Privacy policy

What data the platform collects, why, who it is shared with and how to exercise your rights over it.

1. Who is responsible for the data

The data controller is [Company name], tax ID [CUIT], registered at [legal address], Argentina ("Coralia"). For any privacy question: [privacy email].

The platform is a business service. The customer company decides what information it uploads and who on its team has access; Coralia processes it to provide the contracted service.

2. What data we collect

We collect only the data needed to calculate the carbon footprint, issue reports and manage accounts.

Type of dataExamplesSource
AccountName, email, role, companyThe user or the admin who invites them
CompanyCompany name, tax ID, sector, country, plan, logo and brand for reportsThe company admin
Product and operationsFormulas, raw materials, packaging, consumption, transport, targetsCompany users
DocumentsInvoices, delivery notes, data sheets and audit evidenceCompany users
AI assistantQuestions to Coral IA, answers and generated notesCompany users
AuditsComments, messages, observations and signatures; for each signature, IP address and browserUsers, auditors and consultants
SupportName, email, company and messageThe user who writes
IntegrationsGoogle Calendar access, if the user connects it; company API keysThe user
PaymentsPlan, amounts and status of each paymentMercado Pago; Coralia does not receive card details

We do not ask for sensitive data as defined by Argentine Law 25,326 (health, ethnic origin, political opinions, etc.) and ask users not to upload it.

3. How we use the data

We use the data to provide the contracted service. We do not sell it or use it for advertising.

  • Calculate the carbon footprint and generate reports.
  • Review and certify emission factors and reports with Coralia's technical team.
  • Manage audits between the company and the auditors it chooses.
  • Manage accounts, invitations, permissions and plans.
  • Send service notices and answer support requests.
  • Charge for contracted services.
  • Keep the platform secure and prevent misuse.
  • [To be confirmed] Produce aggregated, anonymous sector statistics that do not identify any company or product.

Legal basis. We process data because it is needed to perform the contract with the customer company and, where applicable, with the user's consent, under Argentine Law 25,326.

4. Use of artificial intelligence

  • When it is used. When uploading an invoice, delivery note or product document for the platform to interpret; when asking Coral IA; when estimating the emission factor of a new raw material; and when generating reduction opportunities.
  • What is sent. Only the content needed for that task.
  • What Anthropic does with it. It does not use it to train models and deletes it within 30 days, except content flagged for violating its usage policy.
  • Human review. AI results are proposals. Values in a certified report are reviewed by a Coralia consultant.

5. Who we share data with

ProviderRoleLocation
SupabaseDatabase, files and sign-in[To be confirmed: São Paulo, Brazil]
VercelRunning the applicationUnited States
AnthropicDocument reading and AI assistantUnited States
ResendSending emails[To be confirmed]
Mercado PagoPayments[To be confirmed]
Google and MicrosoftCorporate sign-in and Google Calendar[To be confirmed]

Auditors. The auditor a company accepts can access only the information of the audited project.

Coralia team. Consultants access the data needed to review, certify and provide support.

Authorities. We hand over data only when a law or an order requires it.

International transfers. Some providers have servers outside Argentina, including in countries Argentine regulations do not consider adequate, such as the United States. Coralia requires those providers to apply security and confidentiality measures equivalent to Law 25,326. By using the platform, the user consents to those transfers.

6. How long we keep data

  • During the service. For as long as the company has an active account.
  • After cancellation. The company can request a copy of its data. It is deleted [90] days after cancellation.
  • Exceptions. We keep longer what a law requires, and the records of certified reports and signed audits needed to verify their authenticity.
  • Backups. Deleted data may remain in backups for up to [7] days.

7. Security

We protect data with encryption, per-company access control and providers with SOC 2 Type 2 audits. Details are in Platform security. If an incident affects personal data, we notify the affected company within [72] hours of detecting it.

8. Cookies

The platform uses only cookies it needs to work; it does not use analytics, advertising or tracking cookies.

Cookie or stored dataPurposeDuration
Session (Supabase)Keep the user securely signed inFor the session
LanguageRemember the chosen language1 year
Display preferencesRemember, for example, the size of the assistant windowUntil the user clears browser data

If we add analytics cookies in the future, we will list them here and ask for consent before turning them on.

9. Your rights

You can ask to see, correct, update or delete your personal data by writing to [privacy email].

  • Access. Know what data we hold and why. We answer within 10 calendar days.
  • Correction and update. Fix incorrect or outdated data.
  • Deletion. Ask us to delete data, except what we must keep by law or contract. Correction and deletion are handled within 5 business days.

Under Article 14(3) of Argentine Law 25,326, data subjects may exercise their right of access free of charge at intervals of no less than six months, unless a legitimate interest is shown.

The Argentine Agency for Access to Public Information (AAIP), as the supervisory authority of Law 25,326, handles complaints from anyone whose rights are affected by a breach of data protection rules.

10. Changes and contact

If we change this policy, we email each company's admins at least [15] days in advance. Contact: [privacy email] · [Company name], [legal address], Argentina.