Privacy Policy
How CBAM-OK processes and protects personal data.
Last updated: 22 July 2026
1. Controller and contact
The controller under the GDPR is RADOM UG (haftungsbeschränkt), Telemannstr. 2, 60323 Frankfurt am Main, Germany. Privacy requests can be sent to support@cbam-ok.eu.
2. Data, purposes and legal bases
We process only the data needed to provide, secure and bill CBAM-OK.
- Account, authentication and support data: to create and operate your account and answer requests, under Article 6(1)(b) GDPR.
- Imported CBAM working data, corrections and annual export packages: to provide the requested service, under Article 6(1)(b) GDPR.
- Subscription, invoice and transaction references: for contract performance and statutory tax or accounting duties, under Articles 6(1)(b) and 6(1)(c) GDPR.
- IP address, request time, status and security events: to prevent abuse and maintain reliable operations, under Article 6(1)(f) GDPR. Our legitimate interest is service and information-security protection.
4. Recipients and processors
We use processors only where required for the service and under data-processing terms.
- Hetzner for EU-based application, database and backup hosting.
- Brevo or the configured SMTP provider for transactional email and support delivery.
- Stripe Payments Europe for checkout, subscriptions and payment records; CBAM-OK does not store full card details.
- Microsoft Azure OpenAI only when the classification feature is configured and used. Product descriptions and related working fields may be sent to produce a suggestion, which the user must review.
- Sentry or an OpenTelemetry endpoint only when configured for operational monitoring. PII capture is disabled by default.
5. International transfers
Core application data is hosted in the EU. Some global providers may process limited data outside the EEA. Where no adequacy decision applies, we require an approved safeguard such as the EU Standard Contractual Clauses and limit the transferred data to what is necessary.
6. Retention and deletion
Account and contract records are retained while the service is active and for any statutory limitation, tax or accounting period that applies. CBAM working records with no later activity are automatically soft-deleted after 90 days by default.
An account-deletion request makes account and working data unavailable immediately. Soft-deleted working records are permanently purged after 30 days. Encrypted operational backups rotate after 30 days. A record may be retained longer only where a legal hold or statutory duty applies.
7. Classification assistance
Classification and plausibility features produce reviewable suggestions. They do not make legal decisions, submit data to the EU CBAM Registry or replace customs or legal advice. There is no solely automated decision with legal or similarly significant effect.
8. Your rights
You may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Send requests to support@cbam-ok.eu. You may also complain to a supervisory authority.