Data Processing Agreementdpa-v0.1 · last updated 2026-05-13

Data Processing Agreement

Effective 2026-05-13 · dpa-v0.1

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Carbonorm (“Processor”) and the customer (“Controller”). It sets out the parties’ obligations when Processor handles personal data on Controller’s behalf, in accordance with Article 28 of the GDPR.

1. Roles

The Controller determines the purposes and means of processing personal data uploaded to the Service. The Processor processes that data only on the Controller’s documented instructions, which include the parties’ use of the Service in accordance with the Terms and this DPA.

2. Scope of processing

Subject matter: hosting and processing of packaging compliance data, including supplier contact data, to deliver the Service.
Duration: the term of the Controller’s subscription, plus the retention windows in Section 7.
Nature & purpose: ingestion, storage, transformation, rendering as PDF, transmission of magic-link emails initiated by Controller.
Data subjects: Controller employees, Controller suppliers, and end-users of Controller products to the extent identified in uploaded data.
Categories of data: names, work emails, organisational role, packaging-specification metadata. Special categories (Art. 9 GDPR) should not be uploaded.

3. Processor obligations

Processor shall: (a) process personal data only on documented instructions; (b) ensure persons authorised to process are bound by confidentiality; (c) implement appropriate technical & organisational measures (see Annex I); (d) assist Controller in fulfilling data-subject requests (Art. 12–22 GDPR); (e) notify Controller of personal data breaches without undue delay, and in any event within [TODO: e.g. 72 hours] of becoming aware; (f) make available information necessary to demonstrate compliance with this DPA; (g) on Controller’s instruction, delete or return personal data at end of term.

4. Sub-processors

Controller authorises the use of sub-processors listed in Annex II. Processor will provide at least [TODO] days’ advance notice of new sub-processors and gives Controller the right to object on reasonable grounds. Processor remains liable for the acts and omissions of its sub-processors as if they were its own.

5. International transfers

Where a sub-processor processes personal data outside the EEA, transfers are governed by EU Standard Contractual Clauses (Commission Decision 2021/914) plus such supplementary measures as may be required. [TODO: lawyer to specify SCC modules used and Annex IV technical measures.]

6. Security measures (Annex I)

Processor maintains appropriate measures including: encryption in transit (TLS 1.2+) and at rest, role-based access control, audit logging, vulnerability scanning, vendor security review, and least-privilege production access.[TODO: lawyer + security to finalise Annex I before signature].

7. Retention & deletion

During the term, personal data are retained as needed to operate the Service. On termination, Controller may export data for [TODO] days; after that period Processor will delete all personal data, except where retention is required by EU or member-state law.

8. Sub-processor list (Annex II)

As of 2026-05-13, Processor uses the following sub-processors:

  • Supabase, Inc. — database, authentication, file storage. EU (Frankfurt).
  • Resend Inc. — transactional email. [TODO: region].
  • Vercel, Inc. — hosting and edge delivery.
  • [TODO] — analytics, if applicable.
Lawyer TODOKeep Annex II in sync with the Privacy Notice and the Sub-processor section above. Confirm SCC module(s) and Annex IV measures for each non-EEA processor.