Greener Ahead
VSME reportYour customer or your bank asked for it. Answer once, send one link, this week.Available now
Carbon accountingLitres, kilowatt hours, kilometres. Scope 1, 2 and 3 from what you actually used.Available Q3 2026
Climate strategyKnow which changes cut the most carbon, what they cost, and when they pay back.Available Q4 2026
Life cycle assessmentOne product, from raw material to end of life. The number your buyer is asking for.Available Q1 2027
PricingBlogResources
LoginSign up

Product

VSME reportAvailable now
Carbon accountingAvailable Q3 2026
Climate strategyAvailable Q4 2026
Life cycle assessmentAvailable Q1 2027
PricingBlogResources
Login

Privacy Policy

Version 1.0 · Effective 2 September 2026 · Greener Ahead

Greener Ahead helps companies prepare sustainability reports, carbon footprints, climate strategies and life cycle assessments. That work involves data about people: the account holders who use the application, the colleagues and suppliers they ask for figures, the employees who answer a survey, and the contacts at the banks and customers who receive a report.

This policy explains what we do with that data, on what legal basis, for how long, and which rights you have under the General Data Protection Regulation (GDPR) and the Dutch implementing act (UAVG). It is written to be read; if anything is unclear, ask us at privacy@greenerahead.com.

Contents
  1. 1. Who is responsible for your data
  2. 2. When this policy applies, and when your employer's does
  3. 3. What personal data we process
  4. 4. Why we process it, and on what legal basis
  5. 5. AI-assisted features
  6. 6. Who receives your data
  7. 7. International transfers
  8. 8. How long we keep it
  9. 9. How we protect it
  10. 10. Cookies and similar technologies
  11. 11. Your rights
  12. 12. Children
  13. 13. Changes to this policy
  14. 14. Contact
Terms of Service →

1.Who is responsible for your data

Greener Ahead is the controller for the processing described in this policy.

  • Established at: Philitelaan 59 57, 5617 AK Eindhoven, the Netherlands
  • Chamber of Commerce (KvK): 85351660
  • VAT number: NL004086201B68
  • Privacy questions and requests: privacy@greenerahead.com

We have not appointed a data protection officer because we are not required to under article 37 GDPR. The privacy address above reaches the people responsible for data protection.

2.When this policy applies, and when your employer's does

This policy applies to personal data that we decide how and why to process. That is the case when you:

  • visit https://greenerahead.com,
  • email us, request trial access or otherwise contact us,
  • hold an account in the Greener Ahead application at https://app.greenerahead.com, for the data we need to run your account, bill your organisation, support you and keep the service secure,
  • receive an invitation, survey or shared report link from a customer, for the technical data we need to deliver it securely.

It does not apply to the content that our customers put into their workspace. A company that prepares a VSME report, a carbon footprint, a climate strategy or a life cycle assessment in Greener Ahead decides what goes in it, including data about its employees, suppliers and contacts. For that content the customer is the controller and we are its processor under the Data Processing Addendum in our Terms of Service. If you are an employee, supplier or business contact of one of our customers and want to know what they entered about you, or want it corrected or deleted, please ask that company. We will help them respond.

Example. If your employer asks you to answer a commuting survey through a Greener Ahead link, your answers belong to your employer's footprint. Your employer is the controller. We store the answers for them and do not use them for anything else.

3.What personal data we process

Visitors of the website

Optional cookies are set only after you allow them in the cookie dialog; see Cookies and similar technologies below and the Cookie Declaration. Separately, we measure a limited set of page visits, resource downloads and product-link clicks using PostHog, which Dutch law allows without consent and which you can switch off in the same dialog. We do not collect form contents or make session recordings on the website. Fonts are served from our own domain. Our hosting provider keeps standard server logs with your IP address, the pages requested, the time, and your browser type, which we use only to keep the site available and secure.

People who contact us or request a trial

When you email us, the email address, your name, your company and what you write. When you request trial access, additionally the company details needed to set up a workspace.

Account holders in the application

  • Identity and sign-in: name, business email address, the identifier assigned by our sign-in provider, the sign-in method you use (password or your organisation's single sign-on), session tokens, and the time and IP address of sign-ins.
  • Workspace membership: which workspace and company you belong to, your role and permissions, invitations you sent or accepted.
  • Activity history: the actions you take in the workspace (for example answering a disclosure, approving a report, exporting a file or sharing a link), the resource concerned and the time. This history is a feature of the product: workspace administrators can see it, and it exists so that a report can be traced back to who changed what.
  • Preferences: language, theme and similar settings, stored in your browser.
  • Support: the content of support conversations and the technical context you or the application share with us to resolve them.
  • Product analytics: if you consent, which screens you visit and which features you use in the application, linked to your user identifier, name and email address, so that we can see where people get stuck. See section 10.
  • Notifications: if you enable browser notifications, the push subscription your browser issues.

Billing contacts

The name, email address, company name, billing address and VAT number given at checkout, invoice history and payment status. Card details are entered directly with our payment provider, Stripe, and never reach our systems; we receive only the payment method type, its last four digits and expiry for display.

People invited by a customer

When a customer sends you a request, a survey or a report link, we process the email address they entered for you, the signed token that opens the page, the time the link was opened or answered, your IP address and browser type for security, and what you submit. What you submit is the customer's content (section 2). We do not create an account for you and do not contact you for our own purposes.

Uploaded documents

Customers can upload invoices, meter readings, payroll summaries and similar evidence. These documents often contain personal data, such as the name of an account holder or a fleet driver. They are processed on the customer's behalf as described in section 2 and section 5.

4.Why we process it, and on what legal basis

The GDPR requires a legal basis for every processing purpose. Ours are set out below. Where we rely on legitimate interests we have weighed them against your interests and rights; you can ask us for the assessment.

PurposeDataLegal basis
Providing the application to your organisation: accounts, sign-in, permissions, workspace features, exportsIdentity, membership, activity history, preferencesPerformance of a contract with your organisation (art. 6(1)(b)); where you are a user but not the contracting party, our legitimate interest in delivering the service our customer bought (art. 6(1)(f))
Setting up and running a trialContact and company detailsSteps at your request prior to a contract, and performance of the trial (art. 6(1)(b))
Invoicing, VAT determination, payment collection and the billing portalBilling contact data, invoice historyPerformance of a contract (art. 6(1)(b)); legal obligation to keep accounting records (art. 6(1)(c), art. 52 Dutch General Tax Act and art. 2:10 Dutch Civil Code)
Delivering invitations, surveys and shared report links securely, and recording that they were usedEmail address, token, access time, IP addressLegitimate interest of our customer and of us in a reliable and traceable collaboration feature (art. 6(1)(f))
Keeping an activity history in the workspaceActor, action, resource, timePerformance of a contract: traceability is part of the product (art. 6(1)(b)); our legitimate interest in demonstrating integrity of reports (art. 6(1)(f))
Security: detecting abuse, protecting accounts, investigating incidents, keeping server logsIP address, sign-in data, technical logsLegitimate interest in the security of the service (art. 6(1)(f)); legal obligation to secure personal data (art. 32 GDPR)
Support and answering questionsContact data, conversation contentPerformance of a contract or steps prior to one (art. 6(1)(b)); otherwise legitimate interest in answering people who write to us (art. 6(1)(f))
Product analytics in the applicationScreens visited, features used, user identifier, name, emailYour consent (art. 6(1)(a) GDPR and art. 11.7a Dutch Telecommunications Act), which you can withdraw at any time in the application
Service emails: invitations, notifications you enabled, changes to terms, security notices, invoicesEmail address, namePerformance of a contract (art. 6(1)(b)); legal obligation for certain notices (art. 6(1)(c))
Telling existing customers about new products and features by emailBusiness email addressLegitimate interest in informing customers about similar products (art. 6(1)(f), art. 11.7(3) Dutch Telecommunications Act); every such email has an unsubscribe link
Improving the service using aggregated, de-identified usage informationAggregated statistics that do not identify anyoneNot personal data once aggregated; the aggregation itself rests on legitimate interest (art. 6(1)(f))
Establishing, exercising or defending legal claims; complying with lawful requests from authoritiesWhatever is relevant to the claim or requestLegal obligation (art. 6(1)(c)); legitimate interest (art. 6(1)(f))

We do not sell personal data, do not use it for advertising and do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.

5.AI-assisted features

Some features in the application use text recognition and large language models: reading the figures out of an uploaded invoice or meter statement so you do not have to type them, suggesting a category for an expense line or a supplier, or drafting a narrative answer you then edit. These features are optional, are always shown as suggestions, and a person accepts or rejects every suggestion.

When a customer uses such a feature, the relevant document or text excerpt is sent to the provider named in section 6 for that purpose. Text recognition runs on Google Cloud's Document AI at its European Union endpoint. Language model requests go to OpenAI under its business API terms, which prohibit using the data to train models and require deletion after a short abuse-monitoring window. We do not train models of our own on customer content.

Because these features process whatever is in the document, the customer's Terms of Service require them not to use AI-assisted features on special categories of data or data about children. Personal data that appears incidentally, such as a name on an invoice, is processed only to extract the figures and is not used for any other purpose.

6.Who receives your data

We use a small number of service providers that process personal data on our behalf (sub-processors). Each is bound by a data processing agreement that meets article 28 GDPR. At the effective date they are:

ProviderWhat forWhereTransfer safeguard
Amazon Web Services EMEA SARLHosting, database, encrypted file storage, transactional email (Amazon SES)Frankfurt, Germany (eu-central-1)None: data is stored and processed in the EU
WorkOS, Inc.Sign-in, single sign-on and session management (AuthKit)United StatesEU Standard Contractual Clauses
Stripe Payments Europe, Ltd.Payments, invoicing, VAT calculation and the billing portalIreland, with processing in the United StatesEU Standard Contractual Clauses (intra-group)
Google Cloud EMEA Ltd.Text recognition (Document AI) on documents you upload to pre-fill answersEuropean Union (eu-documentai.googleapis.com endpoint)None: the EU endpoint is used
PostHog, Inc.Optional website and application analyticsUnited StatesEU Standard Contractual Clauses
OpenAI Ireland Ltd.Drafting suggestions and document extraction when you use an AI-assisted featureIreland, with processing in the United StatesEU Standard Contractual Clauses; the OpenAI API terms exclude training on your data

Customers with a workspace receive at least 30 days' notice by email before we add or replace a sub-processor, as set out in the Data Processing Addendum.

Beyond sub-processors, personal data may be received by:

  • Your own organisation. Workspace administrators see the members, roles and activity history of their workspace.
  • People our customers share with. When a customer shares a report link with a bank, customer or auditor, the recipient sees what the customer chose to disclose. The customer decides this, not us.
  • Professional advisers such as our accountant, lawyers and insurers, under confidentiality, where needed.
  • Authorities where we are legally required to, such as the tax authority for accounting records or a court order. We check every request and disclose no more than required.
  • A successor if our business is sold or merged, under the same commitments as this policy, with notice to you.

7.International transfers

Your data is stored in the European Union. The application, its database, its file storage and its email delivery run in Amazon Web Services' Frankfurt region, and text recognition uses Google Cloud's EU endpoint.

Four providers process some data in the United States: our sign-in provider (name, email address, sign-in events), our payment provider (billing details), our analytics provider (usage events, only with consent) and, when an AI-assisted feature is used, OpenAI (the document or text excerpt concerned). For these transfers we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), supplemented by a transfer impact assessment and additional measures such as encryption in transit and at rest, and on the EU-US Data Privacy Framework where the provider is certified under it. You can request a copy of the relevant clauses at privacy@greenerahead.com.

8.How long we keep it

We keep personal data no longer than needed for the purpose it was collected for, and then delete or anonymise it. The main periods are:

DataRetention
Account and membership dataFor the life of the account, then deleted with the workspace under the periods below. An individual account that is removed from a workspace is deleted within 30 days.
Workspace content, including activity history and uploaded documentsUntil the customer deletes it or the subscription ends. After a subscription ends the workspace is read-only for 30 days for export, then deleted within 90 days, and purged from rotating backups within a further 35 days. Read-only trial workspaces may be deleted 90 days after the trial ends, with 14 days' notice.
Invitation, survey and share-link tokens and their access recordsUntil the link expires or is revoked, then as part of the activity history of the workspace.
Invoices and billing records7 years after the end of the financial year, as required by Dutch tax and accounting law.
Support and contact emails2 years after the conversation closes, unless it concerns a contract or claim that lasts longer.
Trial requests that do not lead to an account12 months.
Server and security logs90 days, longer only if needed for an ongoing investigation.
Product analytics events12 months, then deleted or aggregated. Deleted earlier when you withdraw consent or your account is deleted.
Browser push subscriptionsUntil you disable notifications or your account is deleted.
Data relevant to a legal claimUntil the claim is settled and any limitation period has passed.

9.How we protect it

We apply the technical and organisational measures described in Annex 2 of our Terms of Service. In short: hosting in the EU on private networks, encryption in transit and at rest with customer-managed keys for file storage, strict separation between customers enforced in every query, role-based access down to a single datapoint, signed single-purpose links that expire and can be revoked, an append-only activity history, daily backups, reviewed code changes and multi-factor authentication for anyone who operates the service.

If a personal data breach nevertheless occurs and is likely to result in a risk to you, we will inform the Dutch Data Protection Authority within 72 hours and, where the risk is high, you directly. Where the data belongs to a customer's workspace, we inform the customer within 48 hours so that it can meet its own obligations.

10.Cookies and similar technologies

Website (https://greenerahead.com)

On your first visit the website asks what it may store in your browser, with equal buttons to deny, to choose per purpose, and to allow all. Nothing optional is set before you answer, and the answer is never inferred from scrolling or continuing. Your choice is stored in a first-party cookie named ga_cookie_consent for 12 months, with a copy in local storage so that the cookie can be restored if your browser shortens it; the record holds a random consent ID, the declaration version, your choice per purpose and the time. We ask again when it expires or when the declaration changes.

Limited website analytics with PostHog runs without consent under article 11.7a, paragraph 3 under b, of the Dutch Telecommunicatiewet and article 6(1)(f) GDPR: we send the page path, the downloaded worksheet or product destination, a broad discovery category (such as Google or direct) and a random identifier for the browser tab, held in session storage under ga_marketing_session_v1 until the tab closes. We exclude query strings, form contents, names and email addresses, and we instruct the provider to store no IP address, no location and no person profile. You can object at any time with the “Limited analytics” switch in the cookie dialog; a Global Privacy Control signal from your browser is treated as an objection and also keeps statistics and marketing off.

The button above, the “Cookie settings” link in the footer and the round button at the bottom left of every page all reopen the dialog, where you can change or withdraw your choice as easily as you gave it. The full list of cookies and storage entries, by purpose, provider and duration, is the Cookie Declaration. Declining leaves all pages and downloads available. Website analytics are separate from sign-in and application analytics; a visit to the sign-up holding page does not establish that an account was created.

Application (https://app.greenerahead.com)

Name or typePurposeCategoryDuration
Session cookie set by our sign-in providerKeeps you signed in and protects the session against forgeryStrictly necessary, no consent requiredSession, refreshed while you use the application; removed on sign-out
Local storage keys for language, theme, font size and which items you have already reviewedRemembers your preferences on this browserStrictly necessary for a setting you chose, no consent requiredUntil you clear your browser storage
PostHog analytics cookies and local storage (ph_*)Records which screens you visit and which features you use, linked to your user account, so that we can improve the productAnalytics, only after your consent12 months, or until you withdraw consent

You are asked for consent to analytics the first time you sign in, and you can change your choice at any time under Settings in the application. Until you allow it, no analytics library is loaded and no usage events are recorded. Declining does not affect any feature. We do not use advertising or cross-site tracking cookies anywhere.

11.Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy (art. 15);
  • rectify inaccurate or incomplete data (art. 16);
  • erase your data in the circumstances set out in art. 17, for example when it is no longer needed or you withdraw consent;
  • restrict processing while a dispute about accuracy or lawfulness is resolved (art. 18);
  • receive data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another provider where technically feasible (art. 20);
  • object to processing based on legitimate interests on grounds relating to your particular situation, and to object at any time to direct marketing (art. 21);
  • withdraw consent at any time, without affecting processing that took place before the withdrawal (art. 7(3)).

To exercise a right, email privacy@greenerahead.com from the address we know you by, or from another address with enough information for us to verify that you are the person concerned. We respond within one month; for complex or numerous requests we may extend this by two months and will tell you if so. Exercising your rights is free unless a request is manifestly unfounded or excessive.

If your request concerns data that a customer entered into its workspace, we will forward it to that customer, because they decide about that data (section 2), and support them in answering it.

You also have the right to lodge a complaint with a supervisory authority. In the Netherlands that is the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl. You may also complain to the authority of the EU country where you live or work. We would appreciate the chance to address your concern first.

12.Children

The website and the application are intended for businesses and their staff. We do not knowingly process personal data of children under 16 for our own purposes. If you believe a child has provided us with personal data, contact privacy@greenerahead.com and we will delete it.

13.Changes to this policy

We update this policy when our processing changes, for example when we add a product, a sub-processor or a feature. The version number and effective date at the top tell you which version you are reading. Material changes are announced to account holders by email or in the application before they take effect. Earlier versions are available on request.

14.Contact

Greener Ahead
Philitelaan 59 57, 5617 AK Eindhoven, the Netherlands
Chamber of Commerce 85351660

Privacy: privacy@greenerahead.com
Security: security@greenerahead.com
General: hello@greenerahead.com

Greener Ahead
ProductVSME reportPricing
CompanyBlogResourcesCareers
LegalTerms of ServicePrivacy PolicyCookie declaration
© 2026 Greener AheadNetherlandsEuropean UnionMade in the EUBack to top ↑