How CarbonAtlas collects, uses, and protects your personal data.
Last updated: 20 April 2026
Entity notice: CarbonAtlas is currently operated by Ilumatra ArtIfice OÜ, incorporated in the Republic of Estonia (Reg. No. 17585418), an EU member state. Ilumatra ArtIfice OÜis the sole operating entity for the CarbonAtlas platform. As an EU-resident controller, CarbonAtlas does not require Standard Contractual Clauses for controller-level processing of EU personal data. See §9 below for sub-processor transfer details. Questions: connect@ilumatraartifice.com
⚠️ Legal Disclaimer: This Privacy Policy is provided for informational purposes. CarbonAtlas is a software platform operated by Ilumatra ArtIfice OÜ. This document has been drafted to reflect GDPR principles and should be reviewed by qualified legal counsel before reliance in a commercial or regulatory context.
CarbonAtlas is an EU Carbon Border Adjustment Mechanism (CBAM) compliance platform operated by Ilumatra ArtIfice OÜ, a private limited company incorporated in the Republic of Estonia (Reg. No. 17585418) ("we", "us", "our").
For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), Ilumatra ArtIfice OÜ acts as the Data Controllerfor personal data collected from users of the CarbonAtlas platform (GDPR Art. 3(2) — extra-territorial scope applies). Where we process data on behalf of your organisation, we act as a Data Processorin accordance with a separate Data Processing Agreement (DPA).
Contact: connect@ilumatraartifice.com
We collect the following categories of personal data:
Account Data
Usage Data
Compliance Data (Operator-specific)
Verification Data (Verifier-specific)
We process your personal data on the following legal bases under GDPR Article 6:
Achievers League: Only aggregated, non-personal SEE data is published on the public Achievers League. Operator organisations must explicitly opt in. No shipment records, liability amounts, or personal data are ever published.
We do not sell your personal data. We share data only:
| Data Category | Retention Period | Rationale |
|---|---|---|
| Account data | 7 years after account closure | EU accounting / audit requirements |
| Import records & SEE data | 10 years | CBAM Reg. 2023/956 audit trail requirement |
| Verification audit logs | 10 years | ISO 17029 accreditation record-keeping |
| Session / usage data | 12 months (anonymised after 30 days) | Security and fraud detection |
| Invite tokens | 48 hours | Single-use security tokens |
As a data subject, you have the following rights:
Right of Access (Art. 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your data (subject to legal retention obligations).
Right to Restriction (Art. 18)
Restrict processing of your data in certain circumstances.
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format.
Right to Object (Art. 21)
Object to processing based on legitimate interests.
To exercise any right, contact connect@ilumatraartifice.com. We will respond within 30 days. You also have the right to lodge a complaint with your national Data Protection Authority (DPA).
We implement appropriate technical and organisational measures to protect your data, including: AES-256 encryption at rest, TLS 1.3 in transit, multi-tenant data isolation (org-scoped queries — no cross-organisation data access without explicit mandate), SHA-256 tamper-evident audit hashing for verification records, JWT authentication with short-lived tokens, and regular penetration testing.
All customer data is hosted on infrastructure located within the EU/EEA. Ilumatra ArtIfice OÜ is incorporated in the Republic of Estonia, an EU member state, so controller-level processing of personal data does not constitute an international transfer under GDPR Chapter V and no Standard Contractual Clauses are required for that processing.
Some development and support work on the platform is performed under a separate service agreement by LimKnot ArtIfice Pvt Ltd (India), acting as a vendor/processorto Ilumatra ArtIfice OÜ. As of the date of this notice, that vendor's work does not involve access to live customer personal data. A copy of the applicable safeguards for this relationship is available on request at connect@ilumatraartifice.com.
Where data is also transferred to third-party sub-processors outside the EEA (e.g., Anthropic for AI processing, Stripe for billing), we ensure adequate safeguards via their own SCC or BCR frameworks as described in §5 above.
This section reflects Ilumatra ArtIfice OÜ's status as an EU-resident controller. It will be updated promptly if the scope of work performed by any non-EU vendor changes to include access to customer personal data.
We may update this Privacy Policy from time to time. Material changes will be notified to registered users via email and/or in-platform notification at least 30 days before taking effect. Continued use of CarbonAtlas after the effective date constitutes acceptance of the updated policy.
Data Controller
Ilumatra ArtIfice OÜ
Incorporated in Estonia (Reg. No. 17585418), operating the CarbonAtlas CBAM compliance platform for EU and global customers
Email: connect@ilumatraartifice.com
Platform: www.ilumatraartifice.com