Launch draft

Privacy information

This page records what is true for the current website prototype. OmniOrigin must approve the complete processing, retention and supplier details before production launch.

Status: not yet a final production privacy notice. The existing public OmniOrigin privacy page contains placeholders and should not be reused.

Who is responsible

OmniOrigin Limited, company number 16418695. Public contact: info@omniorigin.co.uk, 44 High Street, Stonehouse, GL10 2NA.

What this prototype does

The planning calculation itself runs in your browser. Its secure server hand-off is disabled until OmniOrigin approves and configures the production database and intake service. When enabled, choosing to continue stores only the allow-listed estimate inputs in encrypted form for no more than 30 minutes. A single-use random token carries those inputs to the separate smart energy check; the website does not put postcode, usage or site details in the continuation URL. Consumed payloads are erased immediately and expired records are removed automatically. A keyed, non-reversible hash of the request IP address is retained briefly to prevent abuse; it is not used for marketing or visitor profiling.

Campaign and partner links

A tagged website link may use only utm_source, utm_medium, utm_campaign and a short ref partner code. The browser normalises and keeps those codes only for the current tab session so the eventual enquiry can be attributed to its source. Names, email addresses, telephone numbers and customer identifiers must never be placed in these codes. Click identifiers such as gclid and fbclid, arbitrary query fields and invalid values are discarded. With the secure calculator hand-off, the approved codes travel inside the encrypted payload and the continuation URL contains only the one-use token. A direct fallback link may place only those non-personal campaign codes in the intake URL. This is not a visitor analytics profile and no third-party analytics is enabled by this prototype; OmniOrigin must approve the final consent and privacy treatment before launch.

Independent reviews

The safe fallback links directly to Trustpilot and Checkatrade and does not copy or paraphrase customer reviews. If OmniOrigin activates its official TrustBox or licensed Trustpilot API, the homepage may show recent public review text, public display name, rating and review date. The API cache is refreshed at least every 24 hours, stores only the current display set and is not used to profile reviewers. Without licensed access, no review text is copied into the website database.

Information you choose to send

If you email, telephone or use the future intake service, OmniOrigin may receive contact details, project information, energy usage, property or business details, uploaded bills or images, and correspondence. The purpose is to understand and respond to your enquiry, prepare requested services and manage any resulting customer relationship.

Before launch, OmniOrigin must confirm

  • The lawful basis used for each purpose, including any marketing.
  • Every processor and recipient, including hosting, email, CRM, AI and analytics providers.
  • Any international transfers and the safeguards used.
  • Retention periods for enquiries, customers, quotes, uploads and lead data.
  • How people exercise access, correction, deletion, restriction, objection and portability rights.
  • Cookie and analytics choices, if non-essential tools are enabled.

Your rights and concerns

For a privacy request, contact OmniOrigin at the email above. You may also raise a concern with the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint.