Utility Data Sync

Document 03 of 03

Privacy policy

What the app processes, what we store, who receives it, and how long we keep it.

Effective 2 September 2026 · Last updated 2 September 2026

This Privacy Policy explains how Nidish LLC ("we", "us", "our") collects, uses, discloses, and protects information in connection with the Utility Data Sync application (the "App") for HubSpot.

It applies to the customer that installs the App in its HubSpot account (the "Customer") and to the individuals whose contact records the Customer chooses to synchronise through the App ("Contacts").

For information the Customer processes in HubSpot itself, HubSpot's own privacy notices apply. For information processed in the connected utility-data provider account, that provider's privacy notice applies — see Third parties and sub-processors.

Roles

The Customer is the controller of its HubSpot Contact data and decides which Contacts to synchronise. We act as a processor / service provider on the Customer's instructions when the App transfers and returns Contact data. For our own operational records — the account, authentication, and log data described below — we act as a controller.

Information the App processes

2.1 Connection credentials, stored by us

When the Customer installs the App and connects a provider account, we store:

DataPurposeStorage
HubSpot OAuth access token and refresh token Authenticate API calls to the Customer's HubSpot account Encrypted at rest (AES-256-GCM) on our server
Utility-data provider API key and selected environment Authenticate API calls to the Customer's provider account Encrypted at rest (AES-256-GCM) on our server
HubSpot Account ID (Hub ID) Identify which connection a request belongs to Encrypted at rest with the above

2.2 Contact data, transferred but not retained by us

When the Customer opts a Contact in by setting the Sync to Utility Provider property, the App reads the following fields from that Contact in HubSpot and sends them to the connected utility-data provider to create or update a customer record:

  • First name, last name
  • Email address
  • Phone number
  • Street address, city, state or region, ZIP or postal code
  • Utility provider name
  • The HubSpot Contact ID, used as an external reference

The App then reads the following back from the provider and writes it into custom properties on the same HubSpot Contact:

  • Provider customer ID and status
  • Onboarding link and onboarding token
  • Utility account number, meter ID, meter type, tariff, and additional meter attributes
  • Billing data: billing date, outstanding balance, electricity and gas consumption and amounts, delivery and supply charges, community-solar bill credit, total amount
  • Links to recent bill files
  • The provider's full raw response for the customer, stored for troubleshooting

We do not maintain our own separate database of Contact data. Contact data passes through our server in transit and is written into HubSpot and the provider account, which are the systems of record.

2.3 Operational logs

Our server writes application logs for reliability and troubleshooting. These logs may include HubSpot Account IDs, HubSpot Contact IDs, Contact email addresses, and error messages. Authentication tokens and the provider API key are redacted from logs. Logs are retained for 30 days and then deleted.

2.4 Webhook and request metadata

HubSpot sends the App signed webhook and request metadata, for example the HubSpot Account ID, user ID, and the changed property. We use this only to determine which Contact to synchronise and to verify the request is genuinely from HubSpot.

How we use information

We use the information above only to:

  • authenticate and make API calls to the Customer's HubSpot and provider accounts;
  • create and update customer records in the provider account for opted-in Contacts;
  • retrieve onboarding and billing data from the provider and write it back to the corresponding HubSpot Contact;
  • operate, secure, monitor, and troubleshoot the App.

We do not sell personal information, share it for cross-context behavioural advertising, or use it to train machine-learning models. We do not use Contact data for any purpose other than providing the App to the Customer.

Legal bases, where GDPR or UK GDPR applies

Where we act as a processor, the Customer is responsible for establishing a legal basis for the processing it instructs. Where we act as a controller — sections 2.1, 2.3 and 2.4 — we rely on our legitimate interests in operating and securing the App, and on performing our contract with the Customer.

Third parties and sub-processors

RecipientRoleData
Bayou Energy, Inc. The utility-data service the Customer connects. Receives Contact data to create utility customers and returns utility and billing data. The Contact identity and address fields listed in section 2.2
Hosting provider — confirm Hosts our server infrastructure All data in section 2, encrypted at rest
HubSpot, Inc. The platform the App integrates with; source and destination of Contact data Data the Customer stores in HubSpot

We do not disclose personal information to any other third party except as required by law, to enforce our terms, or to protect the rights, property, or safety of any person.

The utility-data provider processes Contact data under its own agreement with the Customer and its own privacy notice: Provider privacy policy URL — confirm.

International transfers

Our infrastructure is located in Infrastructure region — confirm. The utility-data provider processes data in Provider region — confirm. Where personal data is transferred out of the EEA, the UK, or other regulated regions, the transfer is covered by Transfer mechanism — confirm.

Retention

  • Connection credentials (2.1) are retained for as long as the App is installed. When the Customer disconnects the provider connection, the provider API key is deleted. When the Customer uninstalls the App, HubSpot revokes the OAuth tokens and we delete the stored connection record within 30 days.
  • Operational logs (2.3) are retained for 30 days.
  • Contact data written into HubSpot properties or the provider account persists in those systems and is controlled by the Customer and the provider, not by us.

Data subject and privacy deletion requests

Because we act as a processor for Contact data, individuals should direct access, correction, deletion, portability, and objection requests to the Customer — the HubSpot account owner.

When a Contact is deleted in HubSpot, including via a HubSpot GDPR or privacy deletion, HubSpot notifies the App and the App stops synchronising that Contact. Data already written to the provider account is governed by the Customer's agreement with the provider; the Customer should contact the provider to have it removed.

The Customer can also stop all processing at any time by disconnecting or uninstalling the App. See the setup guide.

Security

  • All connection credentials are encrypted at rest (AES-256-GCM) and transmitted over TLS.
  • All requests from HubSpot are cryptographically signature-verified before they are processed.
  • Access to production infrastructure is limited to authorised personnel.
  • We keep backups of the encrypted credential store to prevent data loss.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children

The App is a business tool and is not directed to children. We do not knowingly process the personal information of children.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date and, where required, communicated to the Customer.

Contact

Questions about this Privacy Policy or our data practices:

EntityNidish LLC
Emailprivacy@nidish.com
Postal addressPostal address — confirm