Legal information

Raysly Privacy Notice

Version
1.0.1
Effective date
2026-10-01
Country
GLOBAL
Language
EN

Scope note. This notice covers the personal data Raysly processes as controller: our own partner (installer) account holders, their team members, business/billing contacts, website visitors and prospects, and people we contact through installer outreach. It does not cover the personal data a partner collects from its own storefront visitors, leads and customers — for that processing, the partner is the controller and Raysly acts only as its processor under the Raysly Data Processing Agreement. Each partner's own storefront has its own Privacy Notice (linked in its site footer or consent banner) which governs that processing; this notice does not replace it.

Key points

  • If you are a Raysly partner, a member of a partner's team, a billing or support contact, or someone we contact as part of installer outreach, this notice applies to you.
  • If you are a customer or lead of one of our partners' storefronts, this notice does not describe how your data is used — see that partner's own privacy notice, or ask us and we will refer you to the correct controller.
  • We are [COMPANY_NAME], a [COMPANY_LEGAL_FORM] registered in [COMPANY_COUNTRY] under [COMPANY_REGISTRATION], at [COMPANY_ADDRESS].
  • Contact us about privacy at [COMPANY_PRIVACY_EMAIL].
  • If Raysly is acquired, restructured or its business is transferred to another entity, we will tell you and you keep your rights — see "Change of controller" below.

1. Who we are

Raysly is operated by [COMPANY_NAME] ([COMPANY_LEGAL_FORM], registered under [COMPANY_REGISTRATION] in [COMPANY_COUNTRY], registered office [COMPANY_ADDRESS], VAT [COMPANY_VAT]). Directors: [COMPANY_DIRECTORS].

  • Privacy contact: [COMPANY_PRIVACY_EMAIL]
  • Data protection officer (if appointed): [COMPANY_DPO]
  • EU representative (Art. 27 GDPR, where we have no EU establishment): [COMPANY_EU_REPRESENTATIVE]
  • UK representative (Art. 27 UK GDPR, where we have no UK establishment): [COMPANY_UK_REPRESENTATIVE]
  • Lead supervisory authority: [SUPERVISORY_AUTHORITY]

The Luxa Energy Ltd entity-registry values for these tokens are recorded in DECISIONS.md section 9; the admin's Luxa entity record must be populated with them (and the DPO field either filled or, if none is appointed, stated as such) before this notice is published — this document itself stays tokenised.

2. Who this notice is for, and who it is not for

Raysly plays two different roles, and this notice only covers one of them.

As controller (this notice): we decide the purposes and means for the personal data of:

  • people who sign up for or hold a Raysly partner account, and their team members;
  • billing, support and other business contacts at partner companies;
  • visitors to raysly.com and our marketing pages;
  • prospective installers we research and contact through our outreach programme (see §4); and
  • people whose data we process for our own security, fraud-prevention, legal and accounting purposes.

As processor (see the DPA, not this notice): each partner is the controller for the personal data of its own storefront visitors, leads and customers — names, contact details, addresses, billing details, and any documents (including photo ID or property-title documents) a customer uploads to complete an order. We process that data only on the partner's documented instructions, as described in the Raysly Data Processing Agreement. If you are one of a partner's customers or leads and you want to know how your data is used, you should contact that partner directly using the contact details on their storefront; if you are unsure who your installer is, contact us at [COMPANY_PRIVACY_EMAIL] and we will help you find the right contact. For the partner's lead and order records we act only on the partner's instructions, so we will pass your request to the partner rather than decide it ourselves.

Two of these activities are ours as controller, not the partner's, and are covered by this notice rather than the DPA: (a) the shared end-customer login account (marketplace_customers), which is keyed by email across every storefront and Comparisun, and which the Business Terms of Service (Section 12) say end customers manage directly with us — see §3a below; and (b) our own platform-level analytics and error-monitoring telemetry (PostHog, Sentry, Vercel) that runs on storefronts for our own purposes (as distinct from any storefront analytics we run on a partner's behalf as its processor, which is addressed in the DPA) — see §3a below.

3. What we collect and why (as controller)

Who What we collect Why Legal basis
Partner sign-up Company name, contact name, email, phone, region, and (for OAuth sign-up) your Google/Apple account identifier. If you sign up through an outreach link, an attribution token linking you to that outreach campaign. Create and verify your account, review your application, communicate with you Contract (steps to enter one) / legitimate interest in vetting new partners
Company profile & KYC-adjacent data Legal name, registration number, VAT number, address, number of employees, years established/experience, website, and (where you connect a payment provider) information that provider collects directly for its own KYC checks Administer your account, verify your business, meet our own accounting and fraud-prevention duties Contract, legal obligation, legitimate interest
Team members Name, email, phone, job title, role Manage access and permissions on your account Contract, legitimate interest
Billing Billing contact details, plan, payment method status (card/mandate details are held by our payment providers, not by us), invoices, VAT status Charge subscription fees, issue invoices, handle refunds/dunning, meet tax obligations Contract, legal obligation
Support & communications Your messages to us, support tickets and attachments, call/SMS metadata where you use our communication tools Respond to you, operate the service Contract, legitimate interest
Login & security Login method (magic link, SMS OTP, passkey, TOTP, social login), IP address, device/user-agent, session identifiers Authenticate you, keep the account secure, investigate misuse Legitimate interest, legal obligation
Marketing (opt-in) Your marketing communication preference Send you product updates and marketing you asked for Consent
Website visitors Standard analytics and error-monitoring data — see the Cookie Policy Understand and improve raysly.com and the portal Consent (where required) / legitimate interest

We minimise this table to the services actually enabled for your account; not every partner uses every feature listed above.

3a. Two activities where we are controller even though they touch storefront visitors. (a) Shared end-customer login. If an end customer creates an account to interact with more than one storefront, or with both a storefront and Comparisun, we are the controller of that login account itself (email, authentication method, and which storefronts/orders it is linked to), because we decide how that shared identity works across surfaces; the individual lead, order and document records tied to a specific storefront remain the partner's, as its controller (Section 2). (b) Our own platform analytics and error monitoring on storefronts (PostHog, Sentry, Vercel) — where we run these for our own product-improvement and reliability purposes rather than on a partner's instructions, we are the controller, on a consent or legitimate-interest basis depending on the tool, as described in the storefront's own Cookie Policy; this is separate from any storefront analytics we run as a partner's processor under the DPA.

4. Installer outreach (prospecting)

We run an outreach programme to identify and contact installers who are not yet Raysly partners, using public sources such as business registers, mapping services (Google Maps, OpenStreetMap), industry directories (e.g. MCS, MECI, Swissolar) and public company websites.

  • What we collect: business name, business email/phone, website, approximate location, and — only where a public source names one — a named contact person (owner or similar).
  • Legal basis for collecting and storing prospect data: our legitimate interest (Art. 6(1)(f) GDPR) in identifying prospective business customers, balanced against the low sensitivity of business-context data and your right to object at any time.
  • Rules for sending outreach messages: the legal basis for holding your data does not by itself permit us to email or text you. Electronic-marketing law applies separately and differs by country:
    • Switzerland: we send outreach emails or SMS only with your prior consent. Swiss unfair-competition law (UWG Art. 3(1)(o)) requires prior consent for mass advertising by email or SMS, including to businesses, apart from a narrow exception for existing customers.
    • Germany and Austria: we send outreach emails only with your prior consent, because both countries require prior consent for email advertising, including to businesses.
    • United Kingdom: we email or text sole traders and unincorporated partnerships only with prior consent (PECR reg. 22); messages to corporate addresses always identify us and offer an opt-out (PECR reg. 23).
    • Other countries, including Cyprus: we follow local electronic-marketing rules; where these require consent for the recipient type, we obtain it first.
  • Telling you where your data came from: our first message to you identifies us, names the source of your contact details, links to this notice and tells you, clearly and separately from other information, that you can object to further contact at any time (Arts. 14 and 21(4) GDPR).
  • Your rights: every message includes a one-click unsubscribe. If you ask us not to contact you, we keep a suppression record (a hashed form of your email address) indefinitely so we do not contact you again — this is the minimum data needed to honour your objection.
  • Named individuals: where a source names an individual rather than a general business address, we still process only role-relevant, publicly available business contact information, and the same objection right applies.

5. Recipients

We share your data with:

  • Processors who help us run Raysly — hosting and database providers, email and SMS providers, our payment processors (for your subscription), customer-support tooling, and analytics/monitoring providers. See the Subprocessor Schedule for the current list used for our controller activities. The schedule has a separate table, "Vendors handling data for Raysly's own controller activities", listing the vendors used for this notice's processing.
  • Payment and accounting providers — Mollie, Stripe or Revolut process your subscription payments; where you connect Xero, QuickBooks or another accounting tool, your billing contact and invoice data is shared with that tool at your direction.
  • Other Raysly entities and successors — see "Change of controller" below.
  • Authorities and professional advisers where required by law, or to establish, exercise or defend legal claims.

We do not sell your personal data.

6. International transfers

We and our providers may process your data outside your country. Where this involves a transfer out of the EU/EEA, the UK or Switzerland to a country without an adequacy decision, we rely on Standard Contractual Clauses (for the EU/EEA), the UK International Data Transfer Addendum, or the Swiss Federal Data Protection and Information Commissioner's recognised equivalent, supplemented where necessary by additional safeguards.

If you are in Switzerland

Where we transfer your personal data outside Switzerland, we apply the same safeguards described above, adapted as required by the Swiss Federal Act on Data Protection (revFADP) — including the Swiss Federal Council's list of countries with adequate protection and, where relevant, the Swiss-specific addendum to Standard Contractual Clauses.

If you are in the UK

Transfers out of the UK rely on the UK International Data Transfer Agreement/Addendum or an applicable UK adequacy regulation.

7. Retention

We keep your personal data for as long as your account is active, plus:

  • After you close your partner account: closure is scheduled 30 days later ([ACCOUNT_DELETION_GRACE_DAYS]), during which it can be cancelled; closing your account stops your paid subscription as part of scheduling closure. After the 30 days, we delete or anonymise your account data and revoke connected integrations, except the items listed in the Business Terms of Service, Section 12 (accounting records, acceptance and erasure evidence, a suppression marker, backup rotation, and your end customers' data where you are its controller).
  • Financial and tax records: kept for [ACCOUNTING_RETENTION_YEARS] (currently 10) years in every country we operate in (one rule that meets the longest statutory period that applies to us, including Switzerland, Art. 958f CO), from the relevant tax point or the end of the financial year to which they relate.
  • Team-member records: anonymised after a 30-day grace period once you leave every partner account you belonged to.
  • Outreach suppression records: kept indefinitely, as the minimum data needed to make sure we do not contact you again after you object.
  • Records with no automatic deletion today: login-session records (IP address, device/user agent, approximate city and country), our log of emails sent to you (including the full message body) and security audit logs are currently kept without an automatic deletion schedule.
  • Backups: deleted data can remain in our database backups for up to about 6 months until the backup rotation overwrites it.

8. Your rights

Depending on where you are, you may have the right to: access your data; correct it; ask us to delete it; restrict or object to our processing; receive a portable copy; and withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Right to object. Where we rely on legitimate interests (for example for outreach, security and vetting new partners), you may object at any time on grounds relating to your particular situation, and you may object to direct marketing at any time without giving a reason, after which we will stop.

To exercise a right, contact us at [COMPANY_PRIVACY_EMAIL]. We may need to verify your identity before acting on a request — we will ask only for what is proportionate to do so.

Do you have to give us your data? The partner sign-up and billing data in §3 is needed to enter into and perform your contract with us; without it we cannot open or run your account. Marketing preferences are optional. We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects; new partner applications are reviewed by our staff.

Evidence of your acceptances. Where you or your team tick a checkbox to accept the Business Terms of Service, the Data Processing Agreement or the Acceptable Use Policy, we keep a tamper-evident record of that action: which version was accepted, a hash of the exact text shown, the date and time, and technical evidence such as a pseudonymised device/session reference, not your name or email directly. We keep this evidence for at least 10 years as proof of what was agreed; if your account is later deleted, we delete the personal link to the record but keep the evidence itself, which by then can no longer be tied to you (GDPR Art. 17(3)(e)).

You also have the right to complain to a supervisory authority. This will usually be the authority where you live, work, or where the issue arose:

  • General: [SUPERVISORY_AUTHORITY]
  • If you are in Switzerland: the Federal Data Protection and Information Commissioner (FDPIC).
  • If you are in the UK: the Information Commissioner's Office (ICO).

9. Change of controller / business transfer

Raysly's operating entity may change — for example if the business is sold, restructured, or transferred to an affiliate or successor entity (including a change from one group entity to another as our corporate structure evolves).

If this happens:

  • We (or the new operator) will tell you before or as soon as reasonably possible after the change, by email or an in-product notice, identifying the new controller, its contact details, and whether anything about how your data is used will change.
  • We will only transfer your data to a new controller where doing so is compatible with the purpose for which we originally collected it, or where we have a separate valid legal basis to do so.
  • Marketing consent and cookie consent do not automatically transfer. Where continued marketing communications or non-essential cookies would rely on your consent, the new controller will ask for a fresh consent under its own name before continuing that specific processing, rather than relying on a consent you gave to the previous entity's name.
  • You keep all the rights described in this notice against the new controller.

The founder has decided the interim operator for both Comparisun and Raysly is Luxa Energy Ltd (Cyprus), and the target is a single Swiss company ("Avitra") replacing Luxa everywhere at once (see 00-operating-entity-advice.md). This section is written to work under either state — no entity name is hard-coded.

10. Changes to this notice

We will post any changes to this notice here and update the effective date above. Where a change is material, we will give you more prominent notice (e.g. by email).

11. Contact us

[COMPANY_NAME] [COMPANY_ADDRESS] Privacy: [COMPANY_PRIVACY_EMAIL] General: [COMPANY_EMAIL]

Version history

  • Version 1.0.1 · 2026-10-01
  • Version 1.0.1 · 2026-10-01
  • Version 1.0.0 · 2026-10-01
© Raysly — the operating system for solar installers.
Terms of ServicePrivacy NoticeContactCookie NoticeLegal information
Raysly
FeaturesPricingNetworkSign inGet started