CarbonSynqCarbonSynqEarth
Solutions
Net Zero
Track and manage carbon footprint
Supply Chain
Monitor value chain impact
Platform
Plans
Flexible pricing for every business size
Company
About Us
Our mission and vision
Careers
Join our mission
Contact Us
Get in touch with our team
Log inRegisterBook a demo
CarbonSynqCarbonSynqEarth
Net Zero
Track and manage carbon footprint
Supply Chain
Monitor value chain impact
Plans
Flexible pricing for every business size
About Us
Our mission and vision
Careers
Join our mission
Contact Us
Get in touch with our team
Log inRegister
Book a demo
CarbonSynqEarthCarbonSynqEarth

Built on the belief in a greener, more sustainable future.

LINKEDINX

Solutions

  • Net Zero
  • Supply Chain

Company

  • About Us
  • Careers
  • Contact Us

© 2026 CarbonSynq Pvt. Ltd.

Privacy Policy·Terms of Service·Data Processing Agreement

© 2026 CarbonSynq Pvt. Ltd.

Privacy Policy
Terms of Service
Data Processing Agreement
Enterprise Compliance v4.0

DPA Protocol.

A comprehensive framework for the lawful, secure, and transparent processing of data within CarbonSynq.

Agreement Sections

DefinitionsRoles of the PartiesPurpose of ProcessingData Processing TermsRestricted TransfersPrecedenceIndemnitySeverabilityData RetentionData Subject RightsMiscellaneousAnnex 1: ActivitiesAnnex 2: Sub-processorsSecurity MeasuresTechnical AnnexFAQSignatoriesContact Us
1

01.Definitions

The following terms shall have the meanings set forth below for the purposes of this Agreement:

Affiliate

Any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.

Data Protection Laws

All laws and regulations, including laws and regulations of the European Union, the European Economic Area and their member states, Switzerland, the United Kingdom and the United States and its states, applicable to the Processing of Personal Data.

Data Subject

The identified or identifiable person to whom Personal Data relates.

Personal Data

Any information relating to (i) an identified or identifiable natural person and (ii) an identified or identifiable legal entity.

Processing

Any operation or set of operations which is performed upon Personal Data, whether or not by automatic means.

Processor

The entity which Processes Personal Data on behalf of the Controller.

Security Breach

Any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise Processed.

Sub-processor

Any Processor engaged by CarbonSynq or its Affiliates to assist in fulfilling its obligations with respect to providing the Services.

EEA

The European Economic Area, which constitutes the member states of the European Union plus Iceland, Liechtenstein and Norway.

Standard Contractual Clauses

The standard contractual clauses for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection.

2

02.Roles of the Parties

Controller

The Customer, who determines the purpose and means of data processing. Full ownership remains with the data originator.

Processor

CarbonSynq, which processes data strictly on behalf of the Controller under these rigorous safety protocols.

3

03.Description and Purpose of Personal Data Processing

CarbonSynq processes data solely to provide ESG tracking, carbon footprint calculations, and sustainability reporting analytics. The processing operations include:

Scope 3 Analytics

Aggregating supply chain emissions data to provide a holistic view of the organization's indirect environmental impact.

Historical Benchmarking

Analyzing multi-year data sets to identify trends, efficiency gains, and areas requiring strategic sustainability intervention.

Regulatory Compliance

Generating BRSR, CSRD, and TCFD aligned reports automatically based on uploaded operational metrics.

Real-time Optimization

Providing immediate feedback on energy usage spikes and recommending carbon-offsetting strategies.

4

04.Data Processing Terms

Processor shall comply with the following specific obligations in respect of all Processing of Personal Data:

Compliance & Instructions

CarbonSynq shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by applicable law.

Processor shall immediately inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.

Confidentiality & Training

CarbonSynq ensures that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

Regular security awareness training is mandatory for all personnel having access to the processing environment.

Security of Processing

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, CarbonSynq shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

Assistance to Controller

Processor shall assist the Controller by appropriate technical and organizational measures for the fulfillment of the Controller's obligation to respond to requests for exercising the Data Subject's rights.

5

05.Restricted Transfers

Global Compliance

Any transfer of data to a third country shall only occur if the requirements of applicable Data Protection Laws are met (e.g., Standard Contractual Clauses).

6

06.Precedence

In the event of any conflict between this DPA and the Main Service Agreement, the provisions of this DPA shall prevail regarding data protection obligations.

7

07.Indemnity & Limitation of Liability

The parties' liability under this DPA shall be subject to the limitations and exclusions of liability set out in the Main Service Agreement, provided that neither party shall be entitled to limit its liability to the other party for any breach of this DPA that leads to a Security Breach.

Indemnification Clause

Controller shall indemnify CarbonSynq against all costs, claims, and damages arising out of the Controller's failure to provide adequate notice or obtain necessary consents from Data Subjects.

Breach Liability

CarbonSynq's liability for a Security Breach caused by its gross negligence shall be capped at three times (3x) the annual fees paid by the Customer.

8

08.Severability

Should any provision of this DPA be invalid or unenforceable, then the remainder of this DPA shall remain valid and in force.

10

010.Data Retention and Deletion

Processor shall retain Personal Data only for as long as necessary to fulfill the purposes outlined in the Main Agreement.

Active Period

Full data accessibility throughout the active subscription term.

Post-Termination

Data is securely deleted or anonymized within 90 days of contract termination unless legal retention is required.

11

011.Data Subject Rights

Processor shall assist the Controller in fulfilling its obligations to respond to requests from Data Subjects under Data Protection Laws.

Right to Access & Portability
Right to Rectification
Right to Erasure (Right to be Forgotten)
Right to Restriction of Processing
9

09.Miscellaneous

Governing Law

Laws of the Republic of India.

Jurisdiction

Courts of Bangalore, India.

10

010.Annex 1: Description of Processing Activities

A. Categories of Data Subjects

CarbonSynq processes data relating to: Employees (full-time/contract), On-site visitors, Supply chain partners, Logistical coordinators, and Authorized administrative users.

B. Categories of Personal Data
  • Professional Identification (Name, Work Email)
  • Utility Usage Data (kWh, Water consumption)
  • Travel Logs (Business trips, Commute modes)
  • IT Usage Data (Logs for emission calculations)
  • Facilities Metadata (Square footage, HVAC stats)
C. Frequency and Nature

Data is processed on a continuous, real-time basis via API integration or recurring batch uploads. The nature of processing involves algorithmic aggregation, trend analysis, and predictive modeling for net-zero strategy.

11

011.Annex 2: CarbonSynq's Sub-processors

Partner EntityTechnical PurposeJurisdictionSafety Tier
Amazon Web ServicesCompute & Database StorageMumbai / IrelandTier 4
Stripe, Inc.Financial Gateway InfrastructureGlobal (USA Central)PCI-DSS v4
CarbonPulse AIOptimized Emission ModelingIndia (Bangalore)ISO 27001
Auth0 (Okta)Enterprise IAM & AuthenticationFrankfurt / USASOC2 Type II
SendGridAutomated Compliance AlertsUSAGDPR Compliant
12

012.Technical and Organisational Security Measures

Advanced TOMs Framework

Physical Security

Biometric access controls, 24/7 CCTV surveillance, and specialized fire suppression systems at all data center locations.

Data Isolation

Logical separation of tenant data via specialized VPC architectures and unique encryption keys for every customer.

Resilience

99.99% uptime SLA with automated failover and multi-region data redundancy to prevent any localized outages.

Encryption

End-to-end encryption for all data packets, utilizing XTS-AES 256 for local storage and TLS 1.3 for API calls.

Incident Management

Dedicated Security Operations Center (SOC) monitoring traffic 24/7 with automated AI-driven threat detection.

Auditability

Immutable write-only audit logs capturing all administrative actions for forensic review if necessary.

12

012.Technical Annex: Security Protocols

CarbonSynq maintains the following technical security measures to ensure the highest level of data protection:

Pseudonymization and encryption of personal data at rest.

The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems.

The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident.

A process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures.

User identification and authorization (MFA, RBAC).

Protection of data during transmission (TLS 1.3, SSH).

Protection of data during storage (AES-256 GCM).

Physical security of locations at which personal data are processed.

Events logging and monitoring.

System configuration, including default security configurations.

Internal IT and IT security governance and management.

Data protection by design and by default.

Disaster recovery and business continuity planning.

Certification/assurance of processes and products (SOC2, ISO 27001).

Data minimization and purpose limitation.

Data quality and limited retention.

Accountability and transparency protocols.

Continuous threat intelligence and monitoring.

13

013.Frequently Asked Questions (FAQ)

Is my data encrypted during transit?

Yes, all data transmitted between your browser and our servers is encrypted using industry-standard TLS 1.3 protocols.

How often are security audits performed?

We conduct internal security audits quarterly and engage independent third-party auditors for annual SOC2 and ISO 27001 assessments.

Can I request a copy of my processed data?

Absolutely. Customers can request a full export of their data in a machine-readable format at any time via the admin console.

Where is my data physically stored?

Primary data storage is in AWS Mumbai (India) and AWS Ireland (EU) regions, with failover clusters in AWS USA regions.

What happens to my data if I cancel my subscription?

Upon cancellation, your data is archived for 90 days. After this period, it is permanently purged from our active systems and backups.

14

014.Signatories

Please complete the digital execution fields below to acknowledge this agreement.

On behalf of the Customer

On behalf of CarbonSynq

Pushkar Singh
Managing Director

By clicking above, you agree to the electronic execution of this DPA.

15

015.Contact Us

DPO Office.

For all data processing inquiries and SCC execution requests.

Direct Legal Contact

pushkarsingh.carbonsynqearth@gmail.com