Privacy Policy

Last updated: January 2025

1. Information We Collect

We collect information you provide directly to us, such as when you create an account, complete our CSRD assessment, or contact us for support.

  • Contact information (name, email address, company details)
  • Assessment responses and sustainability data
  • Payment information (processed securely through Stripe)
  • Communication preferences and support requests

2. How We Use Your Information

We use the information we collect to:

  • Provide and improve our CSRD compliance services
  • Generate personalized sustainability reports
  • Process payments and manage subscriptions
  • Send important updates about your account and our services
  • Provide customer support and respond to inquiries
  • Comply with legal obligations and protect our rights

3. Information Sharing

We do not sell, trade, or otherwise transfer your personal information to third parties, except:

  • With your explicit consent
  • To trusted service providers who assist in our operations (e.g., Stripe for payments)
  • When required by law or to protect our rights
  • In connection with a business transfer or acquisition

4. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. This includes:

  • SSL encryption for data transmission
  • Secure data storage with access controls
  • Regular security assessments and updates
  • Limited access to personal information on a need-to-know basis

5. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR), you have the right to:

  • Access your personal data
  • Rectify inaccurate or incomplete data
  • Erase your personal data (right to be forgotten)
  • Restrict processing of your data
  • Data portability
  • Object to processing
  • Withdraw consent at any time

6. Data Retention

We retain your personal information for as long as necessary to provide our services and comply with legal obligations. Assessment data is retained for 7 years to comply with regulatory requirements.

7. Cookies and Tracking

We use cookies and similar technologies to improve your experience, analyze usage patterns, and provide personalized content. You can control cookie settings through your browser preferences.

8. International Transfers

Your data may be transferred to and processed in countries outside the European Economic Area. We ensure appropriate safeguards are in place to protect your data in accordance with GDPR requirements.

9. Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal information from children under 16.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and updating the "Last updated" date.

11. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: privacy@csrdprosme.com

Data Protection Officer: dpo@csrdprosme.com