Last updated: 9 September 2026 · Version 1.0
Annex to the Terms of Service, accepted by the Customer at registration. Enterprise customers may sign it separately with amendments.
The Carbonvia service (provisional name) is provided by Pipex Energy S.r.l.; inside the application the service is called CBAM Calculator. The texts below are the same as those published in the application.
This is a courtesy translation. The Italian version prevails for legal purposes.
Controller: the Customer, as identified at registration (company name and VAT number recorded in the tenant).
Processor: Pipex Energy S.r.l., Viale Gian Galeazzo 15, 20136 Milan (MI), Italy, VAT 11674300964, email privacy@pipexenergy.it ("Pipex").
This agreement governs the processing Pipex carries out on behalf of the Customer in providing CBAM Calculator. It does not cover data Pipex processes as an independent controller (User accounts, billing, security), which is governed by the privacy notice.
| Element | Description |
|---|---|
| Subject matter | Storage, processing, display, calculation, export and backup of Customer Data in the application |
| Duration | Term of the contract, plus the transition period provided by the Terms (Art. 13), then deletion |
| Nature and purpose | Providing the Customer with a tool to manage CBAM obligations: recording imports, foreign supplier records, calculation of embedded emissions, simulations, reports, preparation of declarations; at the Customer's choice, automatic extraction of data from uploaded documents with human confirmation |
| Categories of data subjects | Contact persons and employees of the Customer's foreign suppliers, producers and installation operators; employees and collaborators of the Customer mentioned in documents (signatories, customs contacts); the Customer's customs representatives |
| Categories of data | Identification and contact data (name, email, phone, role), business and tax data (company name, tax identifier, addresses, geographic coordinates of installations), content of customs declarations and uploaded documents (including data possibly present in extracted text), emissions data and certificates. No special categories (Art. 9) or criminal conviction data (Art. 10) are foreseen: the Customer undertakes not to upload any |
Pipex:
4.1. The Customer gives general authorisation to engage the sub-processors listed in Annex 2. Pipex imposes on them by contract obligations equivalent to those of this agreement and remains liable to the Customer for their performance.
4.2. Pipex notifies the tenant administrators by email of any addition or replacement at least 30 days in advance, updating the list published on this page. The Customer may object on reasonable, documented grounds within that period; if no solution is found, the Customer may withdraw from the contract free of charge with a refund of the unused period.
5.1. On request Pipex provides: the description of security measures, the report of the most recent security review, the sub-processors' certifications (Microsoft: ISO 27001, ISO 27018, SOC 2; Stripe: PCI DSS Level 1) and answers to reasonable security questionnaires, at most once a year except in case of incidents.
5.2. The Customer, or an independent auditor appointed by it and bound by confidentiality, may carry out an on-site or remote audit at most once a year, with 30 days' notice, on working days, without compromising the security of other Customers. Audit costs are borne by the Customer, unless substantial breaches emerge. Access to sub-processors' systems is not permitted: their certification reports apply.
Data is stored and processed in the European Union. Any access from third countries by sub-processors (technical support, security operations) is covered by the Standard Contractual Clauses (Decision (EU) 2021/914) included in the respective contracts and, where applicable, by the EU-US Data Privacy Framework. Pipex will not transfer data outside the EU for other reasons without the Customer's prior written authorisation, except where required by EU or Italian law, in which case it informs the Customer before processing if the law allows.
The Customer warrants that it has a legal basis for processing the data it uploads, that it has provided data subjects with the required information (Arts. 13-14 GDPR) and that it does not upload data unnecessary for the purposes of the Service, in particular special categories of data. The Customer is responsible for managing the Users of its tenant (assigning roles, promptly removing those who leave), API keys and the Partners to whom it grants access.
The parties are liable in accordance with Art. 82 GDPR. Towards the Customer, the limitation of liability provided by the Terms of Service (Art. 11) applies, but it does not apply to compensation owed to data subjects under Art. 82.
This agreement lasts for the term of the contract and survives until the data is deleted. In case of conflict with the Terms, this agreement prevails as regards the processing of personal data. Italian law applies; jurisdiction as per the Terms.
| Sub-processor | Location | Activity | Place of processing | Safeguards |
|---|---|---|---|---|
| Microsoft Ireland Operations Ltd (Microsoft Corporation group) | Dublin, Ireland | Application hosting, database, file storage, secret management, logs and monitoring (Azure); data extraction from documents (Azure AI Document Intelligence); language model for document reading (Azure OpenAI). Microsoft does not use the data to train models; it may retain prompts and outputs for up to 30 days for abuse monitoring | Azure Sweden Central region (Sweden) | Microsoft Products and Services Data Protection Addendum, Standard Contractual Clauses, EU Data Boundary, ISO 27001/27018, SOC 2, Data Privacy Framework |
| Brevo (Sendinblue SAS) | Paris, France | Delivery of transactional emails (invitations, notifications, alerts) containing recipients' name and email | European Union | Brevo Data Processing Agreement, ISO 27001 |
| Stripe Payments Europe Ltd | Dublin, Ireland | Payment and subscription management. Receives the Customer's billing data (controller: Pipex), not the Customer's suppliers' data. Listed for transparency: it acts mainly as an independent controller | European Union, with transfers to Stripe Inc. (USA) covered by Standard Contractual Clauses and Data Privacy Framework | PCI DSS Level 1, Stripe Data Processing Agreement |
No other party receives Customer Data. No analytics, tracking or advertising services are used.