BoxPowerBoxPower EASI

Data Privacy
Policy

Effective: March 30, 2026Last Updated: March 30, 2026
01

Introduction & Scope

BoxPower, Inc. ("BoxPower," "we," "us," or "our") provides the EASI platform — a comprehensive techno-economic modeling and EPC-ready pricing tool for microgrid design and system sizing. This Privacy Policy governs the collection, use, and protection of personal identifiers, energy-related data, and Critical Energy Infrastructure Information (CEII) within the EASI platform and associated services. BoxPower acts as a Trusted Curator, balancing the necessity of protecting national security grid assets with the industry requirement for data transparency to support economy-wide decarbonization. EASI is intended for users aged 13 and above. We do not knowingly collect information from children under 13, in compliance with COPPA.

02

Definitions & Data Roles

To ensure compliance with data protection frameworks, We follow US privacy laws (CCPA/CPRA) and apply GDPR principles where applicable to establish the following roles:

RoleDescription
Data ControllerBoxPower acts as a Controller for personal information related to account registration, professional credentials, and direct business/marketing interactions.
Data Processor / Sub-processorWhen Partners or Installers upload load profiles or facility information belonging to End-Consumers, BoxPower acts as a Processor. Data is handled strictly according to Customer instructions and Data Processing Agreements (DPAs).
End-ConsumersProperty owners or facility managers whose consumption data is modeled.
Partners/InstallersUtilities, developers, and EPC firms utilizing EASI for design and procurement.
03

Categories of Information Collected

We collect information that constitutes "Personal Information" under applicable law:

Account Identifiers: Legal names, professional titles, company affiliation, and contact info (email, phone, business address).

Technical & Authentication Data: Processed via secure identity providers, including IP addresses, MAC addresses, and credentials required for Multi-Factor Authentication (MFA) or Corporate Single Sign-On (SSO).

Project & Energy Data: Site coordinates, 8760 load profiles, raw meter data, and solar production data imported from third-party modeling software.

Usage & Behavioral Data: We track sub-hourly interval interactions and feature engagement to optimize platform performance and facilitate targeted marketing. Sensitive energy and infrastructure data (including CEII and load profiles) is never used for advertising or marketing purposes.

Financial Data: Billing information, transaction codes, and modeling inputs (NPV, IRR, and utility rate structures).

04

Purpose of Processing & Marketing Use

BoxPower processes data for the following legal and operational objectives:

Techno-Economic Optimization: Utilizing AI-driven profiling and the EASI engine to recommend optimal PV, BESS, and generator sizing.

Marketing & Advertising: We use contact details and usage data to provide tailored communications and measure the effectiveness of our marketing efforts. This includes the use of third-party advertising platforms such as LinkedIn. We may share hashed identifiers (such as obfuscated email addresses), device identifiers, and event data with these platforms. This allows us to perform conversion tracking, retargeting, and 'Matched Audience' campaigns. Sensitive energy and infrastructure data is never shared for these purposes.

Synthetic Data Generation: Leveraging "Smart Gap Fill" strategies to reconstruct incomplete load datasets using neighboring data patterns.

Procurement & Pricing: Matching optimization results to BoxPower hardware kits and contractual Bills of Materials (BOM).

Research & Grid Planning: Supporting coordinated decision-making for integrated grid planning and carbon pricing reporting.

06

Tracking Technologies (Including Non-Cookie Technologies)

The EASI platform uses modern tracking technologies to ensure functionality, security, and product improvement. These technologies may not rely on traditional browser cookies.

TechnologyFunctionality
NecessaryEssential for authentication, session management, and platform security
AuthenticationManaged via Auth0 using secure tokens and session mechanisms
Analytics (Pre-Login)We use Google Analytics on our public-facing website to understand traffic, page performance, and user engagement prior to account creation
Analytics (Post-Login)Within authenticated sessions, we use Mixpanel to collect pseudonymous product usage data for service improvement.
Marketing (LinkedIn)We use LinkedIn Insight Tag to collect information such as IP address, device and browser information, cookies, page interactions, and event data. This data is shared with LinkedIn Corporation to enable conversion tracking, audience insights, retargeting, and personalized advertising. Sensitive energy and infrastructure data is never shared for these purposes. EU/EEA users may be required to provide consent for tracking under GDPR before these technologies are used. Users can opt out or manage their settings at LinkedIn’s Ads Settings page: https://www.linkedin.com/psettings/advertising/
PreferenceStores user-defined settings such as custom utility rates and regional preferences.

We do not sell personal information. However, we may share limited data with analytics and advertising partners for business purposes, including campaign measurement and audience insights, which may be considered “sharing” under certain U.S. privacy laws (such as the California Consumer Privacy Act (CCPA/CPRA)).

07

Grid Data Privacy & Statistical Safeguards

Traditional masking is insufficient for energy data. We employ rigorous technical safeguards:

Differential Privacy (DP): We apply mathematical noise (Laplacian/Gaussian) to query results to ensure individual consumption records cannot be inferred. We implement a Privacy Budget to prevent joint privacy leakage across sessions.

Trusted Execution Environments (TEEs): For sensitive computing, we utilize hardware-based isolation (e.g., AWS Nitro Enclaves, Intel SGX) to protect data in use from system administrators.

Anonymized Sharing: Data shared with grid stakeholders or research laboratories (e.g., for carbon reporting) undergoes strict DP transformation to prevent re-identification.

08

Data Security & Residency

Our infrastructure is designed with enterprise-grade security standards:

Infrastructure: EASI is hosted in an AWS Virtual Private Cloud (VPC) with isolated Security Groups and ACLs.

Encryption: Data is encrypted in transit (TLS 1.2/1.3) and at rest (AES-256).

Compliance: We align with SOC 2 Type II standards to ensure operational integrity.

Residency: Data is primarily stored on AWS servers in the United States (US-East-1).

Data Breach: In the event of a data breach, BoxPower will notify affected users in accordance with applicable US state laws.

09

International Data Transfers

For data originating in the EEA, UK, or Switzerland, we utilize:

Standard Contractual Clauses (SCCs): To ensure a level of protection equivalent to the GDPR.

Data Privacy Framework (DPF): Adherence to the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF as overseen by the U.S. Department of Commerce.

10

User Rights (US & EU)

BoxPower respects the privacy rights of all users. For US users, we comply with CCPA/CPRA and applicable state privacy laws. EU users may exercise rights under GDPR where applicable. All users may exercise rights including access, correction, deletion, and opt-out of certain processing, subject to legal obligations.

Access & Portability: Request copies of your personal data in a machine-readable format.

Correction & Erasure: Request updates or deletion of your data where no legal retention requirement exists.

Opt-Out: California and Nevada residents may opt-out of the sale or sharing of personal information for cross-context behavioral advertising.

Non-Discrimination: Users will not be penalized for exercising their privacy rights.

To opt-out of LinkedIn tracking specifically, adjust your settings in your LinkedIn account or visit the LinkedIn Opt-Out page. BoxPower also honors Global Privacy Control (GPC) signals sent by your browser.

11

Contact Information

For inquiries or to exercise your privacy rights, please contact our Privacy Officer:

BoxPower, Inc.

Attn: Privacy Officer

12438 Loma Rica Drive, STE C

Grass Valley, CA 95945

info@boxpower.io →