Privacy Policy | GreenCalculus.com — Environmental Calculator Data Protection

Privacy Policy

Your environmental data is sensitive. Scope 1, 2, and 3 inventories, fuel volumes, fleet distances, refrigerant quantities — these are commercially valuable, operationally revealing, and proprietary to your organisation. We built GreenCalculus.com knowing that.

Our position is simple: your calculator inputs are none of our business. We compute your result and discard everything. No storage. No logging. No profiling. No sale. Ever.

Our Absolute Commitments

We will never sell, rent, or monetise your personal data. We will never store your calculator inputs. We will never use your emissions data for advertising or AI training. We will never share your data with third parties for their own purposes. These are not policy promises — they are technical constraints built into how the platform works.

1. Privacy at a Glance

This table is your complete quick-reference summary. Every row is expanded in full detail below. The guiding principle behind every decision in this table is the same: collect less, keep less, sell never.

Data Category Why We Collect It Retention Sold to Third Parties?
Calculator Inputs Real-time computation only. Processed and immediately discarded. Never stored Never
Account Identity Account creation, signing you in, newsletter delivery, support communications Account + 2 yrs Never
Technical / log data Security monitoring, load balancing and error diagnosis. These logs record your IP address and the web address requested, which can include search terms passed in the address. Request bodies — including calculator inputs — are never written to them. Held by our hosting provider on a rolling basis and not separately retained by us. The window depends on traffic volume rather than a fixed period; it was approximately 30 days when last measured. Never
Website analytics Aggregate usage metrics only — cookieless, no personal data 12 months Never
API usage records Service integrity, abuse prevention, quota enforcement, and contacting you if data you retrieved is later corrected. One record per API call: the endpoint called, your plan, the emission factor requested, and a one-way hash of your account identifier. Request bodies are never included. 3 months. This period is set by Cloudflare Analytics Engine, the processor for this dataset, and applies to these records only. It does not describe the retention of any other data in this policy. Never
Billing data Taking payment for paid API plans and listings Held by Stripe under Stripe’s own retention terms. We retain only the customer and subscription identifiers needed to manage your subscription. Never
Directory enquiries Passing your message to the provider you chose Not stored. Your message is forwarded to them and discarded. We keep only that an enquiry was sent, which listing it was for, and that the bot check passed. Never
Directory listing contents Publishing a paid provider listing you asked us to publish Kept while the listing is published, and removed when it comes down. We keep the business record of the purchase under Billing data. Never
Google Sheets add-on Returning the emission factors you look up from inside Google Sheets. Only the factor names and search terms you enter leave the spreadsheet; they are handled as API requests (see API usage records and Technical / log data). An API key you choose to save is stored by Google in your own Google account, not by us. As API usage records and Technical / log data above Never
Cookie Data Essential session management only. No advertising cookies. Session / 12 mo Never

About the contact details in a directory listing. A paid directory listing may publish a named individual, their role and a telephone number, because the listing exists to let a reader contact a person. We do not publish their email address. Enquiries are sent through a form on the listing, and your message is passed to them and not kept. Those details are supplied by the business buying the listing, which confirms it is entitled to publish them and that the individual is aware. If you are the person named, you can ask us to remove your details directly — you do not need to go through the business that listed them — by writing to dpo@greencalculus.com. We will act on that request whether or not the business agrees, and the listing will run without a named contact.

2. About This Policy — Who We Are and What This Covers

GreenCalculus.com (“GreenCalculus,” “we,” “our,” or “us”) is a premier B2B platform providing 1,000+ high-precision environmental and carbon calculators to sustainability officers, corporate compliance teams, and government engineers worldwide.

Controller identity: This website is operated by GreenCalculus.com. For all data protection enquiries, our appointed Data Protection Officer is contactable at dpo@greencalculus.com. For general privacy questions that do not constitute a formal data subject request, contact privacy@greencalculus.com.

This Privacy Policy explains what data we collect, why we collect it, how long we retain it, and the rights you hold over it. It applies to all services accessible via GreenCalculus.com and any associated APIs, widgets, or integrations.

This Policy was drafted in accordance with applicable data protection law including the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, Canada’s PIPEDA, Singapore’s PDPA, and Thailand’s PDPA. Where laws differ in the standard they impose, we apply the higher standard globally.

3. Calculator Input Data — Our Binding Pledge

Our calculators process commercially sensitive operational data: energy consumption figures, fuel volumes, fleet distances, refrigerant quantities, Scope 1, 2, and 3 emissions inventories, land-use metrics, supply chain figures, and more. This data is proprietary to the organisations that generate it. We treat it accordingly.

Binding Guarantee — Calculator Inputs

Every figure you enter into any GreenCalculus calculator is processed for the sole purpose of computing your result. This data is NOT stored on our servers. It is NOT logged to any database. It is NOT associated with your account. It is NOT used for marketing, research, or profiling. It is NEVER sold, licensed, or shared with any third party. This applies to every calculator on the platform without exception.

This is technically enforced, not merely a policy statement:

  • Stateless computation: Our calculation engine processes inputs and returns results without writing any input values to persistent storage at any point in the request lifecycle.
  • Calculator inputs are not logged: Calculator figures are submitted in the body of a request, and request bodies are not written to any log — verified across our application code, web-server logs, PHP logs and our web application firewall. Web-server logs do record the web address requested, which includes any parameters contained in that address, such as a search term.
  • Session isolation: Where multi-step calculators use temporary server-side state, sessions are cryptographically isolated and purged immediately upon session termination or browser close.
  • GHG Protocol alignment: Our data handling practices align with the confidentiality requirements of the GHG Protocol Corporate Standard and the 2026 GHG Protocol Land Sector and Removals Standard. Organisations using GreenCalculus outputs in formal sustainability disclosures can confirm their underlying inputs are not accessible to any external party.
  • IEA data integrity: Regional grid emission factors in our energy calculators are sourced from the IEA Global Energy Review 2026 and updated annually. These are reference constants, not user inputs, and are publicly available.

4. What Data We Collect and Why

4.1 Identity Data

We collect the following identity information only when you voluntarily provide it:

  • Name and professional title — to personalise your account experience.
  • Business email address — for account creation, authentication, newsletter delivery, and support communications.
  • Organisation name — to contextualise your usage and provide organisation-level features where applicable.

How signing in works. We do not store a password, because we never ask you for one. When you sign in we email you a link and a six-digit code. Both are single-use and expire after fifteen minutes, and we keep only a one-way hash of each — so what we hold cannot be turned back into a working link, by us or by anyone who obtained a copy of it. Using either one deletes it.

Signing in successfully creates a session record. It holds your account identifier, your email address, when the session started and was last used, and — so that a session appearing from somewhere unexpected can be recognised — the IP address and browser user-agent string it was created from. It expires after 30 days without use, and after 90 days regardless. Signing out deletes it immediately.

Legal basis (GDPR Art. 6): Contract performance for account functionality and for signing you in. Consent for newsletter communications. You may withdraw newsletter consent at any time via the unsubscribe link in any email or by contacting dpo@greencalculus.com.

4.2 Technical Data

We automatically collect the minimum technical information required to operate a secure, performant service:

  • IP address: We do not truncate IP addresses. Your IP address is processed in the following places:
    • Content delivery and security filtering (Cloudflare). Our website and API are served through Cloudflare, which receives your IP address with every request in order to deliver the page and filter malicious traffic.
    • Abuse limits (Cloudflare Workers KV). When a free API key is requested, or a key is re-sent, we hold a counter against your IP address for 24 hours to limit how many such requests come from one address.
    • Bot challenge (Cloudflare Turnstile). The free API key form sends your IP address to Cloudflare so it can verify the challenge.
    • Sign-in sessions (Cloudflare Workers KV). A session record stores the IP address it was created from, so that a session appearing from somewhere unexpected can be recognised. It is deleted with the session.
    • Server logs (our hosting provider). Web-server logs record your IP address against each request. Retention for those logs is described under “Technical / log data”.
    • Website analytics (Umami Cloud). Our analytics script is loaded from Umami Cloud, so your browser’s request for that script reveals your IP address to that provider.
    API usage records do not include your IP address.
  • User-agent string: Browser and operating system information, used solely for rendering compatibility decisions.
  • HTTP request logs: Our hosting provider’s web-server logs record the endpoint called, the HTTP response code, the response time, your IP address, and the full web address requested — including any query parameters it contains. Request body content is not logged.
  • De-identified error data: Stack traces for debugging, stripped of any user-identifiable information before storage.

Legal basis (GDPR Art. 6(1)(f)): Legitimate interests — maintaining the security and performance of the platform. Retention: these logs are held by our hosting provider on a rolling basis and are not separately retained by us. The window depends on traffic volume rather than a fixed schedule, and was approximately 30 days when last measured. Legitimate Interests Assessments (LIAs) are available from our DPO on request.

4.3 Analytics Data

We use cookieless, privacy-first analytics to understand how our tools are used in aggregate. Our analytics are provided by Umami — a privacy-first, cookieless, open-source analytics service — chosen specifically because it:

  • Does not use cookies or any persistent cross-session identifiers.
  • Does not collect personal data or construct user profiles.
  • Does not track users across websites or sessions.
  • Provided by Umami Cloud, an open-source service operated from the EU (Germany) data region that receives only aggregate, non-personal page metrics — never shared with advertising networks and never used to build user profiles.
  • Produces only aggregate statistics (e.g., “The Scope 3 Category 1 Calculator received 2,400 sessions this week”).

Legal basis (GDPR Art. 6(1)(f)): Legitimate interests — improving product quality through aggregate usage insight. No consent banner is required for this analytics implementation because no personal data is processed.

4.4 Google Sheets Add-on

GreenCalculus for Google Sheets is an add-on that puts emission factors from our API into spreadsheet cells. It runs inside your Google account, on Google’s servers, under your own agreement with Google; Google is not our processor for it, and Google’s handling of the add-on is governed by Google’s privacy policy. This is what the add-on does with data:

  • What leaves your spreadsheet: the factor names (keys) you look up and the words you type into the add-on’s search box, sent to api.greencalculus.com in the same way as any other use of our API. If you have saved an API key, it is sent with those requests; if you have pinned a workbook to a data version, that version is sent too. Nothing else in your spreadsheet is sent. The amounts you multiply factors by are calculated inside Google Sheets and never reach us, and the add-on cannot read other files or other spreadsheets.
  • What we receive from Google about you: nothing. The add-on does not request or receive your name, email address or Google account details. Because the requests are made by Google’s servers on your behalf, our API does not receive your device’s IP address for add-on lookups. Once the add-on is listed, Google reports installation counts to us in aggregate only.
  • The Google permissions it asks for: to connect to an external service (our API); to read and change only the spreadsheet it is open in, so that it can write the cells you ask for; and to show its sidebar and menu. It requests no access to Google Drive, Gmail, Calendar or any other Google data.
  • What is stored, and where: if you save an API key, Google stores it in the add-on’s per-user storage for your Google account; other users of the spreadsheet cannot see it, and Clear in the sidebar deletes it. A small flag records that you have seen the welcome panel. Factor values you have looked up are cached on Google’s servers for up to six hours so that repeated formulas do not re-request them; the cache holds factor data only, no personal data. Uninstalling the add-on stops all requests.
  • What we keep: add-on requests are handled exactly like other API requests. A request made without an API key is recorded in the API usage records with a client tag (sheets) and no account identifier; a request made with your key is recorded as your API usage. The factor names and search terms travel in the web address of the request and therefore also appear in the technical logs described in 4.2 above.

Legal basis (GDPR Art. 6(1)(b) and 6(1)(f)): Contract performance — returning the factors you ask for. Legitimate interests — service integrity and abuse prevention, as for the API generally.

5. Our Data Minimisation Pledge

Our Zero-Bloat engineering philosophy extends directly into our data practices. We believe organisations should never have to choose between accessing powerful environmental tools and protecting proprietary operational data.

What We Deliberately Do Not Use

  • No third-party advertising pixels — not Google Ads, Meta Pixel, LinkedIn Insight Tag, or any equivalent.
  • No cross-site behavioural tracking or fingerprinting of any kind.
  • No session-replay or heatmap tools that record keystrokes, mouse movements, or form inputs.
  • No data broker integrations, lead enrichment services, or CRM data pipelines.
  • No AI training data pipelines that incorporate user-submitted content or calculator inputs.

Every tracking script that does not exist on this page is one fewer vector for data leakage, one fewer third-party dependency that could be compromised, and measurably lower page weight — which reduces both load time and the carbon footprint of each page view served.

6. Cookie Policy

A cookie is a small data file stored in your browser. GreenCalculus.com sets four cookies. All four are strictly necessary, the table below names every one of them, and there are no others.

We use no advertising, tracking, profiling or attribution cookies, and our analytics are cookieless by design (see §4.3). Two of the four are set by Cloudflare, which serves and protects this site; we would rather name them than tell you we use nothing from a third party.

Cookie What it does Set by Duration
__cf_bm Bot management. Lets the firewall tell a browser apart from an automated scraper. Cloudflare ~30 minutes
cf_clearance Records that you passed a security challenge, so you are not challenged again on every page. Only set if you were challenged. Cloudflare Challenge-length
gc_sess Keeps you signed in to your API account. Set on api.greencalculus.com only, and never sent to this website. GreenCalculus 30 days idle, 90 max
gc_slr Ties a sign-in link to the browser that asked for it, so a link intercepted in transit cannot simply be used elsewhere. Same domain as above. GreenCalculus 15 minutes

There is no cookie banner on this site, and that is a decision rather than an oversight. A consent tool exists so that you can refuse non-essential cookies; we do not set any, so there would be nothing for it to ask you about. Every cookie above is needed either to keep you signed in or to keep the site up, which is why none of them requires consent.

You can still block or delete cookies in your browser — refer to your browser’s help documentation. Blocking the two Cloudflare cookies may mean you are shown a security challenge more often, and blocking the two GreenCalculus ones means you cannot stay signed in to an API account.

We check this rather than assume it. After any release that could introduce a cookie, an automated test loads nine pages of this site in a real browser and reports every cookie it finds that is not named in the table above. It is how this section stays true as the site changes, and it is what would oblige us to update this page before any new cookie reached you.

Legal basis (GDPR Art. 6(1)(f); PECR Reg. 6(4)): Legitimate interests — keeping the service secure, and providing the sign-in you asked for. Cookies strictly necessary to deliver a service you requested are exempt from the consent requirement, and we set none that fall outside that exemption.

7. Global Compliance — Your Privacy Rights by Jurisdiction

We honour privacy rights for all users regardless of location. The following table summarises your rights under the major frameworks we comply with. All requests are responded to at no charge.

Regulation Jurisdiction Key Rights Response Time How to Submit
GDPR EU / UK Access, Rectification, Erasure, Portability, Restriction, Objection 30 days dpo@greencalculus.com
CCPA / CPRA California, USA Know, Delete, Correct, Opt-Out of Sale (N/A), Non-Discrimination 45 days privacy@greencalculus.com
PIPEDA Canada Access, Correction, Withdrawal of Consent 30 days dpo@greencalculus.com
PDPA Singapore / Thailand Access, Correction, Data Portability 30 days dpo@greencalculus.com
All other jurisdictions Global We apply GDPR-equivalent standards globally by default 30 days privacy@greencalculus.com

7.1 GDPR — European Union and United Kingdom

For users in the EU and UK, GreenCalculus.com acts as the Data Controller under Regulation (EU) 2016/679 and its UK equivalent (UK GDPR).

Lawful Bases for Processing

  • Contract performance (Art. 6(1)(b)): Processing necessary to provide the service you have requested — account management and calculator computation.
  • Legitimate interests (Art. 6(1)(f)): Technical logging for security and platform performance; aggregate anonymised analytics. LIAs available on request from our DPO.
  • Consent (Art. 6(1)(a)): Newsletter subscriptions and functional cookies. Consent is freely given, specific, informed, and unambiguous, and may be withdrawn at any time without detriment to your access to the platform.

Your GDPR Rights — Exercisable Free of Charge Within 30 Days

You may obtain a copy of all personal data we hold about you, along with information about how it is processed, where it is stored, and who it has been shared with. Submit your request to dpo@greencalculus.com.

You may request correction of inaccurate or incomplete personal data we hold about you. Most identity data can be corrected directly in your account settings; for anything else, contact dpo@greencalculus.com.

You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, where you withdraw consent, or where you object to processing. We will comply unless we are required to retain the data by law. Contact dpo@greencalculus.com.

You may request that we limit how we process your data while a dispute about accuracy or lawfulness is resolved. During this period, your data will be stored but not actively processed beyond what you authorise.

You may receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV) for transfer to another data controller. This right applies to data you have provided to us and which is processed on the basis of consent or contract performance.

You may object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for the establishment or defence of legal claims.

We do not make any automated decisions that produce legal or similarly significant effects for individuals. Our calculators produce outputs for your own use — they do not make decisions about you.

Data Transfers Outside the EEA

Where personal data is transferred outside the European Economic Area, we ensure adequate safeguards are in place — including Standard Contractual Clauses (SCCs) approved by the European Commission under Decision 2021/914/EU, and Transfer Impact Assessments (TIAs) where required by applicable guidance.

Supervisory Authority

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority. We strongly encourage you to contact our DPO at dpo@greencalculus.com first — we commit to responding within 2 business days and resolving most concerns without the need for regulatory escalation.

7.2 CCPA and CPRA — California Consumers

GreenCalculus.com complies with the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020.

CCPA Position Statement

GreenCalculus.com does not sell or share personal information as defined under the CCPA/CPRA. We do not sell data to brokers. We do not permit third parties to use your data for their own commercial purposes. The “Do Not Sell or Share My Personal Information” right exists — and we honour it unconditionally — but there is nothing to opt out of because no sale or sharing occurs.

California Consumer Rights

  • Right to Know: Request disclosure of the categories and specific pieces of personal information collected about you in the past 12 months, and the purposes for which it was collected.
  • Right to Delete: Request deletion of personal information we have collected, subject to certain legal exceptions.
  • Right to Correct: Request correction of inaccurate personal information we hold about you.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share data, but we acknowledge and honour all opt-out requests submitted.
  • Right to Limit Sensitive Personal Information: We do not process sensitive personal information for any purpose beyond providing the requested service.
  • Right to Non-Discrimination: We will never discriminate against you — in service quality, pricing, or access — for exercising any privacy right.

To exercise your California rights, email privacy@greencalculus.com. We will respond within 45 days. In complex cases, we may extend by a further 45 days with written notice.

8. Data Security and Hosting

We apply industry-standard technical and organisational security measures at every layer of the platform.

8.1 Hosting Infrastructure

  • Cloud hosting: Production infrastructure is hosted on SOC 2 Type II certified data centres — EU-West region for EU/UK users, Singapore region for Asia-Pacific users. Our hosting infrastructure is also aligned with ISO/IEC 27001 information security management standards.
  • Data residency: EU/UK user data does not leave EU-West data centres under normal operating conditions. Asia-Pacific user data is processed in Singapore-region data centres.

8.2 Encryption

  • Data in transit: All connections to GreenCalculus.com are encrypted using TLS 1.3 (minimum TLS 1.2). HTTP Strict Transport Security (HSTS) is enforced with a max-age of one year and the domain is included in the HSTS preload list.
  • Data at rest: All data stored in our databases is encrypted at rest using AES-256, including all database backups.
  • Credentials and secrets: API keys, database credentials, and secrets are managed via industry-standard secrets management systems. They are never stored in source code, configuration files, or logs.

8.3 Access Controls

  • Least privilege: Staff access to production systems is role-based and restricted to the minimum required to perform the relevant function.
  • Multi-factor authentication: Required for all staff access to production systems and administrative interfaces without exception.
  • Audit logging: All administrative access to systems that store personal data is logged and reviewed on a quarterly basis.

8.4 Incident Response

In the event of a data breach likely to result in a risk to the rights and freedoms of individuals, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.
  • Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights, in accordance with GDPR Article 34.
  • Maintain a documented internal record of all breaches, including those not requiring external notification, in accordance with GDPR Article 33(5).
Security Vulnerability Disclosure

To report a security vulnerability, contact security@greencalculus.com. We operate a responsible disclosure policy and will acknowledge all reports within 24 hours. We do not pursue legal action against good-faith security researchers.

9. Data Retention — How Long We Keep What We Hold

We retain data only for as long as strictly necessary for the purpose it was collected, or as required by applicable law. At the end of every retention period, data is deleted using secure erasure methods that render recovery infeasible.

Data Type Retention Period Deletion Method
Calculator input data Not retained — processed in memory and discarded immediately Never written to storage
Account identity data Duration of active account + 2 years after closure Automated secure deletion
Newsletter email addresses Until unsubscribe or deletion request is received Immediate on request
Technical log data No fixed period. Rotated by our hosting provider based on traffic volume and available storage; approximately 30 days when last measured. Automatic rotation by the hosting provider
Website analytics data 12 months (aggregate statistics only, no personal data) Automated deletion on schedule
API usage records 3 months, set and applied by Cloudflare Analytics Engine Automatic expiry by the processor
Functional cookie data 12 months from last activity Browser-managed expiry

You may request earlier deletion of any personal data we hold at any time — see Section 7 for your rights and the contact details to use.

10. Third-Party Processors — Who Touches Your Data

We use a small number of carefully vetted sub-processors. Each is bound by a Data Processing Agreement (DPA) that meets GDPR Article 28 requirements. We do not permit any sub-processor to use your data for their own commercial purposes.

Processor Purpose Data Processed Location
Cloud Hosting Provider Production infrastructure, storage, compute All platform data within defined regions EU-West / Singapore
Umami Cloud Aggregate usage analytics No personal data — aggregate statistics only EU / Germany data region (operator: Umami Software, Inc., USA)
Resend Transactional email — delivering your API key and service alerts — and delivery of the optional Factor Watch update list Your email address. A message that delivers an API key contains that key. For the update list, your email address and the page you signed up from. United States. Safeguarded by Standard Contractual Clauses (EU and UK) and Resend’s EU-U.S. Data Privacy Framework certification. Resend publishes its own sub-processor list at resend.com/legal/subprocessors
Cloudflare, Inc. Content delivery, security filtering, and hosting of the GreenCalculus API API keys and the email address each key was issued to; full IP addresses, held for up to 24 hours, for abuse prevention; API usage records (see “API usage records” above) Global. Cloudflare stores data in a small number of central locations and caches it across its global network, so international transfers occur. Safeguarded by Cloudflare’s Data Processing Addendum and Standard Contractual Clauses. We do not offer region-specific data residency.
Cloudflare Turnstile Bot and abuse challenge on the free API key request form Your IP address and browser challenge signals, sent to Cloudflare for verification Global (SCC-protected), under the Cloudflare terms above
Stripe, Inc. Payment processing for paid API plans and directory listings Name, email address, billing address and payment card details, collected directly by Stripe on its own checkout pages and not passed through our systems. We store only the resulting customer and subscription identifiers. Global (SCC-protected). Stripe publishes its own sub-processor list at stripe.com/legal/service-providers

Enterprise customers may request our standard Data Processing Agreement by contacting dpo@greencalculus.com. We will notify account holders of any material changes to our sub-processor list at least 30 days in advance.

11. Children’s Privacy

GreenCalculus.com is a professional B2B platform designed for use by corporate teams, sustainability officers, and government engineers. Our services are not directed at persons under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child has submitted personal data to this platform, please contact dpo@greencalculus.com immediately and we will delete it without delay.

12. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, or our data practices. We will notify you of any material changes by:

  • Publishing the revised policy at greencalculus.com/privacy with an updated Effective Date and version number.
  • Sending an email notification to all registered account holders at least 14 days before any material change takes effect.
  • Displaying a prominent notice on the platform for 30 days following any material change.

The current version is always the authoritative version. Earlier versions are available on request from dpo@greencalculus.com.

13. Contact Our Data Protection Officer

GreenCalculus.com has appointed a Data Protection Officer (DPO) as required under GDPR Article 37. Our DPO is your primary contact for all formal privacy matters. We commit to acknowledging all data subject requests within 2 business days and resolving them within the statutory timeframe.

DPO

Data Rights & GDPR

Access, erasure, portability, rectification, objection requests. GDPR, PIPEDA, PDPA enquiries.

Privacy

General Privacy Questions

CCPA requests, cookie preferences, policy clarifications, and general data privacy enquiries.

Security

Security Disclosures

Vulnerability reports, suspected breaches, or security-related concerns. 24-hour acknowledgement guaranteed.

Support

Account & General Support

Account access issues, billing questions, technical support, and general platform enquiries.

This Privacy Policy constitutes a legally binding commitment of GreenCalculus.com and supersedes all prior versions. Version 1.2 was reviewed and approved by our appointed Data Protection Officer on 1 June 2026. Version 1.6 rebuilt the cookie section around the cookies this site actually sets and described how passwordless sign-in works. This version adds Section 4.4, describing the Google Sheets add-on; it introduces no new processor and no new category of data. It has not yet been reviewed by the Data Protection Officer.

© 2026 GreenCalculus.com  ·  Privacy Policy Version 1.7  ·  Effective 9 September 2026

Scroll to Top