CDSA Privacy Notice
Version 1.0 (effective 1 October 2026). Terms of Use · Print or save
Carbon Disclosure SA (Pty) Ltd, registration number 2009/023392/07, Cape Town
Issued under the Protection of Personal Information Act 4 of 2013. Published under the name of Dr Marco Lotz, Information Officer
Version 1.0, 27 September 2026. Effective date: 1 October 2026
In short
- We collect what we need to run your account and produce your outputs, and nothing more.
- Information about your organisation is protected under POPIA, and we treat it as confidential.
- We turn data into de-identified aggregate statistics, which belong to CDSA. We never publish anything that identifies you without your consent.
- Some of our service providers are outside South Africa. We use them only under POPIA's cross-border rules.
- You can ask for access, correction or deletion at any time, and complain to the Information Regulator.
1 Who we are and how to contact us
1.1 Carbon Disclosure SA (Pty) Ltd, registration number 2009/023392/07 (CDSA, we, us), is the responsible party, as defined in the Protection of Personal Information Act 4 of 2013 (POPIA), for the personal information processed through our websites, the CDSA Platform and our Services (the Carbon Footprint Calculator, the Carbon Tax and GHG Reporting Workspace and the CBAM Installation Data Pack Service).
1.2 Our Information Officer is Dr Marco Lotz. Contact details:
| Information Officer | Dr Marco Lotz |
| postbox@carbondisclosuresa.co.za | |
| Physical address | 5 Bethanie Street, Sonstraal, Durbanville, 7550, Western Cape, South Africa |
1.3 This Privacy Notice forms part of the CDSA Platform Terms of Use. Words defined in those Terms have the same meaning here.
2 Whose information this notice covers
2.1 This notice applies to anyone whose personal information we process in connection with the Platform and Services, including visitors, registered users, the organisations they represent, contact persons at customers, Review Partners, verifiers and suppliers, and people who receive our communications.
2.2 Under POPIA, personal information includes information relating to an identifiable, existing juristic person, such as a company. Information about your organisation, its facilities, energy use, emissions and tax position may therefore be personal information of your organisation, and we treat it as such.
2.3 The Services are for business use and are not directed at children. We do not knowingly process personal information of anyone under 18. Please do not upload special personal information (for example health, religious or biometric information) or information about children.
3 What we collect
3.1 We collect the following categories of information:
(a) Account and contact information: name, job title, organisation, email address, telephone number, log-in details (stored in hashed form) and communication preferences.
(b) Organisation information: registered name and number, VAT number, sector, addresses, facility names and locations, and licence or registration numbers you choose to enter.
(c) Customer Data: the answers, figures and documents you enter or upload, such as fuel, electricity and other energy use, production volumes, process data, spend data, travel and waste data, emissions, carbon tax figures, allowance elections, offsets, CBAM data and supporting records.
(d) Transaction information: what you bought, when and for how much, invoices and refund records. Card details are captured by the Payment Provider, not by us; we receive only limited details such as the payment status and the last four digits of a card.
(e) Technical information: IP address, browser and device type, log files, pages viewed, time stamps, error reports and security events.
(f) Communications: emails, support requests, feedback and survey answers.
4 Where we get it
4.1 Mostly directly from you or from the person who registers your organisation. We may also receive information from Payment Providers (payment confirmations), Review Partners and verifiers you ask us to work with, and public sources such as company registers, published sustainability reports and Authority publications.
5 Why we process it and on what lawful basis
5.1 We process personal information only for specific, lawful purposes, and only as much as we need (sections 9 to 13 of POPIA). The table below sets out our purposes and the lawful grounds in section 11 of POPIA on which we rely.
| Purpose | Information used | Lawful ground (POPIA s11) |
|---|---|---|
| Creating and managing your account; providing the Services and Outputs; support | Account, organisation, Customer Data, technical | Performance of a contract with you (s11(1)(b)); your consent where required (s11(1)(a)) |
| Taking payment, invoicing, refunds and keeping financial records | Account, transaction | Contract (s11(1)(b)); legal obligation under tax and company law (s11(1)(c)) |
| Security, fraud prevention, troubleshooting and service improvement | Technical, account | Our legitimate interests and yours (s11(1)(f)) |
| Creating De-identified Aggregate Data such as benchmarks and factors | Customer Data, technical | Legitimate interests (s11(1)(f)) and a purpose compatible with collection (s15); once de-identified, POPIA no longer applies (s6(1)(b)) |
| Sharing with a Review Partner, verifier or declarant at your request | Customer Data, organisation, contact | Contract (s11(1)(b)); your consent (s11(1)(a)) |
| Retiring carbon credits in your name in the Verra Registry | Organisation name, purpose of retirement | Contract (s11(1)(b)) |
| Service messages, deadline reminders and changes to Terms | Contact | Contract (s11(1)(b)); legitimate interests (s11(1)(f)) |
| Direct marketing (see clause 6) | Contact, organisation | Consent, or existing customer relationship under s69(3) |
| Complying with law, court orders and Authority requests; defending claims | Any relevant information | Legal obligation (s11(1)(c)); legitimate interests (s11(1)(f)) |
5.2 Where we rely on consent, you may withdraw it at any time. This does not affect processing already done, or processing we may carry out on another lawful ground.
5.3 You may object to processing based on legitimate interests under section 11(3) of POPIA. We will then stop unless the law allows us to continue.
6 Direct marketing
6.1 We send electronic direct marketing only (a) to customers, about similar products or services, where we obtained your details in the context of a sale and gave you the chance to object; or (b) to other people who have given us their consent, as section 69 of POPIA and its regulations require. Opting out is not treated as consent.
6.2 Every marketing message tells you how to unsubscribe, free of charge. You may also object by email, post or any other reasonable means. We also respect any opt-out registered under the Consumer Protection Act and its regulations.
7 De-identified and aggregated data
7.1 We de-identify Customer Data and usage data and combine it with other data to create De-identified Aggregate Data, such as sector benchmarks, emission intensities and factor libraries. We remove or alter identifiers so that the data cannot reasonably be re-identified as relating to you, your organisation, your facilities or any other person, and we apply controls against re-identification, such as minimum group sizes before publishing any statistic.
7.2 As the Terms of Use record, De-identified Aggregate Data belongs to CDSA and we may use, publish and license it. We will not publish or sell information that identifies you or your organisation without your consent.
8 Who we share it with
8.1 We share personal information only as needed, with:
(a) operators who process it on our behalf, such as our hosting, database, backup, email delivery, customer support, analytics and software providers, including providers of artificial intelligence tools used to help deliver the Services. Each operator is bound by a written agreement that requires it to process information only on our instructions and to keep it secure, as sections 20 and 21 of POPIA require;
(b) Payment Providers, including Dodo Payments where it acts as merchant of record, which process payment information under their own privacy terms;
(c) Review Partners, verifiers, importers and declarants, only when you ask us to;
(d) Verra, when we retire or transfer carbon credits for you;
(e) our professional advisers, auditors and insurers, under a duty of confidence;
(f) Authorities, courts and law enforcement, where the law requires it; and
(g) a successor to all or part of our business, under the same protections.
8.2 We do not sell personal information.
9 Transfers outside South Africa
9.1 Some of our operators store or process information outside South Africa. We transfer personal information across borders only as section 72 of POPIA permits, namely where the recipient is bound by a law, binding corporate rules or a binding agreement that gives adequate protection, where the transfer is necessary to perform our contract with you, or with your consent.
9.2 Our current principal operators and the countries where they process data are:
| Operator | Purpose | Country | Basis |
|---|---|---|---|
| Railway Corporation | Application hosting and database | European Union: Railway EU West region (Amsterdam, the Netherlands); Railway Corporation is a United States company | Binding agreement; contract necessity |
| Dodo Payments | Card payments as merchant of record, where offered | India and the United States | Contract necessity; its own terms |
| Resend | Transactional email | European Union (Ireland); a United States company | Binding agreement; contract necessity |
| Microsoft (Microsoft 365) | Business email and documents | South Africa or the European Union (Microsoft data centres) | Binding agreement |
| Anthropic (Claude) | Drafting and support assistance | United States | Binding agreement |
| A South African payment provider or bank | Invoice, EFT and card payments | South Africa | Not a cross-border transfer |
9.3 By using the Services you consent to these transfers, which are also necessary to provide the Services to you. We will update this list when we change operators.
10 How we protect it
10.1 We take appropriate, reasonable technical and organisational measures to protect personal information, as section 19 of POPIA requires, including encryption in transit, access controls based on least privilege, hashed passwords, logging, regular backups and prompt software updates.
10.2 If we have reasonable grounds to believe that your personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and you as soon as reasonably possible, as section 22 of POPIA requires.
10.3 No online system is completely secure. Please use a strong, unique password and tell us immediately of any suspected unauthorised use of your account.
11 How long we keep it
11.1 We keep personal information only as long as we need it for the purpose for which it was collected, unless the law requires or allows longer retention (section 14 of POPIA). In general:
(a) account information: while your account is active, and for up to 12 months after it closes;
(b) Customer Data: for the term of your Service and 90 days after it ends (the first 30 days of which are your export window), after which it is deleted or de-identified, unless you ask us to keep it longer or the law requires it;
(c) invoices, payment and accounting records: at least five years for tax purposes, and seven years where company law requires it;
(d) records of carbon credit retirements and transfers: for as long as the credits and related claims may be verified or audited;
(e) technical and security logs: up to 12 months; and
(f) marketing records: until you opt out, and a suppression record after that so we do not contact you again.
11.2 De-identified Aggregate Data is not personal information and may be kept indefinitely.
12 Your rights
12.1 Subject to POPIA and the Promotion of Access to Information Act 2 of 2000 (PAIA), you have the right to:
(a) ask whether we hold your personal information and request a copy of it (section 23 of POPIA);
(b) ask us to correct, delete or destroy personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (section 24);
(c) object to processing on the grounds in section 11(3), including direct marketing;
(d) withdraw your consent where we rely on consent;
(e) not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you (section 71). We do not make such decisions; our calculations produce estimates for you to review; and
(f) lodge a complaint with the Information Regulator.
12.2 You may send a request by email, post or any other reasonable means, using the contact details in clause 1. We may need to verify your identity and, for access requests, may charge the fee that PAIA prescribes. We will respond within the time the law allows.
13 Cookies
13.1 The Platform uses strictly necessary cookies to keep you signed in, secure your session and remember your progress. We do not use advertising or cross-site tracking cookies.
14 The Information Regulator
14.1 If you are not satisfied with how we have handled your personal information, please contact our Information Officer first. You may also complain to the Information Regulator:
| Address | Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191 |
| POPIA complaints | POPIAComplaints@inforegulator.org.za |
| General enquiries | enquiries@inforegulator.org.za; 010 023 5200; toll free 0800 017 160 |
| Website | www.inforegulator.org.za |
15 Changes to this notice
15.1 We may update this notice from time to time. We will publish the new version on the Platform with its effective date and, for material changes, notify registered users by email before the change takes effect.