Data Protection Statement
This statement sets out how we approach data protection as an organisation: the principles we apply, the roles we hold, and the measures we take to comply with the GDPR and Cyprus Law 125(I)/2018. It complements, and should be read together with, our Privacy Policy.
1. Our commitment
The Carbon Co, a trading name of Themis Carbon CY Limited (registration number HE 450468), is committed to protecting personal data and to processing it lawfully, fairly and transparently. We treat data protection as integral to the integrity we ask others to trust, and we hold ourselves to the standards of the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the Cyprus Law Providing for the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018).
2. The principles we apply
We process personal data in accordance with the principles set out in Article 5 GDPR:
- Lawfulness, fairness and transparency — we process personal data on a valid legal basis and are open about how and why.
- Purpose limitation — we collect personal data for specified, explicit and legitimate purposes and do not process it in a manner incompatible with them.
- Data minimisation — we limit personal data to what is adequate, relevant and necessary.
- Accuracy — we take reasonable steps to keep personal data accurate and up to date.
- Storage limitation — we keep personal data in identifiable form no longer than necessary.
- Integrity and confidentiality — we protect personal data with appropriate security.
- Accountability — we take responsibility for compliance and are able to demonstrate it.
3. Our roles: controller and processor
We act as a data controller where we determine the purposes and means of processing — for example, in managing our own relationships and website. We may act as a data processor where we process personal data on behalf of another party under their instructions. In each engagement we identify our role and put the appropriate agreements in place.
4. Lawful bases and consent
We identify and document a lawful basis under Article 6 GDPR before processing personal data, and, where applicable, a condition under Article 9 for any special categories of data. Where we rely on consent, we obtain it through a clear affirmative action and make it as easy to withdraw as to give.
5. Data protection by design and by default
In line with Article 25 GDPR, we consider data protection from the outset when designing new processes, systems and services, and we configure them so that, by default, only the personal data necessary for each purpose is processed. Where a type of processing is likely to result in a high risk to individuals, we carry out a Data Protection Impact Assessment (Article 35) before proceeding.
6. Working with processors
Where we engage service providers to process personal data on our behalf, we select providers offering sufficient guarantees of GDPR compliance and put in place written contracts meeting the requirements of Article 28. We remain accountable for personal data entrusted to our processors.
7. International transfers
Where personal data is transferred outside the European Economic Area, we rely on a valid transfer mechanism under Chapter V GDPR — an adequacy decision, or appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with any supplementary measures needed to ensure an essentially equivalent level of protection.
8. Security of processing
We implement appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to individuals. These measures address confidentiality, integrity, availability and resilience, and are reviewed and tested for effectiveness.
9. Personal data breaches
We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to result in a risk to individuals’ rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33. Where the breach is likely to result in a high risk, we will also inform the affected individuals in accordance with Article 34.
10. Records and accountability
We maintain records of our processing activities as appropriate to our role and scale, and we keep documentation demonstrating our compliance, including our lawful-basis assessments, impact assessments and processor agreements.
11. Individuals’ rights
We uphold the rights of individuals under the GDPR, including access, rectification, erasure, restriction, portability, objection and rights relating to automated decision-making. Our procedures for handling requests, and the ways to exercise these rights, are set out in our Privacy Policy. We respond to requests within the statutory time limits.
12. Governance and responsibility
Responsibility for data protection sits at management level. Our data protection contact oversees our compliance programme, advises on obligations, and acts as the point of contact for individuals and for the supervisory authority. We keep under review whether we are required to formally designate a Data Protection Officer under Article 37 and will do so if that threshold is met.
13. Contact and complaints
To raise a data protection matter, contact us at privacy@thecarbon.co, or by post to Themis Carbon CY Limited at our registered office in the Republic of Cyprus. You have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy), or with the supervisory authority in your country of residence or work.
This statement is provided as a template drafted to the standard of applicable EU and Cyprus data protection law. The registered office address, the designation and identity of any Data Protection Officer, and any bracketed items should be finalised and verified by qualified counsel before publication.
