KarbonKit

Privacy and security

Last updated 5 September 2026

A KarbonKit widget sets no cookies and does no tracking. It does not know who your visitor is, and neither do we. A visitor can use every widget – calculator, installer finder, grant finder, boiler escape plan, AR, sound, house tour – without giving us anything that identifies them.

Three features ask for an email address: the boiler escape plan, the "get a quote" step of the calculator, and the enquiry form that an embedding organisation can switch on. All are opt-in, all require an explicit tick, and none of them happens unless the visitor chooses it.

Who we are

KarbonKit is built and run by Michael Fell, a researcher at University College London. For the data described on this page, KarbonKit is the data controller. Contact: hello@karbonkit.com.

KarbonKit is a working product not a UCL research project, and data collected through the widgets is not used as research data.

Cookies and tracking

The widget sets no cookies. It stores nothing in your visitor's browser, it contains no advertising or analytics trackers, no pixels, no fingerprinting, and no third-party scripts. There is nothing here that needs a cookie banner on your site.

The embed loader is a single small script that mounts a sandboxed iframe and stops. It makes no network request of its own, so nothing about your page is reported back to us.

KarbonKit's own marketing site uses one browser storage entry to remember UTM parameters within a single session, so we can tell which link brought a prospective embedder to us. It is not present on the widget.

What a widget collects

DataWhenWhyKept
Postcode, and optionally a house numberOnly if the visitor types oneTo look up the property’s EPC record and find nearby installersNot stored. Used for the lookup and discarded.
EPC property details (floor area, energy rating, wall and window type)Returned by the public EPC register after a postcode lookupTo size a heat pump or solar array for that specific homeNot stored.
Answers to the widget’s own questions (boiler age, radiators, insulation and so on)As the visitor answers themTo produce the estimate on screenHeld in the browser. Only sent to us if the visitor asks for an emailed plan or a quote.
Load and interaction countsEvery widget view, unless the embedder turns analytics offSo the embedder can see whether their widget is being usedWidget id, event type, timestamp, browser user-agent, and a truncated IP.
Email addressOnly in the boiler escape plan, the quote request and the enquiry form, and only with an explicit tickTo send the plan, to pass the enquiry to installers the visitor chose, or to pass it to the organisation running the widgetBoiler escape plan: not kept – the plan is sent and the address is discarded. Quote request and enquiry: see below.
Name, and phone number if asked forOnly in the quote request and the enquiry form, and only with an explicit tickSo the organisation the visitor asked to hear from can get back to themSee below. The enquiry form only exists on widgets whose owner has switched it on.

On the IP address. We record a truncated one against usage events: the last part is removed before it is stored, so 203.0.113.47 is kept as 203.0.113.0. That is enough to spot abuse and see roughly which region a widget is used in, and not enough to pick out a household. We do not hold the full address at any point after the request is served.

The features that ask for an email address

Boiler escape plan. A visitor can have their plan emailed with calendar reminders attached. This needs a ticked consent box; there is no pre-ticked box and no way to reach it accidentally. The plan is emailed once, and then we do not keep the email address at all. It is used to send the message and discarded with the request. What we do keep is anonymous: boiler age, fuel, heat demand, readiness score, the outward half of the postcode – SG12, not SG12 9XY – and two flags recording that the box was ticked and that the message sent. We do not keep the full postcode, the address, or the EPC certificate reference. There is no column anywhere in that record that says who the visitor was. They are not added to any mailing list and are not emailed again.

Quote requests. If a visitor fills in the quote form and picks installers to contact, we hold their name, email, optionally phone and address, their postcode, and the calculator result they are asking about – and we pass it to the installers they selected. That forwarding is the thing being consented to. It does not happen any other way, and no installer receives anything about a visitor who did not choose them.

Enquiries. Some widgets carry a short "get in touch" form. It is off by default and only appears where the organisation running that widget has switched it on and named itself, so a visitor always knows who they are about to hear from before they tick the box. We hold the name, email, optionally a phone number, the postcode, anything typed into the message box, what they are hoping to achieve where the organisation chose to ask, and a summary of what the widget worked out – including a suggested next step worked out from the answers already given – and we send it straight to that organisation. From that point they hold the details and they are the ones who will make contact; our copy exists so a bounced email is not a lost enquiry and so the record can be looked up if someone asks. We store the exact wording that was consented to alongside it.

We never market to your visitors. KarbonKit does not send promotional email to people who use a widget on your site. The widget is your conversation with your audience, not ours.

Lawful basis

ProcessingBasis
Running the widget and calculating an estimateLegitimate interests – the visitor asked for the estimate
Usage counts with a truncated IPLegitimate interests – knowing whether an embedded tool works, with the identifying part removed
Emailing a boiler escape planConsent – an explicit tick, withdrawable at any time
Passing a quote request to chosen installersConsent – the visitor selects the installers
Passing an enquiry to the organisation running the widgetConsent – an explicit tick naming that organisation
Account data for people who sign up to embed widgetsContract

How long we keep things

Postcodes, addresses and EPC lookups used to produce an on-screen estimate are not stored at all – they exist for the length of the request.

Boiler escape plan records hold no email address and nothing else that identifies anyone, so there is no one for them to be about; the anonymous rows are kept for 24 months and then deleted anyway. Quote requests are kept for 24 months. Usage events are kept for 24 months. Enquiries are kept for 12 months – shorter, because they hold the most identifying set of details we handle and a year-old enquiry is no longer a live one. Account data is kept while the account is open and deleted within 30 days of closure.

Deletion is a scheduled monthly job. We can evidence the runs if your governance process needs that.

If you want something removed sooner – yours or, as an embedder, on behalf of one of your visitors – email us and we will do it.

Who else touches the data

We keep this list short on purpose. Everything below is in the UK or the EEA, or covered by the UK's adequacy and transfer arrangements. There are no advertising or analytics companies on it, because we use none.

ServiceWhat it doesWhat it sees
SupabaseDatabaseStored records – accounts, widget configuration, usage events, anonymous boiler plan records, quote submissions
RenderApplication and static site hostingTraffic in transit; standard server logs
ClerkSign-in for embedder accountsAccount holders only. Never loaded on a widget page, so it never sees your visitors.
postcodes.ioTurns a postcode into coordinatesThe postcode being searched
EPC Open Data (MHCLG)The public EPC registerThe postcode being searched
GOV.UK local authority lookupNames the council for a postcode, on grant finders whose owner has turned on the council linkThe postcode being searched
Email delivery (SMTP)Sends the boiler escape plan and quote notificationsThe recipient address and the message

We do not sell data, and we do not share it with anyone not listed here – with the single exception of installers a visitor has explicitly chosen to contact.

Security

  • Everything is served over HTTPS. Widgets run in a sandboxed iframe, so a widget cannot read or alter the page it is embedded in, and the host page cannot read the widget.
  • Database tables have row-level security enabled with no public grants. There is no browser-direct database access from anywhere in the product; the application server is the only path in.
  • Personal data is never written to application logs. Email addresses are excluded explicitly, not incidentally.
  • Each embed is issued a random configuration id. An embedder can restrict their widget to named domains. We are straight with you that this is a convenience control rather than a security boundary: some browsers do not tell an iframe which site it is on, and in that case the widget still loads.
  • API endpoints are rate limited, and the paid third-party lookups have hard daily caps.
  • Payment card details are never handled by KarbonKit and never touch our servers.

Your rights

Under UK GDPR you can ask us for a copy of your data, ask us to correct or delete it, object to processing, or withdraw consent. Email hello@karbonkit.com and we will respond within one month, usually much sooner.

Because most widget use is not linked to anyone's identity, we often hold nothing about a given visitor at all – and that includes the boiler escape plan, where the email address is discarded once the plan is sent, so there is nothing left to look up, hand over or delete. If you sent a quote request or an enquiry, tell us the email address you used and we can find it. For an enquiry, note that the organisation you sent it to holds their own copy – we will tell you who that was so you can ask them too.

If you are unhappy with how we have handled it you can complain to the Information Commissioner's Office at ico.org.uk.

If you are embedding a widget

This section is for the organisation putting a widget on its site – a council, a housing association, a community energy group, an installer – and is the part worth forwarding to a data protection officer.

  • Roles. For the widget's own processing, KarbonKit is a controller in its own right, not your processor: we decide what the calculator collects and why, and we are accountable for it. You do not need a processor agreement to embed a widget. Where you send us your own data – a curated installer list, your branding, your account details – we act on your instructions, and we will sign a data processing agreement covering that if your governance requires one.
  • Enquiry collection changes that. It is off unless you switch it on. If you do, you are asking visitors to hand you their contact details, and from the moment they arrive with you, you are the controller of them: your own privacy notice needs to cover contacting people who use the widget, and the lawful basis is the consent they gave to hear from you, named on the form. We hold our copy for 12 months so you can retrieve an enquiry a bounced email lost, and we will sign a processing agreement for that. We do not contact your visitors ourselves and we do not pass them to anyone else.
  • Cookie consent. The widget sets no cookies and stores nothing in the visitor's browser, so embedding one does not add anything to your cookie banner or your consent management platform.
  • DPIA. If your process requires a data protection impact assessment for a new digital tool, we will help fill it in. The material facts are on this page; ask us for anything else and we will answer specifically rather than pointing at a policy.
  • Analytics are yours to turn off. Usage counting can be disabled per widget in the configuration. With it off, nothing at all is recorded about visits to your widget.
  • Accessibility and estimates. Widgets present ranges and confidence bands, never quotes, and the installer directory is explicitly labelled as a public-records listing rather than a recommendation. That matters for a public-sector site and it is deliberate – see how we work.

Changes to this page

If we change what we collect, we will change this page and move the date at the top. Material changes affecting existing embedders will be emailed rather than only posted here.

Something here look wrong, or does your DPO need an answer this page doesn't give? Email hello@karbonkit.com. We would much rather answer a hard question now than have you discover the answer later.