This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Carbonorm (“Processor”) and the customer (“Controller”). It sets out the parties’ obligations when Processor handles personal data on Controller’s behalf, in accordance with Article 28 of the GDPR.
The Controller determines the purposes and means of processing personal data uploaded to the Service. The Processor processes that data only on the Controller’s documented instructions, which include the parties’ use of the Service in accordance with the Terms and this DPA.
Subject matter: hosting and processing of packaging compliance data, including supplier contact data, to deliver the Service.
Duration: the term of the Controller’s subscription, plus the retention windows in Section 7.
Nature & purpose: ingestion, storage, transformation, rendering as PDF, transmission of magic-link emails initiated by Controller.
Data subjects: Controller employees, Controller suppliers, and end-users of Controller products to the extent identified in uploaded data.
Categories of data: names, work emails, organisational role, packaging-specification metadata. Special categories (Art. 9 GDPR) should not be uploaded.
Processor shall: (a) process personal data only on documented instructions; (b) ensure persons authorised to process are bound by confidentiality; (c) implement appropriate technical & organisational measures (see Annex I); (d) assist Controller in fulfilling data-subject requests (Art. 12–22 GDPR); (e) notify Controller of personal data breaches without undue delay, and in any event within [TODO: e.g. 72 hours] of becoming aware; (f) make available information necessary to demonstrate compliance with this DPA; (g) on Controller’s instruction, delete or return personal data at end of term.
Controller authorises the use of sub-processors listed in Annex II. Processor will provide at least [TODO] days’ advance notice of new sub-processors and gives Controller the right to object on reasonable grounds. Processor remains liable for the acts and omissions of its sub-processors as if they were its own.
Where a sub-processor processes personal data outside the EEA, transfers are governed by EU Standard Contractual Clauses (Commission Decision 2021/914) plus such supplementary measures as may be required. [TODO: lawyer to specify SCC modules used and Annex IV technical measures.]
Processor maintains appropriate measures including: encryption in transit (TLS 1.2+) and at rest, role-based access control, audit logging, vulnerability scanning, vendor security review, and least-privilege production access.[TODO: lawyer + security to finalise Annex I before signature].
During the term, personal data are retained as needed to operate the Service. On termination, Controller may export data for [TODO] days; after that period Processor will delete all personal data, except where retention is required by EU or member-state law.
As of 2026-05-13, Processor uses the following sub-processors: