← Back to Carbon Sorted

Data Processing Agreement

Last updated: 26 June 2026

This Data Processing Agreement ("DPA") is incorporated into, and forms part of, the Terms of Service between Carbon Sorted ("we", "us", "Processor") and you, the customer ("Controller"). It applies wherever we process personal data on your behalf in connection with the Carbon Sorted service. Terms not defined here have the meaning given in UK GDPR (UK General Data Protection Regulation, as retained in UK law by the Data Protection Act 2018).

1. Roles

You are the Controller of the personal data you submit to the Service. We act as your Processor in respect of that data, processing it only on your documented instructions (which include use of the Service as described in the Terms of Service). Where we process data for our own purposes (e.g. billing, security, legal obligations), we act as an independent Controller.

2. Categories of personal data processed

3. Purposes of processing

4. Legal basis

As Processor, we do not determine the legal basis for processing, that is your responsibility as Controller. You confirm that you have a lawful basis under UK GDPR for supplying any personal data to the Service.

5. Sub-processors

We use the following sub-processors to deliver the Service. By accepting this DPA you grant general authorisation to engage these sub-processors. We will give at least 30 days' notice of any new sub-processor via email and by updating this page, giving you the right to object.

Sub-processorPurposeData locationPrivacy reference
Amazon Web Services (AWS)Cloud hosting, database storage (RDS), file storage (S3), email sending (SES), Redis cache (ElastiCache)EU-West-2 (London)aws.amazon.com/privacy
Stripe, Inc.Payment processing, subscription management, invoicingUS / EU (Standard Contractual Clauses)stripe.com/gb/privacy
Anthropic, PBCLarge language model API, drafting narrative sections of CRPsUS (Standard Contractual Clauses)anthropic.com/privacy

Important note on AI processing: Prompts sent to the AI include narrative context from your CRP (company name, sector, figures, measures) but are designed to contain the minimum personal data necessary. Anthropic's API usage policies state that API inputs are not used to train models. Verify current terms at the link above before submitting highly sensitive personal data as narrative context.

6. Data retention

7. Data subject rights

As Controller, you are responsible for responding to data subject rights requests (access, rectification, erasure, portability, restriction, objection) from individuals whose data you have submitted to the Service. We will assist you at no extra charge by:

8. Security measures

We implement the following technical and organisational measures:

9. International transfers

Stripe and Anthropic are US-based. Transfers to these sub-processors are covered by the UK International Data Transfer Agreement (IDTA) or equivalent UK adequacy mechanism. Copies of the relevant transfer mechanisms are available on request from [email protected].

10. Data breach notification

In the event of a personal data breach that is likely to result in risk to individuals, we will notify you without undue delay and in any case within 48 hours of becoming aware of the breach. The notification will include: the nature of the breach, categories and approximate number of individuals and records concerned, likely consequences, and measures taken or proposed. You remain responsible for notifying the ICO within 72 hours where required.

11. Agency customers

If you use Carbon Sorted on behalf of multiple client organisations (Agency tier), you act as Controller for each client's data. You are responsible for ensuring that your clients are informed of, and consent to, processing under this DPA and the associated sub-processors. You must not submit a client's data without a lawful basis under UK GDPR.

12. Audit rights

You have the right to audit our compliance with this DPA no more than once per calendar year, on 30 days' written notice, at your cost. We may satisfy an audit request by providing a current third-party security certification or summary audit report where available.

13. Term and termination

This DPA remains in effect for as long as we process personal data on your behalf. On termination of the Terms of Service, we will delete or return all personal data within 30 days, subject to the retention obligations in section 6.

14. Governing law

This DPA is governed by the laws of England and Wales. Any dispute arising from it is subject to the exclusive jurisdiction of the courts of England and Wales.

Contact

Data protection enquiries: [email protected]. We do not currently require a Data Protection Officer but can appoint a named point of contact on request.