Climate Zero Data Security & Privacy Policy

Last updated: March 2025.

At Climate Zero (of Impact Sustainability Pty Ltd. ACN 152 891 122) (“Climate Zero”, “we”, “us”) your privacy is important to us. We are committed to protecting your privacy when managing your personal information. Our policies and procedures ensure that all personal information is handled carefully and securely in accordance with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (” Privacy Act”).

The purpose of this Data Security & Privacy Policy is to inform you about:

  • The kind of personal information we collect
  • How we use that information
  • Our data security measures to protect your privacy
  • Whether we disclose your personal information to anyone
  • How you may inquire, access and/or seek correction of your personal information and our access and correction handling procedure; and
  • How you may alert us about an alleged breach of the APPs and our complaint handling procedure

By accessing or using our services, you agree to the practices described in this policy.

1. Information we collect

Account information

When you sign up for our services, we may collect personal information such as your name, email address, mobile number and job title to create and manage your account.

Company information

We collect information about your company or organisation including location and address information, utility meters (and their ID’s) and the number of employees.

Consumption and usage data

We process consumption and usage data provided by you or your company. This data may include things like amount of electricity consumed (kWh’s), amount of waste produced (in kgs) and distance travelled by different transport methods.

Financial accounting data

We process financial accounting data provided by you or your company, including data obtained from third party integrations with your accounting software. This data may include financial transactions, invoices, receipts, and related information.
We do not collect or store any payment,  banking details or data.

Usage information

We collect information about how you interact with our services, such as your IP address, browser type, device information, pages visited, and actions taken on our platform.

Metadata

When data records are created, metadata is stored on a per record basis. Metadata includes information such as the user that created the record and the date created.

Cookies

We may use cookies and similar technologies to enhance your user experience and collect certain information about your interactions with our website and services. We may use a combination of functional and analytical cookies.

2. How we use your information

Provision of services

We use the information you provide to deliver our carbon accounting services, including the accurate calculation and reporting of your carbon footprint data. The legal basis for this processing is contractual necessity.

Carbon footprint analysis

As an emissions management platform, our primary purpose for collecting and processing your information is to accurately calculate your organisation’s carbon footprint. We use the data provided by you or your organisation to calculate carbon emissions associated with your business operations. The legal basis for this processing is legitimate interest.

Insights & recommendations

The carbon footprint analysis allows us to generate valuable insights and recommendations aimed at helping your company reduce its carbon emissions. These insights may include identifying areas of inefficiency, suggesting sustainable practices, and measuring the impact of emission reduction initiatives. The legal basis for this processing is legitimate interest.

Communication

We may use your personal information collected to communicate with you including information about our services or products, updates on your reduction efforts, related news and updates or new features available in the platform. The legal basis for this processing is contractual necessity, as these communications are essential for the performance of our contract with you.

Improvement of services

We analyse aggregated usage data to improve our platform’s functionalities, enhance our carbon accounting services, and optimise the user experience for our customers. The legal basis for this processing is our legitimate interests in providing and improving our services.

3. Data security

Identity and authentication controls

We use an industry-standard approach to handle user authentication to prevent personal data being accessed by unauthorised individuals. This includes secure password handling through hashing and salting. All user passwords are encrypted and no employees are able to access this information. We never provide temporary employee generated passwords. Only users can create and manage their own password. For user authentication, we utilise Firebase Authentication so all authentication data, including login credentials and tokens, are securely stored in data centres located in the United States. These facilities are equipped with state-of-the-art security measures. All other user data, such as personal information and usage data, are stored on secure servers located in Australia. These servers are protected with both physical and electronic safeguards to prevent unauthorised access.

Encryption and data storage

We understand the sensitivity of the data we handle. We use industry-standard encryption methods to safeguard your information at rest and in transit. 
Encryption In Transit:

  • All data transmitted between our clients and our servers is secured using Transport Layer Security (TLS) 1.2 or higher. This protocol ensures that data is encrypted during its journey over the internet, protecting it from interception or tampering.
  • Firebase Authentication employs secure token-based mechanisms. This ensures that user credentials are handled and transmitted securely, without exposure.

Encryption At Rest:

  • All personal data stored in our systems, including databases and backups, is encrypted using Advanced Encryption Standard (AES-256). We do not store customer data on personal devices or devices used by company employees.
  • All personal data is stored in a Google Cloud Provider through services such as Firebase Authentication and CloudSQL, all adhering to strict security standards and compliance certifications, namely SOC-1, SOC-2, SOC-3, and ISO 27001.

Access controls

Access to customer data is limited to authorised personnel who require it for providing our carbon accounting services. Access to our systems is strictly based on predefined user roles (Role Based Access Controls). Each role is assigned specific access rights and privileges, depending on the individual’s job function and data access requirements. We provide the option of external access roles for third parties, such as consultants or auditors, who require access to the software. We adhere to the principle of least privilege, meaning users are granted only the access necessary to perform their job duties. This minimises the risk of unauthorised access, modification or disclosure of sensitive data.

Secure servers

Your data is stored on servers located in Sydney, Australia. These servers are protected with both physical and electronic safeguards to prevent unauthorised access. The servers are hosted by Google Cloud adhering to strict security standards and certifications namely SOC-2, SOC-3, and ISO 27001. The application is run on servers provisioned by Vercel, which maintains strict security standards and holds ISO 27001, SOC-2, HIPAA, GDPR and DPF certifications.

Data minimisation

We only collect and retain the data necessary for conducting carbon footprint analysis and providing our services. For example, when collecting company information, we only request location, address, and utility meter IDs that are essential for carbon footprint calculations. Similarly, financial accounting data is processed only to the extent necessary for emissions analysis. We do not store personal data beyond the required retention period, as outlined in our Data retention policy.

Data backup

Customer data is automatically backed up on a daily basis and backups are retained for 30 days before being destroyed automatically. In addition to the daily backups, we are also backed by a Point in Time data restoration service, covering the seven most recent days.

Cyber incident response plan

We have a Cyber incident response plan (CIRP) which provides a checklist of steps required when responding to a security incident. All potential cyber security incidents are required to be reported immediately and then investigated using different data sources and event logs to determine if there has been a breach.

Third-party vendors

In cases where we engage third-party vendors (including Firebase & Google Cloud) to support our services, we conduct due diligence to ensure their security practices align with our high standards.

User responsibility

As a user of our platform, you are responsible for maintaining the security of your account credentials. Please ensure that you keep your login information confidential and refrain from sharing it with unauthorised individuals.

Auditing

We work with a third party cyber security company to perform penetration testing on our software. We regularly audit and update all third party packages ensuring we are protected from latest updates.

Data destruction

When you store data on Climate Zero, you retain full ownership of that data. We believe that your information is yours, and we have policies in place to ensure that you can access, manage, and export your data at any time. We do not store personal data beyond the required retention period. If you cancel your agreement or switch providers your data can easily be exported from Climate Zero in a reusable format. Following a contractual termination, we will delete, and ensure that all of our applicable third party providers delete, all copies of your customer data.

4. Data portability

Your data is available for export either via the application or by request. All data can be exported in standard format and therefore is available for reuse.

5. Sharing of information

Third-party service providers

Where necessary, we may share or disclose your personal information with trusted third-party service providers and contractors who assist us in delivering our services and maintaining our infrastructure. Where information is shared with third parties, we take reasonable steps to ensure that third parties observe the confidential nature of such information and are prohibited from using any or all of this information beyond what is necessary to assist us in delivering our services.

Some of these third-party providers include:
Google Firebase Authentication: We use Google Firebase Authentication for authentication. Authentication data including login credentials and tokens, are securely stored and processed in data centres located in the United States. These facilities are equipped with state-of-the-art security measures. For further information regarding Google Firebase’s security measures, please refer to their Privacy & Security policy.

Google Cloud: We store your data on servers hosted by Google Cloud through the CloudSQL service. In addition any uploaded files and attachments are securely stored in Google Cloud and are protected from access through our Role Based Access Controls (RBAC). For further information regarding Google Cloud’s security measures, please refer to their Trust Centre

Amplitude: We use Amplitude for our user Analytics. We share data with Amplitude to understand usage so we can improve our products and services and customer experience. For further information regarding Amplitue’s security measures, please refer to their Trust Centre.

Postmark: We transmit user email addresses to Postmark, a third-party email service provider, to facilitate password retrieval. Postmark uses data centres located in the United States, operated by Amazon Web Services. We ensure that appropriate safeguards are in place to protect the transferred data, consistent with applicable data protection laws. For further information regarding Postmark’s security measures, please refer to their Security Centre.

Legal compliance

We may share your data to comply with legal obligations such as a law, regulation, court order, subpoena, warrant, in the course of a legal proceeding or in response to a law enforcement agency request.

Business transfers

In the event of a merger, acquisition, or sale of our assets, your information may be transferred to the acquiring entity.

International transfers

As Climate Zero may be considered a data controller for the purposes of the GDPR and Climate Zero does not maintain a physical presence in the European Union, you consent to us transferring your personal information to Australia. In doing this, we are informing you:

  • you have the rights set out in this privacy policy and at law under the Privacy Act; 
  • we process your personal information purely for the purposes of providing services to you and do not process this information for any other purpose; and 
  • the transfer of your personal information to Australia is necessary for the performance of a contract with you, your employer or any other person who has engaged us to perform services for them.

6. Your rights

You have the right to access, rectify, and delete your personal information. Under GDPR, you have the right to delete your data in certain circumstances, including, but not limited to where the information is no longer necessary for the purpose for which it was collected, or where the individual withdraws their consent and there is no other legal ground for processing their data.

If you wish to exercise any of these rights or have questions regarding your data, please contact us at [email protected]

You may be required to put your request in writing for security reasons. For most requests, your information will be provided free of charge, however a small administrative fee may be payable for the provision of information where it requires substantial effort to do so. We reserve the right to refuse to provide you with information that we hold about you, in certain circumstances set out in the Privacy Act.

7. Updates to the privacy policy

We review this Privacy policy annually at minimum, and may update it periodically to reflect changes in our practices or legal requirements. We encourage you to review the policy periodically for any updates. Any updates will be posted with a revised ‘Last Updated’ date.

Contact us

If you have any questions, feedback, or complaints regarding this Privacy policy or our data practices in rIf you have any questions, feedback, or complaints regarding this Privacy policy or our data practices in relation to your personal data collection, please contact us.

Climate Zero Privacy Officer
85 Dundas Place, Albert Park 
[email protected]