Data Processing Agreement
Son güncelleme:
This Data Processing Agreement (“DPA”) is part of the Terms of Service. It applies whenever ZincirX Inc. processes personal data on behalf of a customer and the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection or the Turkish KVKK applies to that processing. It takes effect when you accept the Terms; no signature is needed. If you need a countersigned copy, write to info@zincirx.com.
Bu belge yalnızca İngilizce olarak sunulmaktadır.
1. Roles and scope of the processing
You are the controller (or a processor acting for your own client). We are your processor.
| Item | Description |
|---|---|
| Subject matter and purpose | Hosting and operating the Karbonet workspace so that you can record activity data, calculate emissions, collect supplier figures, give auditors access and generate reports. |
| Duration | The term of your trial or subscription, plus the read-only period afterwards, until the workspace is deleted. |
| Nature of the processing | Storage, retrieval, calculation, display, transmission to the recipients you choose, and deletion. |
| Categories of data subjects | Your users and invited team members; contact persons at your suppliers; your auditors and verifiers; anyone mentioned in free-text fields or documents you upload. |
| Types of personal data | Names, business e-mail addresses, roles, records of actions taken in the workspace, and whatever personal data your free-text entries and uploaded documents contain. No special categories of data — the Terms prohibit uploading them. |
Your own account, billing and contact data are not covered by this DPA. For those we are a controller, as described in the Privacy Policy.
2. Your instructions
We process the personal data only on your documented instructions. The Terms, this DPA and the way you use and configure the service are your instructions. If the law requires us to process the data in another way, we tell you first unless that law forbids it. If we believe an instruction breaks data protection law, we tell you.
3. Confidentiality
Only people who need access to do their work have it, and they are bound to confidentiality.
4. Security measures
Under Article 32 GDPR we maintain the technical and organisational measures below. The list is deliberately limited to what is in place today.
- Encryption in transit: the production site is served over HTTPS, and the session cookie is flagged Secure, HTTP-only and SameSite=Lax.
- Passwords are stored only as one-way bcrypt hashes. E-mail addresses must be verified before the app can be used. Sign-in attempts are rate-limited.
- Tenant separation: all workspaces share one database, every workspace record carries the workspace’s identifier, and the app and the API filter every query by the workspace of the signed-in user or token.
- Role-based access: owner and member roles inside a workspace, with team and billing management reserved for owners, and a separate administrator role for our own staff.
- API tokens are stored only as SHA-256 hashes and shown once. Each token is scoped to read, or to read and write. API requests are rate-limited.
- Supplier, invitation and auditor links use long random tokens and are rate-limited. Auditor links are read-only, expire and can be revoked.
- Webhook signing secrets are encrypted in the database. Outgoing webhooks are signed with HMAC-SHA-256, and webhook destinations must resolve to public internet addresses.
- All forms are protected against cross-site request forgery. Incoming payment notifications from Stripe are checked against Stripe’s webhook signature.
- Uploaded proof documents and generated reports are kept in private storage outside the public web root and are not published under a public web address. Downloads go through the app’s access checks.
- The application’s database account can connect only from the application server itself.
- The blockchain signing key is held by a separate service that listens only on the server’s internal interface, requires a shared secret and receives nothing but the hash and the network details.
- Card data never reaches our servers. It is entered on Stripe’s pages.
- Credentials and keys are kept in server-side environment files that are excluded from the code repository and from deployments.
5. Sub-processors
You give us general authorisation to use sub-processors. The current ones are listed on the Sub-processors page. We bind each of them by contract to data protection duties equivalent to those in this DPA, and we remain responsible to you for what they do.
Before a new sub-processor starts processing your personal data, we update that page and e-mail workspace owners at least 30 days in advance. You may object within that time on reasonable data protection grounds. If we cannot resolve your objection, you may cancel the affected subscription and we refund the prepaid fees for the unused period.
6. Helping you meet your duties
The app lets you correct, export and delete most data yourself. Beyond that, and taking into account the nature of the processing, we help you with reasonable means to answer requests from data subjects, to carry out data protection impact assessments and to consult supervisory authorities. If a data subject contacts us about your data, we pass the request on to you and do not answer it ourselves.
7. Personal data breaches
If we become aware of a personal data breach that affects your data, we notify the workspace owners without undue delay. We tell you what we know about what happened, which data is affected and what we are doing about it, and we update you as we learn more, so that you can meet your own notification duties.
8. International transfers
We are a USA company, so using Karbonet means transferring personal data to a third country.
- EEA: the Standard Contractual Clauses in the Annex to Commission Implementing Decision (EU) 2021/914 are incorporated into this DPA by reference — Module Two where you are a controller, Module Three where you are a processor. You are the data exporter and ZincirX Inc. is the data importer. The optional docking clause (Clause 7) applies. Under Clause 9, Option 2 (general written authorisation) applies with the notice period stated above. The optional wording in Clause 11 does not apply. For Clauses 17 and 18 the clauses are governed by the law of, and disputes go to the courts of, the EU member state in which you are established, or Ireland if you are not established in a member state. The competent supervisory authority is the one responsible for you. Annex I is completed by the section “Roles and scope of the processing”, Annex II by the section “Security measures”, and Annex III by the Sub-processors page.
- United Kingdom: the UK International Data Transfer Addendum issued by the Information Commissioner applies to transfers subject to the UK GDPR, with the information above completing its tables.
- Switzerland: for transfers subject to the Swiss Federal Act on Data Protection, references in the clauses to the GDPR are read as references to that act, and the Federal Data Protection and Information Commissioner is the competent authority.
- Türkiye: where Article 9 KVKK requires it, we sign the standard contract published by the Personal Data Protection Board with you on request, so that you can notify it to the Board.
If these clauses conflict with the rest of this DPA or the Terms, the clauses prevail.
9. Return and deletion
You can export your data at any time, including while the workspace is read-only after your subscription has ended. When an owner asks us to delete the workspace, we delete the personal data in it within 30 days of verifying the request, unless a law requires us to keep it.
Blockchain anchors cannot be deleted. They consist of hashes only and contain no personal data — see “What is written to the blockchain” in the Privacy Policy.
10. Information and audits
On request we give you the information you need to show that Article 28 GDPR is complied with, and once a year we answer a reasonable written security questionnaire. If that is not enough to meet a legal duty, or if a supervisory authority requires it, you or an independent auditor bound to confidentiality may carry out an audit: with at least 30 days’ notice, during business hours, at your cost, and without access to other customers’ data.
11. Liability and order of precedence
The limits of liability in the Terms apply to this DPA as far as the law allows; they do not limit what either of us owes to data subjects or authorities under data protection law. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails.
12. Getting a signed copy
This DPA binds both of us without signatures. If your procurement or your auditor needs a countersigned copy, write to info@zincirx.com from the workspace owner’s address with your company’s legal name and address and the name and title of your signatory. We send you a PDF of this version to countersign.