Data Processing Agreement
Last updated: 9 August 2026
This Data Processing Agreement ("DPA") forms part of the terms of service between Digital Search Group Limited (trading as Carbon Verified (CarbonVerified.org), "we", "us") and you ("the Customer") when the Customer uses the service to process personal data on behalf of its clients. It reflects the requirements of the UK GDPR and EU GDPR.
1. Definitions
In this DPA, the following terms have the meanings below:
- "Controller" means the Customer, who determines the purposes and means of processing personal data.
- "Processor" means us, Digital Search Group Limited, who processes personal data on behalf of the Customer.
- "Personal data" means any information relating to an identified or identifiable natural person.
- "Subprocessor" means a third party engaged by us to assist in processing personal data.
2. Roles and responsibilities
The Customer is the Controller (or Processor acting on behalf of its own Controller). We are the Processor. We process personal data only on the Customer's documented instructions — namely, to run the assessment and verification service as described in the Terms of Service.
The Customer warrants that it has the right to submit website URLs for assessment and that doing so does not breach any applicable law or third-party rights.
3. Security measures
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS) and at rest (database-level encryption).
- Row-level security policies restricting data access to authorised users.
- Role-based access control for administrative functions.
- Regular security scanning and dependency monitoring.
- Authentication using hashed credentials with rate limiting.
4. Subprocessors
We engage the subprocessors listed at /subprocessors. We remain liable for the acts and omissions of our subprocessors to the same extent as our own.
We will give the Customer at least 30 days' notice before adding or replacing a subprocessor. The Customer may object and, if we cannot resolve the objection, terminate the service without penalty.
5. Data subject rights
We will assist the Customer in responding to data subject requests to the extent they relate to data processed through the service. We will forward any request we receive directly to the Customer unless we are legally prohibited from doing so.
6. Breach notification
If we become aware of a personal data breach, we will notify the Customer without undue delay and provide the information the Customer needs to meet its own breach notification obligations.
7. Deletion on termination
On termination of the service, we will delete the Customer's personal data in accordance with the retention periods set out in our Privacy Notice at /privacy, unless applicable law requires longer retention.
8. Audit
The Customer may audit our compliance with this DPA once per calendar year with at least 30 days' notice, subject to confidentiality obligations.
9. Contact
To execute this DPA or ask a question, contact privacy@carbonverified.org.