Enterprise Agreement
This Data Processing Addendum ('DPA') governs the processing of Customer Personal Data by Carbonatoz on behalf of Enterprise Tenant Customers, satisfying ISO/IEC 27701:2025 (Annex A.2), EU GDPR Article 28, and the Digital Personal Data Protection (DPDP) Act 2023.
The parties acknowledge and agree that with respect to the processing of Customer Personal Data and Compliance Data inside the SaaS platform:
Carbonatoz shall process Customer Data exclusively to deliver, maintain, and secure the SaaS platform services as specified in the Master Subscription Agreement and this DPA.
Carbonatoz implements and maintains rigorous technical and organizational measures (TOMs) designed to protect Customer Data against unauthorized access, destruction, loss, or alteration:
Customer grants general written authorization for Carbonatoz to engage the sub-processors listed in the public Sub-Processor Directory.
In the event of a confirmed Personal Data Breach impacting Customer Data, Carbonatoz shall notify the Customer in writing without undue delay and in any event within **24 to 48 hours** of becoming aware of the incident.
The notification shall detail the nature of the breach, affected data categories, likely consequences, and remediation measures taken or planned.
Taking into account the nature of the processing, Carbonatoz provides self-service platform tools (RBAC, export features, correction interfaces) to assist Customer in fulfilling its obligations to respond to data subject requests. If Carbonatoz receives a direct request from a data subject regarding tenant-held data, Carbonatoz shall promptly forward the request to the Customer's administrator.
Upon termination or expiration of the SaaS Agreement, Carbonatoz shall provide a 30-day window for the Customer to export all compliance and emissions records. Following the export window, Carbonatoz shall permanently and securely delete all Customer Data from production environments and backup archives within 90 days, unless statutory retention is required by applicable law.
Carbonatoz shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports (SOC 2 Type II, ISO 27001, ISO 27701) and security certifications, provided under executed confidentiality agreements.