# Data Processing Agreement (Template)

**This is a template for discussion, not legal advice.** Have your own adviser
review it before signing. To execute a final version, email contact@iyman-ahmed.tech.

This Data Processing Agreement ("DPA") forms part of the agreement between:

- **Controller:** the customer using CarbonProxy ("you"), and
- **Processor:** CarbonProxy ("we"),

and reflects the parties' agreement on the processing of personal data under the
EU General Data Protection Regulation (GDPR), Article 28.

## 1. Subject matter and duration
We process personal data only to provide the CarbonProxy service — turning the
documents you upload into an emissions report and questionnaire answers — for as
long as you hold an account, plus any short period required to delete it.

## 2. Nature and purpose of processing
Reading uploaded business documents to extract activity data, computing emissions
figures, generating reports, and storing the resulting figures in your account.

## 3. Types of personal data
Account data (name, email, hashed password, company name) and any personal data
incidentally contained in the business documents you choose to upload.

## 4. Categories of data subjects
Your authorised users, and any individuals named in the documents you upload.

## 5. Our obligations as processor
We will:
(a) process personal data only on your documented instructions;
(b) ensure people authorised to process it are bound by confidentiality;
(c) implement appropriate technical and organisational security measures
    (see Section 8);
(d) not use your data to train any AI or machine-learning model;
(e) assist you, so far as possible, in responding to data-subject requests;
(f) assist you with security, breach notification, and impact assessments;
(g) delete or return all personal data at the end of the service, and delete
    existing copies, unless law requires storage.

## 6. Sub-processors
We use a limited set of sub-processors to run the service (hosting, and the AI
provider that reads documents). We will keep an up-to-date list available on
request and give you notice of intended changes so you may object.

## 7. International transfers
Data is hosted in the European Union. Where any sub-processor processing occurs
outside the EU/EEA, it will be covered by an appropriate transfer mechanism
(such as Standard Contractual Clauses).

## 8. Security measures
Including, at minimum: encryption in transit; passwords stored only as salted
PBKDF2 hashes; per-account data isolation; deletion of uploaded source documents
after extraction; access controls; and prompt patching. Details in our Security
page.

## 9. Data-subject rights
We provide self-service data export and account deletion so you can meet access,
portability, and erasure requests without delay.

## 10. Personal data breach
We will notify you without undue delay after becoming aware of a personal data
breach affecting your data, with the information you need to meet your own
notification obligations.

## 11. Deletion and return
On termination, or on your request, we delete your personal data (and copies)
within a reasonable period, unless retention is legally required.

## 12. Audits
We will make available information reasonably necessary to demonstrate
compliance with Article 28 and allow for audits on reasonable notice.

## 13. Governing law
This DPA is governed by the law agreed in the main service agreement, or absent
that, the law of the controller's place of establishment within the EU.

---
CarbonProxy · contact@iyman-ahmed.tech · Template version 2026-07
