Information Security

    How we protect the data our clients and partners share with us

    Hosted in London

    Platform data is stored in the UK on Supabase (AWS London).

    MFA on every sign-in

    Password plus authenticator app, with database-level access rules.

    48-hour breach notice

    Affected clients and partners are told within 48 hours.

    Named sub-processors

    Every provider that touches client data is listed below.

    The Carbon Stamp Ltd

    Information Security & Data Handling Policy

    Last updated 30 September 2026 · Next review September 2027

    1. Purpose and scope

    This policy sets out how The Carbon Stamp Ltd protects the data that clients and partners share with us. It covers all client data we handle to deliver carbon footprints, reports and supplier engagement: on our data platform, in email and on company devices. The Carbon Stamp is run by its sole director, Frazer Holroyd, who is responsible for this policy.

    When we work as a subcontractor to a partner consultancy, the end client is the data controller and we act as a sub-processor. In that role we process data only on documented instructions, and where the partner's contract sets stricter terms, those terms apply.

    2. Data we process

    Most of what we handle is business activity data: energy and fuel use, refrigerants, waste, water, purchased goods and spend, freight, business travel and supplier emissions data.

    We process a limited amount of personal data: names and work contact details of client and supplier contacts, and responses to staff commuting, business travel and fan travel surveys. We ask for data in aggregated or anonymised form wherever that still gives an accurate result, and we do not ask for special category data.

    3. Where data is stored

    Client data is hosted in the UK (London) on Supabase, which holds SOC 2 Type II certification. This covers our database and uploaded files, which sit in Amazon Web Services' London region (eu-west-2), and Supabase backs the database up daily. Files that clients email to us are held in Google Workspace before being moved onto the platform. Working files on company laptops are protected by full-disk encryption.

    4. Access control

    • Only the director has access to client data. There are no other staff accounts and public sign-up to our platform is switched off.
    • Signing in to the platform needs a password and a code from an authenticator app (MFA). MFA is also switched on for every service account that can reach client data.
    • Row-level security is enabled on every database table, so each request is checked against the signed-in account before any data is returned.
    • Everything else gets the least access it needs. AI assistant connections are read-only. Survey respondents and suppliers use unique links that only let them submit their own response. Server keys stay on the server and are never sent to browsers.

    5. Encryption

    All data is encrypted in transit using TLS (HTTPS). Data at rest in the database and file storage is encrypted with AES-256, as provided by Supabase and AWS. Company laptops use full-disk encryption.

    6. Sub-processors

    ProviderPurposeDataLocation
    Supabase (on AWS)Database, file storage, sign-in and server functionsAll client data held on our platformUK (London)
    CloudflareServes our web application and DNSData in transit to and from the platformGlobal network
    OpenAIAI help with data checks and report draftingExtracts of assessment data and filesUSA
    AnthropicAI reading of survey spreadsheets and freight routesSurvey contents and shipment locationsUSA
    Google Maps PlatformTravel distance calculationsLocation dataUSA
    Google WorkspaceEmail and documentsCorrespondence and files clients send usGlobal
    ResendSurvey and data request emailsContact names and email addressesUSA

    7. AI use

    We use AI to speed up routine work such as reading survey spreadsheets, checking data and drafting report text. It does not replace professional judgement: emissions figures are calculated by our own engine from published emission factors, and a person reviews everything before it reaches a client.

    We use the business APIs of OpenAI and Anthropic and send only the data a task needs. Under their commercial terms, client data sent through the API is not used to train their models. When we use Claude or ChatGPT to analyse client data, access is read-only and model training is switched off on those accounts.

    8. Retention and deletion

    We keep client data for the length of the engagement plus 7 years, so clients can compare against earlier years and we can support audits and assurance. The same period applies to personal data in survey responses, unless the client asks us to delete it sooner.

    Clients and partners can ask us to delete their data at any time, or at the end of an engagement. We delete it from our platform and files within 30 days and confirm in writing. Copies in Supabase's rolling backups expire within 7 days after that.

    9. Breach response

    If we become aware of a security incident affecting client data, we will:

    • contain it and assess the risk straight away;
    • notify affected clients and partners without undue delay, and within 48 hours of becoming aware, with what we know at that point;
    • report it to the ICO within 72 hours where the law requires, or support the controller to do so where we act on their behalf;
    • record the incident and the changes we make to stop it happening again.

    10. International transfers

    Client data on our platform is stored in the UK and is not transferred abroad for storage. Some sub-processors handle data outside the UK to carry out their task: OpenAI, Anthropic, Google and Resend in the USA, and Cloudflare on its global network. Email held in Google Workspace may be stored in Google data centres outside the UK. These transfers rely on the safeguards in each provider's data processing terms.

    11. Certifications and registrations

    • Registered with the Information Commissioner's Office (ICO), registration number ZC257230.
    • Cyber Essentials: certification in progress.
    • We do not currently hold ISO 27001 or SOC 2 certification ourselves. SOC 2 Type II certification is held by our hosting provider, Supabase.

    12. Review and contact

    We review this policy at least once a year and after any significant change to our systems or suppliers. Questions, requests and incident reports go to info@thecarbonstamp.com.

    Signed

    Frazer Holroyd

    Managing Director, The Carbon Stamp Ltd · 30 September 2026