Formal privacy information
Privacy notice
Last updated: 2 August 2026
This notice explains processing on the public website, for pilot enquiries, in organizer accounts, and during cleanup campaigns. It states the actual purposes, legal bases, recipients, and deletion criteria.
For a shorter product-focused explanation, visit the
Privacy Center.
1. Controller
The following provider is the controller for the public website, pilot enquiries, and its own business, security, and account data:
Behzad Norouzi Kiaroudi
Email: [email protected]
2. Roles in customer campaigns
- For a campaign, the organizing customer normally determines its purpose, participant group, photo use, and publication scope. In that case, the organization will normally be the controller for campaign data.
- Green Impact Report provides the platform and processes that data for the organization within the agreed scope. Before a real customer pilot, roles and instructions are recorded in the customer agreement or a data processing agreement.
- Green Impact Report acts as controller for technical security, website, account, support, and its own business data. Participants can contact the organizer about the purpose of a campaign and Green Impact Report about technical privacy matters.
3. Processing activities
The information processed depends on whether you only visit the website, send an enquiry, use an organizer account, or participate in a campaign.
Website, hosting, and security
- Data
- IP address, time, requested address, status and error data, browser and device information, and technical request data.
- Purpose
- Deliver the website and API, fix errors, detect attacks, limit abuse, and demonstrate secure operation.
- Legal basis
- Article 6(1)(f) GDPR. The legitimate interest is secure, stable operation protected against misuse.
- Retention
- Normal API and worker logs are generally kept for 7 days in the pilot environment and up to 30 days in stage/production. Relevant entries may be secured for a limited longer period for a specific security incident.
- Recipients
- Amazon Web Services (AWS) and Cloudflare for hosting, DNS, and protection.
Organizer account and protected area
- Data
- Name, email address, invitation status and expiry, authentication ID, organization, role, session and access information, plus important campaign-access and result-review changes with their time and acting account. Event preparation may also store expected attendance, duration, setting, meeting point, cleanup area, permission and disposal status, completed preparation steps, and an optional emergency contact.
- Purpose
- Secure invitation, login, access control, organization assignment, accountable campaign and event preparation, support, and account security.
- Legal basis
- Article 6(1)(b) GDPR for contracts and pre-contractual steps and Article 6(1)(f) GDPR for secure access control.
- Retention
- Invitation links can be used for 7 days. Invitation, account, and access records are kept for the customer relationship, then only while support, security evidence, or legal duties require them. Event-preparation data is automatically removed with detailed campaign data, by default 12 months after the campaign ends.
- Recipients
- Auth0 by Okta and AWS.
Organization settings and logo
- Data
- Organization name, primary and secondary colors, and an optional logo. The uploaded logo may contain embedded image metadata; the stored display copy is re-encoded, limited to 1200 × 1200 pixels, and saved without that metadata.
- Purpose
- Display customer branding in the public report, PDF, and social image and manage branding settings.
- Legal basis
- The settings are processed to provide the agreed platform function. If a logo contains personal information, the organizing customer must determine an appropriate legal basis; Green Impact Report processes it within the agreed scope. Its own security processing relies on Article 6(1)(f) GDPR.
- Retention
- The current logo is kept while the organization uses it. On replacement, the safely attributed previous storage object is deleted; without an immediate invalidation, CDN or browser copies may remain for up to one hour. The current logo is also removed when the organization is permanently deleted.
- Recipients
- AWS and people who receive a branded report, PDF file, or social media image.
Pilot enquiry, email, and support
- Data
- Email address and organization as required fields; optionally name, city, participant count, period, message, and other information sent voluntarily. Language, page, and technical connection data are also processed.
- Purpose
- Answer an enquiry, plan a pilot, prepare an offer, provide support, or handle a privacy request.
- Legal basis
- Article 6(1)(b) GDPR for requested pre-contractual steps; Article 6(1)(f) GDPR for general enquiries and the interest in appropriate communication; Article 6(1)(c) GDPR where a legal request must be handled.
- Retention
- Until the enquiry is complete. If a business relationship begins, necessary records are kept under contractual and legal retention criteria; contact data that is no longer needed is deleted.
- Recipients
- The protected internal admin inbox, Web3Forms for form delivery, and the email service used.
Participation in a cleanup campaign
- Data
- Technical participant session, campaign, team, optional nickname, value in bags or kilograms, optional note, and submission and processing timestamps. Full Evidence Trail campaigns also process the measurement method, waste category, review status, and review history.
- Purpose
- Enable participation, assign contributions, show progress and team results, moderate submissions, and provide reports.
- Legal basis
- The organizing customer determines the legal basis for its campaign. Green Impact Report processes campaign data for that organization within the agreed scope. Its own technical security processing relies on Article 6(1)(f) GDPR.
- Retention
- During the active campaign and, by default, until 12 months after the campaign ends. Submissions, notes, technical sessions, optional nicknames, and team details are then removed automatically. Only anonymous campaign totals remain as a historical record. An authorized verified request may result in earlier deletion.
- Recipients
- AWS and the authorized organizing customer and its authorized organizers.
Photos, visible results, and reports
- Data
- Original photo, including device metadata that may be embedded, processed preview and display versions, technical processing data, and generated PDF and share reports. A Full Evidence Trail may also include optional before and scale photos and a SHA-256 file fingerprint used to flag identical files. Precise GPS is not deliberately requested or extracted.
- Purpose
- Review and display a cleanup contribution, remove photo metadata from display versions, and produce a traceable impact report.
- Legal basis
- The organizing customer must determine the photo use and appropriate legal basis before the campaign starts. Where consent is required, it must be freely given, informed, and withdrawable.
- Retention
- Original uploads in private raw-photo storage are automatically deleted 30 days after upload. Processed photos, stored PDF reports, and public report links are removed automatically, by default 12 months after the campaign ends. CDN or browser copies of deleted display files may remain for up to one hour.
- Recipients
- AWS and, for visible content, people who receive a valid campaign, report, or direct image link.
Privacy-friendly reach and performance measurement
- Data
- Aggregated page views, URL path, technical performance information, and coarse device, browser, operating system, and country information. Form fields, photos, and campaign submissions are not sent.
- Purpose
- Understand which public information pages are used and identify technical loading problems.
- Legal basis
- Article 6(1)(f) GDPR. The legitimate interest is data-minimizing improvement of the public website. The measurement used does not use cookies or local browser storage.
- Retention
- Cloudflare documents 7 days of retention for unsampled beacon data. Aggregated Web Analytics data is available for the previous 6 months. Measurement is separated from organizer, participant, API, and report routes.
- Recipients
- Cloudflare.
External booking and communication links
- Data
- Only after you open an external Calendly or WhatsApp link does that provider process connection data and the information you enter there.
- Purpose
- Optionally arrange a meeting or start a conversation.
- Legal basis
- Article 6(1)(b) GDPR for information Green Impact Report subsequently receives to handle your enquiry. The external site processes data under its own notice.
- Retention
- Under the external provider’s settings and notice and our criteria for enquiries and business communication.
- Recipients
- Calendly or WhatsApp/Meta only after you deliberately open the external link.
4. Cookies and local browser storage
- Organizer login uses technically necessary authentication cookies.
- Participation stores a technical session in local browser storage so team selection and later submissions work on the same device. It may contain the session ID, campaign, team, optional nickname, and consent time and remains until the person or browser removes it.
- A separate return shortcut for the last campaign expires after 48 hours. A short-lived portal check in the current tab expires after five minutes.
- We use no advertising cookies, advertising pixels, or cross-site profiles.
This storage provides the participation, session, or login function explicitly requested. It is not used for advertising. Where section 25 TDDDG applies, technically necessary access relies on section 25(2)(2) TDDDG.
5. Recipients and service providers
We do not sell data. Access is limited to authorized people and service providers where required for the relevant purpose.
CloudflareDNS, protection, and optional web analytics
Web3FormsDelivery of voluntarily submitted pilot enquiries
CalendlyOptional external booking after opening the link
6. Data location and transfers outside the EEA
Primary campaign infrastructure is configured for AWS Europe (Frankfurt), eu-central-1. Individual providers or subprocessors may process data outside the European Economic Area. Where required, an adequacy decision, Standard Contractual Clauses, or another permitted transfer mechanism is used. The specific service scope is reviewed before a customer contract with special location requirements.
7. Required information and data sources
- Pilot form: email address and organization are required so we can reply and understand the request. The form cannot be sent without them. All other fields are optional.
- Campaign participation requires a team, value, technical session, and photo. Full Evidence Trail campaigns also require a measurement method and waste category; before and scale photos remain optional. Nickname and note are optional.
- Organizer account: identity and account details required by the login and permission system are necessary for protected access.
- Data mainly comes directly from the person, from the organizing customer, or is generated technically when the service is used.
8. Rights of individuals
Subject to the GDPR conditions, individuals have the following rights in particular:
- Access and a copy of personal data being processed
- Correction of inaccurate or incomplete data
- Deletion or restriction of processing
- Data portability where the legal conditions apply
- Withdrawal of consent with future effect
- Objection to processing based on legitimate interests
Send a privacy requestObjection under Article 21 GDPR
You may object to processing based on Article 6(1)(f) GDPR for reasons arising from your particular situation. We do not use campaign or participant data for direct advertising.
9. Right to complain
You may complain to a data protection supervisory authority, in particular where you live, work, or believe an infringement occurred. You are also welcome to contact us first.
10. Automated decisions
There is no solely automated decision with legal or similarly significant effect and no profiling for advertising.
11. Security and privacy requests
We use technical and organizational measures to protect data against unauthorized access, loss, and alteration. For a request, we must verify identity, campaign, and authority sufficiently so that another person’s data is not disclosed or deleted. Do not send passwords, report tokens, or sensitive credentials by email.
12. Changes to this notice
We update this notice when providers, functions, retention, or legal requirements change materially. The date above identifies the current version.