🌱 Karbonet
Accueil Solution Tarifs Équipe Contact
  • English en
  • Türkçe tr
  • Deutsch de
  • Français fr
  • Italiano it
  • Español es
  • Nederlands nl
  • Polski pl
  • Português pt
  • العربية ar
  • 简体中文 zh
Connexion Essai gratuit
Accueil Solution Tarifs Équipe Contact
  • English
  • Türkçe
  • Deutsch
  • Français
  • Italiano
  • Español
  • Nederlands
  • Polski
  • Português
  • العربية
  • 简体中文
Connexion Essai gratuit
Mentions légales

Data Processing Agreement

Dernière mise à jour: 18 sept. 2026

This Data Processing Agreement (“DPA”) is part of the Terms of Service. It applies whenever ZincirX Inc. processes personal data on behalf of a customer and the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection or the Turkish KVKK applies to that processing. It takes effect when you accept the Terms; no signature is needed. If you need a countersigned copy, write to info@zincirx.com.

Ce document n'est disponible qu'en anglais.

Sur cette page

  1. 1. Roles and scope of the processing
  2. 2. Your instructions
  3. 3. Confidentiality
  4. 4. Security measures
  5. 5. Sub-processors
  6. 6. Helping you meet your duties
  7. 7. Personal data breaches
  8. 8. International transfers
  9. 9. Return and deletion
  10. 10. Information and audits
  11. 11. Liability and order of precedence
  12. 12. Getting a signed copy

1. Roles and scope of the processing

You are the controller (or a processor acting for your own client). We are your processor.

Details of the processing (Article 28(3) GDPR)
Item Description
Subject matter and purpose Hosting and operating the Karbonet workspace so that you can record activity data, calculate emissions, collect supplier figures, give auditors access and generate reports.
Duration The term of your trial or subscription, plus the read-only period afterwards, until the workspace is deleted.
Nature of the processing Storage, retrieval, calculation, display, transmission to the recipients you choose, and deletion.
Categories of data subjects Your users and invited team members; contact persons at your suppliers; your auditors and verifiers; anyone mentioned in free-text fields or documents you upload.
Types of personal data Names, business e-mail addresses, roles, records of actions taken in the workspace, and whatever personal data your free-text entries and uploaded documents contain. No special categories of data — the Terms prohibit uploading them.

Your own account, billing and contact data are not covered by this DPA. For those we are a controller, as described in the Privacy Policy.

2. Your instructions

We process the personal data only on your documented instructions. The Terms, this DPA and the way you use and configure the service are your instructions. If the law requires us to process the data in another way, we tell you first unless that law forbids it. If we believe an instruction breaks data protection law, we tell you.

3. Confidentiality

Only people who need access to do their work have it, and they are bound to confidentiality.

4. Security measures

Under Article 32 GDPR we maintain the technical and organisational measures below. The list is deliberately limited to what is in place today.

  • Encryption in transit: the production site is served over HTTPS, and the session cookie is flagged Secure, HTTP-only and SameSite=Lax.
  • Passwords are stored only as one-way bcrypt hashes. E-mail addresses must be verified before the app can be used. Sign-in attempts are rate-limited.
  • Tenant separation: all workspaces share one database, every workspace record carries the workspace’s identifier, and the app and the API filter every query by the workspace of the signed-in user or token.
  • Role-based access: owner and member roles inside a workspace, with team and billing management reserved for owners, and a separate administrator role for our own staff.
  • API tokens are stored only as SHA-256 hashes and shown once. Each token is scoped to read, or to read and write. API requests are rate-limited.
  • Supplier, invitation and auditor links use long random tokens and are rate-limited. Auditor links are read-only, expire and can be revoked.
  • Webhook signing secrets are encrypted in the database. Outgoing webhooks are signed with HMAC-SHA-256, and webhook destinations must resolve to public internet addresses.
  • All forms are protected against cross-site request forgery. Incoming payment notifications from Stripe are checked against Stripe’s webhook signature.
  • Uploaded proof documents and generated reports are kept in private storage outside the public web root and are not published under a public web address. Downloads go through the app’s access checks.
  • The application’s database account can connect only from the application server itself.
  • The blockchain signing key is held by a separate service that listens only on the server’s internal interface, requires a shared secret and receives nothing but the hash and the network details.
  • Card data never reaches our servers. It is entered on Stripe’s pages.
  • Credentials and keys are kept in server-side environment files that are excluded from the code repository and from deployments.
What this document does not claim: we hold no third-party security certification such as ISO 27001 or SOC 2, and we make no commitment here about encryption at rest, a particular data location, or a backup and recovery schedule. If you need any of these by contract, talk to us before you subscribe.

5. Sub-processors

You give us general authorisation to use sub-processors. The current ones are listed on the Sub-processors page. We bind each of them by contract to data protection duties equivalent to those in this DPA, and we remain responsible to you for what they do.

Before a new sub-processor starts processing your personal data, we update that page and e-mail workspace owners at least 30 days in advance. You may object within that time on reasonable data protection grounds. If we cannot resolve your objection, you may cancel the affected subscription and we refund the prepaid fees for the unused period.

6. Helping you meet your duties

The app lets you correct, export and delete most data yourself. Beyond that, and taking into account the nature of the processing, we help you with reasonable means to answer requests from data subjects, to carry out data protection impact assessments and to consult supervisory authorities. If a data subject contacts us about your data, we pass the request on to you and do not answer it ourselves.

7. Personal data breaches

If we become aware of a personal data breach that affects your data, we notify the workspace owners without undue delay. We tell you what we know about what happened, which data is affected and what we are doing about it, and we update you as we learn more, so that you can meet your own notification duties.

8. International transfers

We are a USA company, so using Karbonet means transferring personal data to a third country.

  • EEA: the Standard Contractual Clauses in the Annex to Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference — Module Two where you are a controller, Module Three where you are a processor. You are the data exporter and ZincirX Inc. is the data importer. The optional docking clause (Clause 7) applies. Under Clause 9, Option 2 (general written authorisation) applies with the notice period stated above. The optional wording in Clause 11 does not apply. For Clauses 17 and 18 the clauses are governed by the law of, and disputes go to the courts of, the EU member state in which you are established, or Ireland if you are not established in a member state. The competent supervisory authority is the one responsible for you. Annex I is completed by the section “Roles and scope of the processing”, Annex II by the section “Security measures”, and Annex III by the Sub-processors page.
  • United Kingdom: the UK International Data Transfer Addendum issued by the Information Commissioner applies to transfers subject to the UK GDPR, with the information above completing its tables.
  • Switzerland: for transfers subject to the Swiss Federal Act on Data Protection, references in the clauses to the GDPR are read as references to that act, and the Federal Data Protection and Information Commissioner is the competent authority.
  • Türkiye: where Article 9 KVKK requires it, we sign the standard contract published by the Personal Data Protection Board with you on request, so that you can notify it to the Board.

If these clauses conflict with the rest of this DPA or the Terms, the clauses prevail.

9. Return and deletion

You can export your data at any time, including while the workspace is read-only after your subscription has ended. When an owner asks us to delete the workspace, we delete the personal data in it within 30 days of verifying the request, unless a law requires us to keep it.

Blockchain anchors cannot be deleted. They consist of hashes only and contain no personal data — see “What is written to the blockchain” in the Privacy Policy.

10. Information and audits

On request we give you the information you need to show that Article 28 GDPR is complied with, and once a year we answer a reasonable written security questionnaire. If that is not enough to meet a legal duty, or if a supervisory authority requires it, you or an independent auditor bound to confidentiality may carry out an audit: with at least 30 days’ notice, during business hours, at your cost, and without access to other customers’ data.

11. Liability and order of precedence

The limits of liability in the Terms apply to this DPA as far as the law allows; they do not limit what either of us owes to data subjects or authorities under data protection law. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails.

12. Getting a signed copy

This DPA binds both of us without signatures. If your procurement or your auditor needs a countersigned copy, write to info@zincirx.com from the workspace owner’s address with your company’s legal name and address and the name and title of your signatory. We send you a PDF of this version to countersign.

Des questions sur ce document ? Écrivez à info@zincirx.com.

Autres documents juridiques

  • Conditions générales
  • Politique de confidentialité
  • Remboursement et résiliation
  • Sous-traitants ultérieurs
  • Mentions légales
Retour en haut
🌱 Karbonet

Suivi de l'empreinte carbone par blockchain pour les PME. Transformez vos données carbone en preuves vérifiables, prêtes pour l'audit.

ZincirX Inc. 131 Continental Dr, Suite 305 Newark, DE 19713 USA info@zincirx.com

Produit

  • Solution
  • Tarifs
  • Méthodologie
  • Vérifier un enregistrement carbone
  • API
  • Partenaires

Entreprise

  • Équipe
  • Contact
  • info@zincirx.com

Mentions légales

  • Conditions générales
  • Politique de confidentialité
  • Remboursement et résiliation
  • Accord de traitement des données
  • Sous-traitants ultérieurs
  • Mentions légales
  • Cookies

© 2026 ZincirX Inc. · Tous droits réservés.