Privacy Policy
Last updated: 25 July 2026
This Privacy Policy explains how Represent Digital LLC (“Carbon,” “we,” “us”) collects, uses, and protects personal information in connection with the Carbon consent‑certification platform (the “Service”). It applies to our websites and to the Service we provide to business customers (“Customers”).
1. Our two roles
Carbon handles personal information in two distinct roles:
- As a controller — for information about our Customers and their personnel (account, billing, and support data), and for visitors to our own marketing websites.
- As a processor — for the consumer interaction data that we record, certify, and retain on behalf of a Customer when a consumer interacts with a page carrying that Customer’s Carbon snippet. For that data, the Customer determines the purposes and means, and this Policy is provided for transparency; the Customer’s own privacy notice governs the consumer relationship.
2. Information we collect
Account and website data (as controller)
- Contact and account details (name, work email, company, role).
- Billing information processed by our payment provider.
- Usage, device, and log data from our websites and dashboard, and cookies strictly necessary to operate them.
Consumer interaction data (as processor)
- A recording of the consumer’s interaction with the Customer’s form or disclosure — such as what was displayed, page and form state, and interaction events — captured to produce a certificate.
- Certificate metadata (timestamps, versions, and cryptographic signatures).
We are designed to avoid capturing payment card numbers and similar sensitive identifiers in recordings, and we scan batches to reduce the risk of such data being retained.
3. How we use information
- To provide, secure, and improve the Service, including minting and retaining certificates and enabling replay.
- To manage accounts, process payments, and provide support.
- To communicate service and security notices.
- To comply with legal obligations and enforce our agreements.
Consumer interaction data is processed only to provide the Service to the relevant Customer and per that Customer’s instructions; we do not sell it or use it for our own marketing.
4. Legal bases
Where required, we rely on legitimate interests (operating and securing the Service), performance of a contract (providing the Service to Customers), consent (where applicable), and compliance with legal obligations. For consumer data processed on a Customer’s behalf, the Customer is responsible for the legal basis.
5. Sharing and subprocessors
We share personal information with service providers who help us operate the Service under contractual confidentiality and security obligations — including cloud infrastructure and a payment processor. We do not sell personal information. We may disclose information where required by law or to protect rights and safety. A current list of subprocessors is available on request.
6. Security and tenant isolation
We use technical and organizational measures designed to protect personal information, including encryption in transit and at rest, access controls, and strict logical separation so that one Customer cannot access another Customer’s certificates, recordings, or configuration. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Retention
Account and website data is retained for as long as needed for the purposes described above and to meet legal obligations. Certificates and recordings are retained on the relevant Customer’s behalf according to that Customer’s plan and instructions; because certificates are evidentiary records, retention may be long‑lived by design, and deletion is performed on Customer instruction or as required by law.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict the use of your personal information, or to object or port it. For data we hold as a controller, contact us using the details below. For consumer interaction data we process on a Customer’s behalf, please contact that Customer, who is responsible for handling such requests; we will assist Customers in responding.
9. International transfers
We may process information in countries other than your own. Where we transfer personal information across borders, we use appropriate safeguards as required by applicable law.
10. Children
The Service is not directed to children, and we do not knowingly collect personal information from children. Customers must not deploy the Service on pages directed to children.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted here with an updated date and, where appropriate, communicated to Customers.
12. Contact
For privacy questions or to exercise your rights, contact privacy@getcarbon.io.