How CarbonAtlas processes personal data as a data processor on behalf of your organisation, in accordance with Article 28 of the General Data Protection Regulation (EU) 2016/679.
Last updated: 20 April 2026
Entity notice: CarbonAtlas is operated by Ilumatra ArtIfice OÜ, incorporated in the Republic of Estonia (Reg. No. 17585418), acting as data controller / processoron behalf of EU customers as an EU-resident entity. For questions about this entity structure, contact connect@ilumatraartifice.com
About this document: This page summarises the data processing terms that apply to your use of CarbonAtlas. It is not a substitute for a signed Data Processing Agreement. Enterprise and regulated customers requiring an executed DPA should contact connect@ilumatraartifice.com.
When you use CarbonAtlas to manage CBAM compliance data, your organisation acts as the data controllerwith respect to the personal data you upload or generate within the platform (e.g. user accounts, supplier contacts, verifier communications). CarbonAtlas processes this data solely on your documented instructions, for the purpose of providing the CarbonAtlas service.
This section describes the respective GDPR obligations of each party and does not alter the allocation of responsibility set out in your organisation's Terms of Service or any executed Data Processing Agreement.
Data Controller (Your Organisation)
Data Processor (CarbonAtlas / Ilumatra ArtIfice OÜ)
| Element | Detail |
|---|---|
| Duration of processing | For the duration of the subscription agreement, plus any retention period required by applicable regulation (e.g. CBAM record-keeping obligations) or requested by the controller |
| Nature of processing | Collection, storage, structuring, retrieval, and secure transmission of data supporting CBAM emissions reporting, verification, and declaration workflows |
| Purpose of processing | Provision of the CarbonAtlas CBAM compliance platform, including import record management, embedded emissions calculation, verifier engagement, and declaration export |
| Categories of data subjects | Employees and authorised users of the controller, supplier and operator organisation contacts, verifier organisation contacts, and agent/customs broker contacts |
| Types of personal data | Name, business email address, organisation, job role, login credentials, and audit trail metadata (IP address, timestamp of actions) |
| Special category data | None. CarbonAtlas does not knowingly process special category data as defined under Article 9 GDPR |
CarbonAtlas implements the following measures to protect personal data against unauthorised access, loss, or disclosure, in line with Article 32 GDPR:
Encryption
Data encrypted in transit (TLS 1.2+) and at rest; sensitive fields (PII, credentials, API keys) additionally encrypted at the field level
Access Control
Role-based access control enforced at the backend; multi-tenant data is org-scoped at the query level, never relying on UI filtering alone
Audit Trails
Immutable, append-only audit log recording all significant state transitions, including who performed an action, when, and to whose data
Data Isolation
Cross-organisation access (verifiers, agents, auditors) requires an explicit, auditable engagement or mandate with an invitation, acceptance, and revocation lifecycle
Breach Response
Documented incident response procedure with controller notification within 72 hours of becoming aware of a qualifying personal data breach
Penetration Testing
Regular vulnerability assessment and penetration testing of the platform infrastructure and application layer
CarbonAtlas engages the following sub-processors to deliver the service. Each sub-processor is bound by data protection terms consistent with this Agreement.
| Sub-Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| LimKnot ArtIfice Pvt Ltd (India) | Software development and technical support vendor, under contract to Ilumatra ArtIfice OÜ; does not currently have access to live customer or personal data | India | EU Standard Contractual Clauses (SCCs); formal DPA with this vendor pending |
| Cloud Infrastructure Provider | Application hosting, database, and file storage | European Union | Data residency within the EU; provider's own GDPR-compliant Data Processing Addendum |
| Anthropic | AI-assisted document extraction (Mill Test Certificates, evidence documents) and classification features | United States | EU Standard Contractual Clauses (SCCs); no customer data used for model training |
| Stripe / Razorpay | Subscription billing and payment processing | United States / India | PCI DSS Level 1 certified; EU Standard Contractual Clauses (SCCs) |
| Email Delivery Provider | Transactional notifications and, where configured, per-organisation SMTP relay | European Union / United States | TLS-encrypted delivery; EU Standard Contractual Clauses (SCCs) where applicable |
CarbonAtlas assists the controller in fulfilling its obligations to respond to data subject requests exercising their rights under Chapter III of the GDPR, including:
Where personal data is transferred outside the European Economic Area, CarbonAtlas relies on the following safeguards in accordance with Chapter V of the GDPR:
LimKnot ArtIfice Pvt Ltd (India), dev vendor
EU Standard Contractual Clauses (SCCs), 2021/914/EU, incorporating supplementary technical and organisational measures; formal DPA with this vendor pending
Note: primary application data is hosted within the European Union. This vendor performs software development and support work for Ilumatra ArtIfice OÜ under a separate commercial service agreement and does not currently have access to live customer or personal data.
Anthropic (United States)
EU Standard Contractual Clauses (SCCs); Anthropic does not retain or train on customer data submitted via the API
Stripe (United States)
EU Standard Contractual Clauses (SCCs); PCI DSS Level 1 certified payment processing
CarbonAtlas retains personal data only for as long as necessary to provide the service and to meet applicable legal and regulatory obligations, including:
CarbonAtlas maintains a current list of sub-processors and will notify controllers of any intended changes, giving the controller the opportunity to object:
Need an executed Data Processing Agreement?
Enterprise, regulated, and Big 4-audited customers may request a fully executed Data Processing Agreement incorporating the EU Standard Contractual Clauses. Our legal team will respond within 2 business days.
Request a Signed DPAPlease include your organisation's legal name, registered address, and the name of your designated data protection contact.
Data Controller Contact — Ilumatra ArtIfice OÜ
Ilumatra ArtIfice OÜ
Incorporated in Estonia (Reg. No. 17585418), operating the CarbonAtlas CBAM compliance platform for EU and global customers
Privacy enquiries: connect@ilumatraartifice.com
Legal enquiries: connect@ilumatraartifice.com
Website: www.ilumatraartifice.com