Privacy Policy
Last updated: 19 February 2026
C&T Group is committed to protecting your personal information. This policy explains what data we collect, why we collect it, and how we use it — in plain English.
1. Who We Are
C&T Group ("we", "us", "our") is the data controller for the personal information you provide to us. We are a domestic energy efficiency and retrofit company operating across Wales and South West England.
- Company: C&T Group
- Email: [email protected]
- Phone: 01792 44 66 46
- Website: www.ctgroup.wales
2. What Personal Data We Collect
We may collect the following types of personal data:
- Identity data: name, date of birth
- Contact data: email address, phone number, postal address
- Property data: address, postcode, property type, EPC rating
- Financial data: benefit status, household income (for grant eligibility purposes only)
- Health data: medical conditions relevant to heating needs (Route 3 LA Flex only, with explicit consent)
- Technical data: IP address, browser type, pages visited (via cookies)
- Communications data: messages sent via our website, chat, or email
3. How We Collect Your Data
- Directly from you — via our eligibility check form, phone calls, emails, or live chat
- From third parties — referrals from local authorities, utilities, or community organisations
- Automatically — via cookies and analytics tools when you visit our website
4. Why We Use Your Data (Legal Basis)
| Purpose | Legal Basis |
|---|---|
| Assess your eligibility for government-funded upgrades | Legitimate interests / Contract performance |
| Process and submit grant applications on your behalf | Contract performance / Legal obligation |
| Arrange and carry out installations | Contract performance |
| Send you updates about your project | Contract performance |
| Send marketing emails (if you opt in) | Consent |
| Comply with TrustMark, Ofgem, and PAS 2035 requirements | Legal obligation |
| Improve our website and services | Legitimate interests |
5. Who We Share Your Data With
We only share your data where necessary:
- Energy suppliers (e.g. E.ON, Scottish Power, Octopus) — to process ECO4 grant applications
- Local authorities — for LA Flex scheme eligibility verification
- TrustMark — for certification and compliance reporting
- Ofgem — as required by the ECO4 scheme rules
- Installation subcontractors — only the data they need to carry out your installation
- IT and software providers — who process data on our behalf under strict data processing agreements
We do not sell your personal data. We do not share it with third parties for their own marketing purposes.
6. How Long We Keep Your Data
- Customer records: 7 years after project completion (for audit and compliance purposes)
- Enquiry data (not converted): 12 months
- Marketing consent records: Until you withdraw consent
- Website analytics: 26 months
7. Your Rights
Under UK GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data (subject to legal obligations)
- Restriction — ask us to limit how we use your data
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests
- Withdraw consent — at any time, where processing is based on consent
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
You also have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
8. Cookies
Our website uses cookies to improve your experience. These include:
- Essential cookies — necessary for the website to function
- Analytics cookies — help us understand how visitors use our site (anonymised)
- Functional cookies — remember your preferences
You can control cookies through your browser settings. Disabling certain cookies may affect website functionality.
9. Data Security
We take data security seriously. We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. All staff with access to personal data receive data protection training.
10. Changes to This Policy
We may update this policy from time to time. The most current version will always be available on this page, with the date of last update shown at the top.
