1. Who we are and when this notice applies
SustainPro AI provides sustainability evidence, calculation, reporting and verification workflows. SustainPro Solutions is the published service contact; the entity named in an executed order form or enterprise agreement is the contracting entity for that customer.
For account administration, security and direct product use, that entity normally decides why and how personal data is processed and acts as controller. For content an organisation submits for its own sustainability programme, the organisation normally acts as controller and SustainPro processes that content on its documented instructions. An executed data processing agreement or applicable law may allocate these roles differently.
2. Data categories and sources
Depending on the features used, we process: account identifiers and work contact details; organisation, membership, role and security events; sustainability readings and calculation inputs; evidence files and their metadata; integrity hashes, approvals, audit history and public verification projections; support communications; device, network and diagnostic data; and prompts, retrieved references and generated outputs.
Data comes from users and their organisations, invited suppliers, configured integrations, public or licensed reference sources, and technical events created when the service is used. Public response flows are designed to avoid names, email addresses and free text where the page says the response is anonymous.
3. Purposes and legal grounds
We use data to authenticate users; deliver contracted workflows; isolate organisations and enforce permissions; calculate, retrieve, generate and verify outputs; preserve evidence lineage and tamper-evident history; prevent abuse; diagnose incidents; provide support; and meet legal obligations.
The legal ground depends on the relationship and jurisdiction. It may be performance of a contract, steps requested before a contract, legitimate interests in operating and securing the service, consent where required, or compliance with law. Where SustainPro acts as processor, the customer determines the legal ground. We do not treat AI output as a legal basis for processing.
4. Evidence, AI and automated processing
Evidence may be parsed, indexed, matched to calculations and fingerprinted with SHA-256. Questions and relevant extracts may be sent to configured retrieval or model providers to create source-grounded drafts. Customers should avoid placing unrelated personal or special-category data in prompts or files.
Generated text can be incomplete or wrong and is not, by itself, a legal, regulatory or assurance decision. Governed approvals remain human actions. We do not state that the service makes solely automated decisions producing legal or similarly significant effects about individuals.
6. Hosting locations and international transfers
The current database, authentication and storage deployment is in Supabase’s Asia-Pacific Southeast 2 region (Sydney, Australia). Vercel uses globally distributed delivery infrastructure. Retrieval and model providers may process requests in other locations according to their configured service.
When a restricted transfer mechanism is required, the controller and processor should document the appropriate contractual safeguard and transfer assessment in the enterprise agreement or data processing agreement. A customer with mandatory residency requirements must confirm an agreed deployment profile before uploading regulated data; this public notice does not promise UAE-only residency.
7. Retention and deletion
Implemented product schedules are listed below. A shorter legal hold, customer instruction or contract period may change the applicable result where law permits.
| Data | Current schedule | Scope |
|---|---|---|
| Raw event-pulse responses | Maximum 365 days from dataset start | Raw responses; permanent aggregate provenance belongs in the sealed manifest |
| Pulse submission queue | No later than 7 days, capped by the campaign deadline | Temporary queued submissions |
| Pulse bulk-import sessions | Expire after 24 hours; purge after 7 days | Temporary import coordination state |
| Supplier offline-recovery responses | 90 days by default | Offline synchronization recovery rows |
| Public rate-limit state | Rows older than 1 hour are removed by cleanup | Hashed abuse-control keys and counters |
| Operations audit events | Minimum 180 days | Checked-in production operations policy |
| Pilot voucher records and backup manifests | Indefinite under the current pilot policy, unless law requires deletion | Operational records; this is not a promise for all customer content |
| Accounts, evidence, calculations and workpapers | No single public period is configured | Order form, workspace instructions, exit terms, backup lifecycle and legal holds must supply the period |
| Sealed records and public transparency receipts | Durable where immutable history is the stated feature | Corrections, revocation status or privacy-safe suppression may preserve integrity without exposing removed content |
Enterprise order forms should state missing periods, legal holds, backup expiry and deletion evidence. This schedule describes the current release and must change when implemented storage behaviour changes.
8. Security and incident handling
Controls include authenticated organisation boundaries, role-based operations, evidence integrity fingerprints, governed approval records, rate and abuse controls, and restricted public projections. No internet service can guarantee absolute security, and customers remain responsible for authorised-user management, endpoint security and appropriate data classification.
We investigate suspected incidents, contain and remediate them, preserve necessary evidence, and notify the affected controller or individuals when the applicable contract or law requires it. Security concerns should be sent to the contact below with no sensitive evidence in the initial email.
9. Your choices and data-subject rights
Subject to applicable law, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data where applicable, individuals may request access, correction, portability, restriction, objection, deletion, withdrawal of consent and review of relevant automated processing, and may complain to the competent authority. Rights are not absolute; identity, authority, legal holds, other people’s rights and immutable audit obligations may affect the response.
If your organisation provided the data, contact its administrator first because it is normally the controller. SustainPro will support verified controller instructions. An explicit language choice on a device overrides the organisation’s saved language default.
11. Contact, complaints and notice changes
For privacy requests, enterprise data-processing terms, the current subprocessor schedule or a security report, contact SustainPro Solutions at info@sustainpro.ae, +971 2 445 1552, or Al Wahda Tower, Mezzanine Floor, Abu Dhabi, UAE. Include your organisation and request type, but do not email evidence files or credentials. We may require identity and authority verification.
Material changes will be published with a new version and effective date and communicated through the contracted channel where required. This notice describes the product’s current posture; it is not legal advice and makes no claim of external endorsement.