CarboneticaRegistry
RegistryCredit directoryProjectsHow it worksContact
IT
Home/Legal information

Carbonetica Registry · Transparency

Privacy notice

How personal data is processed when you browse the registry, request information or use access-controlled areas.

Last updated: 3 September 2026IT / EN

At a glance

  • Controller: ABC & P S.R.L.
  • Marketing is always optional
  • Accessible contacts and rights
Read the document

On this page

  1. 01Data controller and scope of this notice
  2. 02Data categories and sources
  3. 03Purposes and legal bases
  4. 04Required and optional data; marketing consent
  5. 05Public data, documents and private information
  6. 06Cookies, sessions and technical storage
  7. 07Anti-spam protection and external services
  8. 08Recipients and international transfers
  9. 09Retention criteria
  10. 10Processing methods, security and automated decisions
  11. 11Your rights and how to exercise them
  12. 12Notice updates

Need clarification?

info@carbonetica.it

01Data controller and scope of this notice

ABC & P S.R.L., Via Enrico Berlinguer 5, 27012 Certosa di Pavia (PV), Italy, VAT and tax identification number 02778030185, is the controller of personal data processed through Carbonetica Registry. Contact the controller at info@carbonetica.it or the certified email address abcpconsulenze@pec.it, using the subject ‘Privacy Carbonetica Registry’.

This notice covers carboneticaregistry.com, catalogue access, contact forms, invitation-based project intake and the operator area. It provides information about data collected directly and, where relevant, data received from project contacts or consulted in official sources, under Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR).

02Data categories and sources

  • Browsing and security: IP address, technical browser information, service requests, dates, check results and access events; these are not payment data.
  • Catalogue: first and last name, professional email, telephone number, company, language, privacy acknowledgement, optional marketing consent, verification status and access records.
  • Commercial enquiries: company, contact person, contact details, country, project of interest, purpose, indicative quantity, message and notes needed to handle the enquiry.
  • Projects and organisations: contacts, roles, company information and minimum identifiers, statements, checks and technical documents. Data also comes from project leads, authorised parties and official sources used for verification.
  • Operators: account identity, email, role, credentials handled by the authentication system, security factors, sessions and action history. Optional Google sign-in provides the information needed to authenticate an invited account.

03Purposes and legal bases

  • Providing requested catalogue access and handling enquiries, invitations and project activities: performance of the service or steps requested before a contract (Article 6(1)(b) GDPR). For contacts acting for an organisation, the legitimate interest in managing the professional relationship (Article 6(1)(f)).
  • Protecting accounts and infrastructure, preventing abuse, checking authorisations and reconstructing operations: the legitimate interest in registry security and integrity (Article 6(1)(f)), taking account of affected individuals’ rights.
  • Making projects, public ownership and credit statuses verifiable: the legitimate interest in transparency and traceability of the voluntary registry (Article 6(1)(f)), limiting disclosure to relevant data. Participation in a project does not justify indiscriminate publication of personal data.
  • Sending promotional communications: separate, optional consent (Article 6(1)(a)). Complying with specific applicable obligations or binding authority requests: a legal obligation (Article 6(1)(c)). Establishing, exercising or defending a claim: the legitimate interest in protecting rights, subject to necessity and proportionality.

04Required and optional data; marketing consent

Fields marked as required are used to provide the requested function; withholding them prevents completion of that service, not access to freely available pages. Do not enter health data, criminal-record information or other irrelevant personal information in free-text fields.

Acknowledging this notice is not blanket consent to all processing. Marketing consent is separate: refusing or withdrawing it does not prevent catalogue access. Catalogue registration does not automatically create a commercial enquiry. Withdraw consent by contacting the controller; withdrawal does not affect lawful processing carried out beforehand.

05Public data, documents and private information

Public pages show project leads and other entities designated for publication, aggregate information, the verifier, selected documents, serials, statuses and minimum retirement-beneficiary information. Personal data in public documents may be viewed, downloaded and indexed by third parties; a watermark does not prevent reproduction.

Issuance certificates are published with their documentary content and only a watermark added: they may therefore contain representatives’ or professionals’ data appearing in the certificate. Complete anonymity of those documents is not promised. Other public versions follow the applicable selection and redaction process; originals and non-public attachments remain access-restricted.

The registry does not create public profiles or individual balances for participants other than project leads. Private organisational identifiers are protected through encryption and role controls. Operational uploads do not accept company KYC dossiers, identity documents, company extracts or documentary transfer evidence: technical project documentation is a separate category.

Anyone identifying irrelevant data or disputing publication may notify the controller, identifying the page or document. Requests are assessed even when a document is already public; authorisation to upload does not exclude privacy rights.

06Cookies, sessions and technical storage

The portal uses technical mechanisms to maintain requested access and protect forms. The current application configuration does not integrate advertising profiling or behavioural analytics tools. The Google Search Console tag verifies site ownership and is not a visit-tracking script.

  • ce_registry_access: a technical catalogue authentication cookie with a configured maximum lifetime of 400 days; it may be renewed during use, revoked by the service or removed by the browser. The email activation link is single-use and expires after 30 minutes.
  • Operator authentication cookies (the better-auth family, potentially with a security prefix): maintain sessions and access checks. The ordinary session is configured for 8 hours, with renewal during use; temporary authentication checks may have shorter lifetimes.
  • carbonetica_intake_session: a technical cookie for invitation-based project intake, with a 12-hour session. It does not grant operator-area access.
  • You can delete or block cookies in your browser settings; areas requiring authentication may then stop working. A cookie’s lifetime is not the retention period for all data associated with the service.

07Anti-spam protection and external services

Protected forms use Cloudflare Turnstile to distinguish legitimate from automated requests. The browser communicates with Cloudflare and the server verifies the check result, transmitting the IP address where available. The service processes technical device and interaction signals for security purposes; it is not marketing consent.

See the specific notice linked below for information about Cloudflare’s processing. Any provider verification mechanisms or technical storage depend on the protection mode used. Blocking the service may prevent protected forms from being submitted; email contact remains available.

Cloudflare Turnstile — provider privacy notice (opens in a new tab)

08Recipients and international transfers

Data is accessible to authorised personnel according to role and need, and to providers involved in hosting, storage and backups, maintenance, email, authentication and security. Parties acting on the controller’s behalf must be bound by the instructions and safeguards required by Article 28 GDPR. Verifiers, advisers or authorities may receive information relevant to their engagement or duty, according to their actual role.

Cloudflare Turnstile and optional Google authentication involve providers with international infrastructure. Processing is therefore not represented as exclusively located in Italy or Europe. Transfers outside the European Economic Area require a permitted basis under GDPR Chapter V: an applicable adequacy decision or appropriate safeguards, such as standard contractual clauses and supplementary measures where necessary. You may ask the controller about actual recipients, countries and safeguards for processing concerning you.

09Retention criteria

Data is retained in relation to its purpose, the duration of the service and documented security and rights-protection needs. Session expiry, access revocation and archiving an enquiry do not automatically delete data. The following criteria distinguish records and do not authorise indiscriminate retention.

  • Catalogue access and invitations: to manage the requested access; after termination or revocation, only what is necessary to document the request, resolve disputes or prevent identified abuse.
  • Commercial enquiries: until the enquiry and any negotiations are concluded; if a contract follows, relevant data is subject to the periods applicable to that relationship and its record-keeping obligations.
  • Marketing: until consent is withdrawn or the contact ceases to be relevant, with review of necessity. Minimum withdrawal information may be retained to honour the objection and demonstrate consent management.
  • Structured certification records: five years after the monitoring period under registry policy, unless a reasoned and documented need requires longer retention. Serial and terminal-status history serves to prevent unit reuse; its continuity does not require unlimited disclosure of unnecessary personal data.
  • Technical logs, sessions and backups: to diagnose faults, manage incidents and restore service, limited to data useful for those purposes. An incident or dispute may require separate retention of relevant evidence until it is resolved. Backups follow their rotation cycle and are not intended for routine use.

10Processing methods, security and automated decisions

Processing is primarily electronic. Application measures include role-based access, authentication of restricted areas, separate proposal and approval, encryption of private organisational identifiers, separation of originals from public documents and event logging. No system can promise absolute absence of risk.

Anti-abuse checks may block a submission or require verification again. The portal does not use these checks to automatically decide purchases or credit allocations with legal effects; registry operations undergo the prescribed checks and approvals. If blocked, you can contact the operator to investigate.

11Your rights and how to exercise them

Where GDPR conditions are met, you may request access, correction, erasure or restriction, object to legitimate-interest processing and obtain portability where applicable. You may always withdraw marketing consent and object to direct marketing. Erasure is not absolute: any restriction requires a specific basis and does not automatically follow from the existence of registry history.

Write to info@carbonetica.it or abcpconsulenze@pec.it. Only proportionate information is requested to locate data and, where reasonable doubts arise, verify identity: do not send document copies in advance. The ordinary response period is one month; any permitted extension must be communicated and explained.

You may complain to the Italian data protection authority (Garante), or the competent authority under the GDPR, and seek a judicial remedy. For current forms, contact details and instructions, consult the Garante’s official website.

Garante — data subject rights (opens in a new tab)

12Notice updates

This notice is updated when purposes, features or processing conditions change materially. The date at the top indicates an editorial revision, not a conformity certification. Where necessary, changes are communicated through service channels and new consent is requested for processing that requires it; continuing to browse does not constitute marketing consent.

Company contacts

ABC & P S.R.L.

Via Enrico Berlinguer 5, 27012 Certosa di Pavia (PV), Italy

VAT / Tax ID
02778030185
REA
PV – 300756
Email
info@carbonetica.it
PEC
abcpconsulenze@pec.it
Read alsoRegistry rulesRead alsoLegal notice
Carbonetica

Private voluntary carbon credit registry.

TransparencyVerify a creditCredit directoryProjectsLifecycleContact
ReferencesEU Union Registry CRCF Regulation
Legal notice

This portal is not the EU Union Registry and does not, by itself, constitute a recognised CRCF scheme.

info@carbonetica.itRegistry rulesLegal noticePrivacy policy Staff area
Created byE-ROE