← Back to home

Data Processing Addendum

Last updated: July 16, 2026 · Incorporated into the Terms of Service for organizational customers

Draft under legal review. This addendum describes today's pilot behavior; bracketed items and the transfer mechanism will be finalized with counsel before general availability. A signed DPA supersedes this page where a customer has one.

1. Roles

  • For data your organization uploads (questionnaires, vault entries, spend category totals, supplier lists): you are the controller, Climacope is the processor, acting only on your documented instructions — using the service is the instruction.
  • Supplier contact details a buyer uploads remain under the buyer's controllership; we process them solely to deliver that buyer's data requests (with the safeguards in §4) and to honor unsubscribes.
  • Data a supplier submits in response to a buyer's request is processed to deliver it to that buyer — the disclosed purpose of the request.

2. Processing details

ItemDescription
Subject matter & purposeSustainability-questionnaire completion, emissions estimation, Scope 3 supplier data collection
DurationThe account's life + the deletion window in §6
Data categoriesAccount/contact data; business sustainability data; spend category totals (the raw ledger is preprocessed in your browser and never received); supplier business data; supplier contact emails (encrypted at rest)
Data subjectsCustomer personnel; supplier contact persons
Special categoriesNone intended; do not submit any

3. Our obligations

Process only on your instructions; ensure personnel confidentiality; assist you (as reasonably needed) with data-subject requests and regulator inquiries; make available information reasonably necessary to demonstrate compliance; notify you without undue delay, and in any case within [72 hours] of confirming a personal-data breach affecting your data.

4. Security measures (implemented, not aspirational)

  • Per-tenant row-level security, enforced in CI against a real database.
  • Supplier contact emails encrypted at rest (AES-256-GCM); addresses decrypted only at explicit send time and masked everywhere else.
  • Spend data minimized at the source: category totals only, aggregated client-side.
  • Third-party identifiers redacted before LLM calls; billing-enabled (paid-tier) Gemini access under which Google does not use prompts/responses to improve its products.
  • TLS in transit; hosting and storage on the subprocessors in §5.
  • Certification status, stated honestly: SOC 2 / ISO 27001 are not held; this list describes actual controls, not certifications.

5. Subprocessors

Supabase (database, auth, storage) · Vercel (hosting) · Google Gemini API, paid tier (AI drafting) · Resend (outreach delivery). We'll post changes to this list on this page [and notify account owners] at least [30 days] before a new subprocessor processes your data; continued use after the notice period constitutes acceptance, and you may terminate before it takes effect.

6. Deletion, export, transfers, liability

On request or termination we export and then delete your organization's data within [30 days] (suppression-list entries persist — deleting them would re-enable contact). International transfers: processing occurs in the subprocessors' regions; the transfer mechanism for EEA/UK customers (SCCs module 2 / UK IDTA) is a counsel item before GA. Liability follows the Terms of Service; a negotiated agreement supersedes both.

See also: Privacy Policy · Terms of Service · Contact: climacope.com/contact