PRIVACY POLICY
data governance & telemetry notice
Legal notice governing personal data processing, carbon accounting telemetry, and cryptographic verification on the ZeroCarbon Enterprise Operating System.
1. Regulatory Framework & Scope
ZeroCarbon Technologies Inc. ("ZeroCarbon", "we", "us", or "our") provides enterprise-grade carbon accounting, greenhouse gas inventory automation, SEBI BRSR Core reporting, and corporate emissions telemetry. This Privacy Policy describes how we process personal data, enterprise identity credentials, and operational metadata collected through our web applications, API endpoints, SDKs, and enterprise integrations.
This policy has been prepared in compliance with the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK Data Protection Act 2018, and the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA/CPRA").
2. Information We Collect
We collect information across three distinct operational layers:
Account & Identity Credentials
Names, corporate work email addresses, job titles, business entity registrations, password hashes (salted Argon2id / bcrypt), 2FA secret keys, and SAML/SSO directory attributes.
Emissions Activity Telemetry
Utility billing records, ERP purchase ledger entries, fuel consumption receipts, logistics waybills, flight telemetry, and supply chain Scope 3 disclosures uploaded by client organizations.
Technical & Session Telemetry
Originating IP addresses, browser user-agents, cryptographic session tokens, TLS handshake metrics, API key access logs, and audit trail verification queries.
Cryptographic Audit Records
SHA-256 content hashes of raw files, timestamped immutable verification receipts, and public ledger anchor proofs generated during statutory report generation.
3. Purposes & Lawful Basis of Processing
ZeroCarbon processes personal and corporate data strictly under documented lawful bases:
| Processing Purpose | Category of Data | Lawful Basis (GDPR Art. 6 / DPDP) |
|---|---|---|
| Provision of Carbon Accounting Services | Account details, emissions records | Performance of Contract (Art. 6(1)(b)) |
| SEBI BRSR Core & Statutory Compliance | Corporate activity records, site audits | Compliance with Legal Obligation (Art. 6(1)(c)) |
| Authentication & Fraud Prevention | IP, 2FA tokens, session logs | Legitimate Interests & Security (Art. 6(1)(f)) |
| AI Classification & OCR Parsing | Raw invoice attachments, utility bills | Contractual Performance & Explicit Consent |
4. Corporate Emissions Telemetry & Lineage
ZeroCarbon implements deterministic calculation pipelines. When your organization connects ERP data or uploads supplier disclosures:
- Data is parsed in isolated ephemeral execution environments with end-to-end TLS 1.3 encryption.
- Every calculation maps to a published emission factor version (e.g., CEA CO2 Baseline v20, DEFRA 2025, IPCC AR6).
- We do not sell, rent, or monetize your company's proprietary operational metrics or supplier emissions data.
- Aggregated, anonymized benchmark statistics may be produced only where all identifying markers are permanently removed.
5. Data Sharing & Sub-processors
We share data with sub-processors only under strict Data Processing Agreements (DPAs) incorporating standard contractual clauses:
- Cloud Infrastructure: AWS (Mumbai ap-south-1 & Frankfurt eu-central-1) and Vercel for platform hosting.
- Cryptographic & OCR Engine: Self-hosted deterministic OCR parsers and secured AI classification pipelines.
- Transactional Communications: Resend / Postmark for delivery of security alerts, 2FA codes, and reports.
- Carbon Registries: Verra VCS, Gold Standard, and Indian CCTS registries strictly when retirement certificates are generated.
6. Cross-Border Data Transfers
Where customer data is transferred outside the European Economic Area (EEA), the United Kingdom, or India, ZeroCarbon utilizes standard contractual clauses adopted by the European Commission, UK International Data Transfer Agreements (IDTAs), and adheres to the cross-border guidelines established under Section 16 of India's DPDP Act, 2023.
7. Cryptographic Security & Verification
We enforce bank-grade security standards across our infrastructure:
Enterprise Security Controls
- AES-256 encryption at rest across all database partitions and blob stores.
- TLS 1.3 enforced for all client and API traffic with strict HSTS headers.
- Immutable audit ledgers with SHA-256 lineage chains to prevent data tampering.
- Automated vulnerability scanning, static code analysis, and regular independent penetration testing.
8. Data Subject Rights (GDPR & DPDP)
Depending on your jurisdiction, you have the right to access, rectify, erase, restrict, or port your personal data:
- Right to Access: Request a complete export of personal data held about you.
- Right to Rectification: Correct inaccurate or incomplete company and user profile details.
- Right to Erasure ("Right to be Forgotten"): Request deletion of account records, subject to statutory retention obligations.
- Right to Withdraw Consent: Revoke consent for voluntary analytics or newsletter subscriptions at any time.
To exercise any of these rights, email our Data Protection Officer at privacy@zerocarbon.org.in. We respond to all verified requests within 30 days.
9. Retention Periods & Cryptographic Deletion
We retain personal data only as long as necessary to fulfill the services contracted or to satisfy statutory obligations under company law, tax law, and ESG reporting standards. For a complete schedule of retention windows across all data categories, refer to our comprehensive Data Retention Policy.
10. Data Protection Officer & Governance
ZeroCarbon has appointed a designated Data Protection Officer to supervise regulatory compliance and handle customer grievances:
Office of the Data Protection Officer
ZeroCarbon Technologies Inc.
New Delhi & Bengaluru, India
Email: privacy@zerocarbon.org.in
Grievance Officer: grievance@zerocarbon.org.in