Enterprise Agreement

Data Processing Addendum (DPA)

This Data Processing Addendum ('DPA') governs the processing of Customer Personal Data by Carbonatoz on behalf of Enterprise Tenant Customers, satisfying ISO/IEC 27701:2025 (Annex A.2), EU GDPR Article 28, and the Digital Personal Data Protection (DPDP) Act 2023.

Last updated 20 August 2026Frontend legal surface

1. Scope & Roles of the Parties

The parties acknowledge and agree that with respect to the processing of Customer Personal Data and Compliance Data inside the SaaS platform:

  • Customer is the Data Controller (or Data Fiduciary under the DPDP Act 2023) and retains sole determination over the purpose and scope of emissions activity data, facility configurations, and reporting parameters.
  • Carbonatoz is the Data Processor (or Data Fiduciary Service Provider) and processes Customer Data strictly on behalf of and pursuant to the documented instructions of the Customer.

2. Documented Instructions & Purpose Limitation

Carbonatoz shall process Customer Data exclusively to deliver, maintain, and secure the SaaS platform services as specified in the Master Subscription Agreement and this DPA.

  • No Secondary Use: Carbonatoz shall not sell, retain, disclose, or process Customer Data for marketing, advertising, or any purpose outside the contracted scope.
  • Strict AI Model Training Prohibition: Carbonatoz is contractually and architecturally prohibited from using Customer emissions inventories, confidential facility parameters, or uploaded documents to train, fine-tune, or benchmark public or proprietary artificial intelligence or machine learning models without express, written prior authorization.
  • Infringing Instructions: If Carbonatoz determines that any Customer instruction violates applicable data protection laws, Carbonatoz shall promptly notify the Customer in writing.

3. Technical & Organizational Security Safeguards

Carbonatoz implements and maintains rigorous technical and organizational measures (TOMs) designed to protect Customer Data against unauthorized access, destruction, loss, or alteration:

  • Multi-Tenant Isolation: Database-level tenant isolation policies enforce strict data segregation across tenant accounts.
  • Encryption: AES-256 encryption at rest across all databases, backups, and storage buckets; TLS 1.3 encryption in transit.
  • Access Controls: Strict Role-Based Access Control (RBAC), multi-factor authentication (MFA) enforcement for privileged roles, and session-bound CSRF protection.
  • Non-Repudiation Audit Logs: Immutable cryptographic audit trails record all calculation updates and statutory modifications.

4. Sub-Processor Engagement & Notification

Customer grants general written authorization for Carbonatoz to engage the sub-processors listed in the public Sub-Processor Directory.

  • Contractual Flow-Down: Carbonatoz imposes data protection obligations on each sub-processor no less protective than those in this DPA.
  • 30-Day Advance Notice:Carbonatoz shall provide at least thirty (30) calendar days' advance notice of any intended appointment of a new sub-processor.
  • Objection Mechanism: Customer may object to a new sub-processor on reasonable data protection grounds within fourteen (14) days of notice.

5. Security Incident & Breach Notification

In the event of a confirmed Personal Data Breach impacting Customer Data, Carbonatoz shall notify the Customer in writing without undue delay and in any event within **24 to 48 hours** of becoming aware of the incident.

The notification shall detail the nature of the breach, affected data categories, likely consequences, and remediation measures taken or planned.

6. Data Subject Rights Assistance

Taking into account the nature of the processing, Carbonatoz provides self-service platform tools (RBAC, export features, correction interfaces) to assist Customer in fulfilling its obligations to respond to data subject requests. If Carbonatoz receives a direct request from a data subject regarding tenant-held data, Carbonatoz shall promptly forward the request to the Customer's administrator.

7. Data Return, Deletion & Post-Termination Purge

Upon termination or expiration of the SaaS Agreement, Carbonatoz shall provide a 30-day window for the Customer to export all compliance and emissions records. Following the export window, Carbonatoz shall permanently and securely delete all Customer Data from production environments and backup archives within 90 days, unless statutory retention is required by applicable law.

8. Audits & Compliance Verification

Carbonatoz shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports (SOC 2 Type II, ISO 27001, ISO 27701) and security certifications, provided under executed confidentiality agreements.