Privacy explained clearly

Privacy Center

This page explains what Green Impact Report processes, what we deliberately do not collect, how photos are handled, and which controls are still manual today.

Last updated: 21 July 2026

Our privacy principles

Minimal participant data

Standard participation works without a participant account or participant email address.

No advertising use

We do not sell customer or participant data or use customer or participant photos to train AI models.

Controlled sharing

Campaigns and reports are unlisted by default. A valid link must still be treated like an access key.

Visible limitations

We distinguish between automatic controls, manual processes, and future functionality.

Privacy at a glance

Participant account required
No
Participant email required
No
Nickname required
No

Optional when enabled by the campaign.

Precise GPS requested or extracted
No
Facial recognition
No
EXIF retained in processed photos
No
Participant data sold
No
AI training with customer or participant photos
No

Who is responsible for which data?

The exact data protection role depends on the activity and customer agreement. Roles must be documented before a pilot with special requirements.

Website and pilot enquiries

Green Impact Report determines how website, contact, and its own business data are processed and is the contact for that processing.

Customer campaigns

The organization normally determines the purpose, participant group, and process for its campaign. Green Impact Report processes campaign data to provide the platform. The exact roles belong in the customer agreement or data processing agreement.

Participant questions

Questions about the purpose of a specific campaign should first go to its organizer. Technical privacy and deletion requests can also be sent to Green Impact Report.

What happens when someone participates?

A QR code opens an unlisted campaign page. Participants select a team, accept required notices, and can submit a contribution.

Processed by default

  • Technical participant session ID
  • Campaign and selected team
  • Optional nickname
  • Value in bags or kilograms
  • Optional contribution note
  • Photo and generated display versions
  • Submission and processing timestamps
  • Technical security and error data

Not collected by default

  • Participant account or password
  • Participant email address
  • A separate precise-GPS field
  • Device contacts or address book
  • Facial biometrics or identity recognition
  • Advertising profile across other websites

How photos are processed

  • The original is placed in private upload storage and is not used directly in public views.
  • The media process creates smaller thumbnails and medium-sized display versions.
  • EXIF and other embedded original metadata are removed when these versions are created. Image orientation is corrected first.
  • The platform does not request or extract precise GPS. An original upload may still temporarily contain device metadata until it is processed and automatically deleted.
  • Processed photos may appear in the leaderboard, organizer dashboard, public report, and PDF when the submission is visible.
  • Participants are asked to avoid faces, name badges, licence plates, addresses, and private documents.
  • Organizers can hide unsuitable submissions. Hiding is not the same as deletion.

Links, visibility, and reports

  • Participant and report pages are not listed in the public website navigation or sitemap.
  • Search engines receive a noindex signal for participant, application, and report routes.
  • Anyone with a valid campaign or report link can generally open the relevant page. Links must not be shared without control.
  • Processed display photos are delivered through direct CDN links. Anyone who receives such an image link can generally open it as well. Permanent deletion removes the stored object and the CDN cache.
  • Organizers can regenerate, revoke, and set an expiry for report links.
  • A publicly shared report should contain only reviewed submissions and approved photos.

Retention and current automation

Automatic periods are explicitly identified as automatic. Other data is reviewed and deleted through a controlled process using the operational criteria below.

Original raw photos

Automatically deleted 30 days after upload

An authorized deletion request is handled manually sooner; we do not wait for automatic expiry.

Processed photos

For the active campaign and agreed reporting period

Deletion then, or earlier after an authorized request, is currently controlled and manual. A fixed automatic expiry is not active yet.

Organization logo

While the organization uses its current branding

The stored copy is re-encoded without embedded metadata. On replacement, the API deletes the safely attributed previous object; without an immediate invalidation, CDN or browser copies may remain for up to one hour.

Submissions and sessions

For the active campaign, agreed reporting period, and required support

Complete deletion or anonymization is currently controlled and manual. Entries marked as removed in the dashboard remain stored until then.

PDF reports

For the agreed reporting period

PDFs remain in processed storage until controlled manual deletion.

API and worker logs

7 days in the pilot environment, 30 days in stage/production

Security-related information may be retained longer where necessary for a specific incident.

Database backups

1 day in the pilot environment, 7 days configured for stage/production

Deleted data may remain in access-controlled backups until they expire naturally and is not restored to recover intentionally deleted data.

Export, correction, and deletion

Organizers and affected people can do more than view data. They can request correction, export, or deletion, and organizers can moderate submissions.

Campaign export

Authorized organizers can download a protected ZIP containing campaign, team, and submission data, visible processed photos, and the latest ready PDF. Raw photos and hidden or removed submissions are excluded.

Moderation

Organizers can hide, restore, or remove incorrect or unsuitable submissions from visible campaign results. Hidden and removed data remains stored until controlled permanent deletion.

Deletion requests

Authorized requests are handled after identity and authority checks. Public links are revoked first, followed by targeted removal of database records, photos, and reports within the agreed scope.

No second export copy

The export archive is generated on demand and streamed directly. Green Impact Report does not store an additional finished ZIP copy.

Website analytics and cookies

  • The website may use Cloudflare Web Analytics for aggregated page views and technical performance information.
  • Cloudflare describes Web Analytics as privacy-first and says it does not collect or use visitors’ personal data. It is not used to create advertising profiles.
  • Cloudflare documents 7 days for unsampled beacon data. Aggregated Web Analytics data is available for the previous 6 months.
  • Form fields, campaign submissions, and photos are not sent to website analytics.
  • Organizer login may use technically necessary authentication cookies. External booking services such as Calendly are governed by that provider’s settings and notices.
  • Participation stores a technical session locally in the browser so team selection and later submissions work on the same device. A separate return shortcut expires after 48 hours.
  • We do not use advertising pixels or sell analytics data.

Service providers and subprocessors

Only services needed for hosting, authentication, domains, analytics, or contact should receive data. Optional services depend on the contact or booking method selected.

Amazon Web Services (AWS)

Provider information ↗

Web hosting, API, database, file storage, media processing, queues, backups, and operational logs

Campaign, account, submission, photo, report, and technical operational data. Primary application infrastructure is configured for AWS Europe (Frankfurt), eu-central-1.

Organizer login and access protection

Organizer identity and authentication data. Participants do not use Auth0. The tenant is created for the Europe region.

DNS, domain protection, and optional privacy-friendly web analytics

Technical website requests and aggregated page-view and performance information, depending on the active Cloudflare configuration.

Delivery of voluntarily submitted pilot enquiries

Contact, company, and message information entered in the pilot form. The service may use its disclosed infrastructure and spam-protection providers.

Optional external meeting booking

Information entered on Calendly’s external page to arrange a meeting. Calendly is used only after the external link is opened.

Optional external communication

Technical connection and communication data processed by WhatsApp after the external link is deliberately opened and during communication there.

Data location and international transfers

Primary campaign infrastructure is configured in AWS Europe (Frankfurt). Individual providers or their subprocessors may process data outside the European Economic Area. Their applicable agreements and transfer mechanisms, such as Standard Contractual Clauses where required, apply. Before a customer contract with specific location requirements, we review and document the exact service scope.

Technical and organizational foundations

  • HTTPS for the website, API, and file transfer
  • Private raw-photo storage with time-limited upload URLs
  • A database that is not publicly accessible
  • Role-based access to the organizer area
  • Organization separation and organization-scoped permission checks
  • Redaction of sensitive tokens and credentials from application logs
  • Rate limits for public sessions, uploads, and submissions
  • Monitoring for the API, worker, queues, database, and failure conditions

Schools and participants who are minors

The platform does not yet have a finished school privacy mode. Before a campaign involving children, the organizer, permission process, photo use, public visibility, and shorter retention must be reviewed separately. Such campaigns should not require real names, participant emails, or precise locations.

What is not yet fully automated

  • Automatic deletion of processed photos, submissions, PDFs, campaigns, and organizations
  • Customer-specific retention settings in the organizer interface
  • An automatically generated campaign-specific privacy summary
  • Customer-specific controller and privacy-contact details directly in the participant flow
  • A complete participant self-service deletion workflow
  • Individually signed or user-bound access links for every processed display photo
  • Global rate-limit counters shared across multiple API instances
  • Independent privacy, security, or ESG certification of the product

Make a privacy request

Depending on applicable law, people may request access, correction, deletion, restriction, portability, or objection. We must verify identity, campaign, and scope sufficiently so that data belonging to the wrong person or organization is not disclosed or deleted.

  • Provide the organization and campaign name or campaign ID
  • Describe the relevant submission, photo, or session as precisely as possible
  • State the requested action: access, correction, export, or deletion
  • Do not send report tokens, passwords, or sensitive credentials by email
Send a privacy request

Common privacy questions

Do participants need an account?

No. The standard flow uses a technical session and requires neither a participant account nor participant email address.

Is location data copied from photos?

The platform does not request or extract precise GPS. An original upload may temporarily contain device metadata. Processed display versions are generated without EXIF and other embedded original metadata.

Is an unlisted report completely private?

Not completely. It is not publicly linked or indexed, but anyone with the valid link can open it. The link should be shared carefully, given an expiry, and revoked when necessary.

Can an organization download its campaign data?

Yes. Authorized organizers can download a protected campaign export. It excludes raw photos and hidden or removed submissions.

Are original photos deleted automatically?

Yes. Private raw-photo storage automatically expires original uploads after 30 days. Processed display versions do not yet have an automatic deletion job.

Version history

Version 1.1

21 July 2026

Clarified GPS metadata, manual retention, moderation, backups, and the AI-training statement.

Version 1.0

21 July 2026

First publication covering data categories, retention, providers, rights, and current limitations.

Review privacy together before the pilot

If you have special requirements for retention, schools, photos, or data location, we will document the scope before launch.