A comprehensive framework for the lawful, secure, and transparent processing of data within CarbonSynq.
The following terms shall have the meanings set forth below for the purposes of this Agreement:
Any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.
All laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, Switzerland, the United Kingdom and the United States and its states, applicable to the Processing of Personal Data.
The identified or identifiable person to whom Personal Data relates.
Any information relating to (i) an identified or identifiable natural person and (ii) an identified or identifiable legal entity.
Any operation or set of operations which is performed upon Personal Data, whether or not by automatic means.
The entity which Processes Personal Data on behalf of the Controller.
Any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.
Any Processor engaged by CarbonSynq or its Affiliates to assist in fulfilling its obligations with respect to providing the Services.
The European Economic Area, which constitutes the member states of the European Union plus Iceland, Liechtenstein and Norway.
The standard contractual clauses for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection.
The Customer, who determines the purpose and means of data processing. Full ownership remains with the data originator.
CarbonSynq, which processes data strictly on behalf of the Controller under these rigorous safety protocols.
CarbonSynq processes data solely to provide ESG tracking, carbon footprint calculations, and sustainability reporting analytics. The processing operations include:
Aggregating supply chain emissions data to provide a holistic view of the organization's indirect environmental impact.
Analyzing multi-year data sets to identify trends, efficiency gains, and areas requiring strategic sustainability intervention.
Generating BRSR, CSRD, and TCFD aligned reports automatically based on uploaded operational metrics.
Providing immediate feedback on energy usage spikes and recommending carbon-offsetting strategies.
Processor shall comply with the following specific obligations in respect of all Processing of Personal Data:
CarbonSynq shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law.
Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.
CarbonSynq ensures that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Regular security awareness training is mandatory for all personnel having access to the processing environment.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, CarbonSynq shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
Processor shall assist the Controller by appropriate technical and organizational measures for the fulfillment of the Controller's obligation to respond to requests for exercising the Data Subject's rights.
Any transfer of data to a third country shall only occur if the requirements of applicable Data Protection Laws are met (e.g., Standard Contractual Clauses).
In the event of any conflict between this DPA and the Main Service Agreement, the provisions of this DPA shall prevail regarding data protection obligations.
The parties' liability under this DPA shall be subject to the limitations and exclusions of liability set out in the Main Service Agreement, provided that neither party shall be entitled to limit its liability to the other party for any breach of this DPA that leads to a Security Breach.
Controller shall indemnify CarbonSynq against all costs, claims, and damages arising out of the Controller's failure to provide adequate notice or obtain necessary consents from Data Subjects.
CarbonSynq's liability for a Security Breach caused by its gross negligence shall be capped at three times (3x) the annual fees paid by the Customer.
Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force.
Processor shall retain Personal Data only for as long as necessary to fulfill the purposes outlined in the Main Agreement.
Full data accessibility throughout the active subscription term.
Data is securely deleted or anonymized within 90 days of contract termination unless legal retention is required.
Processor shall assist the Controller in fulfilling its obligations to respond to requests from Data Subjects under Data Protection Laws.
Laws of the Republic of India.
Courts of Bangalore, India.
CarbonSynq processes data relating to: Employees (full-time/contract), On-site visitors, Supply chain partners, Logistical coordinators, and Authorized administrative users.
Data is processed on a continuous, real-time basis via API integration or recurring batch uploads. The nature of processing involves algorithmic aggregation, trend analysis, and predictive modeling for net-zero strategy.
| Partner Entity | Technical Purpose | Jurisdiction | Safety Tier |
|---|---|---|---|
| Amazon Web Services | Compute & Database Storage | Mumbai / Ireland | Tier 4 |
| Stripe, Inc. | Financial Gateway Infrastructure | Global (USA Central) | PCI-DSS v4 |
| CarbonPulse AI | Optimized Emission Modeling | India (Bangalore) | ISO 27001 |
| Auth0 (Okta) | Enterprise IAM & Authentication | Frankfurt / USA | SOC2 Type II |
| SendGrid | Automated Compliance Alerts | USA | GDPR Compliant |
Biometric access controls, 24/7 CCTV surveillance, and specialized fire suppression systems at all data center locations.
Logical separation of tenant data via specialized VPC architectures and unique encryption keys for every customer.
99.99% uptime SLA with automated failover and multi-region data redundancy to prevent any localized outages.
End-to-end encryption for all data packets, utilizing XTS-AES 256 for local storage and TLS 1.3 for API calls.
Dedicated Security Operations Center (SOC) monitoring traffic 24/7 with automated AI-driven threat detection.
Immutable write-only audit logs capturing all administrative actions for forensic review if necessary.
CarbonSynq maintains the following technical security measures to ensure the highest level of data protection:
Pseudonymization and encryption of personal data at rest.
The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems.
The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.
A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures.
User identification and authorization (MFA, RBAC).
Protection of data during transmission (TLS 1.3, SSH).
Protection of data during storage (AES-256 GCM).
Physical security of locations at which personal data are processed.
Events logging and monitoring.
System configuration, including default security configurations.
Internal IT and IT security governance and management.
Data protection by design and by default.
Disaster recovery and business continuity planning.
Certification/assurance of processes and products (SOC2, ISO 27001).
Data minimization and purpose limitation.
Data quality and limited retention.
Accountability and transparency protocols.
Continuous threat intelligence and monitoring.
Yes, all data transmitted between your browser and our servers is encrypted using industry-standard TLS 1.3 protocols.
We conduct internal security audits quarterly and engage independent third-party auditors for annual SOC2 and ISO 27001 assessments.
Absolutely. Customers can request a full export of their data in a machine-readable format at any time via the admin console.
Primary data storage is in AWS Mumbai (India) and AWS Ireland (EU) regions, with failover clusters in AWS USA regions.
Upon cancellation, your data is archived for 90 days. After this period, it is permanently purged from our active systems and backups.
For all data processing inquiries and SCC execution requests.
Direct Legal Contact
pushkarsingh.carbonsynqearth@gmail.com