Aretia Climate
Climate Intelligence
ISO/IEC 27701:2019 Compliant

Privacy Notice

This notice explains what personal data Aretia Climate collects, why we collect it, how we use it, and the rights you have over it. It applies to all users of the Aretia Climate platform and our public website.

Effective: 19 June 2026Version: 1.0Framework: ISO/IEC 27701:2019 · GDPRController: Aretia Climate LLC

1. Data Controller

The data controller responsible for your personal data is:

Aretia Climate LLC
1000 N West Street, Wilmington, Delaware 19801, United States
Data Protection contact: legal@aretiaclimate.com

For all privacy-related enquiries · including exercising your rights · contact us at the address above. We aim to respond to all requests within five business days.


2. Personal Data We Collect

We collect only the personal data necessary to provide our services (data minimisation, ISO 27701 Section 7.4.5).

CategoryData ElementsSource
Identity dataFull name, job title, employerProvided by you at signup
Contact dataEmail address, countryProvided by you at signup
Organisation dataCompany name, sector, headcount, websiteProvided by you at signup
Account credentialsHashed password (bcrypt, never stored plaintext)Provided by you
Platform usage dataFeature usage, report generation, session timestampsCollected automatically
Climate & emissions dataGHG inventory figures, asset data, scenario inputsProvided by you or your organisation
Payment dataBilling email, subscription tier (no card numbers · processed by Stripe)Stripe, Inc.
Technical dataIP address, browser type, device type, error logsCollected automatically
Cookie dataSession cookies, preference cookies (see Section 8)Collected automatically

We do not process special category data (GDPR Article 9) or data relating to children under 18.


3. Purposes and Legal Bases (ISO 27701 Section 7.2.1)

Every processing activity has a documented purpose and a lawful basis under GDPR Article 6.

PurposeLegal BasisDetail
Account creation & authenticationContract (Art. 6(1)(b))Required to provide access to the platform
Platform service deliveryContract (Art. 6(1)(b))Running climate risk, emissions, and reporting tools
Subscription management & billingContract + Legal obligation (Art. 6(1)(b)(c))Processing payments and maintaining financial records
Customer supportLegitimate interests (Art. 6(1)(f))Responding to support requests and troubleshooting
Platform analytics & improvementLegitimate interests (Art. 6(1)(f))Improving features and fixing issues; you may opt out
Security & fraud preventionLegal obligation + Legitimate interests (Art. 6(1)(c)(f))Maintaining platform integrity and preventing abuse
Marketing communicationsConsent (Art. 6(1)(a))Sending product updates and climate insights; withdraw any time
Legal complianceLegal obligation (Art. 6(1)(c))Meeting regulatory requirements (GDPR, accounting, tax)
Anonymised research & benchmarkingLegitimate interests (Art. 6(1)(f))Aggregated, non-identifiable industry benchmarks
Where we rely on legitimate interests, you have the right to object at any time (GDPR Art. 21). Contact legal@aretiaclimate.com.

4. Data Retention (ISO 27701 Section 7.6)

We retain personal data only as long as necessary for the purpose it was collected, or as required by law.

Data TypeRetention PeriodReason
Account & profile data5 years after account closureContractual records
Climate & emissions dataDuration of subscription + 7 yearsIFRS S2 audit trail requirements
Billing records7 yearsUK/US financial regulation
Support correspondence3 yearsDispute resolution
Security / access logs2 yearsIncident investigation
Marketing consent recordsUntil consent withdrawn + 3 yearsEvidence of consent (GDPR Art. 7)
Anonymised analyticsIndefinite (not personal data)Aggregated benchmarks only

5. Data Sharing and Third Parties (ISO 27701 Section 6.11)

We do not sell personal data. We share it only with trusted processors under Data Processing Agreements (GDPR Art. 28) or when legally required.

RecipientPurposeLocationSafeguard
Supabase, Inc.Database hosting & authenticationUSA / EUDPA + SCCs
Stripe, Inc.Payment processingUSADPA + SCCs
Vercel, Inc.Application hostingUSA / EUDPA + SCCs
Resend, Inc.Transactional emailUSADPA + SCCs
Supervisory authoritiesLegal obligation (e.g. ICO, DPA)Relevant jurisdictionLegal obligation

International Transfers

Where data is transferred outside the European Economic Area (EEA), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or equivalent safeguards. A copy of applicable transfer mechanisms is available on request at legal@aretiaclimate.com.


6. Security Measures (ISO 27701 Section 7.7 · ISO 27001)

Aretia Climate maintains an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022. Key technical and organisational measures include:

Encryption at rest
AES-256 (Supabase)
Encryption in transit
TLS 1.3
Authentication
Bcrypt-hashed passwords + email verification
Access control
Row-Level Security (RLS) on all tables
Admin access
Role-based; super_admin and admin tiers only
Vulnerability management
Automated dependency scanning
Audit logging
All admin data access logged (ISO 27701 Section 7.9)
Backups
Daily encrypted backups, 30-day retention

7. Your Rights (ISO 27701 Section 7.3 · GDPR Art. 12·22)

You have the following rights regarding your personal data. We respond to all valid requests within 30 days (extendable to 90 days for complex requests with notice).

Art. 15
Right of Access
Obtain a copy of all personal data we hold about you.
Art. 16
Right to Rectification
Correct inaccurate or incomplete personal data.
Art. 17
Right to Erasure ("Right to be forgotten")
Request deletion of your personal data where it is no longer necessary.
Art. 18
Right to Restriction
Limit how we process your data in certain circumstances.
Art. 20
Right to Data Portability
Receive your data in a structured, machine-readable format (JSON/CSV).
Art. 21
Right to Object
Object to processing based on legitimate interests or direct marketing.
Art. 7
Right to Withdraw Consent
Withdraw consent at any time without affecting prior processing.
Art. 77
Right to Lodge a Complaint
Complain to your local supervisory authority (e.g. ICO in the UK, DPC in Ireland).
Exercise your rights: Log in and visit your Data & Privacy settings, or email us at legal@aretiaclimate.com. Include your name and email address so we can verify your identity.

8. Cookies and Tracking (ePrivacy Directive)

We use cookies and similar technologies on our website and platform. You can manage your cookie preferences at any time via the banner shown on your first visit, or by clicking “Cookie Preferences” in the footer.

CategoryPurposeExamplesBasis
EssentialSession management, authentication, securitysb-access-token, sb-refresh-tokenStrictly necessary · no consent required
FunctionalRemembering preferences (cookie consent choice, language)aretia_cookie_consentConsent
AnalyticsUnderstanding platform usage, feature adoptionAnonymous session eventsConsent
MarketingPersonalised product information (opt-in only)UTM parametersConsent

9. Children's Data

The Aretia Climate platform is intended for professional use only. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has provided data, contact us at legal@aretiaclimate.com and we will delete it promptly.


10. Changes to This Notice

We may update this Privacy Notice periodically to reflect changes to our practices or legal requirements. When we make material changes we will notify active users by email at least 30 days in advance and update the “Effective” date at the top. Continued use of the platform after the effective date constitutes acceptance of the updated notice.

Previous versions of this notice are available on request at legal@aretiaclimate.com.


11. Contact Us

Data Controller
Aretia Climate LLC
1000 N West Street, Wilmington, Delaware 19801, United States
legal@aretiaclimate.com
Supervisory Authority
EU residents may lodge complaints with their national DPA.
UK residents may contact the Information Commissioner's Office (ICO).

This Privacy Notice was prepared in accordance with ISO/IEC 27701:2019 (Privacy Information Management), ISO/IEC 27001:2022 (Information Security Management), and the EU General Data Protection Regulation (GDPR) 2016/679. Version 1.0 · effective 19 June 2026.