Where is customer data hosted?
Where your data is hosted, who processes it and which subprocessors are involved is set out in the Security Brief, named and dated.
Volts separates customer access, limits sensitive actions through roles and approvals, and records supported platform events—so IT, operators and auditors can examine the controls before deployment.
Security & data
Each answer below is kept in step with your customer agreement, the privacy notice and how the product actually behaves.
Where your data is hosted, who processes it and which subprocessors are involved is set out in the Security Brief, named and dated.
Access is assigned by role and by site, so a user sees only the portfolios and buildings they have been given.
Sensitive actions run through the approval rules you configure, and execution can be stopped from the platform.
Volts records the actions taken in the platform - who did what, when, and what changed. The exact event coverage and retention are listed in the Security Brief.
Encryption, backup and restore practice is documented and dated in the Security Brief rather than summarised here.
A tenant user sees the consumption, charges and documents for their own unit, and nothing outside it.
Personal data collected on this website is governed by the Privacy Policy. Data processed for customers inside the platform is governed by the customer agreement and, where applicable, the Data Processing Agreement.
Read the Privacy PolicyFAQ
The hosting provider, the region and the current subprocessor list are named in the Security Brief. Request it and we will send the current version.
Administrators assign roles, and scope them to the organisation, portfolio or individual site. The permission matrix and default role settings are available in the Security Brief.
A tenant sees their own unit and the common information you choose to share. Confirm the final permissions during commissioning before inviting any tenant user.
Authentication options, including MFA and SSO, are listed in the Security Brief.
Execution depends on the permissions and workflow agreed for each point. You decide which actions need human approval and which, if any, may run autonomously.
The event coverage, retention period and export route are listed in the Security Brief.
Incident response, notification windows and restoration targets are set out in the Security Brief and in your contract.
Your readings are your data and can be exported. Contract-end retention and deletion are governed by the DPA.
Request the current security brief, subprocessor list and DPA, then bring your access, hosting and audit requirements into the first-site scope - not after commissioning.