Privacy Policy

How CBAM-OK processes and protects personal data.

Last updated: 22 July 2026

1. Controller and contact

The controller under the GDPR is RADOM UG (haftungsbeschränkt), Telemannstr. 2, 60323 Frankfurt am Main, Germany. Privacy requests can be sent to support@cbam-ok.eu.

2. Data, purposes and legal bases

We process only the data needed to provide, secure and bill CBAM-OK.

  • Account, authentication and support data: to create and operate your account and answer requests, under Article 6(1)(b) GDPR.
  • Imported CBAM working data, corrections and annual export packages: to provide the requested service, under Article 6(1)(b) GDPR.
  • Subscription, invoice and transaction references: for contract performance and statutory tax or accounting duties, under Articles 6(1)(b) and 6(1)(c) GDPR.
  • IP address, request time, status and security events: to prevent abuse and maintain reliable operations, under Article 6(1)(f) GDPR. Our legitimate interest is service and information-security protection.

3. Cookies and local storage

The launch version uses only technically necessary authentication, security and language-preference storage. Access tokens expire after about 30 minutes and refresh tokens after about seven days unless you sign out or revoke the session sooner.

We do not load advertising, Google Analytics or Trustpilot widgets and do not set optional marketing or analytics cookies.

4. Recipients and processors

We use processors only where required for the service and under data-processing terms.

  • Hetzner for EU-based application, database and backup hosting.
  • Brevo or the configured SMTP provider for transactional email and support delivery.
  • Stripe Payments Europe for checkout, subscriptions and payment records; CBAM-OK does not store full card details.
  • Microsoft Azure OpenAI only when the classification feature is configured and used. Product descriptions and related working fields may be sent to produce a suggestion, which the user must review.
  • Sentry or an OpenTelemetry endpoint only when configured for operational monitoring. PII capture is disabled by default.

5. International transfers

Core application data is hosted in the EU. Some global providers may process limited data outside the EEA. Where no adequacy decision applies, we require an approved safeguard such as the EU Standard Contractual Clauses and limit the transferred data to what is necessary.

6. Retention and deletion

Account and contract records are retained while the service is active and for any statutory limitation, tax or accounting period that applies. CBAM working records with no later activity are automatically soft-deleted after 90 days by default.

An account-deletion request makes account and working data unavailable immediately. Soft-deleted working records are permanently purged after 30 days. Encrypted operational backups rotate after 30 days. A record may be retained longer only where a legal hold or statutory duty applies.

7. Classification assistance

Classification and plausibility features produce reviewable suggestions. They do not make legal decisions, submit data to the EU CBAM Registry or replace customs or legal advice. There is no solely automated decision with legal or similarly significant effect.

8. Your rights

You may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Send requests to support@cbam-ok.eu. You may also complain to a supervisory authority.

9. Supervisory authority

The competent authority is the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Wilhelmstraße 7, 65185 Wiesbaden, Germany, datenschutz.hessen.de.