Back to CarbonAtlas

GDPR Data Processing Agreement

How CarbonAtlas processes personal data as a data processor on behalf of your organisation, in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679.

Last updated: 20 April 2026

Entity notice: CarbonAtlas is operated by Ilumatra ArtIfice OÜ, incorporated in the Republic of Estonia (Reg. No. 17585418), acting as data controller / processoron behalf of EU customers as an EU-resident entity. For questions about this entity structure, contact connect@ilumatraartifice.com

About this document: This page summarises the data processing terms that apply to your use of CarbonAtlas. It is not a substitute for a signed Data Processing Agreement. Enterprise and regulated customers requiring an executed DPA should contact connect@ilumatraartifice.com.

1. Controller and Processor Roles

When you use CarbonAtlas to manage CBAM compliance data, your organisation acts as the data controllerwith respect to the personal data you upload or generate within the platform (e.g. user accounts, supplier contacts, verifier communications). CarbonAtlas processes this data solely on your documented instructions, for the purpose of providing the CarbonAtlas service.

This section describes the respective GDPR obligations of each party and does not alter the allocation of responsibility set out in your organisation's Terms of Service or any executed Data Processing Agreement.

2. Roles and Responsibilities

Data Controller (Your Organisation)

  • Determines the purposes and means of processing personal data within CarbonAtlas
  • Ensures a lawful basis exists for all personal data uploaded to the platform
  • Manages user access, roles, and permissions for its own organisation
  • Responds to data subject rights requests concerning its own personal data
  • Notifies CarbonAtlas without undue delay of any changes to processing instructions

Data Processor (CarbonAtlas / Ilumatra ArtIfice OÜ)

  • Processes personal data only on the documented instructions of the controller
  • Implements appropriate technical and organisational security measures (see Section 4)
  • Ensures personnel authorised to process personal data are bound by confidentiality obligations
  • Assists the controller in responding to data subject rights requests
  • Notifies the controller without undue delay upon becoming aware of a personal data breach
  • Deletes or returns all personal data at the end of the contractual relationship, upon request

3. Details of Processing

ElementDetail
Duration of processingFor the duration of the subscription agreement, plus any retention period required by applicable regulation (e.g. CBAM record-keeping obligations) or requested by the controller
Nature of processingCollection, storage, structuring, retrieval, and secure transmission of data supporting CBAM emissions reporting, verification, and declaration workflows
Purpose of processingProvision of the CarbonAtlas CBAM compliance platform, including import record management, embedded emissions calculation, verifier engagement, and declaration export
Categories of data subjectsEmployees and authorised users of the controller, supplier and operator organisation contacts, verifier organisation contacts, and agent/customs broker contacts
Types of personal dataName, business email address, organisation, job role, login credentials, and audit trail metadata (IP address, timestamp of actions)
Special category dataNone. CarbonAtlas does not knowingly process special category data as defined under Article 9 GDPR

4. Technical and Organisational Security Measures

CarbonAtlas implements the following measures to protect personal data against unauthorised access, loss, or disclosure, in line with Article 32 GDPR:

Encryption

Data encrypted in transit (TLS 1.2+) and at rest; sensitive fields (PII, credentials, API keys) additionally encrypted at the field level

Access Control

Role-based access control enforced at the backend; multi-tenant data is org-scoped at the query level, never relying on UI filtering alone

Audit Trails

Immutable, append-only audit log recording all significant state transitions, including who performed an action, when, and to whose data

Data Isolation

Cross-organisation access (verifiers, agents, auditors) requires an explicit, auditable engagement or mandate with an invitation, acceptance, and revocation lifecycle

Breach Response

Documented incident response procedure with controller notification within 72 hours of becoming aware of a qualifying personal data breach

Penetration Testing

Regular vulnerability assessment and penetration testing of the platform infrastructure and application layer

5. Sub-Processors

CarbonAtlas engages the following sub-processors to deliver the service. Each sub-processor is bound by data protection terms consistent with this Agreement.

Sub-ProcessorPurposeLocationSafeguard
LimKnot ArtIfice Pvt Ltd (India)Software development and technical support vendor, under contract to Ilumatra ArtIfice OÜ; does not currently have access to live customer or personal dataIndiaEU Standard Contractual Clauses (SCCs); formal DPA with this vendor pending
Cloud Infrastructure ProviderApplication hosting, database, and file storageEuropean UnionData residency within the EU; provider's own GDPR-compliant Data Processing Addendum
AnthropicAI-assisted document extraction (Mill Test Certificates, evidence documents) and classification featuresUnited StatesEU Standard Contractual Clauses (SCCs); no customer data used for model training
Stripe / RazorpaySubscription billing and payment processingUnited States / IndiaPCI DSS Level 1 certified; EU Standard Contractual Clauses (SCCs)
Email Delivery ProviderTransactional notifications and, where configured, per-organisation SMTP relayEuropean Union / United StatesTLS-encrypted delivery; EU Standard Contractual Clauses (SCCs) where applicable

6. Data Subject Rights

CarbonAtlas assists the controller in fulfilling its obligations to respond to data subject requests exercising their rights under Chapter III of the GDPR, including:

  • Right of access — data subjects may request confirmation of, and access to, their personal data
  • Right to rectification — inaccurate personal data can be corrected via account settings or by contacting the controller
  • Right to erasure — personal data can be deleted upon a valid request, subject to any applicable regulatory retention obligations
  • Right to data portability — personal data can be exported in a structured, commonly used, machine-readable format

7. International Data Transfers

Where personal data is transferred outside the European Economic Area, CarbonAtlas relies on the following safeguards in accordance with Chapter V of the GDPR:

LimKnot ArtIfice Pvt Ltd (India), dev vendor

EU Standard Contractual Clauses (SCCs), 2021/914/EU, incorporating supplementary technical and organisational measures; formal DPA with this vendor pending

Note: primary application data is hosted within the European Union. This vendor performs software development and support work for Ilumatra ArtIfice OÜ under a separate commercial service agreement and does not currently have access to live customer or personal data.

Anthropic (United States)

EU Standard Contractual Clauses (SCCs); Anthropic does not retain or train on customer data submitted via the API

Stripe (United States)

EU Standard Contractual Clauses (SCCs); PCI DSS Level 1 certified payment processing

8. Data Retention and Deletion

CarbonAtlas retains personal data only for as long as necessary to provide the service and to meet applicable legal and regulatory obligations, including:

  • For the duration of the active subscription, personal data is retained to support ongoing CBAM declaration and audit functionality
  • CBAM-related records are retained in line with regulatory record-keeping requirements under EU Regulation 2023/956 and its implementing acts
  • Upon termination of the agreement, personal data is deleted or returned to the controller within 90 days, unless a longer retention period is required by law
  • Audit log entries are retained in accordance with SOC 2 and regulatory audit trail requirements, with personal identifiers pseudonymised where legally permissible

9. Sub-Processor Changes

CarbonAtlas maintains a current list of sub-processors and will notify controllers of any intended changes, giving the controller the opportunity to object:

  • Notice of any new sub-processor or replacement of an existing sub-processor will be provided at least 30 days in advance
  • Controllers may object to a proposed sub-processor on reasonable data protection grounds within the notice period
  • The current sub-processor list is published on this page and updated whenever a change takes effect

10. Request a Signed DPA

Need an executed Data Processing Agreement?

Enterprise, regulated, and Big 4-audited customers may request a fully executed Data Processing Agreement incorporating the EU Standard Contractual Clauses. Our legal team will respond within 2 business days.

Request a Signed DPA

Please include your organisation's legal name, registered address, and the name of your designated data protection contact.

11. Contact Information

Data Controller Contact — Ilumatra ArtIfice OÜ

Ilumatra ArtIfice OÜ

Incorporated in Estonia (Reg. No. 17585418), operating the CarbonAtlas CBAM compliance platform for EU and global customers

Privacy enquiries: connect@ilumatraartifice.com

Legal enquiries: connect@ilumatraartifice.com

Website: www.ilumatraartifice.com