ZeroCarbon Enterprise Logo
STATUTORY SPECIFICATION | DPDP ACT 2023 · GDPR · CCPA

PRIVACY POLICY

data governance & telemetry notice

Legal notice governing personal data processing, carbon accounting telemetry, and cryptographic verification on the ZeroCarbon Enterprise Operating System.

Effective DateSeptember 29, 2026
Legal RefZC-LEG-PRV-2026-V3
Audit StatusVerified Compliant
Consent ModelExplicit Opt-In
Last Audited: September 2026
Status: Legally Binding
01/Scope & Governance

1. Regulatory Framework & Scope

ZeroCarbon Technologies Inc. ("ZeroCarbon", "we", "us", or "our") provides enterprise-grade carbon accounting, greenhouse gas inventory automation, SEBI BRSR Core reporting, and corporate emissions telemetry. This Privacy Policy describes how we process personal data, enterprise identity credentials, and operational metadata collected through our web applications, API endpoints, SDKs, and enterprise integrations.

This policy has been prepared in compliance with the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK Data Protection Act 2018, and the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA/CPRA").

02/Data Ingestion

2. Information We Collect

We collect information across three distinct operational layers:

Account & Identity Credentials

Names, corporate work email addresses, job titles, business entity registrations, password hashes (salted Argon2id / bcrypt), 2FA secret keys, and SAML/SSO directory attributes.

Emissions Activity Telemetry

Utility billing records, ERP purchase ledger entries, fuel consumption receipts, logistics waybills, flight telemetry, and supply chain Scope 3 disclosures uploaded by client organizations.

Technical & Session Telemetry

Originating IP addresses, browser user-agents, cryptographic session tokens, TLS handshake metrics, API key access logs, and audit trail verification queries.

Cryptographic Audit Records

SHA-256 content hashes of raw files, timestamped immutable verification receipts, and public ledger anchor proofs generated during statutory report generation.

03/Lawful Grounds

3. Purposes & Lawful Basis of Processing

ZeroCarbon processes personal and corporate data strictly under documented lawful bases:

Processing PurposeCategory of DataLawful Basis (GDPR Art. 6 / DPDP)
Provision of Carbon Accounting ServicesAccount details, emissions recordsPerformance of Contract (Art. 6(1)(b))
SEBI BRSR Core & Statutory ComplianceCorporate activity records, site auditsCompliance with Legal Obligation (Art. 6(1)(c))
Authentication & Fraud PreventionIP, 2FA tokens, session logsLegitimate Interests & Security (Art. 6(1)(f))
AI Classification & OCR ParsingRaw invoice attachments, utility billsContractual Performance & Explicit Consent
04/Data Lineage

4. Corporate Emissions Telemetry & Lineage

ZeroCarbon implements deterministic calculation pipelines. When your organization connects ERP data or uploads supplier disclosures:

  • Data is parsed in isolated ephemeral execution environments with end-to-end TLS 1.3 encryption.
  • Every calculation maps to a published emission factor version (e.g., CEA CO2 Baseline v20, DEFRA 2025, IPCC AR6).
  • We do not sell, rent, or monetize your company's proprietary operational metrics or supplier emissions data.
  • Aggregated, anonymized benchmark statistics may be produced only where all identifying markers are permanently removed.
05/Sub-processors

5. Data Sharing & Sub-processors

We share data with sub-processors only under strict Data Processing Agreements (DPAs) incorporating standard contractual clauses:

  • Cloud Infrastructure: AWS (Mumbai ap-south-1 & Frankfurt eu-central-1) and Vercel for platform hosting.
  • Cryptographic & OCR Engine: Self-hosted deterministic OCR parsers and secured AI classification pipelines.
  • Transactional Communications: Resend / Postmark for delivery of security alerts, 2FA codes, and reports.
  • Carbon Registries: Verra VCS, Gold Standard, and Indian CCTS registries strictly when retirement certificates are generated.
06/International Transfers

6. Cross-Border Data Transfers

Where customer data is transferred outside the European Economic Area (EEA), the United Kingdom, or India, ZeroCarbon utilizes standard contractual clauses adopted by the European Commission, UK International Data Transfer Agreements (IDTAs), and adheres to the cross-border guidelines established under Section 16 of India's DPDP Act, 2023.

07/Information Security

7. Cryptographic Security & Verification

We enforce bank-grade security standards across our infrastructure:

Enterprise Security Controls

  • AES-256 encryption at rest across all database partitions and blob stores.
  • TLS 1.3 enforced for all client and API traffic with strict HSTS headers.
  • Immutable audit ledgers with SHA-256 lineage chains to prevent data tampering.
  • Automated vulnerability scanning, static code analysis, and regular independent penetration testing.
08/Your Rights

8. Data Subject Rights (GDPR & DPDP)

Depending on your jurisdiction, you have the right to access, rectify, erase, restrict, or port your personal data:

  • Right to Access: Request a complete export of personal data held about you.
  • Right to Rectification: Correct inaccurate or incomplete company and user profile details.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of account records, subject to statutory retention obligations.
  • Right to Withdraw Consent: Revoke consent for voluntary analytics or newsletter subscriptions at any time.

To exercise any of these rights, email our Data Protection Officer at privacy@zerocarbon.org.in. We respond to all verified requests within 30 days.

09/Data Lifecycles

9. Retention Periods & Cryptographic Deletion

We retain personal data only as long as necessary to fulfill the services contracted or to satisfy statutory obligations under company law, tax law, and ESG reporting standards. For a complete schedule of retention windows across all data categories, refer to our comprehensive Data Retention Policy.

10/Governance & Contact

10. Data Protection Officer & Governance

ZeroCarbon has appointed a designated Data Protection Officer to supervise regulatory compliance and handle customer grievances:

Office of the Data Protection Officer

ZeroCarbon Technologies Inc.

New Delhi & Bengaluru, India

Email: privacy@zerocarbon.org.in

Grievance Officer: grievance@zerocarbon.org.in