Legal
GDPR & Data Protection
Last updated: July 30, 2026
This page is maintained by Clean Compute LLC to answer common data protection questions about the Clean Compute certification. It summarises how we handle personal information under the EU GDPR, UK GDPR, Swiss FADP, and US state privacy laws such as the CCPA/CPRA. It is a description of our own practices, not an independent certification or audit. Full detail is in our Privacy Policy, Cookie Policy, and Terms of Service.
1. Our role
For the business contact and account information we collect to run the certification, Clean Compute is the controller. We do not process end-customer data on behalf of our clients: the Service requires only a single attested number of subscribed users, never a billing-system integration, customer list, or system access. Because of that, a processor relationship generally does not arise. Where a client's own compliance programme still requires a written data processing addendum for the limited contact data we hold, email trees@cleancompute.eco and we will provide one.
2. Legal bases for processing
- Contract — creating and operating your account, verifying counts, issuing the badge, billing, and Service communications.
- Legitimate interests — securing the Service, preventing fraud and misreporting, maintaining the integrity and audit record of the certification, and improving the product. We balance these against your rights and keep data minimal.
- Consent — non-essential cookies and analytics, and publication of your company name, logo and certification status on the public verification page and registry. Consent can be withdrawn at any time.
- Legal obligation — tax, accounting, and record-keeping requirements.
3. Data minimisation by design
We deliberately do not collect your end-customers' personal data, credentials to your systems, or your revenue figures. Evidence you send in support of a count should be anonymised. Each client account can access only its own records, enforced at the database level, with role-restricted administrative access and audit logging of administrative actions.
4. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability, and withdrawal of consent, and you may opt out of any "sale" or "sharing" of personal information (we do neither) and of targeted advertising (we run none). We do not use automated decision-making that produces legal or similarly significant effects.
Send requests to trees@cleancompute.eco with the email address on the account. We verify identity before acting, respond within one month (GDPR) or 45 days (US state laws) and may extend once where permitted, and we never discriminate against anyone for exercising these rights. Authorised agents may submit requests with written permission. If you are unhappy with our response, you may complain to your supervisory authority — in the UK, the Information Commissioner's Office.
5. Retention
Contact and account data is kept while your account is active and for a reasonable period afterwards. Certification records — attested counts, allocation ledger entries, badge status history, and receipts — are retained as the permanent audit record of impact already funded, in company-level form. Billing records are retained as required by tax law. Deletion requests for personal contact information are honoured without affecting those company-level records.
6. Subprocessors and service providers
We use a small set of providers, each under contract and only as needed to run the Service: payment processing (Stripe), cloud hosting, database and authentication infrastructure, and transactional email delivery. Our reforestation and ocean recovery partners receive no client information — impact is purchased on a consolidated basis. A current list of subprocessors is available on request, and we will give notice of material changes to clients with an active subscription.
7. International transfers
Clean Compute is based in the United States, and personal information is processed in the US and in the locations used by our providers. For transfers from the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum where applicable) together with our providers' transfer frameworks, and we apply additional safeguards such as encryption in transit and access controls.
8. Security and incidents
We use encrypted connections, tenant-scoped access controls, least-privilege administrative access, and audit logging, and we hold as little sensitive information as possible in the first place. If a personal data breach affecting your information occurs, we will notify the relevant supervisory authority and affected individuals as required by law and without undue delay. Report a suspected vulnerability or incident to trees@cleancompute.eco.
9. Marketing and email
Service communications (attestation prompts, receipts, impact reports, certification notices) are sent as part of the contract. Any non-essential updates are opt-in and every email carries a one-click unsubscribe link. You can also manage this from your dashboard or by emailing us.
10. Contact
Clean Compute LLC · 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, USA
Privacy contact: trees@cleancompute.eco
