Data Processing Agreement

Version 1.1 · Effective 2026-06-12 (supersedes v1.0 effective 2026-04-20)

This agreement governs KarbonOS's processing of personal data on behalf of its Customers under Article 28 of the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1. Parties

“Processor” means iTecBrains, operating the KarbonOS platform at karbonos.io. “Controller” means the Customer using the Platform under a separate Master Subscription Agreement (MSA). “Data Subject” means an identified or identifiable natural person whose Personal Data is processed by the Processor on behalf of the Controller.

2. Subject matter + duration

This DPA applies for the term of the underlying MSA and for the period required by applicable law for the return or deletion of Personal Data following termination.

3. Nature and purpose of processing

Processor processes Personal Data to provide greenhouse-gas accounting, carbon inventory reporting, and regulatory disclosure services as described in the Documentation. Categories processed include: (a) identifying data (name, work email, role) of Customer users; (b) identifying data of supplier contacts invited by the Controller into the supplier-engagement workflow; (c) activity and spend data submitted by Controller users for emission calculation.

4. Processor obligations

5. Data-subject rights assistance

The Processor assists the Controller with Data Subject requests (Articles 15 right of access, 16 rectification, 17 erasure, 18 restriction, 20 portability) through a manual process initiated via privacy@karbonos.io. The Processor will respond to a verified request within 10 business days with either the requested data or a written reason for delay (permitted by Article 12(3) GDPR for up to two additional months). This manual process satisfies the Processor's obligation under Article 28(3)(e) GDPR to assist the Controller by appropriate technical and organisational measures. Self-serve export and deletion endpoints are on the Processor's product roadmap; their availability date will be announced via the change-notification mechanism described at §4 above, and their introduction will not reduce the standard or scope of Processor assistance below the manual baseline in this §5.

6. Breach notification

The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach concerning Personal Data processed under this DPA. Notice includes the nature of the breach, the approximate number of Data Subjects and records concerned, likely consequences, and the measures taken or proposed to mitigate adverse effects.

7. Technical and organisational measures

The Processor implements the following measures, with detail published at karbonos.io/security:

8. Sub-processors

8.1 Current Sub-processors as of the Effective Date:

8.2 Sub-processors currently being onboarded (notified here in advance per §4 obligation):

8.3 Customer-elected integrations (not Sub-processors):

Where the Controller authorises an OAuth or API connection to a third-party service through the Platform — including accounting platforms (Xero, QuickBooks Online, Sage, NetSuite, SAP Business One, SAP S/4HANA), banking aggregators (Plaid), utility data providers (Octopus Energy, Green Button issuers), expense and travel platforms (Expensify, Concur, Ramp), logistics carriers (DHL, Flexport), fleet telematics (Geotab, Samsara), workforce platforms (Google Workspace), and HR/payroll providers (ADP) — those third parties are independently Controller or Processor for the data they hold under their own contracts with the Controller and are notSub-processors of iTecBrains under this DPA. The Processor retrieves data from them on the Controller's documented instruction and stores any resulting OAuth credentials encrypted at the column level (AES-256-GCM) per §7 above.

The Processor remains fully liable to the Controller for the performance of each Sub-processor named in §8.1 and §8.2.

9. International transfers

Where Personal Data is transferred from the EU/EEA, UK, or Switzerland to a country not deemed adequate, transfers are governed by the Standard Contractual Clauses adopted by the European Commission under Implementing Decision (EU) 2021/914, with the UK International Data Transfer Addendum where applicable.

10. Audits

The Processor makes available all information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The Controller bears the reasonable cost of such audits; no more than once per twelve-month period, except following a Personal Data Breach.

11. Termination

On termination of the MSA, the Processor will, at the Controller's written instruction, return or delete all Personal Data within 30 days. Backups are purged on the usual rolling schedule (maximum 90 days). A certificate of deletion is provided on request.

12. Contact

Questions or execution of this DPA: privacy@karbonos.io.

This template is provided for Controllers to execute alongside the MSA. A Controller-specific counter-signed copy may be issued on request.