Legal

Privacy Policy

Last Updated: 10 August 2026

1. INTRODUCTION

This Privacy Policy ("Policy") explains how AMMRS Software Solutions and ESG Consulting LLP (LLPIN: ACK-3975), a limited liability partnership registered in India with its principal place of business at Surat, Gujarat, India ("AMMRS", "we", "us", "our"), collects, uses, discloses, stores, transfers and otherwise processes personal data in connection with Sustainity™, our ESG and sustainability management software platform, together with its websites, applications, APIs, and related services (collectively, the "Platform" or "Services").

Sustainity™ provides three principal modules:

  • GHG Inventory Management — measurement, calculation and management of Scope 1, Scope 2 and Scope 3 greenhouse gas emissions inventories;
  • ESG Vendor Assessment — issuance, collection, scoring and management of ESG and sustainability assessments across supply chains and third parties;
  • ESG Framework Reporting — preparation and management of disclosures against frameworks including GRI, SASB, ESRS/CSRD, IFRS S1 & S2, TCFD, BRSR and equivalent standards.

This Policy is drafted to comply with, among other laws, the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018 where applicable, and the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") together with the rules made thereunder.

Please read this Policy carefully. If you do not agree with it, please do not access or use the Platform.

2. SCOPE AND OUR ROLE IN PROCESSING

Sustainity™ is a business-to-business platform. Our role under data protection law depends on the category of data concerned. This distinction is important because it determines who you should contact to exercise your rights.

2.1 Where AMMRS acts as Controller / Data Fiduciary

We determine the purposes and means of processing — and are therefore the Controller (GDPR) and Data Fiduciary (DPDP Act) — in respect of:

  • account registration, administration and authentication data;
  • billing, subscription and payment records;
  • support, service and correspondence records;
  • website visitors, marketing contacts and prospective customers;
  • Platform usage, security, audit and telemetry data;
  • data processed to meet our own legal, tax and regulatory obligations.

2.2 Where AMMRS acts as Processor / Data Processor

We process data solely on the documented instructions of our customer — and are therefore the Processor (GDPR) and Data Processor (DPDP Act) — in respect of Customer Content: the data a subscribing organisation (or its authorised users, vendors or suppliers) uploads to, generates in, or transmits through the Platform. This includes activity data, utility and fuel records, supplier questionnaire responses, ESG evidence documents, disclosure narratives, and any personal data contained within them.

For Customer Content, the subscribing organisation is the Controller / Data Fiduciary. Our processing is governed by the customer's agreement with us, including our Data Processing Addendum ("DPA"). If you are an employee, supplier, vendor representative or other individual whose personal data has been entered into Sustainity™ by one of our customers, please direct your privacy requests to that organisation. We will assist them in responding, but we are not permitted to act on such data independently.

2.3 Where AMMRS acts as Independent Controller

Where we deliver ESG advisory, assurance-readiness or consulting services alongside the Platform, we may act as an independent Controller in respect of professional contact details and engagement records.

3. PERSONAL DATA WE COLLECT

3.1 Data you provide directly

CategoryExamples
Identity dataFull name, job title, designation, employer, professional role, department
Contact dataBusiness email address, business telephone/mobile number, business postal address, country
Account dataUsername, hashed password, security questions, multi-factor authentication settings, user role and permission set, language and time-zone preference
Billing dataBilling contact name, billing address, purchase order references, GSTIN/VAT/tax identifiers, invoice history. We do not store full payment card numbers — these are handled directly by our PCI-DSS compliant payment processors.
Support dataTickets, correspondence, chat logs, call notes, screenshots and attachments you send us
Marketing dataSubscription preferences, event and webinar registrations, consent records

3.2 Data collected automatically

  • Technical data: IP address, browser type and version, device identifiers, operating system, screen resolution, referring URLs, language settings.
  • Usage data: pages and modules accessed, features used, queries run, reports generated, timestamps, session duration, click paths.
  • Security and audit data: login attempts (successful and failed), source IP, changes to records, exports performed, permission changes, and other audit-trail events. Audit logging is a core control requirement of ESG reporting and assurance and cannot be disabled by users.
  • Cookies and similar technologies: see Section 10.

3.3 Data received from third parties

  • Identity data from single sign-on / federated identity providers (e.g. Microsoft Entra ID, Google Workspace, Okta) where your organisation enables SSO;
  • Contact data from your employer or the organisation that invited you to the Platform, including as a vendor or supplier respondent;
  • Business and enrichment data from publicly available sources, ESG data providers, credit reference and sanctions-screening providers where the customer has enabled such features;
  • Records from integration partners connected at your organisation's instruction (e.g. ERP, utility billing, procurement, HRIS or accounting systems).

3.4 Personal data within Customer Content

Customer Content is not intended to contain sensitive personal data. It may nonetheless include the names, business contact details, roles and signatures of employees, vendor representatives, auditors and approvers; site or facility contacts; and, in health-and-safety or human-rights disclosure contexts, aggregated workforce statistics.

Customers must not upload special category / sensitive personal data (including health data, biometric data, data revealing racial or ethnic origin, religious or philosophical beliefs, trade union membership, sexual orientation, or financial account data) to the Platform except where expressly agreed with us in writing and covered by appropriate safeguards under the DPA.

3.5 Children's data

The Platform is designed exclusively for professional and enterprise use and is not directed to children. We do not knowingly collect personal data of children. Under the DPDP Act, a "child" is an individual below eighteen (18) years of age; under the GDPR, thresholds vary by Member State between 13 and 16 years. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If we become aware that we have collected a child's personal data without verifiable consent of a parent or lawful guardian, we will delete it promptly.

4. PURPOSES OF PROCESSING AND LEGAL BASIS

Under the GDPR we must identify a lawful basis for each purpose. Under the DPDP Act, processing is undertaken either on the basis of your consent or for a legitimate use permitted by Section 7 of that Act (including where you have voluntarily provided your data for a specified purpose, or for employment-related purposes).

#PurposeGDPR Legal BasisDPDP Act Basis
1Creating and administering your account; authenticating usersArt. 6(1)(b) — performance of a contractConsent / Certain legitimate use (voluntary provision)
2Delivering the GHG inventory, vendor assessment and framework reporting modulesArt. 6(1)(b) — contractConsent / Certain legitimate use
3Processing subscriptions, invoicing, payments and collectionsArt. 6(1)(b) — contract; Art. 6(1)(c) — legal obligationConsent; compliance with law
4Providing customer support and responding to enquiriesArt. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interestsConsent / Certain legitimate use
5Securing the Platform, preventing fraud, abuse and unauthorised access; maintaining audit trailsArt. 6(1)(f) — legitimate interests in information security; Art. 6(1)(c)Certain legitimate use; compliance with law
6Monitoring performance, diagnosing faults, and improving and developing the PlatformArt. 6(1)(f) — legitimate interests in improving our servicesConsent
7Sending service, security and administrative noticesArt. 6(1)(b) — contract; Art. 6(1)(f)Certain legitimate use
8Direct marketing of related ESG and software services to business contactsArt. 6(1)(f) — legitimate interests, or Art. 6(1)(a) — consent where requiredConsent
9Complying with tax, accounting, corporate, export-control and sanctions obligationsArt. 6(1)(c) — legal obligationCompliance with law
10Establishing, exercising or defending legal claims; responding to lawful requestsArt. 6(1)(f) — legitimate interests; Art. 6(1)(c)Compliance with law; legal proceedings
11Producing aggregated and de-identified benchmarking, emission-factor and sector-trend analyticsArt. 6(1)(f) — legitimate interests (output contains no personal data)Consent (as applicable)
12Corporate transactions (merger, acquisition, restructuring, financing)Art. 6(1)(f) — legitimate interestsCertain legitimate use

Where we rely on legitimate interests, we have carried out a balancing assessment to confirm our interests are not overridden by your rights and freedoms. You may request a summary of that assessment using the contact details in Section 15.

Where we rely on consent, you may withdraw it at any time, with the same ease with which it was given, without affecting the lawfulness of processing carried out before withdrawal. Withdrawal may mean we can no longer provide certain features. We do not use deceptive design patterns to obtain or retain consent.

5. AUTOMATED PROCESSING AND SCORING

The Platform performs automated calculations and scoring, including:

  • conversion of activity data into GHG emissions using published emission factors and global warming potentials (e.g. IPCC AR5/AR6, DEFRA, EPA, IEA, CEA India);
  • automated scoring, risk-banding and flagging of vendor ESG assessment responses;
  • completeness, consistency and gap checks against framework disclosure requirements.

These outputs are decision-support tools produced for and controlled by our customer. AMMRS does not make automated decisions producing legal or similarly significant effects concerning you within the meaning of Article 22 GDPR. Where a customer uses vendor scores to make procurement or onboarding decisions, that customer is the Controller of that decision and is responsible for providing human review, explanation and any required safeguards.

Where any AI or machine-learning assisted feature is enabled, outputs are advisory, may contain errors, and must be reviewed by a competent person before reliance. We do not use Customer Content to train publicly available or third-party general-purpose AI models.

6. DISCLOSURE OF PERSONAL DATA

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We disclose personal data only as follows:

  • (a) Within your organisation. Administrators of your subscribing organisation can access, export, modify and delete data within their tenant, including records associated with your user account.
  • (b) Counterparties in vendor assessments. Where you respond to an ESG assessment, your responses, submitted evidence and identifying details are shared with the requesting organisation — that is the purpose of the module.
  • (c) Sub-processors and service providers. We engage vetted third parties under written contracts imposing GDPR Article 28 obligations (and equivalent DPDP obligations), including:
    CategoryPurpose
    Cloud infrastructure and hostingApplication and database hosting, storage, backup
    Email and notification deliveryTransactional and service emails
    Payment processingSubscription billing and settlement
    Support ticketing and helpdeskManaging service requests
    Product analytics and error monitoringDiagnostics, performance and stability
    Identity and authenticationSSO, MFA, directory integration
    Emission factor and ESG data providersReference datasets and factor libraries
    Professional advisersLegal, audit, accounting and insurance

    A current list of sub-processors is available on request from the contact in Section 15, and enterprise customers may subscribe to advance notice of changes.

  • (d) Legal and regulatory disclosure. We may disclose personal data where required by applicable law, court order, or a lawful request by a competent public authority, and where necessary to protect our rights, safety, property, or those of our users or the public. Where legally permitted, we will notify the affected customer before disclosing Customer Content.
  • (e) Corporate transactions. In connection with a merger, acquisition, reorganisation, financing or sale of assets, subject to the recipient being bound by protections no less protective than this Policy.

7. INTERNATIONAL DATA TRANSFERS

AMMRS is established in India. Personal data may be processed in India and in other jurisdictions where our sub-processors operate. Data may therefore be transferred outside the European Economic Area, the United Kingdom, or your country of residence.

Transfers out of the EEA/UK. Where we transfer personal data from the EEA or UK to a country not benefiting from an adequacy decision, we rely on appropriate safeguards under Chapter V GDPR, principally the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) and, for UK transfers, the UK International Data Transfer Addendum or IDTA, supplemented where necessary by a transfer impact assessment and additional technical measures including encryption in transit and at rest, access controls and pseudonymisation.

Transfers out of India. Under Section 16 of the DPDP Act, we may transfer personal data outside India except to territories notified as restricted by the Central Government. We monitor such notifications and will suspend affected transfers if required.

Data residency. Where a customer requires data residency in a particular region, this may be available under an enterprise agreement. Contact us to discuss.

Copies of the safeguards we rely upon are available on request.

8. DATA RETENTION

We retain personal data only for as long as necessary for the purposes set out in this Policy, or as required by law.

Data categoryIndicative retention period
Active account and profile dataFor the duration of the subscription
Customer Content (tenant data)For the subscription term; then 30 days for export, followed by deletion within a further 60 days unless the customer instructs otherwise
Billing, invoicing and tax records8 years from the end of the relevant financial year (Indian statutory requirement); longer where local law requires
Security, access and audit logs12 months, or longer where required for an ongoing investigation or assurance engagement
Support tickets and correspondence3 years from closure
Marketing contacts and consent recordsUntil consent is withdrawn or after 24 months of inactivity, whichever is earlier; consent withdrawal records retained as proof of compliance
BackupsRolling 35-day cycle; deleted records are purged from backups on expiry of that cycle
Records relating to a legal claim or disputeUntil the claim is fully resolved and applicable limitation periods have expired

Where continued retention is no longer necessary and no legal obligation requires it, we securely erase or irreversibly anonymise the data. Anonymised and aggregated data that cannot identify an individual may be retained indefinitely.

9. SECURITY MEASURES

We implement appropriate technical and organisational measures under Article 32 GDPR and Section 8(5) of the DPDP Act, including:

  • encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256);
  • role-based access control, least-privilege provisioning and tenant isolation;
  • multi-factor authentication and support for enterprise SSO;
  • hashed and salted credential storage;
  • comprehensive audit logging of access, modification and export events;
  • network segmentation, firewalling and intrusion detection;
  • regular vulnerability scanning, patch management and periodic penetration testing;
  • encrypted, geographically redundant backups with documented restoration testing;
  • background-verified personnel bound by confidentiality obligations and trained in data protection;
  • a documented incident response plan, change management process and business continuity plan;
  • contractual security obligations flowed down to all sub-processors.

No system is completely secure. You are responsible for safeguarding your credentials, using strong unique passwords, enabling MFA where available, and notifying us immediately of any suspected compromise.

9.1 Personal data breach notification

Where a personal data breach occurs, we will:

  • notify the competent supervisory authority within 72 hours of becoming aware, where the breach is likely to result in a risk to the rights and freedoms of individuals (Article 33 GDPR);
  • notify affected individuals without undue delay where the breach is likely to result in a high risk to them (Article 34 GDPR);
  • notify the Data Protection Board of India and each affected Data Principal as required by Section 8(6) of the DPDP Act and the rules thereunder;
  • notify affected customers without undue delay where we act as Processor, so that they can meet their own notification obligations.

10. COOKIES AND SIMILAR TECHNOLOGIES

We use the following categories:

  • Strictly necessary cookies — authentication, session management, load balancing, security and CSRF protection. These cannot be disabled without breaking the Platform, and are set on the basis of our legitimate interests / necessity for the service.
  • Functional cookies — remembering language, time zone, module and display preferences.
  • Analytics and performance cookies — understanding aggregate feature usage, diagnosing errors and improving performance.
  • Marketing cookies — used only on our public website, and only with your consent.

Where required by the ePrivacy Directive and national implementing laws, we obtain prior consent for all non-essential cookies through our cookie banner, and you may change or withdraw your preferences at any time via the cookie settings link. You may also configure your browser to refuse cookies, though this may impair Platform functionality. We honour Global Privacy Control signals where technically feasible.

11. YOUR RIGHTS

11.1 Rights under the GDPR / UK GDPR

Subject to the conditions and exemptions in the applicable legislation, you have the right to:

  • Access — obtain confirmation of whether we process your personal data and a copy of it;
  • Rectification — have inaccurate data corrected and incomplete data completed;
  • Erasure — have your data deleted where one of the grounds in Article 17 applies;
  • Restriction — have processing restricted in the circumstances set out in Article 18;
  • Data portability — receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller;
  • Object — object at any time to processing based on legitimate interests, and to object to direct marketing at any time, absolutely and free of charge;
  • Not be subject to solely automated decision-making producing legal or similarly significant effects;
  • Withdraw consent at any time where processing is based on consent;
  • Lodge a complaint with a supervisory authority (see Section 13).

11.2 Rights under the DPDP Act, 2023 (India)

As a Data Principal, you have the right to:

  • Access information about the personal data we process, the processing activities undertaken, and the identities of all other Data Fiduciaries and Processors with whom it has been shared (Section 11);
  • Correction, completion, updating and erasure of your personal data (Section 12);
  • Grievance redressal — a readily available means of registering a grievance with us, which we must respond to within the prescribed period (Section 13);
  • Nominate another individual to exercise your rights in the event of your death or incapacity (Section 14).

You also have duties under Section 15 of the DPDP Act, including not impersonating another person, not suppressing material information, not registering false or frivolous grievances, and furnishing only authentic and verifiably accurate information.

11.3 Exercising your rights

  • Submit a request to kunael.aneja@ammrs.co.in with the subject line "Data Protection Request — Sustainity™", stating the right you wish to exercise and providing sufficient information for us to identify you.
  • We will respond within one (1) month under the GDPR, extendable by a further two months for complex or numerous requests, in which case we will inform you within the first month.
  • We will respond to DPDP grievances within the period prescribed under the DPDP Act and rules, and in any event without undue delay.
  • Requests are handled free of charge, unless manifestly unfounded, excessive or repetitive, in which case we may charge a reasonable fee or refuse the request, giving reasons.
  • We may request additional information to verify your identity before acting. This is a security measure and the information is used only for verification.
  • If your request relates to Customer Content, we will forward it to the relevant customer (Controller / Data Fiduciary) without undue delay and support their response.

12. CONSENT NOTICE UNDER THE DPDP ACT

Where we process your personal data on the basis of consent under the DPDP Act, this Policy, together with any consent request presented to you, constitutes the notice required by Section 5 of the DPDP Act and informs you of:

  • the personal data proposed to be processed and the specified purpose of processing;
  • the manner in which you may exercise your rights under Sections 12 and 13 of the DPDP Act;
  • the manner in which you may make a complaint to the Data Protection Board of India.

Your consent is limited to such personal data as is necessary for the specified purpose. Any part of a consent that infringes the DPDP Act or its rules is invalid to the extent of such infringement. On request, this notice is available in English and in any language specified in the Eighth Schedule to the Constitution of India.

13. COMPLAINTS AND SUPERVISORY AUTHORITIES

If you are dissatisfied with our handling of your personal data, please contact us first using the details in Section 15 so we can attempt to resolve the matter.

You retain the right to complain to a supervisory authority:

  • European Economic Area: the data protection authority of the EU Member State of your habitual residence, place of work, or the place of the alleged infringement. A list is maintained by the European Data Protection Board at edpb.europa.eu.
  • United Kingdom: the Information Commissioner's Office (ICO), ico.org.uk.
  • India: the Data Protection Board of India, constituted under the DPDP Act, 2023, after first exhausting our grievance redressal mechanism as required by Section 13(3) of that Act.

14. THIRD-PARTY LINKS AND INTEGRATIONS

The Platform may contain links to, or integrations with, third-party websites, applications and services (including emission factor databases, regulatory portals, ERP systems and identity providers). We are not responsible for the privacy practices or content of those third parties. Where you enable an integration, personal data may flow to that third party under its own privacy policy, which you should review. Enabling an integration is your organisation's decision and instruction to us.

15. CONTACT DETAILS

Data Protection Contact / Grievance Officer

For all privacy queries, rights requests and grievances under the DPDP Act and the GDPR:

NameKunael Aneja
DesignationGrievance Officer & Data Protection Contact
EntityAMMRS Software Solutions and ESG Consulting LLP (LLPIN: ACK-3975)
Emailkunael.aneja@ammrs.co.in
Telephone+91 7302277302
AddressSurat, Gujarat, India
Websitehttps://ammrs.in

EU / UK Representative

Where we are required to appoint a representative under Article 27 GDPR or the UK GDPR in respect of processing relating to individuals in the EEA or the UK, details of our appointed representative are available on request from the address above and will be published on our website.

16. CHANGES TO THIS POLICY

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements or the Platform. The "Last Updated" date at the top indicates when the Policy was last revised.

Where changes are material, we will provide at least thirty (30) days' prior notice by email to account administrators and by a prominent in-Platform notice before the change takes effect. Where a change requires your consent under applicable law, we will obtain it. Continued use of the Platform after the effective date of a change constitutes acceptance of the revised Policy, except where consent is required.

Previous versions of this Policy are available on request.

17. GOVERNING LAW

This Policy is governed by the laws of India, without prejudice to any mandatory rights or protections available to you under the GDPR, the UK GDPR, or other data protection laws applicable in your jurisdiction of residence.

Chat with us! 💬