This policy covers anyone who visits emissionmetrics.in, holds an account as an owner or member of a client company on the EmissionMetrics platform ("Service"), or receives and responds to a value-chain partner data-request link sent by one of our client companies.
1. Who we are
EmissionMetrics is operated by Ranjeet Kishan, based in Bengaluru, Karnataka, India. EmissionMetrics currently operates as a sole proprietorship; conversion to a One Person Company (OPC) is in progress, and this section will be updated with the registered entity name and CIN once incorporation is complete. Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), EmissionMetrics acts as the Data Fiduciary for the personal data described below.
2. What personal data we collect
- Account holders (company owners/members): name, work email address, and password, stored as a salted hash by our authentication provider — never in plain text — plus your role within your company's workspace.
- Login & security metadata: IP address and browser/device information, captured only to notify us of sign-ins for account-security monitoring — never used for advertising or profiling.
- Value-chain partners: if a client company sends a data-request link to one of its suppliers or partners, that partner's email address is entered by the client company, not by us. When the partner opens the link we receive whatever KPI values, notes, and evidence files they choose to submit. These links expire automatically 30 days after being sent.
- Evidence file uploads: any file a user or partner attaches as supporting evidence (e.g. a utility bill or waste manifest). These are meant to be business records; if a file incidentally includes personal data, we protect it under this policy the same way.
- Contact-form & enquiry submissions: name, company name, work email, phone number (optional), and whatever you tell us in your message.
- Billing contacts: name and email used for manual invoicing (bank transfer / UPI). We don't operate a payment gateway and never collect or store card numbers.
We don't collect special-category or sensitive personal data (health, biometric, financial-account numbers, etc.) as part of the Service, and ask that you avoid including this in evidence uploads or KPI notes unless it's strictly necessary for your own compliance record-keeping.
3. Why we collect it
- Account data → to create and secure your login, identify your company's workspace, and let you and your teammates use the dashboard.
- Login metadata → account-security monitoring, e.g. detecting an unfamiliar sign-in.
- Partner data → to let a client company request, and its partner submit, BRSR Core / value-chain sustainability KPIs directly into a report, without the partner needing an account.
- Evidence files → to give a BRSR Core report and export an audit trail, consistent with SEBI's assurance requirements.
- Contact-form data → to reply to your enquiry.
- Billing contact data → to send invoices and manage your subscription.
We don't use any of this data to build advertising profiles, and we don't sell personal data to anyone.
4. Consent and legal basis
Creating an account, and a company owner sending a partner a data-request link, are both treated as affirmative consent to the processing described in this policy for that purpose. A value-chain partner who opens a data-request link and voluntarily submits KPI values or evidence is treated as providing that data for the specified purpose stated on that page — consistent with the DPDP Act's provision for personal data voluntarily provided by an individual for a specified purpose. You can withdraw consent at any time by contacting us (Section 10) — for account holders this means closing your account; for partners it means asking your requesting company, or us directly, to delete your submitted response.
5. Who we share data with
We use a small number of service providers to run the Service, and we don't sell, rent, or trade personal data to anyone else:
- Supabase — our database and authentication provider; stores account, company, and partner-submission data.
- Vercel — hosts and serves the application and website.
- Resend — sends transactional emails (partner data-request links, login/security notifications, password resets).
These providers process data only as needed to run the Service. If you're evaluating EmissionMetrics for your own compliance purposes and need more detail on our processors, contact us.
6. Where data is processed
Vercel and Resend are US-headquartered services, so parts of the pipeline — page delivery, transactional email sending — may process data on servers located outside India. Our database is hosted via Supabase, in a region we configure. We take reasonable steps to keep your data secure regardless of where it's processed, consistent with the DPDP Act's requirements for transfers outside India.
7. How long we keep it
- Account and company data: for as long as your account is active, plus a reasonable period afterward for any final billing or legal requirements, unless you ask us to delete it sooner.
- Value-chain partner data-request links: expire automatically 30 days after being sent; a partner's submitted responses are retained as part of the requesting company's report data for as long as that account is active.
- Contact-form enquiries: kept only as long as needed to respond, plus a reasonable follow-up period.
- Billing records: retained as required for tax/accounting purposes under Indian law.
On a verified deletion request, we delete or anonymize personal data within a reasonable period, including from routine backups on their normal rotation.
8. Security
- Every company's data is isolated using Postgres Row-Level Security, enforced at the database layer — not just in application code — so one client can never query another's data.
- All traffic to the Service is encrypted in transit (HTTPS).
- Passwords are never stored in plain text.
- Administrative access to client data is restricted to a small, explicitly allowlisted set of platform-admin accounts, for support purposes only.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we'll notify affected users and the Data Protection Board of India as required by law.
9. Your rights, and how to exercise them
Under the DPDP Act, you (as a "Data Principal") have the right to:
- Access a summary of the personal data we hold about you and how it's being processed.
- Correct or update inaccurate or incomplete personal data.
- Erase personal data that's no longer needed for the purpose it was collected for.
- Withdraw consent at any time (Section 4).
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Register a complaint about how we've handled your personal data.
To exercise any of these rights, contact us at contact@emissionmetrics.in — this inbox also serves as our grievance-redressal contact under the DPDP Act. We aim to respond within 30 days. If you're not satisfied with our response, you may escalate your complaint to the Data Protection Board of India.
10. Cookies
We use only the strictly-necessary session cookies set by our authentication provider to keep you signed in securely. We don't use advertising, analytics, or third-party tracking cookies on the Service.
11. Children's data
The Service is intended for business use by adults acting on behalf of a company and isn't directed at, or knowingly used by, anyone under 18. If we become aware that we've collected personal data from a minor without appropriate consent, we'll delete it.
12. Changes to this policy
We'll update the "last reviewed" date in the site footer whenever we make a material change to this policy, and, where required, notify account holders directly.
13. Contact us
Email
contact@emissionmetrics.in
Based in
Bengaluru, Karnataka