Privacy Policy
How we collect, use, and protect your personal data
Quick Summary
We only collect information necessary to assess your ECO4 eligibility and arrange boiler installations. Your data is kept secure, never sold to third parties, and you have full control over your information.
Who We Are
Free Boiler Scheme operates as an ECO4 scheme facilitator, helping UK residents access government-funded energy efficiency improvements. We work with approved installers and energy companies to deliver free boiler replacements and home insulation.
Contact Details:
Information We Collect
Personal Information
We collect only the minimum information necessary to assess your ECO4 eligibility and arrange installations:
- Contact Details: Name, address, phone number, email address
- Benefit Information: Confirmation of qualifying benefits (Universal Credit, Pension Credit, Income Support, etc.)
- Property Details: Property type, age, current heating system, energy efficiency rating
- Household Information: Number of occupants, vulnerable occupants, heating preferences
Technical Information
We automatically collect certain technical information when you visit our website:
- Website Usage: Pages visited, time spent, referring websites
- Device Information: Browser type, device type, IP address
- Location Data: General location for local service matching (postcode level only)
How We Use Your Information
Primary Purposes
Eligibility Assessment
- • Verify ECO4 qualification
- • Match with appropriate schemes
- • Calculate potential savings
- • Determine suitable improvements
Service Delivery
- • Arrange property surveys
- • Coordinate installations
- • Provide customer support
- • Process warranty claims
Communication
We use your contact information to:
- Confirm appointments and survey details
- Send application updates and confirmation emails
- Provide installation documentation and warranties
- Share important updates about your application
Marketing Communications
We may occasionally send information about additional energy-saving opportunities, but only if you explicitly opt-in. You can unsubscribe at any time using the link in our emails or by contacting us directly.
Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
Legitimate Interest
Processing your eligibility application and arranging ECO4 improvements serves our legitimate business interest in providing energy efficiency services.
Contract Performance
When you accept our services, we process your data to fulfill our contractual obligations to arrange surveys, installations, and ongoing support.
Legal Obligation
We may need to share certain information with government agencies and energy companies to comply with ECO4 scheme reporting requirements.
Consent
For marketing communications and non-essential data processing, we rely on your explicit consent, which you can withdraw at any time.
Who We Share Your Information With
We only share your information with trusted partners necessary to deliver ECO4 services:
Approved Installers
Gas Safe registered engineers and installation companies who perform the actual work at your property. They receive only information necessary for installation.
Energy Companies
Major UK energy suppliers who fund ECO4 installations. They require basic eligibility and property information to authorize funding.
Government Agencies
Ofgem and other regulatory bodies may receive anonymized data for ECO4 scheme monitoring and compliance reporting.
Service Providers
Technology providers who help us manage applications, send communications, and maintain our systems. All are bound by strict data protection agreements.
What We DON'T Do
- • We never sell your personal information
- • We don't share data with marketing companies
- • We don't use your information for unrelated purposes
- • We don't transfer data outside the UK without explicit consent
How We Protect Your Information
We implement comprehensive security measures to protect your personal data:
Technical Safeguards
- • SSL encryption for all data transmission
- • Secure servers with regular security updates
- • Firewall protection and intrusion detection
- • Regular security vulnerability assessments
Access Controls
- • Limited staff access on need-to-know basis
- • Multi-factor authentication for systems
- • Regular access reviews and updates
- • Secure password policies enforced
Physical Security
- • Secure data centers with 24/7 monitoring
- • Locked filing cabinets for paper records
- • Clean desk policy for all staff
- • Secure disposal of confidential waste
Staff Training
- • Regular data protection training
- • Confidentiality agreements for all staff
- • Clear data handling procedures
- • Regular compliance monitoring
Your Data Protection Rights
Under GDPR and UK data protection law, you have several important rights regarding your personal data:
Right to Access
Request a copy of all personal data we hold about you, including how it's being used.
Right to Rectification
Correct any inaccurate or incomplete personal information we hold about you.
Right to Erasure
Request deletion of your personal data (subject to legal retention requirements).
Right to Restrict Processing
Limit how we use your personal data while maintaining basic service functionality.
Right to Data Portability
Receive your personal data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for marketing purposes.
Right to Withdraw Consent
Withdraw consent for any processing that requires it, without affecting past processing.
Right to Complain
Lodge a complaint with the Information Commissioner's Office (ICO) about our data handling.
How Long We Keep Your Information
We only keep your personal data for as long as necessary to fulfill the purposes for which it was collected:
Application Data
Successful Applications: 7 years after installation completion (for warranty support and compliance requirements)
Unsuccessful Applications: 2 years after final decision (for appeals and regulatory reporting)
Marketing Data
3 years from last contact or until you opt-out, whichever is sooner. We regularly review and purge old marketing lists.
Website Analytics
13 months for technical data and website usage analytics. This helps us improve our website and services.
Cookies and Tracking
We use cookies and similar technologies to improve your experience on our website:
Essential Cookies
Required for basic website functionality. These cannot be disabled.
Analytics Cookies
Help us understand how visitors use our website to improve services.
Marketing Cookies
Track effectiveness of our advertising and provide relevant content.
You can control cookie preferences through your browser settings or our cookie consent banner. Disabling certain cookies may affect website functionality.
International Data Transfers
We primarily process and store your data within the United Kingdom. However, some of our service providers may process data in other countries:
Third Country Processing
Where data is processed outside the UK/EEA, we ensure adequate protection through:
- • European Commission adequacy decisions
- • Standard Contractual Clauses (SCCs)
- • Binding Corporate Rules where applicable
- • Additional security measures where necessary
Contact Us About Your Data
If you have questions about this privacy policy or want to exercise your data protection rights:
Contact Our Data Protection Team
We aim to respond to all data protection requests within 30 days.
Information Commissioner's Office
If you're not satisfied with our response, you can complain to the UK data protection regulator:
Information Commissioner's Office
Wycliffe House, Water Lane
Wilmslow, Cheshire SK9 5AF
Tel: 0303 123 1113
Website: ico.org.uk
Updates to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make significant changes, we will:
- Update the "last modified" date at the top of this page
- Notify you by email if you've provided contact details
- Display a notice on our website about the changes
- Request new consent where legally required
Current Version: This privacy policy was last updated on 30 December 2025. Please review it periodically to stay informed about how we protect your information.
ECO4 Scheme Data Requirements
The ECO4 government scheme has specific data collection and sharing requirements:
Government Reporting
Energy companies and scheme administrators must report certain information to government agencies for monitoring and compliance purposes. This includes:
- • Property energy efficiency improvements made
- • Geographical distribution of scheme benefits
- • Demographic information about beneficiaries (anonymized)
- • Environmental impact measurements
Your Benefit
This data sharing enables the government to monitor scheme effectiveness, ensure fair distribution of benefits, and plan future energy efficiency programs. All reporting uses anonymized or aggregated data that cannot identify you personally.
Related Legal Information: