SustainPro AI

Privacy Notice

How SustainPro AI handles personal data and customer evidence across account, enterprise and public verification workflows.

Version 1.0Effective: 10 August 2026privacy-2026-08-10.v1

SHA-256: fce4ba600dc46085ee48fd3d4be56b892144c8a9323b89db1802e0a9ca4edfd4

1. Who we are and when this notice applies

SustainPro AI provides sustainability evidence, calculation, reporting and verification workflows. SustainPro Solutions is the published service contact; the entity named in an executed order form or enterprise agreement is the contracting entity for that customer.

For account administration, security and direct product use, that entity normally decides why and how personal data is processed and acts as controller. For content an organisation submits for its own sustainability programme, the organisation normally acts as controller and SustainPro processes that content on its documented instructions. An executed data processing agreement or applicable law may allocate these roles differently.

2. Data categories and sources

Depending on the features used, we process: account identifiers and work contact details; organisation, membership, role and security events; sustainability readings and calculation inputs; evidence files and their metadata; integrity hashes, approvals, audit history and public verification projections; support communications; device, network and diagnostic data; and prompts, retrieved references and generated outputs.

Data comes from users and their organisations, invited suppliers, configured integrations, public or licensed reference sources, and technical events created when the service is used. Public response flows are designed to avoid names, email addresses and free text where the page says the response is anonymous.

3. Purposes and legal grounds

We use data to authenticate users; deliver contracted workflows; isolate organisations and enforce permissions; calculate, retrieve, generate and verify outputs; preserve evidence lineage and tamper-evident history; prevent abuse; diagnose incidents; provide support; and meet legal obligations.

The legal ground depends on the relationship and jurisdiction. It may be performance of a contract, steps requested before a contract, legitimate interests in operating and securing the service, consent where required, or compliance with law. Where SustainPro acts as processor, the customer determines the legal ground. We do not treat AI output as a legal basis for processing.

4. Evidence, AI and automated processing

Evidence may be parsed, indexed, matched to calculations and fingerprinted with SHA-256. Questions and relevant extracts may be sent to configured retrieval or model providers to create source-grounded drafts. Customers should avoid placing unrelated personal or special-category data in prompts or files.

Generated text can be incomplete or wrong and is not, by itself, a legal, regulatory or assurance decision. Governed approvals remain human actions. We do not state that the service makes solely automated decisions producing legal or similarly significant effects about individuals.

5. Recipients and service providers

Authorised customer members, suppliers and reviewers receive data only through the access workflow used. The following schedule reflects providers and conditional lanes named in this release:

ProviderPurposeData involvedLocation / condition
SupabaseDatabase, authentication and object storageAccounts, organisation records, workflow data and evidenceCurrent project: Sydney, Australia
VercelApplication hosting, edge delivery and configured analyticsRequest metadata and application responsesGlobal delivery infrastructure
RunPodRetrieval computeQueries and relevant retrieval excerptsOnly when the retrieval lane is configured
OpenAI, xAI and DeepSeekConfigured model generation lanesPrompts, relevant excerpts and generated outputOnly for the selected server-side lane; provider infrastructure applies
Anthropic and Google GeminiOptional model or document-extraction lanesPrompts, evidence extracts and generated outputOnly when configured; provider infrastructure applies
Cloudflare TurnstileAutomated-abuse challengeNetwork, device and challenge signalsOnly when the public site key is configured
Microsoft Entra or customer IdPEnterprise authenticationAccount identifiers and authentication exchangeOnly when the organisation enables that identity provider

Provider configuration and model selection can change. Contractual notice rights continue to apply. We may also disclose the minimum necessary data to advisers, authorities or transaction counterparties where law or a binding process requires it. We do not sell personal data or use customer evidence for third-party advertising.

6. Hosting locations and international transfers

The current database, authentication and storage deployment is in Supabase’s Asia-Pacific Southeast 2 region (Sydney, Australia). Vercel uses globally distributed delivery infrastructure. Retrieval and model providers may process requests in other locations according to their configured service.

When a restricted transfer mechanism is required, the controller and processor should document the appropriate contractual safeguard and transfer assessment in the enterprise agreement or data processing agreement. A customer with mandatory residency requirements must confirm an agreed deployment profile before uploading regulated data; this public notice does not promise UAE-only residency.

7. Retention and deletion

Implemented product schedules are listed below. A shorter legal hold, customer instruction or contract period may change the applicable result where law permits.

DataCurrent scheduleScope
Raw event-pulse responsesMaximum 365 days from dataset startRaw responses; permanent aggregate provenance belongs in the sealed manifest
Pulse submission queueNo later than 7 days, capped by the campaign deadlineTemporary queued submissions
Pulse bulk-import sessionsExpire after 24 hours; purge after 7 daysTemporary import coordination state
Supplier offline-recovery responses90 days by defaultOffline synchronization recovery rows
Public rate-limit stateRows older than 1 hour are removed by cleanupHashed abuse-control keys and counters
Operations audit eventsMinimum 180 daysChecked-in production operations policy
Pilot voucher records and backup manifestsIndefinite under the current pilot policy, unless law requires deletionOperational records; this is not a promise for all customer content
Accounts, evidence, calculations and workpapersNo single public period is configuredOrder form, workspace instructions, exit terms, backup lifecycle and legal holds must supply the period
Sealed records and public transparency receiptsDurable where immutable history is the stated featureCorrections, revocation status or privacy-safe suppression may preserve integrity without exposing removed content

Enterprise order forms should state missing periods, legal holds, backup expiry and deletion evidence. This schedule describes the current release and must change when implemented storage behaviour changes.

8. Security and incident handling

Controls include authenticated organisation boundaries, role-based operations, evidence integrity fingerprints, governed approval records, rate and abuse controls, and restricted public projections. No internet service can guarantee absolute security, and customers remain responsible for authorised-user management, endpoint security and appropriate data classification.

We investigate suspected incidents, contain and remediate them, preserve necessary evidence, and notify the affected controller or individuals when the applicable contract or law requires it. Security concerns should be sent to the contact below with no sensitive evidence in the initial email.

9. Your choices and data-subject rights

Subject to applicable law, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data where applicable, individuals may request access, correction, portability, restriction, objection, deletion, withdrawal of consent and review of relevant automated processing, and may complain to the competent authority. Rights are not absolute; identity, authority, legal holds, other people’s rights and immutable audit obligations may affect the response.

If your organisation provided the data, contact its administrator first because it is normally the controller. SustainPro will support verified controller instructions. An explicit language choice on a device overrides the organisation’s saved language default.

10. Browser storage, analytics and children

The service uses necessary browser storage for authentication, preferences, workflow continuity and security. The public site may use privacy-respecting, cookieless analytics where configured. A challenge provider may set technical data needed to prevent automated abuse. We do not use customer evidence for behavioural advertising.

The service is intended for organisations and authorised business users, not children acting on their own. Do not submit children’s personal data unless the customer has established a lawful, necessary and contractually permitted workflow.

11. Contact, complaints and notice changes

For privacy requests, enterprise data-processing terms, the current subprocessor schedule or a security report, contact SustainPro Solutions at info@sustainpro.ae, +971 2 445 1552, or Al Wahda Tower, Mezzanine Floor, Abu Dhabi, UAE. Include your organisation and request type, but do not email evidence files or credentials. We may require identity and authority verification.

Material changes will be published with a new version and effective date and communicated through the contracted channel where required. This notice describes the product’s current posture; it is not legal advice and makes no claim of external endorsement.