Privacy Policy

NATURALEDGER LTD · Registered in England and Wales · Company number 16837102 · 20 Wenlock Road, London, England, N1 7GU

1. Introduction and Data Controller

NaturaLedger is the trading name of NATURALEDGER LTD, registered in England and Wales, Company No. 16837102, with its registered office at 20 Wenlock Road, London, England, N1 7GU ("NaturaLedger", "we", "us" or "our").

We are a UK-based ClimateTech and AI company supporting carbon project assessment and development. This Policy explains how we handle personal information when operating our corporate website, communicating with people, recruiting and providing our services. Where we determine why and how personal information is processed, NATURALEDGER LTD is its data controller.

We process personal information in accordance with applicable law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, as amended, including relevant changes introduced by the Data (Use and Access) Act 2025 as they take effect. The EU GDPR and other privacy laws may also apply, depending on the circumstances. This Policy is a transparency notice, not a request for blanket consent. Browsing our website does not constitute consent to personal-data processing.

2. Scope of This Policy

This Policy covers personal information relating to website visitors; business contacts; prospective and existing customers and their authorised users; Pioneer applicants; job applicants; and individuals whose information is included in carbon project materials.

It distinguishes our own controller activities from processing we undertake on a customer's instructions. Where we act as a processor for a customer, the customer's privacy information and applicable contractual processing terms govern that relationship. This Policy does not replace a Data Processing Agreement (DPA).

Separate notices or agreed terms may provide additional information for a particular service or activity. Third-party websites and services operate under their own privacy notices.

3. Personal Information We Collect

Depending on your interaction with us, personal information may include:

  • Identity and business contact information: name, business email address, telephone number, organisation, role and correspondence.
  • Account and service information: registration information, authorised-user details, access records, service requests and communications about contracted work.
  • Contact and Pioneer application information: the details you enter in enquiries or applications, including your organisation, project interests and supporting material.
  • Recruitment information: application details, CV, qualifications, employment history, correspondence and interview or assessment information. References or eligibility information may be requested where relevant to recruitment.
  • Project-related information: documents, maps, location or boundary information, photographs, field records and stakeholder details, to the extent these identify individuals. Environmental or geographical data is not necessarily personal information, but can become so when linked to a person, landholding or household.
  • Transaction information: orders, invoices, billing contacts and payment status. Where a payment provider collects card information directly, we do not need complete card details to administer the transaction.
  • Technical information: information made available through website or service requests, such as IP address, browser and device information, request timestamps and security or error records; and analytics information described in section 9.

We receive information directly from you, from authorised customer representatives, and where relevant from project stakeholders, referees or publicly available professional sources. Where information is obtained indirectly, applicable transparency requirements still apply, subject to lawful exceptions.

Please provide only information needed for the relevant request or service. Do not include sensitive personal information in general enquiries. Where special category information or criminal-offence information is genuinely necessary, an applicable additional legal condition and appropriate safeguards are required; an ordinary business enquiry does not authorise unrestricted processing of such information.

4. How and Why We Use Personal Information

The table below explains the purposes and the legal bases that may apply. The appropriate basis depends on the activity and our relationship with the individual; the bases are not interchangeable.

We do not use one activity's legal basis as blanket authority for unrelated purposes. Where a new purpose requires a new legal basis or additional notice, it must be addressed before the new processing takes place.

6. AI-Assisted Services and Data Processing

Our services may use AI-assisted preliminary feasibility and analysis to support Forest and Biochar assessment workflows and methodology-oriented documentation. Relevant project inputs and instructions may be processed by technical service providers supporting AI functionality, as well as through our own service workflows.

Inputs can contain personal or confidential information. Customers and users should minimise such information and submit only what is necessary and authorised. AI processing must be governed by applicable data protection requirements and contractual arrangements, including appropriate arrangements with relevant providers. We do not represent that all AI processing occurs in the UK, that providers receive no data, that all inputs are fully anonymised, or that every provider operates with zero retention.

This Policy does not give us permission to train general-purpose AI models on confidential customer project information. Any such use would require appropriate separate contractual authorisation, a lawful basis for any personal-data processing and transparent disclosure of the proposed use. The same principle applies to unrelated reuse of confidential customer material.

AI-assisted outputs can be incomplete or inaccurate. Where personal information is used in automated processing that falls within applicable automated decision-making rules, the relevant legal requirements and safeguards apply. You may ask about such processing and exercise applicable rights described in section 13; this Policy does not assert that no solely automated decisions ever occur across all services.

7. Customer and Carbon Project Data

Customers retain ownership of their submitted project information and documents, subject to third-party rights. Ownership does not determine whether material is personal information or who is its controller.

For customer-instructed processing, applicable processing terms should address instructions, confidentiality, security, subprocessors, assistance with rights and breaches, international transfers, and return or deletion of information. Publication of this Policy does not establish that a DPA has already been signed.

Where we separately process customer representative details for our own account administration, invoicing, security or legal compliance, we act as controller for those purposes. We assess that role by the actual processing activity, not simply by labelling all customer information as processor data.

Project owners should ensure they are authorised to provide stakeholder information and that affected individuals receive required privacy information. Project information is not made public merely by submission to NaturaLedger. Sharing for a registry, verification process or other external project purpose must follow the relevant instructions, agreed scope and applicable law.

8. Sharing Personal Information

Information may be disclosed, where necessary and lawful, to:

  • Technical and operational providers supporting hosting, service delivery, AI functionality, communications, analytics or payments.
  • Authorised customer users and project participants involved in the relevant service, within the customer's instructions and agreed scope.
  • Professional advisers, including legal and accounting advisers, where needed for their work.
  • Regulators, courts, public authorities or other recipients where legally required, or where lawful and necessary to establish, exercise or defend legal rights.
  • Parties involved in a proposed business restructuring or transfer, where appropriate safeguards, confidentiality and applicable legal requirements are observed.

The recipient's role and required contractual protections depend on the activity: a processor operates on appropriate instructions, whereas an independent controller is responsible for its own lawful processing. We do not describe all recipients as processors or imply every disclosure requires consent.

9. Analytics, Cookies and Similar Technologies

The current corporate website uses Plausible Analytics, a service designed to provide website usage statistics without analytics tracking cookies. Under our current implementation, Plausible pageviews and tracked interactions activate only after a visitor selects Accept in the analytics notice. Selecting Decline, or dismissing the notice without accepting, does not authorise analytics tracking.

Analytics can include the page address, referrer and broad device or geographic information, along with tracked website interactions. Our pageview implementation omits URL query parameters. Information about successful form submission may be recorded as an event; this does not require sending the form's message or CV as analytics content.

A preference record is stored in your browser's local storage to remember whether you accepted or declined. Local storage is not an analytics tracking cookie. The present preference check asks again after 365 days; this is a preference validity period, not a claim about Plausible's data retention.

To change a previously stored choice, clear this website's stored site data through your browser settings, reload the website and select your preferred option when the notice appears. Clearing site data may also remove other saved settings or sign you out of services. Declining does not remove statistics already lawfully collected. You may also contact us about withdrawal of consent or other privacy rights.

Different contracted platform services may require storage for authentication or other essential functions. Relevant service-specific information applies to those functions.

10. International Data Transfers

International access to or transfers of personal information may be necessary to deliver services, work with technical providers or support projects in other countries. Data protection laws in the destination may differ from those in the UK.

Where a transfer is restricted under UK law, it requires an applicable lawful mechanism. Depending on the circumstances, this can include applicable UK adequacy regulations or appropriate safeguards, such as an approved UK International Data Transfer Agreement or the UK Addendum to relevant EU Standard Contractual Clauses, together with the assessment and any supplementary measures required by applicable law. Statutory exceptions are available only where their conditions are met, not as a routine substitute for safeguards.

Relevant changes introduced by the Data (Use and Access) Act 2025, including the applicable transfer assessment requirements as brought into force, must be taken into account. Where EU GDPR transfer rules apply, they must be addressed separately. This description identifies possible legal mechanisms; it does not confirm that a particular provider, destination or contract has been approved. You may contact us for information about safeguards applicable to your information, including a copy where available, subject to appropriate redactions.

Continued website use is not consent to an international transfer.

11. Information Security

We are responsible for applying technical and organisational measures appropriate to the risk of the processing, taking account of the information, processing context and available technology. Measures must be proportionate to the relevant systems and activities and may address access controls, secure transmission, vulnerability management, recovery and incident handling.

No website, communication channel or storage system can be guaranteed secure. Where a personal-data breach occurs, applicable notification and response requirements apply, including notification to authorities and affected individuals where legally required.

Please protect your credentials and notify us if you suspect unauthorised access or accidental disclosure involving our services.

12. Data Retention

Personal information should be kept only for as long as reasonably necessary for the relevant purposes and applicable obligations. Retention depends on the type of information, the service or request, the duration of the relationship, agreed processing instructions, accounting or legal requirements, security and operational needs, and any dispute or legal hold.

Recruitment records are assessed by reference to the recruitment process, relevant legal obligations and the justification for any further retention. An application does not grant indefinite permission to retain a CV for unrelated future recruitment.

When information is no longer required, appropriate deletion or anonymisation should follow, taking account of backup cycles and lawful retention requirements. This Policy does not promise immediate removal from every backup or prescribe unverified fixed retention periods. You may ask for information about the retention criteria applicable to your records.

13. Individual Privacy Rights

Under the UK GDPR, subject to the applicable conditions and exceptions, you may have the right to:

  • Access: obtain confirmation of processing and a copy of your personal information, with related information.
  • Rectification: correct inaccurate information and complete incomplete information.
  • Erasure: request deletion where the legal conditions are met.
  • Restriction: limit processing in specified circumstances.
  • Portability: receive and transmit information you provided where processing is automated and based on consent or a contract.
  • Object: object to processing based on legitimate interests on grounds relating to your particular situation.
  • Withdraw consent: withdraw consent to consent-based processing at any time.
  • Automated decision-making safeguards: exercise rights applicable to qualifying solely automated decisions with legal or similarly significant effects, including obtaining information, making representations, requesting human intervention and contesting a decision where required by applicable law.

You have the right to object to processing for direct marketing at any time, including related profiling. Where you object to direct marketing, your information must no longer be processed for that purpose. For other legitimate-interest processing, continued processing may be permitted where the applicable legal conditions are met.

Send requests using the contact information in section 18. We may need information reasonably necessary to verify identity or clarify the request. Requests are generally free; any lawful fee or refusal must meet the applicable statutory conditions. We respond within the applicable legal timescale—normally one month under the UK GDPR, subject to lawful extensions and applicable rules on identity checks or clarification. This is not a universal 30-day promise for every jurisdiction.

Where we act as processor, we may refer the request to the relevant customer controller and assist as required. Other laws may provide additional or different rights.

14. Recruitment and Careers Applications

Recruitment information is used to assess applications, communicate with candidates and administer the recruitment process, using the bases described in section 4. Only include information relevant to your application. Do not include unnecessary identity documents, sensitive information or details about other people without an appropriate reason.

Any request for special category information, criminal records or eligibility checks requires its own applicable justification and safeguards. We do not treat submitting a CV as consent to marketing or unrelated commercial use. If we propose to retain your details for future opportunities beyond the current process, the basis and relevant information must be explained. Successful applicants may receive separate employment privacy information.

15. Children's Privacy

Our corporate website and B2B services are not directed at children. Children should not create business accounts or submit personal information through business or recruitment forms. If you believe a child has provided information inappropriately, contact us so that the circumstances and any necessary action can be assessed.

Project materials can relate to households or communities that include children. Such information must not be treated as ordinary business-account data: any processing requires particular care, an appropriate lawful basis and applicable safeguards.

16. Third-Party Websites

Links to publishers, standards organisations, registries or other websites do not make NaturaLedger responsible for their separate privacy practices. Review the relevant third party's notice before providing information to it. Our own responsibilities for disclosures we make remain governed by applicable law.

17. Changes to This Policy

We may revise this Policy to reflect changes in processing, services or law. The published version will show its last-updated and effective dates. Where material changes require further notice, we will provide it by an appropriate method. A revised notice does not itself authorise a new purpose, replace required consent or retrospectively amend an individually signed agreement.

18. Contact and Complaints

For privacy enquiries, rights requests or complaints, write to:

NATURALEDGER LTD
Trading as NaturaLedger
Registered in England and Wales
Company No. 16837102
Registered office: 20 Wenlock Road, London, England, N1 7GU

You may raise a concern with us first, but this is not a condition of complaining to a regulator. You have the right to complain to the UK Information Commissioner's Office at https://ico.org.uk/. Where another country's privacy law applies, you may also have the right to complain to the relevant supervisory authority.

For the contractual terms governing our website and services, see https://www.naturaledger.com/terms.