This Data Processing Agreement ("DPA") is incorporated into, and forms part of, the Terms of Service between Carbon Sorted ("we", "us", "Processor") and you, the customer ("Controller"). It applies wherever we process personal data on your behalf in connection with the Carbon Sorted service. Terms not defined here have the meaning given in UK GDPR (UK General Data Protection Regulation, as retained in UK law by the Data Protection Act 2018).
1. Roles
You are the Controller of the personal data you submit to the Service. We act as your Processor in respect of that data, processing it only on your documented instructions (which include use of the Service as described in the Terms of Service). Where we process data for our own purposes (e.g. billing, security, legal obligations), we act as an independent Controller.
2. Categories of personal data processed
- Account data, name, work email address, hashed password, optional organisation name.
- Company profile data, legal name, trading name, sector, employee count, turnover band, Companies House / charity registration number (if provided), net-zero target year, signatory name and job title.
- Activity and emissions data, energy consumption, fuel use, travel figures, waste volumes, and any other data entered for the purposes of producing a Carbon Reduction Plan. This data relates to business activities and will not ordinarily constitute personal data, but may do so if it is capable of identifying an individual (e.g. named signatory's travel record).
- Generated documents, the Carbon Reduction Plan narrative, compliance scores, version history, and associated provenance records.
- Usage and technical data, IP addresses, browser/device information, session logs, API call timestamps, and error traces captured for security and debugging.
- Billing data, name and email as passed to Stripe; we do not store card numbers (see sub-processors).
- Voice / brand-sample data (optional), any writing samples or tone-preference data you upload to configure the brand-voice feature. These may contain personal data if the samples include named individuals' writing.
3. Purposes of processing
- Providing the Carbon Sorted service: generating, storing, versioning, and exporting Carbon Reduction Plans.
- Operating the compliance engine, provenance log, and AI-use statement.
- Facilitating payment and subscription management.
- Sending transactional emails (magic links, plan-ready notifications, deadline reminders).
- Security, fraud prevention, and debugging.
- Complying with legal and regulatory obligations.
4. Legal basis
As Processor, we do not determine the legal basis for processing, that is your responsibility as Controller. You confirm that you have a lawful basis under UK GDPR for supplying any personal data to the Service.
5. Sub-processors
We use the following sub-processors to deliver the Service. By accepting this DPA you grant general authorisation to engage these sub-processors. We will give at least 30 days' notice of any new sub-processor via email and by updating this page, giving you the right to object.
| Sub-processor | Purpose | Data location | Privacy reference |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database storage (RDS), file storage (S3), email sending (SES), Redis cache (ElastiCache) | EU-West-2 (London) | aws.amazon.com/privacy |
| Stripe, Inc. | Payment processing, subscription management, invoicing | US / EU (Standard Contractual Clauses) | stripe.com/gb/privacy |
| Anthropic, PBC | Large language model API, drafting narrative sections of CRPs | US (Standard Contractual Clauses) | anthropic.com/privacy |
Important note on AI processing: Prompts sent to the AI include narrative context from your CRP (company name, sector, figures, measures) but are designed to contain the minimum personal data necessary. Anthropic's API usage policies state that API inputs are not used to train models. Verify current terms at the link above before submitting highly sensitive personal data as narrative context.
6. Data retention
- Account and company profile data, retained for the duration of your account, plus 90 days after account deletion (to allow recovery on request).
- Carbon Reduction Plans and versions, retained for 7 years from the date of generation (aligned to typical procurement audit requirements under the Procurement Act 2023), unless you request earlier deletion.
- Activity and emissions data, retained with the associated plan under the same 7-year rule.
- Billing records, retained for 7 years from the transaction date (legal requirement for tax and accounting records).
- Usage and technical logs, retained for 90 days, then auto-deleted.
- Brand-voice samples, retained until you delete them or your account is closed.
- Provenance / audit chain, retained for 7 years alongside the plan; cannot be deleted independently (integrity of the hash chain).
7. Data subject rights
As Controller, you are responsible for responding to data subject rights requests (access, rectification, erasure, portability, restriction, objection) from individuals whose data you have submitted to the Service. We will assist you at no extra charge by:
- Providing a GDPR data export of all your account data in JSON format on request from the Settings page or by email to [email protected].
- Erasing your account and associated personal data within 30 days of a written deletion request, subject to retention obligations that override erasure (billing records, 7-year plan archive).
- Providing technical assistance for any other right within 30 days of a written request.
8. Security measures
We implement the following technical and organisational measures:
- All data in transit encrypted via TLS 1.2+; data at rest encrypted (AES-256 on AWS RDS and S3).
- Passwords hashed with bcrypt (cost factor ≥ 12); JWT access tokens signed with RS256.
- Role-based access control: users may only access their own organisation's data.
- Soft-delete and audit logging on all material data changes.
- Tamper-evident SHA-256 hash chain on generation audit records.
- MFA available on all accounts (TOTP); SMS MFA in development.
- Regular dependency updates and automated vulnerability scanning.
- Access to production systems limited to named personnel under principle of least privilege.
9. International transfers
Stripe and Anthropic are US-based. Transfers to these sub-processors are covered by the UK International Data Transfer Agreement (IDTA) or equivalent UK adequacy mechanism. Copies of the relevant transfer mechanisms are available on request from [email protected].
10. Data breach notification
In the event of a personal data breach that is likely to result in risk to individuals, we will notify you without undue delay and in any case within 48 hours of becoming aware of the breach. The notification will include: the nature of the breach, categories and approximate number of individuals and records concerned, likely consequences, and measures taken or proposed. You remain responsible for notifying the ICO within 72 hours where required.
11. Agency customers
If you use Carbon Sorted on behalf of multiple client organisations (Agency tier), you act as Controller for each client's data. You are responsible for ensuring that your clients are informed of, and consent to, processing under this DPA and the associated sub-processors. You must not submit a client's data without a lawful basis under UK GDPR.
12. Audit rights
You have the right to audit our compliance with this DPA no more than once per calendar year, on 30 days' written notice, at your cost. We may satisfy an audit request by providing a current third-party security certification or summary audit report where available.
13. Term and termination
This DPA remains in effect for as long as we process personal data on your behalf. On termination of the Terms of Service, we will delete or return all personal data within 30 days, subject to the retention obligations in section 6.
14. Governing law
This DPA is governed by the laws of England and Wales. Any dispute arising from it is subject to the exclusive jurisdiction of the courts of England and Wales.
Contact
Data protection enquiries: [email protected]. We do not currently require a Data Protection Officer but can appoint a named point of contact on request.