Data Processing Agreement (Article 28 GDPR)

Last updated: 9 September 2026 · Version 1.0

Annex to the Terms of Service, accepted by the Customer at registration. Enterprise customers may sign it separately with amendments.

The Carbonvia service (provisional name) is provided by Pipex Energy S.r.l.; inside the application the service is called CBAM Calculator. The texts below are the same as those published in the application.

This is a courtesy translation. The Italian version prevails for legal purposes.

1. Parties and roles

Controller: the Customer, as identified at registration (company name and VAT number recorded in the tenant).

Processor: Pipex Energy S.r.l., Viale Gian Galeazzo 15, 20136 Milan (MI), Italy, VAT 11674300964, email privacy@pipexenergy.it ("Pipex").

This agreement governs the processing Pipex carries out on behalf of the Customer in providing CBAM Calculator. It does not cover data Pipex processes as an independent controller (User accounts, billing, security), which is governed by the privacy notice.

2. Description of the processing (Art. 28(3))

ElementDescription
Subject matterStorage, processing, display, calculation, export and backup of Customer Data in the application
DurationTerm of the contract, plus the transition period provided by the Terms (Art. 13), then deletion
Nature and purposeProviding the Customer with a tool to manage CBAM obligations: recording imports, foreign supplier records, calculation of embedded emissions, simulations, reports, preparation of declarations; at the Customer's choice, automatic extraction of data from uploaded documents with human confirmation
Categories of data subjectsContact persons and employees of the Customer's foreign suppliers, producers and installation operators; employees and collaborators of the Customer mentioned in documents (signatories, customs contacts); the Customer's customs representatives
Categories of dataIdentification and contact data (name, email, phone, role), business and tax data (company name, tax identifier, addresses, geographic coordinates of installations), content of customs declarations and uploaded documents (including data possibly present in extracted text), emissions data and certificates. No special categories (Art. 9) or criminal conviction data (Art. 10) are foreseen: the Customer undertakes not to upload any

3. Pipex's obligations

Pipex:

4. Sub-processors

4.1. The Customer gives general authorisation to engage the sub-processors listed in Annex 2. Pipex imposes on them by contract obligations equivalent to those of this agreement and remains liable to the Customer for their performance.

4.2. Pipex notifies the tenant administrators by email of any addition or replacement at least 30 days in advance, updating the list published on this page. The Customer may object on reasonable, documented grounds within that period; if no solution is found, the Customer may withdraw from the contract free of charge with a refund of the unused period.

5. Verification and audits

5.1. On request Pipex provides: the description of security measures, the report of the most recent security review, the sub-processors' certifications (Microsoft: ISO 27001, ISO 27018, SOC 2; Stripe: PCI DSS Level 1) and answers to reasonable security questionnaires, at most once a year except in case of incidents.

5.2. The Customer, or an independent auditor appointed by it and bound by confidentiality, may carry out an on-site or remote audit at most once a year, with 30 days' notice, on working days, without compromising the security of other Customers. Audit costs are borne by the Customer, unless substantial breaches emerge. Access to sub-processors' systems is not permitted: their certification reports apply.

6. Transfers outside the EU

Data is stored and processed in the European Union. Any access from third countries by sub-processors (technical support, security operations) is covered by the Standard Contractual Clauses (Decision (EU) 2021/914) included in the respective contracts and, where applicable, by the EU-US Data Privacy Framework. Pipex will not transfer data outside the EU for other reasons without the Customer's prior written authorisation, except where required by EU or Italian law, in which case it informs the Customer before processing if the law allows.

7. Customer's obligations

The Customer warrants that it has a legal basis for processing the data it uploads, that it has provided data subjects with the required information (Arts. 13-14 GDPR) and that it does not upload data unnecessary for the purposes of the Service, in particular special categories of data. The Customer is responsible for managing the Users of its tenant (assigning roles, promptly removing those who leave), API keys and the Partners to whom it grants access.

8. Liability

The parties are liable in accordance with Art. 82 GDPR. Towards the Customer, the limitation of liability provided by the Terms of Service (Art. 11) applies, but it does not apply to compensation owed to data subjects under Art. 82.

9. Term and precedence

This agreement lasts for the term of the contract and survives until the data is deleted. In case of conflict with the Terms, this agreement prevails as regards the processing of personal data. Italian law applies; jurisdiction as per the Terms.

Annex 1 – Technical and organisational measures (Art. 32)

Annex 2 – List of sub-processors

Sub-processorLocationActivityPlace of processingSafeguards
Microsoft Ireland Operations Ltd (Microsoft Corporation group)Dublin, IrelandApplication hosting, database, file storage, secret management, logs and monitoring (Azure); data extraction from documents (Azure AI Document Intelligence); language model for document reading (Azure OpenAI). Microsoft does not use the data to train models; it may retain prompts and outputs for up to 30 days for abuse monitoringAzure Sweden Central region (Sweden)Microsoft Products and Services Data Protection Addendum, Standard Contractual Clauses, EU Data Boundary, ISO 27001/27018, SOC 2, Data Privacy Framework
Brevo (Sendinblue SAS)Paris, FranceDelivery of transactional emails (invitations, notifications, alerts) containing recipients' name and emailEuropean UnionBrevo Data Processing Agreement, ISO 27001
Stripe Payments Europe LtdDublin, IrelandPayment and subscription management. Receives the Customer's billing data (controller: Pipex), not the Customer's suppliers' data. Listed for transparency: it acts mainly as an independent controllerEuropean Union, with transfers to Stripe Inc. (USA) covered by Standard Contractual Clauses and Data Privacy FrameworkPCI DSS Level 1, Stripe Data Processing Agreement

No other party receives Customer Data. No analytics, tracking or advertising services are used.