Privacy Policy
Ultimo aggiornamento:
This policy explains what personal data ZincirX Inc. handles when you visit the Karbonet website, use the app, or appear in it because a customer added you as a team member, supplier contact or auditor. It follows Articles 13 and 14 of the EU General Data Protection Regulation (GDPR). People in Türkiye will find the information required by the Law on the Protection of Personal Data (KVKK) in its own section below.
Questo documento è disponibile solo in inglese.
1. Who is responsible
The controller is ZincirX Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. For anything about privacy, write to info@zincirx.com.
2. Two roles: controller and processor
We are the controller for data we need to run our own business: your user account, billing, the contact form, this website and our security logs.
For the content a customer puts into its workspace — including personal data about its team, its suppliers and its auditors — the customer is the controller and we are its processor under the Data Processing Agreement. If your request is about such content, contact that customer first. If you write to us, we pass the request on to them.
3. What we collect, feature by feature
User account and sign-in
Your name, e-mail address, password (stored only as a one-way hash), language, time zone, when you verified your e-mail address, the workspace you belong to and your role in it. If you tick “Remember me”, a remember token as well; if you ask for a password reset, a short-lived reset token.
Workspace and company data
Company name, country, sector, type of business, a description of activities, employee band, VAT number, contact e-mail and address. Then the carbon data itself: emission and offset records, energy contracts, CBAM installations and goods, reduction plans, proof documents you upload and the reports you generate. Each record notes which user created it. This is mostly business data, but free-text fields and uploaded documents can contain personal data if you put it there.
Team invitations
The invited person’s e-mail address, the role offered, who sent the invitation, when it expires (after 7 days) and when it was accepted. We send the invited person an invitation e-mail. We receive this address from the customer who invites you, not from you.
Supplier contacts and submissions
The supplier’s business name, an optional contact e-mail address and the product supplied — entered by the customer. Through its personal link the supplier then submits an emissions figure and an optional short note, and we record when. We do not e-mail suppliers; the customer sends the link itself.
Auditor access
A label for the link, an optional e-mail address of the auditor, the expiry date, when the link was revoked and when it was last opened — entered by the customer.
Contact form
Your name, e-mail address, and if you give them your company, company size, area of interest and message. We also store the language of the page, the time, and the IP address the form was sent from, to filter spam and abuse.
API tokens and webhooks
For each API token: the name you gave it, its permissions (read, or read and write), when it was created and when it was last used. The token itself is shown once and stored only as a hash. For webhooks: the endpoint address, a signing secret (stored encrypted) and the delivery status.
Activity log
The app keeps a log of significant actions in a workspace — which user did what, and when — so that owners can review changes.
Partner directory
When you send a quote request to a partner, the contact details and message you enter.
Sessions, logs and rate limiting
While you are signed in, a session record holds your user ID, IP address, browser identification and the time of your last activity. Our web server writes standard access logs (IP address, time, address requested, referring page, browser identification). Application error logs can contain technical details of a failed request. We also use IP addresses for a few minutes at a time to enforce rate limits on sign-in, public links and hash lookups.
Billing data through Stripe
When a workspace owner subscribes, payment details are entered on pages hosted by Stripe. We never receive or store full card numbers or security codes. To create the Stripe customer we send Stripe the company name, contact e-mail address, country and language. From Stripe we receive the customer and subscription identifiers, the subscription status and tier, the payment method type and its last four digits, and access to the invoices and to the billing name, address and tax ID entered at checkout.
What we do not collect
We run no analytics, no advertising or tracking cookies, no tracking pixels, no fingerprinting and no social-media plug-ins. Fonts, scripts and styles are served from our own domain, so your browser does not contact third-party content networks when you load our pages. We do not buy personal data from anyone.
4. Why we use it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Create and secure your account, run the app for you, send service e-mails (address verification, password reset, invitations) | Performance of the contract, Art. 6(1)(b). Where you use the app as an employee of our customer: our legitimate interest in providing the service to your employer, Art. 6(1)(f). |
| Bill subscriptions, issue invoices, keep tax and accounting records | Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c). |
| Answer contact-form enquiries | Steps before a contract at your request, Art. 6(1)(b); otherwise our legitimate interest in answering business enquiries, Art. 6(1)(f). |
| Keep the service secure: sessions, logs, rate limiting, spam filtering, abuse investigation | Legitimate interest in a secure and reliable service, Art. 6(1)(f). |
| Establish, exercise or defend legal claims; comply with binding requests from authorities | Legitimate interest, Art. 6(1)(f), and legal obligation, Art. 6(1)(c). |
| Process the content of a customer’s workspace (team, supplier and auditor details included) | On the customer’s instructions as its processor. The customer decides on the legal basis. |
You need to give us your name, e-mail address and a password to have an account; without them we cannot provide the service. Everything else you give us is up to you.
We do not send newsletters or marketing e-mails from the product.
5. Who receives personal data
- Our service providers, listed with their purpose and location on the Sub-processors page. They act on our instructions under a contract.
- Stripe, for payments. For some of what it does — fraud prevention and its own legal duties, for example — Stripe acts as a controller in its own right under its own privacy policy.
- People our customers choose: other members of the workspace, suppliers and auditors who are sent a link, and the systems a customer’s webhooks point to.
- Authorities and courts, where the law obliges us.
- A buyer of the Karbonet business, under the same protections, if it is ever sold.
If a customer sends a quote request through the partner directory, we pass the details entered in that request to the partner the customer selected.
We do not sell personal data.
6. What is written to the blockchain
Karbonet anchors proofs on a blockchain network operated by third parties. Exactly this happens:
- For each emission or offset record we calculate a SHA-256 hash from the record’s internal number, the workspace’s internal number, the activity type, the CO₂e amount, the activity date (for emission records) and the time the record was created.
- For each generated report we calculate a SHA-256 hash from the report’s internal number, the workspace’s internal number, the report type, the period, the total CO₂e and a checksum of the PDF file.
- Only the resulting 32-byte hash is sent to the smart contract, through a queued job that runs when anchoring is enabled and the network is reachable. Next to it the contract stores the block time and the address of Karbonet’s own signing wallet, which is the same for all customers.
No name, e-mail address, company name, amount, document, IP address or user identifier is written on-chain. The inputs to the hash are business figures and internal numbers, not contact details, and a hash cannot be turned back into its inputs. The blockchain network and the network access point we use receive the hash from our server — never from your browser.
On the public verification page anyone who holds a hash can see whether it is anchored, on which network, in which transaction and block, and when. The page shows nothing about the workspace, the record or the amounts.
7. International transfers
ZincirX Inc. is a USA company. Personal data therefore comes under the control of a company outside the EEA and is processed where we and the providers on the Sub-processors page operate; that page states each provider’s location. We do not offer storage in a particular country.
The European Commission has not recognised the United States as providing adequate protection in general; its adequacy decision covers only companies certified under the EU–US Data Privacy Framework, and we make no claim to such a certification. We rely on these safeguards:
- Where we process personal data for a customer in the EEA, the United Kingdom or Switzerland, our Data Processing Agreement incorporates the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the additions required for the United Kingdom and Switzerland.
- With our own providers we rely on the transfer safeguards in their data processing terms: an adequacy decision or a recognised certification where one applies to the recipient, and otherwise Standard Contractual Clauses.
You can ask for a copy of the relevant clauses at info@zincirx.com.
8. How long we keep it
| Data | Kept for |
|---|---|
| User account | Until you delete your account or the workspace is deleted. |
| Workspace content, including supplier and auditor details and uploaded documents | For as long as the workspace exists — also while it is read-only after a subscription has ended; we do not delete lapsed workspaces automatically. Deleted within 30 days of a verified deletion request from an owner. |
| Team invitations | Valid for 7 days. The entry stays in the workspace until an owner removes it or the workspace is deleted. |
| Contact-form enquiries | Up to 24 months after our last contact with you, unless the enquiry leads to a contract. |
| Session records | A session expires 120 minutes after your last activity. Expired session records are purged by the app’s periodic clean-up. |
| Server and application logs | Only as long as they are needed for security and troubleshooting. |
| Invoices and billing records | For as long as the tax and accounting laws that apply to us require. |
| Blockchain anchors (hashes only) | Permanently. They cannot be deleted. |
9. Your rights
Under the GDPR you can ask us for access to your data, for correction, for deletion, for restriction of processing, and for a portable copy of the data you gave us. Where we rely on consent you can withdraw it at any time for the future.
Write to info@zincirx.com. We may need to confirm your identity first. We answer within one month, as the GDPR requires; the law allows an extension for complex requests, and we will tell you if we need it. Exercising your rights is free of charge.
Some things you can do yourself: change your name, e-mail address and password, or delete your account, in Profile settings. If your request concerns data that a Karbonet customer holds about you in its workspace, that customer decides about it — contact them first.
10. Complaints to a supervisory authority
You have the right to complain to a data protection authority, in particular in the EU country where you live, where you work or where you think the infringement happened. The authorities are listed by the European Data Protection Board (si apre in una nuova scheda). In Germany this is the data protection authority of your federal state. We would appreciate the chance to resolve your concern first: info@zincirx.com.
11. No automated decision-making
We do not make decisions about individuals by automated means and we do not profile anyone. The automated calculations in Karbonet — emissions, usage limits, projections — concern company data, not people.
12. Security
The measures we actually have in place are described, without embellishment, in the Data Processing Agreement.
13. Türkiye: information notice under the KVKK (aydınlatma metni)
This section is the information notice required by Article 10 of Law No. 6698 on the Protection of Personal Data (Kişisel Verilerin Korunması Kanunu, “KVKK”) for people in Türkiye.
Data controller (veri sorumlusu)
ZincirX Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Contact: info@zincirx.com.
For the content of a customer’s workspace, that customer is the data controller and we act as its data processor (veri işleyen).
Purposes of processing
We process the personal data described under “What we collect” above in order to: create and run user accounts; provide the carbon-accounting service; bill subscriptions and keep financial records; answer enquiries; and keep the service secure and prevent abuse.
Method of collection and legal grounds
We collect data electronically — through the forms and pages of the website and the app, through our API, from the customer that adds you to its workspace, and from Stripe for billing. The legal grounds under Article 5(2) KVKK are: processing is necessary for the conclusion or performance of a contract (5/2-c); it is necessary for us to comply with a legal obligation (5/2-ç); it is necessary to establish, exercise or protect a right (5/2-e); and it is necessary for our legitimate interests, provided your fundamental rights are not harmed (5/2-f). We do not ask for special categories of personal data.
Who receives the data, and transfers abroad
The recipients are those listed under “Who receives personal data” above, for the purposes stated there. Because ZincirX Inc. is a USA company, the personal data you give us is transferred abroad, and our service providers, listed with their locations on the Sub-processors page, are outside Türkiye as well. Where we transfer personal data abroad on behalf of a customer in Türkiye, the transfer is based on Article 9 KVKK. On request we sign the standard contract published by the Personal Data Protection Board with that customer.
Your rights under Article 11 KVKK
You have the right to:
- learn whether your personal data is processed;
- request information about the processing if it is;
- learn the purpose of the processing and whether the data is used in line with that purpose;
- know the third parties, in Türkiye or abroad, to whom the data is transferred;
- request correction of incomplete or inaccurate data;
- request erasure or destruction of the data under the conditions of Article 7 KVKK;
- request that a correction, erasure or destruction be notified to the third parties to whom the data was transferred;
- object to a result that is to your detriment and that arises from analysis of the data exclusively by automated systems;
- claim compensation if you suffer damage because of unlawful processing.
How to apply
Send your request in Turkish or English to info@zincirx.com from the e-mail address registered on your account, or in writing to the postal address above. Include your full name, the right you wish to use and the details of your request, as set out in the Communiqué on the Principles and Procedures for Applications to the Data Controller. We answer free of charge as soon as possible and within thirty days at the latest. If answering causes additional cost, we may charge the fee in the tariff set by the Personal Data Protection Board.
If we reject your request, if you find our answer insufficient, or if we do not answer in time, you may complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) (si apre in una nuova scheda) within thirty days of learning of our answer and in any case within sixty days of your application.
15. Changes to this policy
When the way we handle personal data changes, we update this page and the date at the top. We tell workspace owners by e-mail about changes that matter.