Home Insights ⚡ Market Intelligence 📊 Analytics Reports 📁 Report Archive 📝 Blog ✦ X Articles ☀ Solar Potential Explorer Grid Intelligence 📡 Live Dashboard 🤖 Ask the Grid 🧭 Grid Compass 📅 Weekly Summary 📄 Grid Pulse Tools About Methodology Support Contact Contact Us
Legal

Privacy Statement

Last updated: 15 August 2026

1. Controller

Quasar Energy (sole trader, The Netherlands) is the data controller responsible for your personal data.

CompanyQuasar Energy
KVK98795589
BTWNL005354375B07
E-mailcontact@quasarenergy.nl
AddressBox C2228, Keurenplein 41
1069 CD Amsterdam
Nederland

2. Data We Collect and Why

2.1 Contact Form

When you send a message via our contact form we collect your name, email address, subject and message to handle and reply to your enquiry.

Legal basis — Art. 6(1)(f) GDPR: legitimate interest in communicating with prospective and existing clients.

2.2 Support Chat Widget

Some pages of this website offer a support chat widget. When you use it, the message you type and the history of your current chat session are sent to our chat backend hosted by Vercel and processed by Anthropic's Claude API to generate an answer. Conversations are processed transiently to answer your question: we do not store chat transcripts on our servers, we do not link them to an account or identity, and per Anthropic's API terms your messages are not used to train AI models. Do not enter personal or confidential information into the chat — it is intended for questions about European energy and this site.

Legal basis — Art. 6(1)(f) GDPR: legitimate interest in offering automated visitor support.

2.3 Solar Explorer Tool

If you type a city name in the Solar Explorer, it is sent to OpenStreetMap Nominatim (geocoding) via our server-side proxy. The resulting coordinates are forwarded to the PVGIS API (European Commission) to retrieve solar irradiance data. The city name relates to a geographic location, not to you personally, and is not stored by us.

2.4 Infrastructure (Cloudflare)

This website is hosted on Cloudflare Pages. Cloudflare processes your IP address and request metadata as our data processor to serve the site reliably and protect it against abuse (DDoS / WAF).

Legal basis — Art. 6(1)(f) GDPR: legitimate interest in operating a secure and available service.

2.5 Web Analytics (Cloudflare Web Analytics)

We use Cloudflare Web Analytics to collect aggregated, anonymous usage statistics such as page views, referrer URLs, browser type, device type and country. This service uses no cookies and does not collect or store IP addresses — your IP is used only transiently to derive your country and is then discarded. No data is linked to individual visitors.

Legal basis — Art. 6(1)(f) GDPR: legitimate interest in understanding aggregate site usage to improve our services.

2.6 Grid Compass Account (Authentication)

When you create a free Grid Compass account, Clerk (our authentication provider) collects your email address to manage passwordless sign-in and grant dashboard access. Community-join metadata (registered site origin, pending mention, and the community_bot grant) is stored in Clerk public metadata. Historical Stripe customer references may still be present on older accounts.

Legal basis — Art. 6(1)(b) GDPR: performance of a contract (providing Grid Compass access).

2.7 AI Grid Analyst & Intelligence Hub

If you use the AI Grid Analyst (community grant) or unlock Intelligence Hub insights (credits), the questions you ask and the parameters you select are processed by our backend hosted on Railway and sent to Anthropic's Claude API to generate the analysis. Chat conversations are not stored on our servers — the conversation history exists only in your browser session and is resent with each question. Per Anthropic's API terms, your questions are not used to train AI models. We do store usage metering data linked to your account: a monthly question counter for the AI Grid Analyst, your credit balance, and a ledger of historical credit purchases and unlocked insights, held in our Neon-hosted PostgreSQL database. Request metadata (timestamps, IP-based rate-limiting counters) is logged for security and abuse prevention.

Legal basis — Art. 6(1)(b) GDPR: performance of a contract; Art. 6(1)(f) GDPR for security logging.

2.8 Payments (Historical) & Future Donations

Stripe processed former AI Grid Analyst subscriptions and credit-pack purchases. Stripe acts as an independent data controller for payment data on its platform. We retain historical subscription status, Stripe customer references, and order records in Clerk metadata and our Neon-hosted database for bookkeeping. We do not collect new subscription payments.

When a voluntary donation path is opened on the support page, the payment provider (expected: Stripe) will process the donor’s payment details. We will store only what we need to acknowledge the gift and meet bookkeeping duties. A donation will not be linked as payment for the Grid Bot grant.

Legal basis — Art. 6(1)(c) GDPR for statutory bookkeeping of historical invoices; Art. 6(1)(b) for any remaining portal access; Art. 6(1)(a) or 6(1)(b) for a future donation you choose to make, as disclosed at that time.

3. Cookies and Local Storage

Strictly necessary (no consent required): We store one item in your browser's localStorage (qe_ad_consent) to remember your cookie preference. This does not require consent under Art. 5(3) ePrivacy Directive / Dutch Telecommunicatiewet Art. 11.7a. If you use Grid Compass, a short-lived session cookie (__session) is set by Clerk to authenticate your signed-in session. The Intelligence Hub additionally caches recently unlocked insights in your browser's localStorage so they can be shown again without a new request — this data stays on your device and is never transmitted to us.

Analytics (consent required): If you click "Accept Analytics" in our cookie banner, we enable Google Analytics 4 (GA4) via gtag.js. GA4 collects website usage data including page views, session duration, scroll depth, navigation paths, and referral sources. These cookies are set by Google (domain: google-analytics.com). We do not load Google Ads tags, advertising cookies, or remarketing pixels. We use Google Consent Mode v2 with region-specific defaults: for visitors in the EEA and United Kingdom, analytics storage is disabled by default until you consent; advertising-related consent signals remain denied at all times. For visitors outside these regions, analytics may be active from page load — you can opt out via the cookie banner at any time. If you decline, Google operates in cookieless mode without analytics cookies. You can change your choice at any time by clearing your browser's localStorage.

4. Third Parties and International Transfers

All transfers of personal data to the United States are covered by either the EU–US Data Privacy Framework or Standard Contractual Clauses (Commission Decision 2021/914).

Party Role Country Safeguard
Cloudflare, Inc.Hosting, WAF & Web Analytics (cookie-free, no personal data)USAEU–US Data Privacy Framework
Resend, Inc.Email delivery (contact form)USAStandard Contractual Clauses
SendGrid (Twilio)Transactional email (report delivery & service notifications)USAStandard Contractual Clauses
Stripe, Inc.Historical invoices; future voluntary donations when activatedUSA / IEEU–US DPF / SCCs
Railway Corp.Application hosting (AI Grid Analyst backend, grid data services & Grafana dashboards)USAStandard Contractual Clauses
Vercel, Inc.Support chat backend hosting (serverless proxy, no chat storage)USAEU–US Data Privacy Framework
Neon, Inc.Database hosting (PostgreSQL — account usage, credit ledger & order data)USAStandard Contractual Clauses
Clerk, Inc.Authentication & user management (Grid Compass)USAStandard Contractual Clauses
Anthropic, PBCAI processing (Claude API) — support chat, AI Grid Analyst, Intelligence Hub insights & archived report generationUSAStandard Contractual Clauses
Google LLCWebsite analytics only (Google Analytics 4 / gtag.js) — no Google Ads or advertising tags; EEA/UK: only when user consents; other regions: analytics may be active by default, opt-out via cookie bannerUSAEU–US Data Privacy Framework

5. Retention

Contact form messages

Kept in our email inbox until the enquiry is resolved; deleted within 2 years if no ongoing business relationship follows.

AI chat conversations

Messages you exchange with the support chat widget or the AI Grid Analyst are not stored on our servers. Conversation history exists only in your browser session and disappears when the session ends. Only usage metering (question counts, credit ledger) is retained — see the Grid Compass account entry below.

Order data from previously sold reports

Until July 2026 we sold AI-generated PDF reports (engineering calculations, market analytics, Grid Pulse). Email addresses and order inputs from those purchases were automatically anonymised 90 days after submission (email replaced with [anonymized], form data erased, PDF deleted); any VAT identification number provided was erased in the same process. The anonymised transaction skeleton (report type, payment status, timestamps) is retained for 7 years to satisfy Dutch bookkeeping obligations (Art. 52 AWR).

Payment records

Retained by Stripe in accordance with their policy and applicable financial regulations (typically 7 years).

Cloudflare access logs

Retained by Cloudflare for up to 72 hours per their standard policy.

Grid Compass account data

Your email address and subscription metadata are retained by Clerk for as long as your account exists. You can request account deletion at any time by emailing contact@quasarenergy.nl. Upon deletion, Clerk removes your data within 30 days. Your current credit balance is retained for as long as your account exists; AI Grid Analyst question counters and detailed intelligence usage history stored in our Neon database are anonymised on a rolling 90-day schedule.

6. Your Rights (Art. 15–22 GDPR / AVG)

You have the right to:

  • Access the personal data we hold about you (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure where data is no longer necessary (Art. 17)
  • Restriction of processing in certain circumstances (Art. 18)
  • Data portability where processing is contract-based (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)

To exercise any right, email contact@quasarenergy.nl. We will respond within 30 days (extendable to 90 days for complex requests, with notice).

7. Complaints

You have the right to lodge a complaint with the Dutch supervisory authority:

Autoriteit Persoonsgegevens

Postbus 93374, 2509 AJ Den Haag
www.autoriteitpersoonsgegevens.nl
Tel: 088 – 1805 250

8. Changes

We may update this Privacy Statement. The date at the top of this page reflects the most recent revision. Material changes will be announced via a notice on this website.