🌱 Karbonet
Start Rozwiązanie Cennik Zespół Kontakt
  • English en
  • Türkçe tr
  • Deutsch de
  • Français fr
  • Italiano it
  • Español es
  • Nederlands nl
  • Polski pl
  • Português pt
  • العربية ar
  • 简体中文 zh
Zaloguj się Wypróbuj bezpłatnie
Start Rozwiązanie Cennik Zespół Kontakt
  • English
  • Türkçe
  • Deutsch
  • Français
  • Italiano
  • Español
  • Nederlands
  • Polski
  • Português
  • العربية
  • 简体中文
Zaloguj się Wypróbuj bezpłatnie
Informacje prawne

Privacy Policy

Ostatnia aktualizacja: 18 wrz 2026

This policy explains what personal data ZincirX Inc. handles when you visit the Karbonet website, use the app, or appear in it because a customer added you as a team member, supplier contact or auditor. It follows Articles 13 and 14 of the EU General Data Protection Regulation (GDPR). People in Türkiye will find the information required by the Law on the Protection of Personal Data (KVKK) in its own section below.

Ten dokument jest dostępny wyłącznie w języku angielskim.

Na tej stronie

  1. 1. Who is responsible
  2. 2. Two roles: controller and processor
  3. 3. What we collect, feature by feature
  4. 4. Why we use it and on what legal basis
  5. 5. Who receives personal data
  6. 6. What is written to the blockchain
  7. 7. International transfers
  8. 8. How long we keep it
  9. 9. Your rights
  10. 10. Complaints to a supervisory authority
  11. 11. No automated decision-making
  12. 12. Security
  13. 13. Türkiye: information notice under the KVKK (aydınlatma metni)
  14. 14. Cookies and browser storage
  15. 15. Changes to this policy

1. Who is responsible

The controller is ZincirX Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. For anything about privacy, write to info@zincirx.com.

2. Two roles: controller and processor

We are the controller for data we need to run our own business: your user account, billing, the contact form, this website and our security logs.

For the content a customer puts into its workspace — including personal data about its team, its suppliers and its auditors — the customer is the controller and we are its processor under the Data Processing Agreement. If your request is about such content, contact that customer first. If you write to us, we pass the request on to them.

3. What we collect, feature by feature

User account and sign-in

Your name, e-mail address, password (stored only as a one-way hash), language, time zone, when you verified your e-mail address, the workspace you belong to and your role in it. If you tick “Remember me”, a remember token as well; if you ask for a password reset, a short-lived reset token.

Workspace and company data

Company name, country, sector, type of business, a description of activities, employee band, VAT number, contact e-mail and address. Then the carbon data itself: emission and offset records, energy contracts, CBAM installations and goods, reduction plans, proof documents you upload and the reports you generate. Each record notes which user created it. This is mostly business data, but free-text fields and uploaded documents can contain personal data if you put it there.

Team invitations

The invited person’s e-mail address, the role offered, who sent the invitation, when it expires (after 7 days) and when it was accepted. We send the invited person an invitation e-mail. We receive this address from the customer who invites you, not from you.

Supplier contacts and submissions

The supplier’s business name, an optional contact e-mail address and the product supplied — entered by the customer. Through its personal link the supplier then submits an emissions figure and an optional short note, and we record when. We do not e-mail suppliers; the customer sends the link itself.

Auditor access

A label for the link, an optional e-mail address of the auditor, the expiry date, when the link was revoked and when it was last opened — entered by the customer.

Contact form

Your name, e-mail address, and if you give them your company, company size, area of interest and message. We also store the language of the page, the time, and the IP address the form was sent from, to filter spam and abuse.

API tokens and webhooks

For each API token: the name you gave it, its permissions (read, or read and write), when it was created and when it was last used. The token itself is shown once and stored only as a hash. For webhooks: the endpoint address, a signing secret (stored encrypted) and the delivery status.

Activity log

The app keeps a log of significant actions in a workspace — which user did what, and when — so that owners can review changes.

Partner directory

When you send a quote request to a partner, the contact details and message you enter.

Sessions, logs and rate limiting

While you are signed in, a session record holds your user ID, IP address, browser identification and the time of your last activity. Our web server writes standard access logs (IP address, time, address requested, referring page, browser identification). Application error logs can contain technical details of a failed request. We also use IP addresses for a few minutes at a time to enforce rate limits on sign-in, public links and hash lookups.

Billing data through Stripe

When a workspace owner subscribes, payment details are entered on pages hosted by Stripe. We never receive or store full card numbers or security codes. To create the Stripe customer we send Stripe the company name, contact e-mail address, country and language. From Stripe we receive the customer and subscription identifiers, the subscription status and tier, the payment method type and its last four digits, and access to the invoices and to the billing name, address and tax ID entered at checkout.

What we do not collect

We run no analytics, no advertising or tracking cookies, no tracking pixels, no fingerprinting and no social-media plug-ins. Fonts, scripts and styles are served from our own domain, so your browser does not contact third-party content networks when you load our pages. We do not buy personal data from anyone.

4. Why we use it and on what legal basis

Purposes and legal bases under Article 6(1) GDPR
Purpose Legal basis
Create and secure your account, run the app for you, send service e-mails (address verification, password reset, invitations) Performance of the contract, Art. 6(1)(b). Where you use the app as an employee of our customer: our legitimate interest in providing the service to your employer, Art. 6(1)(f).
Bill subscriptions, issue invoices, keep tax and accounting records Contract, Art. 6(1)(b), and legal obligation, Art. 6(1)(c).
Answer contact-form enquiries Steps before a contract at your request, Art. 6(1)(b); otherwise our legitimate interest in answering business enquiries, Art. 6(1)(f).
Keep the service secure: sessions, logs, rate limiting, spam filtering, abuse investigation Legitimate interest in a secure and reliable service, Art. 6(1)(f).
Establish, exercise or defend legal claims; comply with binding requests from authorities Legitimate interest, Art. 6(1)(f), and legal obligation, Art. 6(1)(c).
Process the content of a customer’s workspace (team, supplier and auditor details included) On the customer’s instructions as its processor. The customer decides on the legal basis.

You need to give us your name, e-mail address and a password to have an account; without them we cannot provide the service. Everything else you give us is up to you.

We do not send newsletters or marketing e-mails from the product.

5. Who receives personal data

  • Our service providers, listed with their purpose and location on the Sub-processors page. They act on our instructions under a contract.
  • Stripe, for payments. For some of what it does — fraud prevention and its own legal duties, for example — Stripe acts as a controller in its own right under its own privacy policy.
  • People our customers choose: other members of the workspace, suppliers and auditors who are sent a link, and the systems a customer’s webhooks point to.
  • Authorities and courts, where the law obliges us.
  • A buyer of the Karbonet business, under the same protections, if it is ever sold.

If a customer sends a quote request through the partner directory, we pass the details entered in that request to the partner the customer selected.

We do not sell personal data.

6. What is written to the blockchain

Karbonet anchors proofs on a blockchain network operated by third parties. Exactly this happens:

  • For each emission or offset record we calculate a SHA-256 hash from the record’s internal number, the workspace’s internal number, the activity type, the CO₂e amount, the activity date (for emission records) and the time the record was created.
  • For each generated report we calculate a SHA-256 hash from the report’s internal number, the workspace’s internal number, the report type, the period, the total CO₂e and a checksum of the PDF file.
  • Only the resulting 32-byte hash is sent to the smart contract, through a queued job that runs when anchoring is enabled and the network is reachable. Next to it the contract stores the block time and the address of Karbonet’s own signing wallet, which is the same for all customers.

No name, e-mail address, company name, amount, document, IP address or user identifier is written on-chain. The inputs to the hash are business figures and internal numbers, not contact details, and a hash cannot be turned back into its inputs. The blockchain network and the network access point we use receive the hash from our server — never from your browser.

An anchored hash is permanent. Nobody can erase it from the chain, including us. When data is deleted from Karbonet, the off-chain record is deleted and the hash that remains can no longer be linked to anything.

On the public verification page anyone who holds a hash can see whether it is anchored, on which network, in which transaction and block, and when. The page shows nothing about the workspace, the record or the amounts.

7. International transfers

ZincirX Inc. is a USA company. Personal data therefore comes under the control of a company outside the EEA and is processed where we and the providers on the Sub-processors page operate; that page states each provider’s location. We do not offer storage in a particular country.

The European Commission has not recognised the United States as providing adequate protection in general; its adequacy decision covers only companies certified under the EU–US Data Privacy Framework, and we make no claim to such a certification. We rely on these safeguards:

  • Where we process personal data for a customer in the EEA, the United Kingdom or Switzerland, our Data Processing Agreement incorporates the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914), with the additions required for the United Kingdom and Switzerland.
  • With our own providers we rely on the transfer safeguards in their data processing terms: an adequacy decision or a recognised certification where one applies to the recipient, and otherwise Standard Contractual Clauses.

You can ask for a copy of the relevant clauses at info@zincirx.com.

8. How long we keep it

Retention periods
Data Kept for
User account Until you delete your account or the workspace is deleted.
Workspace content, including supplier and auditor details and uploaded documents For as long as the workspace exists — also while it is read-only after a subscription has ended; we do not delete lapsed workspaces automatically. Deleted within 30 days of a verified deletion request from an owner.
Team invitations Valid for 7 days. The entry stays in the workspace until an owner removes it or the workspace is deleted.
Contact-form enquiries Up to 24 months after our last contact with you, unless the enquiry leads to a contract.
Session records A session expires 120 minutes after your last activity. Expired session records are purged by the app’s periodic clean-up.
Server and application logs Only as long as they are needed for security and troubleshooting.
Invoices and billing records For as long as the tax and accounting laws that apply to us require.
Blockchain anchors (hashes only) Permanently. They cannot be deleted.

9. Your rights

Under the GDPR you can ask us for access to your data, for correction, for deletion, for restriction of processing, and for a portable copy of the data you gave us. Where we rely on consent you can withdraw it at any time for the future.

Right to object: where we process your data on the basis of our legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation. We then stop, unless we have compelling legitimate grounds that override your interests or need the data for legal claims.

Write to info@zincirx.com. We may need to confirm your identity first. We answer within one month, as the GDPR requires; the law allows an extension for complex requests, and we will tell you if we need it. Exercising your rights is free of charge.

Some things you can do yourself: change your name, e-mail address and password, or delete your account, in Profile settings. If your request concerns data that a Karbonet customer holds about you in its workspace, that customer decides about it — contact them first.

10. Complaints to a supervisory authority

You have the right to complain to a data protection authority, in particular in the EU country where you live, where you work or where you think the infringement happened. The authorities are listed by the European Data Protection Board (otwiera się w nowej karcie). In Germany this is the data protection authority of your federal state. We would appreciate the chance to resolve your concern first: info@zincirx.com.

11. No automated decision-making

We do not make decisions about individuals by automated means and we do not profile anyone. The automated calculations in Karbonet — emissions, usage limits, projections — concern company data, not people.

12. Security

The measures we actually have in place are described, without embellishment, in the Data Processing Agreement.

13. Türkiye: information notice under the KVKK (aydınlatma metni)

This section is the information notice required by Article 10 of Law No. 6698 on the Protection of Personal Data (Kişisel Verilerin Korunması Kanunu, “KVKK”) for people in Türkiye.

Data controller (veri sorumlusu)

ZincirX Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Contact: info@zincirx.com.

For the content of a customer’s workspace, that customer is the data controller and we act as its data processor (veri işleyen).

Purposes of processing

We process the personal data described under “What we collect” above in order to: create and run user accounts; provide the carbon-accounting service; bill subscriptions and keep financial records; answer enquiries; and keep the service secure and prevent abuse.

Method of collection and legal grounds

We collect data electronically — through the forms and pages of the website and the app, through our API, from the customer that adds you to its workspace, and from Stripe for billing. The legal grounds under Article 5(2) KVKK are: processing is necessary for the conclusion or performance of a contract (5/2-c); it is necessary for us to comply with a legal obligation (5/2-ç); it is necessary to establish, exercise or protect a right (5/2-e); and it is necessary for our legitimate interests, provided your fundamental rights are not harmed (5/2-f). We do not ask for special categories of personal data.

Who receives the data, and transfers abroad

The recipients are those listed under “Who receives personal data” above, for the purposes stated there. Because ZincirX Inc. is a USA company, the personal data you give us is transferred abroad, and our service providers, listed with their locations on the Sub-processors page, are outside Türkiye as well. Where we transfer personal data abroad on behalf of a customer in Türkiye, the transfer is based on Article 9 KVKK. On request we sign the standard contract published by the Personal Data Protection Board with that customer.

Your rights under Article 11 KVKK

You have the right to:

  • learn whether your personal data is processed;
  • request information about the processing if it is;
  • learn the purpose of the processing and whether the data is used in line with that purpose;
  • know the third parties, in Türkiye or abroad, to whom the data is transferred;
  • request correction of incomplete or inaccurate data;
  • request erasure or destruction of the data under the conditions of Article 7 KVKK;
  • request that a correction, erasure or destruction be notified to the third parties to whom the data was transferred;
  • object to a result that is to your detriment and that arises from analysis of the data exclusively by automated systems;
  • claim compensation if you suffer damage because of unlawful processing.

How to apply

Send your request in Turkish or English to info@zincirx.com from the e-mail address registered on your account, or in writing to the postal address above. Include your full name, the right you wish to use and the details of your request, as set out in the Communiqué on the Principles and Procedures for Applications to the Data Controller. We answer free of charge as soon as possible and within thirty days at the latest. If answering causes additional cost, we may charge the fee in the tariff set by the Personal Data Protection Board.

If we reject your request, if you find our answer insufficient, or if we do not answer in time, you may complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) (otwiera się w nowej karcie) within thirty days of learning of our answer and in any case within sixty days of your application.

14. Cookies and browser storage

Karbonet sets only what it needs to work. There are no analytics, advertising or tracking cookies, and no third-party cookies on our pages. Because everything below is strictly necessary for a service you asked for, no consent is required and we do not show a cookie banner.

Cookies and browser storage used by Karbonet
Name What it is for Lifetime
greenledger-session Session cookie. Keeps you signed in and ties your form submissions to your browser session. Not readable by scripts (HTTP-only), marked Secure on the production site so that it is sent only over HTTPS, SameSite=Lax. 120 minutes after your last activity
XSRF-TOKEN Security token that protects forms and in-app requests against cross-site request forgery. Same as the session cookie
remember_web_… Only if you tick “Remember me” when you sign in. Keeps you signed in between visits. Up to 400 days. Removed when you sign out.
gl-theme (local storage, not a cookie) Remembers whether you chose the light or the dark theme. Written only when you use the theme switch. It stays in your browser and is never sent to us. Until you clear your browser’s site data

Fonts are served from our own domain, not from a font network.

Checkout and the billing portal run on Stripe’s own domains. When you go there, Stripe sets its own cookies under the Stripe Cookie Policy (otwiera się w nowej karcie). Our own pages do not embed Stripe scripts.

You can block or delete cookies in your browser settings. Without the session cookie and the security token you cannot sign in or send forms.

15. Changes to this policy

When the way we handle personal data changes, we update this page and the date at the top. We tell workspace owners by e-mail about changes that matter.

Masz pytania do tego dokumentu? Napisz na info@zincirx.com.

Pozostałe dokumenty prawne

  • Regulamin
  • Zwroty i anulowanie
  • Umowa powierzenia przetwarzania danych
  • Podprocesorzy
  • Dane firmy
Wróć na górę
🌱 Karbonet

Oparte na blockchainie śledzenie śladu węglowego dla MŚP. Zamień dane o emisjach w weryfikowalny dowód gotowy do audytu.

ZincirX Inc. 131 Continental Dr, Suite 305 Newark, DE 19713 USA info@zincirx.com

Produkt

  • Rozwiązanie
  • Cennik
  • Metodyka
  • Zweryfikuj zapis emisji
  • API
  • Partnerzy

Firma

  • Zespół
  • Kontakt
  • info@zincirx.com

Informacje prawne

  • Regulamin
  • Polityka prywatności
  • Zwroty i anulowanie
  • Umowa powierzenia przetwarzania danych
  • Podprocesorzy
  • Dane firmy
  • Pliki cookie

© 2026 ZincirX Inc. · Wszelkie prawa zastrzeżone.