Privacy Policy

Last updated: 3 September 2026

1. Who we are

EcoBorder ("we", "us") provides CBAM reporting and compliance tooling. For the personal data you enter into your workspace, EcoBorder acts as a data processor on behalf of your organisation (the controller); for your own account data we act as controller. You can reach us at hello@ecoborder.app.

2. Data we process

  • Account data: your email address and, optionally, your firm name.
  • Workspace data: the clients, product lines, installations, process and emissions data, carbon-price records and CBAM communications you create.
  • Counterparty data: the email addresses and message content of the suppliers and EU buyers you correspond with, but only for workspaces that choose to connect a mailbox.
  • Audit records: who did what, and when, within your workspace.
  • Minimal technical data needed to operate and secure the service.

3. How we use it

Solely to provide the service you request: to store and compute your CBAM data, run the agent that drafts your buyer communications (nothing is sent without your approval), and keep an audit trail. Access is isolated per organisation by database row-level security, so you can reach only your own data. We never sell your data or share it with other customers.

4. Legal basis (GDPR)

We process workspace data to perform our contract with your organisation and on our legitimate interest in providing and securing the service. Connecting a mailbox is optional and based on your consent, which you can withdraw at any time (see §7).

5. Connected mailboxes (Google)

If you connect Gmail, you grant access through Google's OAuth consent screen; we store only an encrypted refresh token, never your password. We use that access only to read the messages relevant to your CBAM work and to send the replies you approve. EcoBorder's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not sell it, and do not let humans read it except as needed to provide the feature, for security, or where required by law. You can revoke access at any time in your Google Account, or by disconnecting the mailbox in your workspace.

6. Subprocessors, storage & transfers

We use a small set of subprocessors to run the service: our database and authentication provider (Supabase, on PostgreSQL), our application host (Vercel), and Google (only for mailboxes you connect). Our AI features currently run on a self-hosted model, so that content is not sent to a third-party AI provider. The current list, and the data each one handles, is kept in our subprocessor register (available on request). Data may be processed outside your country by these providers under appropriate safeguards; we are moving primary storage to the EU region. Email credentials and OAuth tokens are encrypted at rest (AES-256-GCM).

7. Your rights

You can access and exportyour entire workspace as a portable file at any time (Workspace → Data & privacy → Export), and the workspace owner can permanently erase the workspace and all its data from the same place. You may also request rectification, restriction, objection, or portability, and (for personal data) erasure, by emailing hello@ecoborder.app. You have the right to complain to your data-protection supervisory authority.

8. Retention

We keep your workspace data for as long as your account is active. On erasure we delete the workspace data and stored files; short-lived operational logs may persist briefly for security before rotating out.

9. Changes & contact

We will update this policy as the service evolves and revise the date above. Questions? Email hello@ecoborder.app.