Privacy Policy of the 7G Carbon Platform Ecosystem
Unified Rules for the Processing and Protection of Personal Data on Websites, in the Personal Account, and in Registries
| Operator | HPBS LLC |
| Version | 1.0 dated September 12, 2026 |
| Territorial scope | Republic of Uzbekistan and ecosystem users regardless of their place of access |
| Status | Effective from the date of publication on the ecosystem websites |
About This Document
This Policy explains what personal data HPBS LLC receives, why such data is needed, how it is used and protected, to whom it may be disclosed, how long it is retained, and what rights users have. It applies to the entire digital ecosystem of the 7G Carbon Platform.
1 General Provisions
1.1. This Privacy and Personal Data Processing Policy (hereinafter, the “Policy”) sets out the rules for the processing and protection of personal data by HPBS LLC (hereinafter, the “Operator”, “we”) when the 7G Carbon Platform digital ecosystem is used.
1.2. The Policy has been developed in accordance with the Law of the Republic of Uzbekistan “On Personal Data” No. ZRU-547 dated July 2, 2019, as amended, other applicable laws and regulations of the Republic of Uzbekistan, and taking into account the Operator’s contractual obligations to clients and users.
1.3. By using the websites, creating an account, submitting a form, or continuing to use the personal account after reviewing the Policy, the user confirms that they have read and understood its terms. Where consent is required by law, the Operator requests it separately in a form that makes it possible to confirm that such consent has been obtained.
1.4. If a user provides another person’s data, the user confirms that there is a lawful basis for such transfer and is required to inform that person of this Policy.
1.5. This Policy does not replace a separate consent to personal data processing, consent to marketing communications, a contract, a user agreement, or the terms of a specific service where such documents are required.
2 Scope
2.1. The Policy applies to the following ecosystem resources, including their pages, subdomains, forms, and application programming interfaces:
- carbonplatform.asia — corporate greenhouse gas (GHG) emissions accounting
- carbonfin.asia — financed emissions accounting under PCAF
- carbonmodel.asia — project modelling and MRV
- carboncbam.asia — preparation of CBAM data and calculations
- carbonmarket.asia — carbon unit market services
- 7G.carbonplatform.asia — unified personal account and workspace
- registry.carbonmodel.asia — climate project registry
- registry.carbonmarket.uz — registry of climate claims and carbon units.
2.2. The Policy also applies to enquiries submitted through feedback forms, event registrations, demo and commercial proposal requests, support services, CRM integrations, and other information systems used to provide the services.
2.3. Third-party websites and services accessible through external links operate under their own rules. The Operator does not determine the purposes or means of data processing by such independent parties.
3 Key Definitions
| Term | Meaning |
| Personal data | information relating to an identified individual or information that makes it possible to identify an individual. |
| Processing | any operation or set of operations performed on personal data, including collection, systematisation, storage, alteration, use, transfer, anonymisation, and destruction. |
| User | an individual who visits ecosystem resources or uses their functions, including a representative of a client, partner, contractor, or applicant. |
| Client | a legal entity or individual to whom the Operator provides access to the services under a contract or on another lawful basis. |
| Cookies | small files and similar technologies that store information about a session, settings, and website usage. |
4 Personal Data We Process
4.1. The categories of data depend on the selected resource, the user’s role, the terms of the contract, and the function being used. The Operator may process:
- identification data: surname, first name, patronymic, position, organisation, and role in a project or system;
- contact data: business and personal email addresses, telephone number, and correspondence address;
- account data: login, user identifier, information about roles and access rights, profile settings, and account status; passwords are stored securely and are not displayed to the Operator’s employees;
- enquiry and interaction data: the content of applications, correspondence, support requests, feedback, consents, and withdrawals;
- contractual and payment information: client or counterparty details, information about representatives, contracts, invoices, and payments; banking data is processed only to the extent necessary for settlements and accounting;
- project and corporate data that may contain information about employees, experts, auditors, verifiers, suppliers, and other participants in relevant processes;
- registry data: information about applicants, rights holders, climate project participants, experts, and verifiers, where such information is provided for by the rules of the relevant registry;
- technical data: IP address, date and time of access, device and browser type, operating system, language, referring URL, session identifiers, event logs, and information about errors and security;
- usage data: sections visited, actions performed, selected settings, interface interactions, and aggregated usage metrics;
- information from cookies and similar technologies within the settings selected by the user.
4.2. The Operator does not request special categories of personal data, biometric data, or genetic data for ordinary registration and use of the services. If processing such data becomes necessary for a specific function, it will be carried out only on a lawful basis provided for by law and with separate notice to the user.
4.3. Environmental, energy, financial, and production indicators of a legal entity do not, by themselves, constitute personal data. However, the provisions of this Policy apply to such information if it makes it possible to identify an individual directly or indirectly.
5 Sources of Personal Data
5.1. The Operator receives data:
- directly from the user when forms are completed, registration takes place, a contract is concluded, a profile is configured, or support is contacted;
- from the user’s client or employer that grants the user access to the workspace;
- from authorised representatives, partners, contractors, auditors, and verifiers within the framework of a project or contract;
- automatically when the websites and personal account are used;
- from lawfully available government, corporate, and public sources where necessary to verify a project, counterparty, climate claim, or registry entry;
- through integrations authorised by the user and imported files.
6 Purposes and Legal Bases for Processing
| Area | Purpose | Legal basis |
| Providing access | registration, authentication, role management, use of platform functions, and user support | consent, contract, actions taken at the user’s request, and the Operator’s legal obligations |
| Performance of contracts | provision of services, project management, document exchange, settlements, and business communications | contract, legal obligations, and consent where required |
| Calculations and reporting | preparation of GHG, PCAF, MRV, and CBAM calculations, reports, forecasts, and verification materials | contract, client instruction, consent, or another lawful basis |
| Registries | receipt, verification, maintenance of history, and publication of the permitted portion of registry information | consent to publication, contract, registry rules, and legal obligations |
| Security | prevention of misuse, incident investigation, backup, logging, and access control | protection of the rights and legitimate interests of users and the Operator, and legal requirements |
| Support and development | handling enquiries, diagnosing errors, and improving the interface, quality, and performance | contract, consent, and legitimate interests subject to respect for user rights |
| Marketing | sending news, invitations, and offers | separate consent; the user may opt out at any time |
| Legal compliance | accounting and tax compliance, responses to lawful requests, and protection of rights in disputes | compliance with mandatory legal requirements |
7 Processing Procedures
7.1. Processing may be automated, non-automated, or mixed. The Operator performs only those operations that are necessary for the stated purposes.
7.2. Access to data is granted on a role-based basis and only to the extent necessary for an employee, client, expert, verifier, or contractor to perform their tasks. Actions in the system may be recorded in audit logs.
7.3. Within a corporate client account, a workspace administrator may manage users, roles, projects, and data visibility within the scope of the powers granted. The Client is responsible for the lawfulness of uploading personal data relating to its employees and other individuals.
7.4. Automated calculations and platform recommendations are intended for informational and operational support. Decisions that produce legal consequences for an individual must not be made solely on their basis without human review where such review is required by law or contract.
8 Publication of Data in Registries
8.1. Registries may contain publicly available information about climate projects, claims, and carbon units. Before publication, the user is informed of the categories of data to be published and, where required, provides separate consent to their disclosure.
8.2. Contact details, documents, signatures, identifiers, and other restricted-access information are not published unless publication is expressly required by law, registry rules, or the data subject’s separate consent.
8.3. A user may submit a request to correct, restrict access to, or delete published personal data. The Operator considers such requests taking into account the requirements to preserve the accuracy, integrity, and history of registry entries.
9 Cookies and Analytics
9.1. The websites may use the following categories of cookies:
- strictly necessary — ensure security, authentication, session retention, and operation of core functions;
- functional — remember language, interface, and other user settings;
- analytics — help assess traffic, performance, and usability in aggregated form;
- marketing — used only where such cookies are actually enabled and the required consent has been obtained.
9.2. Optional cookies are activated in accordance with the user’s choices in the settings panel. The user may change those choices, delete cookies, or restrict their use through browser settings. Disabling strictly necessary cookies may interfere with authentication and certain functions.
9.3. If third-party analytics, chat, mapping, video, or automated-request protection tools are connected to the websites, the user is provided with the necessary information before such tools are activated, and data is transferred on a lawful basis.
10 Disclosure of Data to Third Parties
10.1. The Operator may disclose data only to the extent necessary to the following categories of recipients:
- providers of hosting, infrastructure, backup, communications, technical support, and information security services;
- providers of CRM systems, business communication services, and enquiry management services;
- auditors, consultants, verifiers, and experts engaged for a specific project;
- partners and contractors involved in providing the requested service;
- banks and payment organisations when settlements are made;
- government authorities, courts, and other authorised persons in the cases and manner prescribed by law;
- a new owner or legal successor in the event of reorganisation or transfer of the relevant business, subject to continued confidentiality requirements.
10.2. Persons processing data on behalf of the Operator are required to maintain confidentiality, use the data only for the specified purposes, and apply appropriate safeguards.
10.3. The Operator does not sell personal data and does not transfer it for independent advertising use without the user’s separate consent.
11 Cross-Border Transfer and Data Storage Location
11.1. The Operator arranges the storage and cross-border transfer of personal data in accordance with the requirements of the legislation of the Republic of Uzbekistan.
11.2. Personal data that is required to be stored in the Republic of Uzbekistan is stored within the Republic of Uzbekistan. Other data may be stored or processed outside the country where the conditions prescribed by law are met and sufficient safeguards are in place.
11.3. Before connecting an external cloud service, the Operator assesses the place of processing, contractual terms, security measures, and permissibility of the transfer. Where necessary, separate consent from the data subject is obtained.
12 Retention Periods and Destruction
12.1. Data is retained no longer than necessary for the purposes of processing, for the duration of the consent, or for performance of the contract, unless a longer period is prescribed by law or is required to protect lawful rights.
12.2. The following general retention guidelines apply unless a different period is established by contract or mandatory rules:
- account data — for the duration of the account and for a reasonable period after closure to resolve enquiries and address security matters;
- applications and correspondence — for the period required to process the enquiry and subsequently confirm its completion;
- contractual, accounting, and payment documents — for the mandatory retention periods;
- security logs and technical backups — for the periods established by internal policies, taking into account risks and the need to investigate incidents;
- marketing contacts — until consent is withdrawn or the relevant mailing is discontinued;
- registry information — in accordance with registry rules and the requirements for accuracy and preservation of the history of entries.
12.3. Once the relevant purpose has been achieved, data is destroyed, anonymised, or blocked unless continued retention is required by law. Deletion from backups takes place as part of the established backup rotation cycle while access restrictions remain in place.
13 Data Protection
13.1. The Operator applies legal, organisational, and technical measures appropriate to the nature of the data and the risks of processing, including:
- role-based access control and the principle of least privilege;
- user identification and authentication, session management, and password management;
- encryption of secure connections and, where applicable, data at rest;
- activity logging, event monitoring, and incident response;
- backup and recovery testing;
- software updates and vulnerability and configuration management;
- employee training and contractual confidentiality obligations;
- assessment of contractors and restriction of their access;
- periodic review of safeguards.
13.2. The user is required to keep account credentials confidential, use a strong password, not provide access to other persons, and promptly report any suspicious activity.
13.3. No method of transmitting or storing information provides absolute security. If an incident is identified, the Operator takes measures to contain it, mitigate its consequences, and notify affected persons and authorised authorities where required by law.
14 User Rights
14.1. To the extent provided by law, the user has the right to:
- find out whether the Operator holds the user’s personal data and obtain information about its categories and processing;
- request correction of incomplete, outdated, or inaccurate data;
- withdraw consent where processing is based on consent;
- request temporary suspension of processing or destruction of data where there are lawful grounds;
- opt out of marketing communications;
- obtain information about the conditions under which access to data is provided;
- apply to an authorised government body or court to protect their rights and legitimate interests.
14.2. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal was received and does not terminate processing that is necessary to comply with legal requirements or protect the rights of the Operator or other persons.
15 Procedure for Submitting Requests
15.1. A request may be submitted through the feedback form or using the contact details of HPBS LLC published in the “Contacts” section of the ecosystem resources.
15.2. It is recommended that the request include the user’s surname and first name, contact details for a response, the resource used, the substance of the request, and information that makes it possible to locate the relevant data. The Operator may request proof of identity and, where applicable, a representative’s authority in order to prevent unauthorised disclosure or alteration of data.
15.3. The Operator considers requests within the period and in the manner established by law. If fulfilment of a request is restricted by law, contractual terms, or the rights of other persons, the user is provided with a reasoned response.
16 Data Relating to Minors
16.1. The services are intended primarily for professional and corporate use and are not designed for independent use by minors.
16.2. If the Operator becomes aware that a minor’s data has been obtained without the required consent of a legal representative, it will take steps to restrict processing and delete the data unless another lawful basis applies.
17 Obligations of Corporate Clients
17.1. A Client that uploads data to the platform or grants its employees access is independently responsible for ensuring a lawful basis, informing data subjects, ensuring the appropriateness and accuracy of the data provided, and complying with access restrictions.
17.2. Where HPBS LLC processes data solely on the documented instructions of a Client, the allocation of responsibilities between the owner and the operator of the personal data database is determined by the contract. The Client must not upload special categories of data, biometric data, genetic data, or excessive data without prior written approval.
18 Amendments to the Policy
18.1. The Operator may amend the Policy as the services develop or where processing activities or legislation change. A new version enters into force on the date of publication unless otherwise stated in that version.
18.2. In the event of material changes affecting user rights or the purposes of processing, the Operator posts a prominent notice on the ecosystem resources and, where necessary, obtains consent again.
19 Operator Contact Details
Personal data Operator: HPBS LLC, Republic of Uzbekistan.
Enquiries concerning personal data are accepted through the feedback form and using the current contact details published in the “Contacts” section of the 7G Carbon Platform ecosystem websites.
20 Legal Basis
Law of the Republic of Uzbekistan “On Personal Data” No. ZRU-547 dated July 2, 2019, as amended: LexUZ
End of Document