GRIDREADYreadiness, evidenced

GridReady privacy notice

GridReady is an early-stage project run by Jan Rosetzky, ahead of incorporation. This notice explains what a screening records and why, in plain terms. Questions or removal requests go to privacy@gridready.eu.

Notice version 1.5, last updated 12 August 2026. It names the five companies that run parts of the service, is exact about the one case where a model provider receives a screening, and covers the waiting list you can join from our landing page. Version 1.5 adds the Certificate of Readiness, which a screening's twelve-month scrub deliberately leaves standing, and says who can read one. No company has been added, and no other retention or removal term has moved.

What we use your data for

We process the data behind a screening for three purposes: to run the screening you asked for, to build an honest benchmark of Dutch battery readiness over time, and to operate and secure the service. We do not use it for anything else.

What a screening records

When you screen a site we store the address you entered, the coordinates it resolves to, the municipality and grid operator, the technical inputs you gave (power, storage, direction), the role you picked if you gave one, and the full readiness result. We keep this to build an honest benchmark of Dutch battery readiness over time. The benchmark is how the score gets better.

A screening that fails is recorded too. If we cannot resolve the address you typed, or the screening breaks on our side, we store the address as you entered it together with the reason it failed. Knowing which addresses we cannot read is how we fix the gaps, and hiding those attempts would leave the benchmark flattering itself.

We also count how the portal page itself is used. We record that the page was opened, and a few in-page actions, such as which example site you opened, which tab you switched to, which button you pressed, and whether a deep dossier finished. If the page hits a script error we record the error message. Each of these carries the same per-visit id as a screening and nothing more. It is our own counting, on our own server, with no cookies and no third party involved, and we delete it after twelve months. The other pages on this portal, including this one, record nothing at all. They run one small script, and it does exactly one thing: it applies the light or dark setting you already chose, so the page you are reading matches the one you came from. It sends nothing anywhere. Our public landing page sits on a separate site and does two things worth naming: it carries a small block of descriptive markup that search engines read, and it remembers your light or dark preference in your own browser, in the same way this portal does. It counts nothing and sets no cookie. The one thing it sends is what you type into its waiting-list form, which goes to our application server when you press the button, and never before.

On what legal basis

Storing a screening record and using it to measure the benchmark rests on our legitimate interest in improving the service, weighed against your right to privacy. The record carries no name, no IP address and no browser details, and it is kept only as long as it is useful. Until the scrub described below runs, it does hold the address you typed and the exact coordinates, so we treat the whole record as personal data throughout. Where you choose to leave contact details, with feedback or on the waiting list, that rests on your consent, which you can withdraw at any time.

What we never store

We never store your name, your IP address, your browser details, or any tracking cookie on the public portal. We never store who owns the land. The only identifier attached to a screening is a short per-visit id that lets us count visits without knowing who you are. The two exceptions are the feedback form and the waiting list: if you tick the box and leave an email address, we store that address, and only then.

Who can see it

Five companies run parts of this service. This is who they are and what each one touches. The application, and the database your screening is stored in, run on Fly.io in its Amsterdam region. That database is continuously copied to Scaleway object storage, also in Amsterdam, so a failure cannot lose it. The landing page at www.gridready.eu is served by Cloudflare Pages, which therefore sees the connection when you open it. Migadu runs our email, so a message you send to any address at gridready.eu, and our reply to it, passes through and is stored on its servers. Anthropic supplies the model behind the reviewer tools described below.

Two of the five are United States companies. Cloudflare processes data under its customer data processing addendum, and Fly.io under a data processing agreement we have signed with them. Both incorporate the European Commission's standard contractual clauses, in the controller to processor form. Scaleway is French, and our contract for the model is with Anthropic Ireland Limited, an Irish company, so neither of those is a transfer out of the European Economic Area. Migadu is Swiss and keeps its mail servers in France. Switzerland has a European Commission adequacy decision, so email reaching it needs no separate safeguard.

Nobody else receives your data: GridReady runs no third-party analytics and no advertising trackers, and shares nothing with a data broker. If error monitoring is switched on we will only use a monitor hosted in the European Union, configured not to send personal data. No name, contact detail, IP address, browser detail or cookie is attached to a report. It does receive the text of the error itself, and an error caused by an address we could not read can carry that address in its text.

Scoring never uses a model. The score is computed by fixed rules on our own server, so running a screening does not send your address or your inputs to a model provider. The score chat is the exception, and it is worth being exact about it. When a signed-in GridReady reviewer opens a conversation about a dossier, that dossier goes to Anthropic, and it carries the address you typed, the coordinates, and any parcel identifiers. No visitor can trigger this, and it does not happen for every screening. It takes a reviewer opening a conversation about one specific site.

Automated decisions

The score is worked out automatically, by a fixed, versioned set of rules, not by a person reviewing your case. It is decision support, not a legal or financial decision about you: it carries no automatic consequence, and we do not use it for profiling. Read our how it works page for what the score does and does not claim.

How long we keep it

After twelve months we scrub the detail from older screenings. The exact address is deleted, the coordinates are truncated to the kilometre square they sit in, and the full dossier is removed. What is left is the benchmark signal, which includes the municipality and grid operator, that kilometre square, the technical inputs, the role and any declarations you gave, the per-visit id, and the scores. That is what the benchmark needs, and it no longer points at a single address.

You can choose to issue a Certificate of Readiness from a screening, which creates a link, and that certificate is not scrubbed at twelve months the way the screening behind it is. After the scrub it still shows its serial, the band, the score, the rubric version and the issue date, but no longer the site address or the dossier, and anyone holding the link can view it, so treat the link as the certificate itself.

What we store in your browser

The public portal sets no cookies. It keeps two small values in your browser's own storage, never sent anywhere but back to us: your colour mode preference (light or dark), under the key gr-mode, kept until you clear it or change browsers; and an anonymous, randomly generated per-visit id, under the key gr-vid, which exists only for that browser tab and disappears the moment you close it. Neither value can be used on its own to identify you.

Our landing page at www.gridready.eu keeps your colour mode preference too, under the same gr-mode key, and keeps nothing else at all: no cookies, no per-visit id, and it sends nothing anywhere unless you submit the waiting list form yourself. Browsers keep this storage separately for each web address, so that is its own copy rather than a shared one, and changing the setting on one leaves the other as it was. You can clear either from your browser settings at any time, and the page will simply follow your device's light or dark setting again.

Feedback and contact

If you leave feedback it is anonymous, unless you tick the box to share your email and ask us to get in touch. We store an email only when you have ticked that box. That email is the one thing we hold that identifies you directly. We keep it until you ask us to delete it, or until the public test ends, whichever comes first. The twelve-month scrub above does not reach it, so if you want it gone sooner, email us and we will remove it.

The waiting list

Our landing page has a waiting-list form. If you join, we store the email address you gave, the role and organisation if you added them, the version of the consent wording you agreed to, and when you joined. We use that to tell you when GridReady opens to new users, and about material changes on the way there, and for nothing else. When you join we send one confirmation email to that address, so you can see that it worked and how to come off the list. It goes through Migadu, which already runs our email and is named above. Joining again sends nothing further. The legal basis is your consent, which you can withdraw at any time. The list lives in the same database as everything else on this page, on Fly.io in Amsterdam, with its backups on Scaleway, also in Amsterdam. We keep the address until you ask to be removed or until the list has served its purpose. The twelve-month scrub above does not reach it, so one email to privacy@gridready.eu removes it.

Where it runs

The application, the database your screening is stored in, and its backups all run in the European Union, in Amsterdam. The mail servers are in France, also in the European Union. Two of the five companies operating all of this are United States companies, and one is Swiss, which is set out above under who can see it.

Your rights

Giving us this data is voluntary: you can use the service without a screening being stored only by not running one, and nothing about using the site is conditional on it. You have the right of access to what we hold about you, rectification of anything inaccurate, erasure, a restriction on how we use it, a right of objection to our use of it, and a right to portability, a copy in a machine-readable format. To use any of these rights, or to ask a question, email privacy@gridready.eu. If you are not satisfied with our answer, you can also lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch data protection authority.