Privacy Policy
This policy explains how FastCBAM processes data, per Articles 13 and 14 GDPR. Short version: calculation data is commercial, not personal; the little personal data we process (account identity, access logs) stays in the EU and is never used for tracking, profiling, or AI training.
1. Who is responsible#
Provider: ArgonGate Ltd — full contact details in the Impressum.
- For tenant-submitted calculation data (installation and activity data, CN codes, emission inputs) the tenant is the controller; we act as processor on documented instructions under an Art. 28 GDPR data processing agreement.
- For account, billing, support and website data we are the controller.
Data protection contact: burkan@argongate.com. We have not designated a statutory data protection officer: our core activity is business emissions calculation, and our processing does not meet the thresholds of Art. 37(1) GDPR (no large-scale regular and systematic monitoring of data subjects, no large-scale special-category data). We will revisit this if our processing changes.
EU representative (GDPR Art. 27): we currently serve customers established outside the European Union. Before we begin offering the service to tenants in the EU, we will appoint an EU representative under Art. 27 GDPR and publish their name and address here. Until then, please direct all data protection matters to burkan@argongate.com.
2. What we process#
- Commercial/industrial data — production, energy and emissions inputs, CN codes, calculation traces. Commercially sensitive, but generally not personal data.
- Account identity (minimal) — authenticated user or service-account identity (subject id, name, email) held in our EU identity provider.
- Access logs — API request metadata (timestamp, route, authenticated subject, status) for security and abuse prevention.
- Billing data — contact and invoicing details; card data is handled by the payment provider and never touches our systems.
- Support communications — emails you send us.
The public website sets no tracking cookies. Aggregate, cookieless page metrics are collected via Cloudflare Web Analytics (no cross-site tracking, no persistent identifiers — legitimate interest, Art. 6(1)(f) GDPR). A language preference may be stored locally in your browser (localStorage) and never leaves it.
3. Purposes and legal bases#
- Providing the service and executing the contract — Art. 6(1)(b) GDPR.
- Security, abuse prevention, access logging — legitimate interest, Art. 6(1)(f) GDPR.
- Invoicing, tax and accounting retention — legal obligation, Art. 6(1)(c) GDPR.
We do not use personal data for marketing profiling, we do not sell data, and we make no automated decisions producing legal effects (Art. 22 GDPR). No AI system processes declarant data in the current release (see our AI Act boundary).
4. Sub-processors#
- Amazon Web Services — compute, database, object storage; region eu-central-1 (Frankfurt).
- Cloudflare — edge, DNS, TLS and DDoS protection for the MCP endpoint, with the EU Data Localization Suite applied.
- ZITADEL (ZITADEL Cloud EU) — OIDC identity provider for user and service-account authentication.
- Stripe Payments Europe, Ltd. — payment processing for online checkout (active once online checkout launches; card data is processed by Stripe, not by us).
We inform tenants of sub-processor changes per the DPA. All sub-processing relevant to calculation data takes place in the EU.
5. Data residency#
Calculation data is processed and stored exclusively in the EU (Frankfurt, eu-central-1). The MCP edge never parses calculation payloads; it forwards them to the EU backend.
6. Retention#
- Declaration-related records and traces: 4 years, aligned with CBAM record-keeping obligations.
- Access logs: 90 days.
- Account data: for the life of the account, then deleted or anonymised within 90 days of closure.
- Invoices: statutory commercial/tax retention periods.
7. Your rights#
Where we are controller, you can request access, rectification, erasure, restriction, portability, and object to legitimate-interest processing. Write to burkan@argongate.com. You also have the right to lodge a complaint with a data protection supervisory authority. Where we act as processor, we route requests to the responsible tenant without undue delay.
8. Security#
TLS everywhere, JWT-based service authentication, least-privilege EU infrastructure, append-only audit records, and independent security review of the serving path. Report vulnerabilities to burkan@argongate.com.
9. Changes#
We update this policy when the service or the law changes; material changes are announced to account holders. This version was published on 2026-07-06.