Back to CarbonAtlas

Privacy Policy

How CarbonAtlas collects, uses, and protects your personal data.

Last updated: 20 April 2026

Entity notice: CarbonAtlas is currently operated by Ilumatra ArtIfice OÜ, incorporated in the Republic of Estonia (Reg. No. 17585418), an EU member state. Ilumatra ArtIfice OÜis the sole operating entity for the CarbonAtlas platform. As an EU-resident controller, CarbonAtlas does not require Standard Contractual Clauses for controller-level processing of EU personal data. See §9 below for sub-processor transfer details. Questions: connect@ilumatraartifice.com

⚠️ Legal Disclaimer: This Privacy Policy is provided for informational purposes. CarbonAtlas is a software platform operated by Ilumatra ArtIfice OÜ. This document has been drafted to reflect GDPR principles and should be reviewed by qualified legal counsel before reliance in a commercial or regulatory context.

1. Who We Are

CarbonAtlas is an EU Carbon Border Adjustment Mechanism (CBAM) compliance platform operated by Ilumatra ArtIfice OÜ, a private limited company incorporated in the Republic of Estonia (Reg. No. 17585418) ("we", "us", "our").

For the purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), Ilumatra ArtIfice OÜ acts as the Data Controllerfor personal data collected from users of the CarbonAtlas platform (GDPR Art. 3(2) — extra-territorial scope applies). Where we process data on behalf of your organisation, we act as a Data Processorin accordance with a separate Data Processing Agreement (DPA).

Contact: connect@ilumatraartifice.com

2. What Personal Data We Collect

We collect the following categories of personal data:

Account Data

  • Full name
  • Work email address
  • Organisation name, type, and EORI number
  • Role within your organisation (ADMIN, DATA_ENTRY, VIEWER)

Usage Data

  • Login timestamps and session data
  • Pages visited and features used within the platform
  • IP address (anonymised after 30 days)
  • Browser type and operating system

Compliance Data (Operator-specific)

  • Specific Embedded Emissions (SEE) data submitted by operators
  • Installation and process chain records
  • Mill Test Certificate documents (processed by AI OCR)

Verification Data (Verifier-specific)

  • Accreditation details and EORI number
  • Engagement mandate records
  • Verification audit trail data

3. Legal Basis for Processing

We process your personal data on the following legal bases under GDPR Article 6:

  • Contract (Art. 6(1)(b)): Processing necessary to provide the CarbonAtlas service and fulfil our Terms of Service.
  • Legal Obligation (Art. 6(1)(c)): Processing required to comply with EU CBAM Regulation (EU) 2023/956 and applicable data retention laws.
  • Legitimate Interests (Art. 6(1)(f)): Platform security, fraud prevention, and product analytics (anonymised).
  • Consent (Art. 6(1)(a)): Marketing communications (where separately collected and revocable at any time).

4. How We Use Your Data

  • Provide, operate, and improve the CarbonAtlas platform
  • Process CBAM import records and calculate Specific Embedded Emissions (SEE)
  • Enable operator data sharing workflows (with explicit consent per mandate)
  • Facilitate ISO 17029 verifier engagement and audit trails
  • Generate and export EU IR 2023/1773 compliant CBAM declaration XML
  • Send platform notifications and compliance reminders
  • Respond to support requests
  • Detect and prevent fraud and unauthorised access

Achievers League: Only aggregated, non-personal SEE data is published on the public Achievers League. Operator organisations must explicitly opt in. No shipment records, liability amounts, or personal data are ever published.

5. Data Sharing and Third Parties

We do not sell your personal data. We share data only:

  • With your explicit consent: Cross-organisation data sharing (e.g., operator SEE data shared with importers via Data Request Portal) requires explicit invitation and acceptance.
  • Service Providers: Cloud hosting (ISO 27001-certified), AI processing (Anthropic Claude Vision for OCR — data is not stored or trained on), and email delivery services. All bound by GDPR-compliant Data Processing Agreements. Certain software development work on the Platform is additionally performed under contract by LimKnot ArtIfice Pvt Ltd (India), acting as a data processor / sub-processor under a separate commercial service agreement; this vendor relationship does not currently involve access to live customer or personal data.
  • Legal Requirements: Where required by law, court order, or regulatory authority.

6. Data Retention

Data CategoryRetention PeriodRationale
Account data7 years after account closureEU accounting / audit requirements
Import records & SEE data10 yearsCBAM Reg. 2023/956 audit trail requirement
Verification audit logs10 yearsISO 17029 accreditation record-keeping
Session / usage data12 months (anonymised after 30 days)Security and fraud detection
Invite tokens48 hoursSingle-use security tokens

7. Your Rights Under GDPR

As a data subject, you have the following rights:

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

Request deletion of your data (subject to legal retention obligations).

Right to Restriction (Art. 18)

Restrict processing of your data in certain circumstances.

Right to Portability (Art. 20)

Receive your data in a structured, machine-readable format.

Right to Object (Art. 21)

Object to processing based on legitimate interests.

To exercise any right, contact connect@ilumatraartifice.com. We will respond within 30 days. You also have the right to lodge a complaint with your national Data Protection Authority (DPA).

8. Security

We implement appropriate technical and organisational measures to protect your data, including: AES-256 encryption at rest, TLS 1.3 in transit, multi-tenant data isolation (org-scoped queries — no cross-organisation data access without explicit mandate), SHA-256 tamper-evident audit hashing for verification records, JWT authentication with short-lived tokens, and regular penetration testing.

9. International Transfers

All customer data is hosted on infrastructure located within the EU/EEA. Ilumatra ArtIfice OÜ is incorporated in the Republic of Estonia, an EU member state, so controller-level processing of personal data does not constitute an international transfer under GDPR Chapter V and no Standard Contractual Clauses are required for that processing.

Some development and support work on the platform is performed under a separate service agreement by LimKnot ArtIfice Pvt Ltd (India), acting as a vendor/processorto Ilumatra ArtIfice OÜ. As of the date of this notice, that vendor's work does not involve access to live customer personal data. A copy of the applicable safeguards for this relationship is available on request at connect@ilumatraartifice.com.

Where data is also transferred to third-party sub-processors outside the EEA (e.g., Anthropic for AI processing, Stripe for billing), we ensure adequate safeguards via their own SCC or BCR frameworks as described in §5 above.

This section reflects Ilumatra ArtIfice OÜ's status as an EU-resident controller. It will be updated promptly if the scope of work performed by any non-EU vendor changes to include access to customer personal data.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified to registered users via email and/or in-platform notification at least 30 days before taking effect. Continued use of CarbonAtlas after the effective date constitutes acceptance of the updated policy.

11. Contact

Data Controller

Ilumatra ArtIfice OÜ

Incorporated in Estonia (Reg. No. 17585418), operating the CarbonAtlas CBAM compliance platform for EU and global customers

Email: connect@ilumatraartifice.com

Platform: www.ilumatraartifice.com