Privacy Noticeprivacy-v0.1 · last updated 2026-05-13

Privacy Notice

Effective 2026-05-13 · privacy-v0.1

This Privacy Notice explains how Carbonorm processes personal data when you use the Carbonorm web application and related services (collectively, the “Service”). It applies to packaging managers, suppliers, and any other natural person whose data we receive through the Service.

1. Controller

The data controller under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) is [TODO: legal entity name + registered address]. You can reach our data protection contact at [TODO: privacy@yourdomain].

Lawyer TODOConfirm controller entity, registered address, and DPO contact. If no DPO is appointed, indicate that and state who handles privacy queries.

2. Categories of personal data we process

Account data — name, work email, organisation, role, authentication identifiers. Lawful basis: contract (GDPR Art. 6(1)(b)).
Usage data — pages viewed, features used, error logs, IP address, browser fingerprint (only when analytics cookies are accepted). Lawful basis: legitimate interest (Art. 6(1)(f)) for security & service improvement; consent (Art. 6(1)(a)) for optional analytics.
Supplier-portal data — emails of suppliers you invite, plus any response data they submit. You are the controller of supplier-side data; we act as processor on your behalf.

3. Why we process this data

(a) to provide PPWR-compliance tooling under our contract with your organisation; (b) to operate the supplier-data-request workflow you initiate; (c) to keep the Service secure and detect abuse; (d) to generate audit-grade artefacts (Declarations of Conformity, GM/CFO Approval Kit PDFs) you can present to authorities under PPWR Art. 11/12.

4. Recipients & subprocessors

We rely on the following sub-processors:

  • Supabase (database, authentication, file storage) — region: EU (Frankfurt, eu-central-1).
  • Resend (transactional email) — region: [TODO: confirm region].
  • Vercel (hosting & edge delivery).
  • [TODO: analytics provider, if any].
Lawyer TODOConfirm exact list of sub-processors, regions, and SCC arrangements. The supplier list should also appear in the DPA (Annex II).

5. International transfers

Where a sub-processor stores data outside the EEA, transfers occur under EU Standard Contractual Clauses (Commission Decision 2021/914) and applicable supplementary measures. [TODO: lawyer to detail which sub-processors trigger which transfer mechanism.]

6. Retention

Account and SKU data are retained for the term of your subscription plus [TODO: retention period — propose 12 months for compliance evidence]. Magic-link tokens expire after 14 days. Audit logs are retained for [TODO].

7. Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and objection (Art. 21). To exercise any right, contact [TODO: privacy@yourdomain]. You also have the right to lodge a complaint with your local supervisory authority.

8. Cookies

We use a small number of cookies for sign-in, session security, and (with your consent) anonymous product analytics. See the cookie banner shown on first visit to set or change your preferences.

9. Changes

We may update this Notice. We will signal material changes via the Service or by email at least [TODO: notice period] before they take effect.