when you use the Phy platform-as-a-service, including our websites, web and mobile applications, dashboards, and API (together, the "Platform"). The Platform supports both Utility Management (metering, billing, invoicing, payments, and reporting for electricity, water, gas, HVAC, solar, genset, and similar utilities) and EV Charger Management(charging station configuration, sessions, and payments under the "Phy Charge" brand).

We designed this policy to be read alongside our Terms of Service and Cookie Policy.

2. Our role: controller and processor

The Platform serves business customers ("Organisations" — utility managers, landlords, property managers, body corporates, charge point operators, and partner companies) and individual end users ("End Users" — residents, tenants, occupants, and EV drivers).

  • Phy as responsible party / controller. For personal information about visitors to our websites, Organisation account users, prospects, and partners, and for information we process to run, secure, bill for, and improve the Platform, Phy decides how and why that information is processed.
  • Phy as operator / processor.For personal information about End Users that an Organisation loads into or generates through the Platform (for example occupancy records, meter and consumption data, invoices, payments, wallet balances, and charging sessions), the Organisation is the responsible party / controller and Phy processes that information on the Organisation's documented instructions, under our Terms and any applicable data processing agreement. If you are an End User and want to exercise your rights or understand a specific charge, contact your Organisation (for example your landlord, property manager, or charge point operator); we will support them and can route your request to them.

3. Information we collect

3.1 Account and Organisation information

  • identity and contact details: name, work email, phone number, job title or role, Organisation name;
  • authentication and security data: hashed passwords, multi-factor authentication settings, session and device identifiers, sign-in logs, IP address;
  • billing and subscription data for Organisations: plan, usage counts, platform fees, and invoicing contacts.

3.2 End User and operational information

  • identity and contact details of residents, tenants, and EV drivers: name, email, phone, and the property, unit, site, or account they are linked to;
  • occupancy and agreement data: move-in and move-out dates, and the split or proportion of shared utilities a party is responsible for;
  • metering and consumption data: meter identifiers and multipliers, interval and cumulative readings, load profiles, validation and estimation states, and virtual meter compositions;
  • billing and financial data: tariffs applied, charges, charge runs, allocations, invoices and invoice lines, credit notes, payments, payment allocations, aging, prepaid wallet balances and transactions, and relay switching events;
  • EV charging data: charger and connector selected, session start and end times, energy delivered, session status, tariff and amount charged, and the charging site location;
  • communications: support requests, emails, and notes you send us.

3.3 Payment information

Card and bank payments are handled by our third-party payment processor. We do not store full card numbers. We store payment references, tokens, status, amounts, the last few digits and card type where provided, and remittance records showing amounts collected on behalf of an Organisation and paid on to it, less our commission and the gateway fee.

3.4 Technical and usage information

  • device and browser type, operating system, language, and approximate location derived from IP address;
  • log data: pages and API endpoints accessed, timestamps, referring pages, error and performance data;
  • cookies and similar technologies, as described in our Cookie Policy.

4. Where we get it

We collect personal information:

  • directly from you, when you register, configure, or use the Platform or contact us;
  • from your Organisation, or from an Organisation's landlord, property manager, or partner, when they add you as a user or End User or import records about you;
  • automatically from meters, sensors, charging stations, and connected devices, and from your use of the Platform;
  • from our payment processor and from accounting integrations (for example Xero) that an Organisation chooses to connect;
  • from service providers that help us with security, fraud prevention, and analytics.

5. How and why we use it

We use personal information for the following purposes, relying on the legal bases noted (framed around POPIA and, where it applies, the GDPR):

  • Provide the Platform— create accounts, ingest and validate meter data, run billing and charge runs, generate invoices and allocations, manage prepaid wallets and vending, operate charging sessions, and display dashboards and reports. Basis: performance of a contract; our and the Organisation's legitimate interests; the Organisation's instructions where we act as processor.
  • Process payments and remittances — collect End User payments as a disclosed agent, remit funds to Organisations, calculate commission and platform fees, and reconcile accounts. Basis: performance of a contract; legal obligation; legitimate interests.
  • Accounting synchronisation— where enabled by an Organisation, sync accounts, invoices, and payments to its accounting system. Basis: the Organisation's instructions; legitimate interests.
  • Security and fraud prevention — authenticate users, enforce tenant isolation, monitor for abuse, and keep audit trails. Basis: legitimate interests; legal obligation.
  • Support and communication — respond to queries, send service and transactional messages, and notify you of changes. Basis: performance of a contract; legitimate interests.
  • Improve and develop the Platform — analyse usage, debug, and build new features, including using aggregated and de-identified data. Basis: legitimate interests.
  • Legal and regulatory compliance — meet tax, accounting, metering, consumer protection, and record-keeping obligations, and respond to lawful requests. Basis: legal obligation.
  • Marketing — send Organisation and prospect contacts relevant updates, where permitted; you can opt out at any time. Basis: consent or legitimate interests.

6. Automated calculations

Bills, charges, allocations, wallet drawdowns, and relay switching are produced automatically from metered or device-reported consumption and the tariffs and rules an Organisation configures. These calculations are deterministic and auditable, and the Organisation is responsible for the rules and for the final decision to issue or adjust any charge. If you believe a charge is wrong, you can query it with your Organisation, which can investigate, correct data, and generate a new charge run.

7. How we share information

We share personal information with:

  • The relevant Organisation— an End User's data is visible to the Organisation that manages that property, site, or charging network;
  • Sub-processors and service providers — cloud hosting and infrastructure providers, our payment processor, accounting integration providers (for example Xero) where an Organisation enables them, email and notification providers, logging and analytics providers, and customer support tools. They may process personal information only on our instructions and under confidentiality and data protection terms;
  • Professional advisers and authorities — auditors, lawyers, insurers, and regulators or law enforcement where required or permitted by law;
  • Corporate transactions — a buyer or successor in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

We do not sell personal information.

8. International transfers

We and our service providers may process personal information in countries other than yours. Where we transfer personal information across borders, we put appropriate safeguards in place as required by applicable law, such as transfer agreements based on standard contractual clauses or transfers to recipients bound by comparable protections. You can contact us for more detail on the safeguards used.

9. Retention

We keep personal information for as long as needed for the purposes above. Financial and billing records — including invoices, payments, charge runs, allocations, and audit trails — are kept as immutable records for the periods required by tax, accounting, and other laws (commonly at least five years, and sometimes longer). Account data is kept for the life of the account and a reasonable period afterwards. Logs and technical data are kept for shorter, rolling periods. When we no longer need personal information, we delete or de-identify it. Where Phy acts as processor, retention also follows the Organisation's instructions and any data processing agreement.

10. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege permissions, tenant isolation between Organisations, multi-factor authentication for privileged access, audit logging, backups, and regular review. No system is perfectly secure; if we become aware of a security compromise affecting your personal information we will notify you and the relevant authorities as required by law.

11. Your rights

Subject to applicable law, you may have the right to access, correct, update, or delete your personal information, to object to or restrict certain processing, to withdraw consent, to data portability, and to lodge a complaint with a supervisory authority.

  • If Phy is the responsible party / controller (for example website visitors and Organisation account users), contact us using the details in Section 14.
  • If your data is processed on behalf of an Organisation (most End User utility and charging data), please direct your request to that Organisation. If you contact us, we will forward your request to the relevant Organisation and assist them in responding.

We may need to verify your identity before acting on a request, and some information must be retained for legal or audit reasons even after a deletion request.

12. Cookies

We use cookies and similar technologies for authentication, security, preferences, and analytics. See our Cookie Policy for details and for how to manage your choices.

13. Children

The Platform is intended for businesses and adults. We do not knowingly collect personal information directly from children. If an Organisation includes household members who are minors in occupancy or billing records, the Organisation is responsible for having an appropriate lawful basis to do so.

14. Contact and complaints

For privacy questions or to exercise your rights, contact Phy Energy at info@phy.energy, or via our contact page. Please mark your message for the attention of the Information Officer.

If you are not satisfied with our response, you may complain to the Information Regulator (South Africa) or, if you are in the European Economic Area or the United Kingdom, to your local data protection authority.

15. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes we will give reasonable notice, for example by email or an in-Platform notice, and we will update the "Last updated" date above.