What we collect
- Account data: work e-mail address, first and last name and, if you give them, company, position and promotional code; your preferred plan, the time you accepted the terms, e-mail confirmation status, interface language, trial and plan status and account events. A site you screened on the public page before registering is stored on your account as a pending claim until you keep it or start a new asset. Your password is stored only as a salted one-way hash.
- Workspace data: asset facts, files, evidence, engine inputs and outputs, comments, tasks, invitations and audit records.
- Collaboration data: expert proposals and evidence, counterparty RFI responses, submitted load profiles, submission notes, comments, and the security and expiry metadata needed to operate purpose-limited links. If a recipient contributes without creating an account, PV8 records the verified e-mail address, verification time and contributions for that single shared record.
- Counterparty contacts: the name, business e-mail address, role and organisation of people you add to your directory or send a request for information (RFI), with the messages sent and the replies received. PV8 can suggest business contacts from public sources, such as an organisation’s own website, OpenStreetMap, Google Places, GLEIF, PeeringDB and official authority pages; nothing is sent until you approve the recipient.
- Public registry data: names of plant operators, licence holders and facility owners from official registers of power plants, licences, permits and industrial facilities, used to identify and describe plants. A register can include a private individual where the official source publishes one. For Czech sites, PV8 also reads the Czech Telecommunication Office’s (ČTÚ) public broadband coverage data and the NetTest speed measurements published near the site, keeping only aggregate figures, not the client identifiers published with the measurements.
- Usage and device data: web-server access logs (IP address, browser, requested page and time), security and audit records, product events and error diagnostics.
- Billing data: Stripe customer and subscription identifiers, plan, billing interval, subscription status and payment events, and the billing e-mail address Stripe reports for payment notices. Stripe Checkout also collects your billing address and, if you give one, a VAT or other tax ID. You enter card details on Stripe’s checkout page; they never reach PV8. Before checkout, PV8 records your request that the service starts immediately (the wording version, the language it was shown in, the time and the plan) on your account, in the security audit log and on the Stripe payment record.
- Support data: messages you send to PV8 and the details of a portfolio enquiry.
Why we use it
We process data to create and secure accounts, provide engines and reports, maintain owner-controlled sharing, send the requests and notifications you initiate, operate billing, answer support requests, prevent misuse, improve reliability, understand how the product is used, comply with law and establish or defend legal claims. The applicable legal bases may include performance of a contract, legitimate interests, legal obligations and consent where required.
E-mails PV8 sends
PV8 sends service e-mails: e-mail confirmation, password reset, payment and billing notices, trial messages (for example a reminder when no first result follows within 24 hours, and reminders while a trial or the decision to keep a workspace is pending), notices about activity on records you share, and the invitations you send. Watch reminders and digests are sent only when Watch delivery is switched on, and each person can turn them off in their preferences.
When you send a request for information, PV8 e-mails the recipient you approved, copies you when your address is confirmed and directs replies to you; where reply filing is enabled, replies also reach a PV8 mailbox that files them in your Evidence Inbox. The e-mail tells the recipient where their address came from and links to this notice. A recipient can decline further requests through PV8; that choice applies to every PV8 workspace.
Contacts from public sources
This section gives the information required when personal data is not obtained from the person concerned (Art. 14 GDPR). To help a PV8 customer send a request for information about a specific project, PV8 may obtain the name, business e-mail address, role and organisation of a business contact from public sources such as the organisation’s own website, OpenStreetMap, Google Places, GLEIF, PeeringDB and official authority pages. The legal basis is the legitimate interest of PV8 and its customers in reaching the right business for that project (Art. 6(1)(f) GDPR). A request is sent only after the customer approves the recipient, and it says where the address came from. Such a contact is kept for 12 months if it is not used. You can object at any time by writing to pv8@pv8.ai, or decline further requests through the link in any request; that choice applies to every PV8 workspace, and PV8 then deletes your contact details, keeping only what is needed to honour the objection. You also have the other rights described below.
Demo, PV8 Concierge and AI features
Representative demos are illustrative and are not evidence about your asset. Ask PV8 / Concierge, where enabled for your organisation, uses OpenAI. When you explicitly submit the chat, PV8 sends the conversation and the displayed asset facts and latest engine summary needed for that task; document files are not automatically included. Contextual Ask actions prepare a question without sending it.
Decision-intelligence actions (evidence summary, decision brief, public-source research and bid comparison) also use OpenAI. They send text from the asset’s documents (up to 20 excerpts), or the results or bids you select; research uses OpenAI’s web search, and the result is saved to the asset.
Specialist AI agents use Anthropic: for example evidence extraction from an uploaded document, the IC paper, deal and design briefs, tender comparison, and turning pasted meeting minutes into a decision record. They may send the documents, asset summary (including its name and location) or text selected for the task, and return proposals for your review.
Translation also uses Anthropic. When you use the workspace in Czech, French or Italian, on-screen text that the reviewed catalogue does not cover is sent for translation, and reports for assets in Czechia, France and Italy are prepared in the local language by default. Report text is sent with its figures masked, and translations are cached on PV8’s servers separately for each workspace. A report downloaded through a share link uses PV8’s reviewed catalogue and translations already cached for that workspace; the download never starts a new AI call. If an Italian report cannot be completed that way, the link serves the PDF stored when the link was created or the English original, labelled as such. Reviewed public-page translations are served from static catalogues.
Some AI features are in preview. PV8 switches them on for individual workspaces; a workspace outside the preview does not see them. Only signed-in members of the workspace can use them: people holding a share or collaboration link and invited expert reviewers cannot, and nothing they open starts an AI call. The preview features in the next paragraphs use Anthropic. Like every AI feature used in a workspace, they are subject to the organisation AI switch described below and to a daily AI spending limit for each workspace. Once the limit is reached, PV8 starts no new AI request for that workspace until 00:00 UTC; a request already under way may finish.
Ask your model answers questions about one completed result. PV8 sends your question, the last three questions and answers of the same conversation, and that result’s figures, inputs, sensitivities and verdict, with the plant’s country, technical data and recorded prices; values you approved from a document are sent like any other input. It does not send the asset’s name or text quoted from documents. Each figure in an answer is checked against PV8’s model before it is shown, and sentences with figures PV8 cannot verify are removed. PV8 does not store your questions or the answers; the conversation is kept only in the open browser page.
Reading documents into the model: you can upload a contract, licence or other document so that PV8 proposes the model values it states. PV8 stores the file with the asset’s other files and sends its file name and the text of up to 60 readable pages to Anthropic, including any names or contact details they contain. PV8 keeps only each proposed value with the page and short quote (at most 400 characters) it rests on, and the document’s date, not the rest of the text; it runs no OCR, so scanned pages are not read. A value enters your model only when you approve it. Deleting the document removes the file and its open proposals; values you approved keep the document’s file name, page and quote they rest on, and approvals you later replace stay in the asset’s history. All of it is erased with the asset or the workspace.
A workspace owner (a member with the manager or admin role) can add an AI-written commentary to an investment memo. PV8 sends the same result data as for a question, not the asset’s name or text quoted from documents, and removes sentences with figures it cannot verify. PV8 stores each complete commentary for its workspace, result and language, keeps the newest 400 per workspace and erases them when their asset or the workspace is erased. Members then see it in memos of that result in that language; a memo shared through a link never includes it. Devil’s advocate cards, which compare the inputs of a result with published benchmarks, and regulatory-impact estimates, which work out what a published decision means for your plant, are produced by PV8’s own code and engines: no AI model writes or calculates them.
Requests for missing facts: a workspace owner can ask PV8 to draft a request to the counterparty who can supply facts the model lacks, such as a grid operator or a lender. On that click PV8 sends Anthropic the recipient’s role, the facts requested (name, unit, and the document and term that usually state them), the plant’s installed and inverter capacity, commissioning year and country, and the request’s language. The model’s current values for those facts are sent only if the owner chooses to include them. PV8 never sends the plant’s name, the owner or the workspace, the counterparty’s name or address, coordinates, financial results, rankings or verdicts, or document text. The owner reviews and edits the draft and sends it as a request for information, as described above.
PV8 keeps up to 200 drafts per workspace, without the recipient or the plant’s name. Drafts expire after 30 days and are erased with their asset or workspace; daily deletion of expired drafts requires the retention job to be enabled. The request’s thread keeps the form fields the owner approved and which facts were asked. An answer the owner approves is recorded on the asset with its value and unit, the respondent’s e-mail domain, the reviewer and the dates, and is erased with the asset. A file the counterparty attaches is read only when the owner chooses, as described for reading documents into the model.
To apply the daily limit and account for AI costs, PV8 keeps each workspace’s daily AI cost totals under a pseudonymised workspace identifier, and a usage log of the calls made by its AI agents and preview features with the time, feature, asset reference, model and token counts. Neither contains text from the calls; the usage log is kept as PV8’s record of AI costs. The security audit log also records each request to these features with your account and workspace, but not its text.
Anthropic and OpenAI process this content as PV8’s processors (sub-processors for customer content) under their business API terms, which state that API inputs and outputs are not used to train their models by default. PV8 switches off provider-side storage where the provider’s API offers that setting; OpenAI requests are sent with storage disabled. PV8 does not promise zero retention: providers may keep data for a limited period under their own terms. AI output can be incomplete or inaccurate. It is screening support, not advice, and you remain responsible for decisions based on it. Your organisation can ask PV8 to switch AI processing off: PV8 then sends nothing to any AI provider for that organisation, and reports use only PV8’s reviewed catalogue translations. Do not submit data to an AI action unless you are authorised to share it with these providers and your organisation permits it. Proposals require review: filling draft scenario inputs does not change accepted asset evidence, run an engine, save a result or send a message. Those actions remain separate and permission-controlled.
Who receives data
Authorised PV8 personnel can be notified of new registrations and can access account and workspace records where needed to operate, support and secure the service; actions taken through PV8’s administration interface are recorded in the audit journal. External experts and share-link recipients receive only the material the owner shares. A counterparty invited through an RFI receives only the purpose-limited request and context chosen by the owner. Its secure submission link expires after seven days by default. A response returns to the owner’s Evidence Inbox as pending material and does not change an asset or output until the owner approves it. We may disclose data where law requires it or in connection with a corporate transaction subject to appropriate safeguards.
PV8 uses these service providers:
- Hetzner Online: hosting of the application, database and uploaded files in a data centre in Nuremberg, Germany.
- Stripe: checkout, subscriptions, invoices and the billing portal.
- GoDaddy: e-mail for pv8.ai, sending PV8’s e-mails and receiving replies.
- Anthropic: specialist AI agents, translation and the AI preview features (Ask your model, reading documents into the model, memo commentary and requests for missing facts).
- OpenAI: Ask PV8 / Concierge and decision-intelligence actions.
- Google: maps loaded by your browser (on the public site screen only when you choose to show one), map images in reports, and place searches for counterparty suggestions.
- Off-site backup storage: encrypted copies of PV8’s backups are also kept off-site with a cloud storage provider; they are encrypted on PV8’s server before they leave it, and the provider cannot read them.
Weather, grid, market, cadastre and other public-data services that PV8 queries for site context receive coordinates or public queries, not your account details.
International transfers
PV8’s application, database and uploaded files are hosted in Germany. Some providers, including the provider that stores encrypted off-site backups, may process data outside your country. Where required, PV8 uses recognised transfer mechanisms and contractual safeguards.
Retention
PV8 keeps personal data for the following periods:
- Account and profile: while the account is active; erased within 30 days after the account is deleted.
- Workspace assets, analyses and uploaded files: while the workspace exists; erased within 30 days after the workspace is erased.
- Documents uploaded for AI reading: until you delete the document, its asset or the workspace. Of the text PV8 reads from them, it keeps only each proposed value with the page and short quote it rests on, and the document’s date; for values you approved, these stay with the asset, with the document’s file name, until the asset is deleted.
- Cached machine translations: until the workspace is erased. AI-written memo commentary: until its asset or the workspace is erased; PV8 keeps at most the newest 400 per workspace.
- Drafted requests for missing facts: up to 200 per workspace. Drafts expire after 30 days and are erased with their asset or workspace; daily deletion of expired drafts requires the retention job to be enabled.
- Sign-ups whose e-mail address is never confirmed: 30 days, unless the account shows any sign of use, such as a sign-in, a plan or an asset.
- Free accounts left unused: PV8 sends a notice to the account e-mail address after 12 months without a sign-in and deletes the account 24 months after the notice; signing in cancels it. Members of paying workspaces are never deleted this way.
- Invoices, payment and billing records: 10 years from 1 January of the year after they were created, as the Bulgarian Accountancy Act requires.
- Checkout consent records (wording version, language and time): kept with the Stripe payment record for the billing-records period, even after the account is erased; the copy on your account is erased with the account.
- Security and audit logs: 12 months.
- Web-server access logs: rolled daily and deleted after 28 days.
- Pseudonymised product analytics: 13 months.
- Daily AI cost and what-if counters, kept under a pseudonymised workspace identifier: the current day and the two most recent earlier days with AI use.
- Share and collaboration links: until they expire or the owner deletes them; a daily clean-up then removes them and the files kept for them.
- Requests for information and their replies: while the asset exists; deleted with the account.
- Business contacts suggested from public sources: 12 months if unused; deleted immediately when the person objects, keeping only what is needed to honour the objection.
- Backups: kept off-site for a rolling 30 days and on PV8’s server for 14 days.
- AI usage log (time, feature, asset reference, model and token counts of each call made by PV8’s AI agents and preview features; no text): 13 months. Erasing an asset or the workspace replaces its asset references with a fixed placeholder; the cost records stay.
Other periods set in the service: e-mail confirmation links expire after 7 days, password-reset links after 1 hour, set-password links for new reviewer accounts after 24 hours and shared-record verification links after 30 minutes. Sign-in sessions end after 8 hours, or after 60 minutes with enterprise single sign-on. Share, collaborative-run and expert links last 7 days unless the owner chooses between 1 and 365 days, and RFI submission links last 7 days. Where the law requires a longer period, or a record is needed to establish or defend a legal claim, PV8 keeps it for that period.
Security
PV8 uses organisational and technical measures proportionate to the service, including tenant-scoped authorisation, protected password storage, secure session cookies, signed purpose-limited submission links, access expiry, upload checks and audit records. No internet service can promise absolute security. See the Security page for the current product controls.
Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent without affecting earlier processing. You may also complain to the competent data-protection authority. Workspace administrators can manage asset records, invitations and links directly.
In account settings you can download your data as a JSON file (your account record, assets, counterparty contacts, request history and billing record; document files are downloaded from each asset) and delete your account; deletion requires your password. Deleting your account removes only your own login, membership, password and pending password-reset, set-password and e-mail confirmation links; the workspace and its data stay with its other members. Only a workspace owner (a member with the manager or admin role) can erase the whole workspace while other members use it, by confirming its ID. If you are the only owner and other members remain, PV8 refuses to delete just your account: first ask PV8 at pv8@pv8.ai to make another member an owner, or erase the workspace. The last member, whatever their role, must erase the workspace to delete their account.
Erasing the workspace erases, within 30 days, its assets (including collaboration copies), analyses, uploaded files, contacts, requests for information, every member account (disabled ones too), reviewer accounts, cached translations, AI-written memo commentary and drafted requests for missing facts. It cancels any active Stripe subscription at once and removes stored payment cards, and a payment event that reaches PV8 afterwards cancels billing rather than restarting it. Stripe’s customer record, invoices and payments, and PV8’s reference to them without personal details, are kept for accounting as the law requires. Deletion does not remove the list of addresses that declined requests through PV8 (kept so that their choice is honoured), pseudonymised entries in the security audit log, which follow the audit-log period, or the AI usage log, which holds no text; copies in backups expire with the backup periods above. You can also ask PV8 to erase your data at the contact below, subject to legal retention duties.
Cookies and local storage
PV8 sets only first-party cookies: the signed sign-in cookie pv8_session (HTTP-only, secure, same-site), which ends after 8 hours (60 minutes with enterprise single sign-on) or when you sign out; a short sign-out marker; and, for a shared record, cookies that last no longer than that link. Local and session storage in your browser keep interface preferences such as language and layout, recoverable drafts, onboarding progress, a site you chose on the public page before registering, and your choice to show the Google map on the public page (session storage, until the tab closes).
Pages send PV8 a limited set of first-party product events: actions on the landing page, the type of site input, screening status, account creation, opening a result, report downloads and feedback. They use a random browser journey identifier kept in local storage, a per-tab session identifier and, once you are signed in, a pseudonymised account reference. PV8 accepts only fixed event names and bounded labels; these events do not include coordinates, addresses, Google links, asset identifiers, result values, files or free-text workspace content. After you allow marketing measurement, PV8 may also attach campaign tags, the referring website’s host and LinkedIn’s campaign identifier.
PV8 draws its pages in fonts already installed on your device; it loads no web fonts from Google or anyone else. The public site screen loads no Google map until you click “Show map”. Only then does your browser contact Google Maps, and Google receives your IP address and the map location. PV8 remembers that choice in your browser’s session storage until you close the tab. In the signed-in workspace, maps are part of the service: Google Maps loads when a map is shown, and Google receives your IP address and the map area. Workspace map layers you turn on are loaded directly from official map services, such as national cadastre and environmental agencies, which receive your IP address and the map area. The Italian edition’s broadband evidence shows AGCOM’s licence image, loaded from agcom.it.
LinkedIn campaign measurement is not active on pv8.ai. If PV8 enables it, the LinkedIn Insight Tag and campaign attribution will load only on public pages, only after you choose “Allow LinkedIn measurement”, and never inside the authenticated workspace; a Global Privacy Control signal counts as a refusal.
Language
This notice is written in English; a translation shown on a market edition is provided for convenience only and the English text governs.
Contact
Controller: Sator Energy EOOD (Сейтор Енерджи ЕООД), a single-member limited liability company registered in Bulgaria, UIC/ЕИК 202053205, VAT BG202053205, 15 Aleko Konstantinov St., Poduyane, 1505 Sofia, Bulgaria. Contact: +420 771 242 881, pv8@pv8.ai.
Use this address for privacy questions, rights requests, support and security reports.