LIVE
ETS€75.36/tPHASE-IN 20262.5%SURRENDER30 SEP 2027CERT PURCHASE OPENS1 FEB 2027Reg (EU) 2023/956ACTIVEIR (EU) 2025/2621ACTIVEIR (EU) 2025/2620ACTIVEReg (EU) 2025/2083ACTIVEXSDMONITOREDSECTORS IN SCOPE6

Legal · Carbon Mandate Ltd

Terms, privacy, cookies & disclaimer.

The operative legal documents governing your use of the Platform and our Services.

01 · Terms & Conditions

Governing terms of service.

02 · Privacy Policy

UK GDPR & EU GDPR compliance.

1. Data Controller

The data controller for the purposes of the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and the Data Protection Act 2018 is:

Carbon Mandate Ltd (Reg 17288007)

Registered Office: 3rd Floor, 45 Albemarle Street, Mayfair, London, W1S 4JL, GB

Email: info [at] carbonmandate [dot] com

Phone: +44 20 3918 3500

2. Scope of This Policy

This Privacy Policy applies to all personal data processed by Carbon Mandate in connection with our website (carbonmandate.com), the secure Client Vault portal, and the delivery of our preparation services. This policy is directed exclusively at business-to-business (B2B) relationships. We do not knowingly collect or process personal data from individual consumers.

3. Categories of Personal Data Collected

In the course of our business operations, we may collect and process the following categories of personal data:

  • Professional contact information: corporate email addresses, business telephone numbers, job titles, and organisational affiliations of client officers and authorised representatives.
  • Industrial facility data: installation-level emissions data, production volumes, energy consumption figures, and MRV documentation submitted by or on behalf of clients for the purposes of CBAM compliance.
  • Engagement records: correspondence, service requests, enquiry submissions, and records of preparation interactions.
  • Technical data: IP addresses, browser type, and device information collected automatically when accessing the Platform, and authentication credentials for the Client Vault portal.
  • Financial data: invoicing details and payment records as required for the administration of engagements.

4. Purposes of Processing and Legal Basis

We process personal data for the following purposes, relying on the legal bases indicated:

  • Performance of a contract (Article 6(1)(b) UK/EU GDPR): Processing data necessary for the delivery of our Services, including MRV data extraction, liability quantification, and CBAM declaration preparation.
  • Legitimate interests (Article 6(1)(f) UK/EU GDPR): Processing data for business development, service improvement, security monitoring, and fraud prevention, where such processing does not override the fundamental rights and freedoms of the data subject.
  • Legal obligation (Article 6(1)(c) UK/EU GDPR): Processing data where necessary for compliance with applicable legal or regulatory obligations, including tax, anti-money laundering, and corporate record-keeping requirements.
  • Consent (Article 6(1)(a) UK/EU GDPR): Where applicable, processing analytical cookies or marketing communications with the explicit consent of the data subject.

5. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected:

  • Client engagement records: retained for seven (7) years from the conclusion of the engagement, in accordance with professional and regulatory obligations.
  • MRV and facility data: retained for the duration of the CBAM compliance period to which it relates, plus an additional five (5) years for audit and compliance purposes.
  • Enquiry requests and prospect data: retained for twenty-four (24) months from the date of submission, unless an engagement is commenced.
  • Technical and cookie data: retained in accordance with the periods specified in our Cookie Policy.

Upon expiry of the applicable retention period, personal data is securely deleted or anonymised.

6. Data Sharing and Transfers

We do not sell personal data to third parties. We may share personal data with:

  • Sub-processors: cloud infrastructure providers (Supabase, Vercel), email service providers (Resend), and security services (Cloudflare) engaged under appropriate data processing agreements.
  • Professional advisers: legal, accounting, and audit advisers, subject to professional confidentiality obligations.
  • Regulatory authorities: where required by law, regulation, or order of a competent authority.

Where personal data is transferred outside the United Kingdom or European Economic Area, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or adequacy decisions, in accordance with Chapter V of the UK/EU GDPR.

7. Rights of Data Subjects

Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:

  • Right of access (Article 15) — the right to obtain confirmation of whether your data is being processed and to request a copy.
  • Right to rectification (Article 16) — the right to request correction of inaccurate or incomplete data.
  • Right to erasure (Article 17) — the right to request deletion of your data, subject to applicable legal retention obligations.
  • Right to restriction of processing (Article 18) — the right to request that processing be restricted in certain circumstances.
  • Right to data portability (Article 20) — the right to receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Article 21) — the right to object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent — where processing is based on consent, the right to withdraw at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at info [at] carbonmandate [dot] com. We will respond within one (1) calendar month.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or, for EU data subjects, with the relevant supervisory authority in your Member State.

8. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest, role-based access controls, and regular security assessments. The audit log on which all administrative actions are recorded is stored under an immutable trigger that prevents update or deletion of historical events.

Effective date: 25 June 2026

03 · Cookie Policy

Cookie usage & preferences.

1. What Are Cookies

Cookies are small text files stored on your device when you access a website. They serve various functions, including enabling essential features, remembering preferences, and collecting analytical data to improve user experience.

2. Strictly Necessary Cookies

These cookies are essential for the operation of the Platform and cannot be disabled. They include:

  • Client Vault authentication: session cookies required to maintain your authenticated state within the secure Client Vault portal.
  • Security cookies: set by Cloudflare Turnstile to verify user authenticity and prevent automated abuse of our forms.
  • CSRF protection: cookies used to prevent cross-site request forgery attacks on form submissions.

3. Analytical Cookies

With your consent, we may use analytical cookies to understand how visitors interact with the Platform. These cookies collect aggregated, anonymised data and do not identify individual users. We do not currently deploy third-party analytics trackers. Should this change, we will update this policy and seek your explicit consent before setting any analytical cookies.

4. Third-Party Cookies

Our Platform relies on the following third-party services that may set cookies:

  • Authentication and session provider: cookies required to maintain authenticated state within the Client Vault portal.
  • Security verification provider: cookies set to verify user authenticity and prevent automated abuse of form submissions.
  • Hosting and performance provider: performance-related cookies set by our hosting infrastructure.

We do not use advertising cookies, social media tracking pixels, or remarketing technologies.

5. Managing Your Cookie Preferences

You can manage cookie preferences through your browser settings. Most browsers allow you to view and delete existing cookies, block cookies from specific or all websites, and set preferences for first-party and third-party cookies separately. Disabling strictly necessary cookies may impair the functionality of the Client Vault portal and form submissions.

For instructions on managing cookies in your specific browser, consult your browser’s help documentation or visit allaboutcookies.org.

Effective date: 25 June 2026

04 · Disclaimer

Important notice regarding information provided.

No legal or financial advice

The information contained on this website and in any materials or communications published by Carbon Mandate Ltd is provided for general informational and educational purposes only. It does not constitute, and shall not be construed as, formal legal advice, financial advice, accounting advice, or any other form of professional advice upon which you should rely.

Scope of service

Carbon Mandate provides preparation services in the field of EU CBAM compliance. While our analysis is grounded in our interpretation of applicable EU and UK regulations, it does not replace the need for independent legal, tax, or accounting counsel qualified in the relevant jurisdiction.

No client-adviser relationship is formed by your access to this website or by the submission of an enquiry. A formal engagement exists only upon the execution of a written engagement letter or service agreement between Carbon Mandate Ltd and the client entity.

Past performance

Any case studies, performance metrics, outcome descriptions, or client references published on this website are provided for illustrative purposes only. Past performance, results, and savings achieved for previous clients do not guarantee or predict future outcomes. Each engagement is subject to its own factual circumstances, regulatory environment, and data quality.

Regulatory changes

The EU Carbon Border Adjustment Mechanism, the EU Emissions Trading System, and related regulatory frameworks are subject to ongoing legislative amendment, implementing regulation, and judicial interpretation. Carbon Mandate does not warrant that the information on this website reflects the current state of applicable law at the time of your access. We endeavour to update our content regularly but accept no liability for inaccuracies arising from regulatory changes occurring after publication.

Acceptance of risk

By accessing and using this website, you acknowledge and agree that you do so at your own risk, and that Carbon Mandate Ltd, its directors, officers, and employees shall not be liable for any loss or damage arising from your reliance on any information published herein.

Effective date: 25 June 2026

Carbon Mandate Ltd · 3rd Floor, 45 Albemarle Street, Mayfair, London, W1S 4JL, GB · Reg 17288007
info [at] carbonmandate [dot] com · +44 20 3918 3500