Privacy Policy

Version 1.1 · Effective 2026-06-12 (supersedes v1.0 effective 2026-04-20)

This Privacy Policy explains how iTecBrains (“we”, “us”) processes personal data when you use the KarbonOS platform or visit karbonos.io. For the contractual processor terms that apply to our enterprise customers, see the Data Processing Agreement.

1. Who we are

The data controller is iTecBrains, operating the KarbonOS platform at karbonos.io. Contact: privacy@karbonos.io. If you are in the EU/EEA, you may also contact your local supervisory authority; we will provide the relevant details on request.

2. What personal data we collect

When you or your organisation uses KarbonOS we process:

  • Account data — name, work email, role, hashed password, MFA factors, and audit-log metadata (IP address, user agent) required to sign you in and keep the account secure.
  • Usage data — activity records, facility data, emission factors, period metadata, reports, and similar business data you enter or import. This is generally organisation data, not personal data, but it may include the name of a colleague or a supplier contact.
  • Supplier-contact data— when your organisation invites suppliers into the engagement workflow, we process the supplier contact's name and email on your behalf.
  • Communication data — support tickets, notifications, and email content you send to or receive from the platform.
  • Technical data — session cookies (strictly necessary), opt-in session-replay cookies for error diagnosis (only if you accept the analytics category in the cookie banner).

3. Lawful basis for processing

  • Contract (Art. 6(1)(b)) — account-related processing (login, service delivery, billing).
  • Legitimate interest (Art. 6(1)(f)) — security logging, rate-limiting, fraud prevention, service improvement. We weigh this against your rights; you may object at any time (§7).
  • Consent (Art. 6(1)(a)) — non-essential cookies (analytics, marketing) and any benchmarking opt-in. Consent is freely given and withdrawable from the Privacy settings page or the cookie banner.
  • Legal obligation (Art. 6(1)(c)) — retention of audit logs and financial records where required by tax, accounting, or assurance law.

4. How long we keep your data

Retention periods:

  • Account data — for the life of the account plus 30 days after closure.
  • Activity and emission data — the retention period configured by your organisation (between 5 and 25 years) under the Privacy settings. The default is 7 years to align with CSRD audit requirements.
  • Audit logs — minimum 12 months for SOC 2, otherwise per the organisation's retention setting.
  • Support tickets — 2 years after resolution.
  • Backups — rolling, maximum 90 days.
  • Marketing consent proof — duration of consent plus 3 years.

Expired data is purged by an automated retention job; see our internal record of processing activities.

5. Sub-processors

We share personal data only with the following sub-processors, each under a Data Processing Agreement. The Processor remains fully liable to the Controller for each Sub-processor's performance.

Currently in service:

  • Supabase — database, authentication, object storage
  • Vercel — application hosting and edge CDN
  • Upstash — rate-limit and short-lived session state
  • Anthropic + OpenAI — AI inference for natural-language queries, document extraction, supplier-outreach drafting. Supplier contact emails are redacted before inference (see FINDING-P003); zero-retention flags enabled where the provider supports them.
  • Trigger.dev — background-job orchestration (scheduled tasks, retries, dead-letter handling) for the workflows listed in our Documentation. Task payloads may contain identifying data named at §2 above.
  • Resend — transactional email delivery
  • Stripe — billing and payment processing
  • Sentry — error monitoring and observability

Being onboarded (will be added on activation):

  • External uptime probe vendor (UptimeRobot or Better Stack) — receives endpoint URLs and response codes only; no Personal Data flows to this Sub-processor.
  • Axiom — application log destination, ingests structured log lines that may include user IDs and action-audit metadata named at §2 above.
  • Grafana Cloud — dashboards over Axiom-sourced metrics; the dashboard surface itself stores no Personal Data beyond the metric series.

The full list with jurisdictions and contractual safeguards is in DPA §8.

6. Customer-elected integrations

Separately from our Sub-processors, your organisation may authorise KarbonOS to connect to third-party services via OAuth or API credential — for example, accounting platforms (Xero, QuickBooks Online, Sage, NetSuite, SAP Business One, SAP S/4HANA), banking aggregators (Plaid), utility data providers (Octopus Energy, Green Button issuers), expense and travel platforms (Expensify, Concur, Ramp), logistics carriers (DHL, Flexport), fleet telematics (Geotab, Samsara), workforce platforms (Google Workspace), and HR/payroll providers (ADP — which processes employee personal data as part of headcount-based emission calculations).

Each of those third parties is independently the data controller or processor for the data they hold under their own terms; they are not our Sub-processors. When you authorise a connection, you direct us to retrieve specific data categories on your behalf, and we encrypt the resulting OAuth credentials at the column level (AES-256-GCM) before storing them. You can revoke any connection from your Connectors settings page; revocation deletes our stored credentials and stops further data retrieval, though we retain the data already ingested per the retention settings in §4. If a customer-elected integration processes personal data covered by GDPR or CCPA (notably ADP for workforce data), the Controller is responsible for the legal basis of that processing under its own data-protection notices.

We do not sell or “share” personal information as those terms are defined by CCPA §1798.140(ad)(1) and (ah)(1). See California-specific rights in §7 below.

7. Your rights

Under GDPR and UK GDPR you have the right to:

  • Access — a copy of your personal data (Art. 15).
  • Rectification — correct inaccurate data (Art. 16).
  • Erasure — delete your data where one of the Art. 17 grounds applies.
  • Restriction — limit processing (Art. 18).
  • Portability — receive your data in a machine-readable format (Art. 20).
  • Objection — to processing based on legitimate interest (Art. 21).
  • Withdraw consent — at any time, without penalty, from the Privacy settings or cookie banner.
  • Lodge a complaint — with your supervisory authority.

To exercise any of these, email privacy@karbonos.io. We respond within 10 business days; the statutory window is 30 days and may be extended up to a further two months for complex requests (Art. 12(3)). You can also export a machine-readable copy of your data yourself at any time from Account → Export my data, and request erasure of your account (Art. 17) from Account → Delete my account. We retain audit-trail and financial records as required by law (Art. 17(3)(b)), anonymising your personal attribution within them. For other rights, email the address above or see the DPA §5.

7.1 California (CCPA / CPRA) rights

If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) gives you the following rights, in addition to those above. The categories of personal information we collect, the sources, purposes, and recipients are set out in §§2, 3, and 5 above.

  • Right to know — categories and specific pieces of personal information we have collected about you in the preceding 12 months, the sources, purposes of collection, and categories of third parties to whom we disclosed it.
  • Right to delete — request deletion of personal information we collected from you, subject to the statutory exceptions in CCPA §1798.105(d).
  • Right to correct — request correction of inaccurate personal information.
  • Right to limit use of sensitive personal information — we do not process sensitive personal information for purposes outside CCPA §1798.121(a), so this right is not engaged by our processing.
  • Right to opt out of sale or sharing— we do not sell or “share” personal information as those terms are defined by CCPA §1798.140(ad)(1) and (ah)(1). No opt-out mechanism is therefore required; this notice serves as the “Do Not Sell or Share My Personal Information” disclosure.
  • Right to non-discrimination — we will not deny services, charge different prices, or provide a different level of quality because you exercised any CCPA right.

To exercise these rights, email privacy@karbonos.io directly or submit through an authorised agent (who must provide a written authorisation signed by you; we will verify the agent's authority per CCPA §1798.135(c)). We verify identity by matching account-of-record details and may request additional information for high-risk requests. Response window: 45 days, with one possible 45-day extension on notice per CCPA §1798.130(a)(2).

8. International transfers

Where personal data is transferred outside the EU/EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) and the UK International Data Transfer Addendum. Transfer Impact Assessments are available on request for enterprise customers.

9. Cookies

We use strictly-necessary cookies (session, CSRF) that do not require consent. If you accept the analytics category in our cookie banner, we use Sentry Session Replay — redacted text and blocked media — to reproduce errors you encounter. You can change your preferences any time from the cookie banner at the bottom of the page or by clearing local storage for this site.

10. Children

KarbonOS is a B2B product and is not directed at children. We do not knowingly collect personal data from anyone under 16.

11. Changes to this policy

We will update this policy when processing changes or regulations evolve. Material changes are surfaced via a re-prompt of the cookie banner and, for enterprise customers, an advance notice per DPA §4.

12. Contact

Questions about this policy or your personal data: privacy@karbonos.io.