1.Who is responsible for your data
Greener Ahead is the controller for the processing described in this policy.
- Established at: Philitelaan 59 57, 5617 AK Eindhoven, the Netherlands
- Chamber of Commerce (KvK): 85351660
- VAT number: NL004086201B68
- Privacy questions and requests: privacy@greenerahead.com
We have not appointed a data protection officer because we are not required to under article 37 GDPR. The privacy address above reaches the people responsible for data protection.
2.When this policy applies, and when your employer's does
This policy applies to personal data that we decide how and why to process. That is the case when you:
- visit https://greenerahead.com,
- email us, request trial access or otherwise contact us,
- hold an account in the Greener Ahead application at https://app.greenerahead.com, for the data we need to run your account, bill your organisation, support you and keep the service secure,
- receive an invitation, survey or shared report link from a customer, for the technical data we need to deliver it securely.
It does not apply to the content that our customers put into their workspace. A company that prepares a VSME report, a carbon footprint, a climate strategy or a life cycle assessment in Greener Ahead decides what goes in it, including data about its employees, suppliers and contacts. For that content the customer is the controller and we are its processor under the Data Processing Addendum in our Terms of Service. If you are an employee, supplier or business contact of one of our customers and want to know what they entered about you, or want it corrected or deleted, please ask that company. We will help them respond.
Example. If your employer asks you to answer a commuting survey through a Greener Ahead link, your answers belong to your employer's footprint. Your employer is the controller. We store the answers for them and do not use them for anything else.
3.What personal data we process
Visitors of the website
Optional cookies are set only after you allow them in the cookie dialog; see Cookies and similar technologies below and the Cookie Declaration. Separately, we measure a limited set of page visits, resource downloads and product-link clicks using PostHog, which Dutch law allows without consent and which you can switch off in the same dialog. We do not collect form contents or make session recordings on the website. Fonts are served from our own domain. Our hosting provider keeps standard server logs with your IP address, the pages requested, the time, and your browser type, which we use only to keep the site available and secure.
People who contact us or request a trial
When you email us, the email address, your name, your company and what you write. When you request trial access, additionally the company details needed to set up a workspace.
Account holders in the application
- Identity and sign-in: name, business email address, the identifier assigned by our sign-in provider, the sign-in method you use (password or your organisation's single sign-on), session tokens, and the time and IP address of sign-ins.
- Workspace membership: which workspace and company you belong to, your role and permissions, invitations you sent or accepted.
- Activity history: the actions you take in the workspace (for example answering a disclosure, approving a report, exporting a file or sharing a link), the resource concerned and the time. This history is a feature of the product: workspace administrators can see it, and it exists so that a report can be traced back to who changed what.
- Preferences: language, theme and similar settings, stored in your browser.
- Support: the content of support conversations and the technical context you or the application share with us to resolve them.
- Product analytics: if you consent, which screens you visit and which features you use in the application, linked to your user identifier, name and email address, so that we can see where people get stuck. See section 10.
- Notifications: if you enable browser notifications, the push subscription your browser issues.
Billing contacts
The name, email address, company name, billing address and VAT number given at checkout, invoice history and payment status. Card details are entered directly with our payment provider, Stripe, and never reach our systems; we receive only the payment method type, its last four digits and expiry for display.
People invited by a customer
When a customer sends you a request, a survey or a report link, we process the email address they entered for you, the signed token that opens the page, the time the link was opened or answered, your IP address and browser type for security, and what you submit. What you submit is the customer's content (section 2). We do not create an account for you and do not contact you for our own purposes.
Uploaded documents
Customers can upload invoices, meter readings, payroll summaries and similar evidence. These documents often contain personal data, such as the name of an account holder or a fleet driver. They are processed on the customer's behalf as described in section 2 and section 5.
4.Why we process it, and on what legal basis
The GDPR requires a legal basis for every processing purpose. Ours are set out below. Where we rely on legitimate interests we have weighed them against your interests and rights; you can ask us for the assessment.
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the application to your organisation: accounts, sign-in, permissions, workspace features, exports | Identity, membership, activity history, preferences | Performance of a contract with your organisation (art. 6(1)(b)); where you are a user but not the contracting party, our legitimate interest in delivering the service our customer bought (art. 6(1)(f)) |
| Setting up and running a trial | Contact and company details | Steps at your request prior to a contract, and performance of the trial (art. 6(1)(b)) |
| Invoicing, VAT determination, payment collection and the billing portal | Billing contact data, invoice history | Performance of a contract (art. 6(1)(b)); legal obligation to keep accounting records (art. 6(1)(c), art. 52 Dutch General Tax Act and art. 2:10 Dutch Civil Code) |
| Delivering invitations, surveys and shared report links securely, and recording that they were used | Email address, token, access time, IP address | Legitimate interest of our customer and of us in a reliable and traceable collaboration feature (art. 6(1)(f)) |
| Keeping an activity history in the workspace | Actor, action, resource, time | Performance of a contract: traceability is part of the product (art. 6(1)(b)); our legitimate interest in demonstrating integrity of reports (art. 6(1)(f)) |
| Security: detecting abuse, protecting accounts, investigating incidents, keeping server logs | IP address, sign-in data, technical logs | Legitimate interest in the security of the service (art. 6(1)(f)); legal obligation to secure personal data (art. 32 GDPR) |
| Support and answering questions | Contact data, conversation content | Performance of a contract or steps prior to one (art. 6(1)(b)); otherwise legitimate interest in answering people who write to us (art. 6(1)(f)) |
| Product analytics in the application | Screens visited, features used, user identifier, name, email | Your consent (art. 6(1)(a) GDPR and art. 11.7a Dutch Telecommunications Act), which you can withdraw at any time in the application |
| Service emails: invitations, notifications you enabled, changes to terms, security notices, invoices | Email address, name | Performance of a contract (art. 6(1)(b)); legal obligation for certain notices (art. 6(1)(c)) |
| Telling existing customers about new products and features by email | Business email address | Legitimate interest in informing customers about similar products (art. 6(1)(f), art. 11.7(3) Dutch Telecommunications Act); every such email has an unsubscribe link |
| Improving the service using aggregated, de-identified usage information | Aggregated statistics that do not identify anyone | Not personal data once aggregated; the aggregation itself rests on legitimate interest (art. 6(1)(f)) |
| Establishing, exercising or defending legal claims; complying with lawful requests from authorities | Whatever is relevant to the claim or request | Legal obligation (art. 6(1)(c)); legitimate interest (art. 6(1)(f)) |
We do not sell personal data, do not use it for advertising and do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
5.AI-assisted features
Some features in the application use text recognition and large language models: reading the figures out of an uploaded invoice or meter statement so you do not have to type them, suggesting a category for an expense line or a supplier, or drafting a narrative answer you then edit. These features are optional, are always shown as suggestions, and a person accepts or rejects every suggestion.
When a customer uses such a feature, the relevant document or text excerpt is sent to the provider named in section 6 for that purpose. Text recognition runs on Google Cloud's Document AI at its European Union endpoint. Language model requests go to OpenAI under its business API terms, which prohibit using the data to train models and require deletion after a short abuse-monitoring window. We do not train models of our own on customer content.
Because these features process whatever is in the document, the customer's Terms of Service require them not to use AI-assisted features on special categories of data or data about children. Personal data that appears incidentally, such as a name on an invoice, is processed only to extract the figures and is not used for any other purpose.
6.Who receives your data
We use a small number of service providers that process personal data on our behalf (sub-processors). Each is bound by a data processing agreement that meets article 28 GDPR. At the effective date they are:
| Provider | What for | Where | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, database, encrypted file storage, transactional email (Amazon SES) | Frankfurt, Germany (eu-central-1) | None: data is stored and processed in the EU |
| WorkOS, Inc. | Sign-in, single sign-on and session management (AuthKit) | United States | EU Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Payments, invoicing, VAT calculation and the billing portal | Ireland, with processing in the United States | EU Standard Contractual Clauses (intra-group) |
| Google Cloud EMEA Ltd. | Text recognition (Document AI) on documents you upload to pre-fill answers | European Union (eu-documentai.googleapis.com endpoint) | None: the EU endpoint is used |
| PostHog, Inc. | Optional website and application analytics | United States | EU Standard Contractual Clauses |
| OpenAI Ireland Ltd. | Drafting suggestions and document extraction when you use an AI-assisted feature | Ireland, with processing in the United States | EU Standard Contractual Clauses; the OpenAI API terms exclude training on your data |
Customers with a workspace receive at least 30 days' notice by email before we add or replace a sub-processor, as set out in the Data Processing Addendum.
Beyond sub-processors, personal data may be received by:
- Your own organisation. Workspace administrators see the members, roles and activity history of their workspace.
- People our customers share with. When a customer shares a report link with a bank, customer or auditor, the recipient sees what the customer chose to disclose. The customer decides this, not us.
- Professional advisers such as our accountant, lawyers and insurers, under confidentiality, where needed.
- Authorities where we are legally required to, such as the tax authority for accounting records or a court order. We check every request and disclose no more than required.
- A successor if our business is sold or merged, under the same commitments as this policy, with notice to you.
7.International transfers
Your data is stored in the European Union. The application, its database, its file storage and its email delivery run in Amazon Web Services' Frankfurt region, and text recognition uses Google Cloud's EU endpoint.
Four providers process some data in the United States: our sign-in provider (name, email address, sign-in events), our payment provider (billing details), our analytics provider (usage events, only with consent) and, when an AI-assisted feature is used, OpenAI (the document or text excerpt concerned). For these transfers we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), supplemented by a transfer impact assessment and additional measures such as encryption in transit and at rest, and on the EU-US Data Privacy Framework where the provider is certified under it. You can request a copy of the relevant clauses at privacy@greenerahead.com.
8.How long we keep it
We keep personal data no longer than needed for the purpose it was collected for, and then delete or anonymise it. The main periods are:
| Data | Retention |
|---|---|
| Account and membership data | For the life of the account, then deleted with the workspace under the periods below. An individual account that is removed from a workspace is deleted within 30 days. |
| Workspace content, including activity history and uploaded documents | Until the customer deletes it or the subscription ends. After a subscription ends the workspace is read-only for 30 days for export, then deleted within 90 days, and purged from rotating backups within a further 35 days. Read-only trial workspaces may be deleted 90 days after the trial ends, with 14 days' notice. |
| Invitation, survey and share-link tokens and their access records | Until the link expires or is revoked, then as part of the activity history of the workspace. |
| Invoices and billing records | 7 years after the end of the financial year, as required by Dutch tax and accounting law. |
| Support and contact emails | 2 years after the conversation closes, unless it concerns a contract or claim that lasts longer. |
| Trial requests that do not lead to an account | 12 months. |
| Server and security logs | 90 days, longer only if needed for an ongoing investigation. |
| Product analytics events | 12 months, then deleted or aggregated. Deleted earlier when you withdraw consent or your account is deleted. |
| Browser push subscriptions | Until you disable notifications or your account is deleted. |
| Data relevant to a legal claim | Until the claim is settled and any limitation period has passed. |
9.How we protect it
We apply the technical and organisational measures described in Annex 2 of our Terms of Service. In short: hosting in the EU on private networks, encryption in transit and at rest with customer-managed keys for file storage, strict separation between customers enforced in every query, role-based access down to a single datapoint, signed single-purpose links that expire and can be revoked, an append-only activity history, daily backups, reviewed code changes and multi-factor authentication for anyone who operates the service.
If a personal data breach nevertheless occurs and is likely to result in a risk to you, we will inform the Dutch Data Protection Authority within 72 hours and, where the risk is high, you directly. Where the data belongs to a customer's workspace, we inform the customer within 48 hours so that it can meet its own obligations.
11.Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy (art. 15);
- rectify inaccurate or incomplete data (art. 16);
- erase your data in the circumstances set out in art. 17, for example when it is no longer needed or you withdraw consent;
- restrict processing while a dispute about accuracy or lawfulness is resolved (art. 18);
- receive data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another provider where technically feasible (art. 20);
- object to processing based on legitimate interests on grounds relating to your particular situation, and to object at any time to direct marketing (art. 21);
- withdraw consent at any time, without affecting processing that took place before the withdrawal (art. 7(3)).
To exercise a right, email privacy@greenerahead.com from the address we know you by, or from another address with enough information for us to verify that you are the person concerned. We respond within one month; for complex or numerous requests we may extend this by two months and will tell you if so. Exercising your rights is free unless a request is manifestly unfounded or excessive.
If your request concerns data that a customer entered into its workspace, we will forward it to that customer, because they decide about that data (section 2), and support them in answering it.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl. You may also complain to the authority of the EU country where you live or work. We would appreciate the chance to address your concern first.
12.Children
The website and the application are intended for businesses and their staff. We do not knowingly process personal data of children under 16 for our own purposes. If you believe a child has provided us with personal data, contact privacy@greenerahead.com and we will delete it.
13.Changes to this policy
We update this policy when our processing changes, for example when we add a product, a sub-processor or a feature. The version number and effective date at the top tell you which version you are reading. Material changes are announced to account holders by email or in the application before they take effect. Earlier versions are available on request.
14.Contact
Greener Ahead
Philitelaan 59 57, 5617 AK Eindhoven, the Netherlands
Chamber of Commerce 85351660
Privacy: privacy@greenerahead.com
Security: security@greenerahead.com
General: hello@greenerahead.com