The Carbon Co | Privacy Policy
The Carbon Co
Legal

Privacy Policy

Version 1.0 · Effective date: [to be set on publication]

This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit this website, contact us, or otherwise engage with The Carbon Co, and sets out your rights under applicable data protection law.

1. Who we are and the scope of this policy

This website is operated by The Carbon Co, a trading name of Themis Carbon CY Limited, a company incorporated in the Republic of Cyprus under registration number HE 450468, with its registered office in the Republic of Cyprus (“we”, “us”, “our”).

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”) and the Cyprus Law Providing for the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018), we are the data controller responsible for the personal data processed in connection with this website and our related business activities.

This policy applies to prospective and existing project developers, partners, counterparties, investors, website visitors, and other individuals whose personal data we process. It should be read together with our Cookie Policy and our Data Protection Statement.

2. The personal data we collect

Depending on how you interact with us, we may collect and process the following categories of personal data:

  • Identity and contact data — your name, job title, employer or organisation, email address, telephone number and postal or business address.
  • Professional and relationship data — information about your role, the organisation you represent, and the nature of our dealings with you, including where you act on behalf of a project, partner or counterparty.
  • Correspondence and enquiry data — the content of messages, enquiries, meeting requests and other communications you send to us, and our responses.
  • Project and due-diligence data — information you provide about a project or transaction, which may incidentally include personal data relating to individuals connected with it, and information required for compliance and integrity checks.
  • Technical and usage data — your IP address, device and browser type, operating system, referring pages, and information about how you use our website, collected through cookies and similar technologies.
  • Preference data — your marketing preferences and your choices regarding cookies and communications.

We do not intentionally collect special categories of personal data (as defined in Article 9 GDPR) or data relating to criminal convictions through this website. Please do not send us such data unless we have specifically requested it on a lawful basis.

3. How we collect your personal data

  • Directly from you — when you contact us, request information, book a call, correspond with us, or engage with us in the course of a project, partnership or transaction.
  • Automatically — when you use our website, through cookies and similar technologies, as described in our Cookie Policy.
  • From third parties and public sources — for example, from your organisation, from professional contacts, from our partners and service providers, and from publicly available sources used for verification, due-diligence and compliance purposes.

4. Why we use your personal data and our legal bases

We process personal data only where we have a lawful basis to do so under Article 6(1) GDPR. The table below sets out our principal purposes and the corresponding legal bases.

PurposeData usedLegal basis
Responding to your enquiries and providing information, materials or meetings you requestIdentity, contact, correspondenceTaking steps at your request prior to entering a contract (Art 6(1)(b)); our legitimate interests (Art 6(1)(f)) in responding to enquiries
Establishing and managing our relationships with project developers, partners, counterparties and investorsIdentity, contact, professional, projectPerformance of a contract (Art 6(1)(b)); our legitimate interests (Art 6(1)(f)) in managing and developing our business
Operating, securing, maintaining and improving our websiteTechnical, usageOur legitimate interests (Art 6(1)(f)) in a secure, functional website; consent for non-essential cookies (Art 6(1)(a))
Sending updates or communications you have asked to receiveContact, preferenceConsent (Art 6(1)(a)); our legitimate interests (Art 6(1)(f)) in business communications where permitted
Meeting legal, regulatory, integrity, anti-money-laundering and know-your-counterparty obligationsIdentity, professional, project, transactionCompliance with a legal obligation (Art 6(1)(c)); our legitimate interests (Art 6(1)(f)) in the integrity of our activities
Establishing, exercising or defending legal claims and protecting our rightsAny relevant categoriesOur legitimate interests (Art 6(1)(f)); compliance with a legal obligation (Art 6(1)(c))

Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

5. Our legitimate interests

Where we rely on legitimate interests, we have carried out a balancing assessment to ensure that our interests are not overridden by your interests, rights and freedoms. Our legitimate interests include responding to enquiries, running and safeguarding our website, developing and managing our business relationships, maintaining the integrity of our activities, and protecting our legal rights. You may ask us for more information about this assessment, and you have the right to object to processing based on legitimate interests (see section 11).

6. Who we share your personal data with

We do not sell your personal data. We may disclose it to the following categories of recipient, in each case subject to appropriate safeguards:

  • Service providers (processors) — including hosting, IT, communications, analytics and professional-services providers who process personal data on our behalf under a written contract that complies with Article 28 GDPR.
  • Professional advisers — such as our lawyers, auditors, accountants and insurers, where necessary for the purposes described in this policy.
  • Partners and counterparties — where necessary to progress a project, partnership or transaction in which you or your organisation is involved.
  • Authorities and regulators — where we are required to disclose personal data to comply with a legal or regulatory obligation, or to establish, exercise or defend legal claims.
  • Corporate transactions — to a prospective buyer, investor or successor in connection with a reorganisation, merger, acquisition or similar event, subject to confidentiality.

7. International transfers of personal data

Where we transfer personal data outside the European Economic Area (the “EEA”), we ensure that an appropriate transfer mechanism under Chapter V GDPR is in place. This means the transfer is made to a country benefiting from an adequacy decision of the European Commission, or subject to appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with any supplementary measures required to ensure an essentially equivalent level of protection. You may request a copy of the relevant safeguards using the contact details in section 17.

8. How long we keep your personal data

We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy any legal, accounting, regulatory or reporting requirements. To determine the appropriate retention period, we consider the amount, nature and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes of processing, and applicable legal requirements. When personal data is no longer required, we will securely delete or anonymise it.

9. How we protect your personal data

In accordance with Article 32 GDPR, we implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include access controls, encryption in transit where appropriate, logging and audit mechanisms, and the principle that access is limited to those who need it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Automated decision-making and profiling

We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing, including profiling, within the meaning of Article 22 GDPR. If this position changes, we will update this policy and, where required, obtain a lawful basis before doing so.

11. Your rights

Subject to the conditions and exceptions in the GDPR, you have the following rights in relation to your personal data:

  • Access — to obtain confirmation of whether we process your personal data and a copy of it (Art 15).
  • Rectification — to have inaccurate personal data corrected and incomplete data completed (Art 16).
  • Erasure — to have your personal data deleted in certain circumstances (Art 17).
  • Restriction — to restrict our processing of your personal data in certain circumstances (Art 18).
  • Portability — to receive certain personal data in a structured, commonly used, machine-readable format and to have it transmitted to another controller (Art 20).
  • Objection — to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing (Art 21).
  • Withdrawal of consent — to withdraw your consent at any time where we rely on it.

To exercise any of these rights, please contact us at privacy@thecarbon.co. We will respond within one month, which may be extended by two further months where necessary, in which case we will inform you. We may need to verify your identity before acting on a request.

12. Cookies and similar technologies

Our website uses cookies and similar technologies. Non-essential cookies are not set without your consent, which is declined by default. For full details, please see our Cookie Policy.

13. Children’s privacy

Our website and services are directed at professionals and organisations and are not intended for children. We do not knowingly collect personal data relating to children. If you believe a child has provided us with personal data, please contact us so that we can take appropriate action.

14. Third-party websites

Our website may contain links to third-party websites and services. We are not responsible for the privacy practices or content of those third parties. We encourage you to read their privacy notices before providing them with your personal data.

15. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or in applicable law. The current version is identified by the version number and effective date at the top of this page. Where changes are material, we will take reasonable steps to bring them to your attention.

16. How to contact us and your right to complain

If you have any questions about this policy or wish to exercise your rights, please contact our Data Protection contact at privacy@thecarbon.co, or by post to Themis Carbon CY Limited at our registered office in the Republic of Cyprus.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work or the place of the alleged infringement. Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy). We would, however, appreciate the opportunity to address your concerns before you approach the authority.

This policy is provided as a template drafted to the standard of applicable EU and Cyprus data protection law. Items shown in square brackets, together with the registered office address and any operational contact details, should be finalised and verified by qualified counsel before publication.