Privacy policy
How we handle personal data on ghgbook.com. This policy applies to the public website only. Privacy matters relating to the GHG Book application and customer data are governed by the applicable Customer Agreement, Data Processing Agreement and any applicable application privacy notice.
At a glance
- One thing is collected by you choosing to give it: your work email address, if you ask for early access.
- No advertising or profiling cookies. None, from anyone. We do not run ad networks, pixels or trackers.
- Analytics are off until you say yes, and they are cookieless and aggregated even then.
- We do not sell personal data or share it with third parties for their own advertising purposes.
- You can change your mind at any time from in the footer.
1. Who we are
GHG Book is a product of Laymansoft India Pvt Ltd, which is the data controller (GDPR) and data fiduciary (DPDP Act) for the personal data described in this policy.
- Entity
- Laymansoft India Pvt Ltd
- Registered address
- New Delhi, India
- Privacy contact
- privacy@ghgbook.com
We have not appointed a Data Protection Officer at this time. Based on the processing described in this policy, we currently consider that Article 37 GDPR does not require us to appoint one. We will reassess this position as our processing activities develop. Privacy questions, requests and complaints all go to the address above and reach a person who can act on them.
2. What we collect and why
The categories below describe the personal data we intentionally collect or instruct our service providers to process through the public website. Service providers may also process limited technical information as necessary to provide hosting, security and form-delivery services.
| What | Why | Basis | Kept for |
|---|---|---|---|
| Work email address | To reply to an early-access request and, if you want it, to tell you when we launch. | Consent | Until you withdraw, or 24 months of no contact |
| Page views, referrer, country, device class, load timings | To see which pages are useful and whether the site is fast enough. | Consent | Aggregated by our analytics provider; no raw identifiers reach us |
| Server request logs, including IP address | To serve the page at all, and to detect abuse and attacks. | Legitimate interests | Short-lived, held by our hosting provider |
| Your privacy choice | We store your privacy choice locally so the site can remember whether you have consented to analytics. | Preference management | Stored in your own browser until you clear it |
We do not ask for, and have no use for, special-category data: health, biometrics, political or religious views, or anything comparable. Please do not send it to us.
3. Our lawful basis
Under GDPR Article 6 we rely on:
- Consent, Art. 6(1)(a), for the early-access list and for analytics. Consent is a free choice here: declining costs you nothing, and every part of the site works either way.
- Legitimate interests, Art. 6(1)(f), for keeping the site available and secure. Our interest is running a service that is not knocked over or defaced; the processing is limited to what a web server needs to answer a request, and we judged that it does not override your rights. Ask us and we will send you the assessment.
Providing your email is entirely optional. There is no contract or statute that requires it, and nothing is withheld from you if you would rather not.
6. International transfers
We are established in India, and the processors above are established in the United States. If you are in the European Economic Area or the United Kingdom, your data is therefore transferred outside it.
Those transfers rely on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies, together with appropriate technical and organisational measures. Write to privacy@ghgbook.com and we will send you a copy of the clauses with commercial terms redacted.
India's DPDP Act permits transfer outside India except to countries the Central Government restricts by notification. We monitor that list and will update this policy if it changes what we are able to do.
7. How long we keep it
- Early-access email: until you ask us to remove it, or after 24 months with no contact from you, whichever comes first. Then it is deleted, not archived.
- Consent record: in your browser, under your control. Clearing site data removes it, and the banner will ask again.
- Server request logs are retained by our hosting provider for a limited period necessary for security, abuse prevention and diagnostics, after which they are deleted or automatically expire.
8. How we protect it
For this website specifically:
- Everything is served over TLS, with HTTP Strict Transport Security so a browser will not fall back to an unencrypted connection.
- A Content Security Policy restricts what the page may load and connect to, which is what stops an injected script from running or exfiltrating anything.
- Fonts and scripts are served from our own origin. The page makes no third-party request until you have allowed one.
- The page cannot be framed by another site, so it cannot be used for clickjacking.
- Access to the early-access inbox is limited to the people who need it, and protected by multi-factor authentication.
If we become aware of a personal-data breach affecting your information, we will assess and respond to it in accordance with applicable law and our contractual obligations.
Security for the GHG Book application itself, which handles customer emissions data, is a much larger subject and is set out in our contracts and security documentation.
9. Your rights
If the GDPR or UK GDPR applies to you, you have the right to:
- Access the personal data we hold about you, and get a copy.
- Rectify anything inaccurate or incomplete.
- Erase it, in the circumstances Article 17 sets out.
- Restrict or object to processing, including anything we do on legitimate interests.
- Port your data to another controller in a machine-readable form.
- Withdraw consent at any time, without affecting what was lawful before you withdrew it.
Write to privacy@ghgbook.com. We answer within one month, and we will not charge you for it. We may ask you to confirm who you are, but only enough to be sure we are not handing your data to someone else.
We take no automated decisions that produce legal or similarly significant effects, so Article 22 does not arise.
If we get it wrong, you may contact us first so that we can try to resolve your concern, but you also have the right to lodge a complaint directly with the supervisory authority in your country.
10. India: notice under the DPDP Act
The Act and the rules under it are being brought into force in phases, so not every obligation is operative yet. This section provides the information required under the Digital Personal Data Protection Act, 2023 and its rules, to the extent the relevant provisions are currently in force, and describes how we intend to meet the remaining requirements as they commence. We will update it as further provisions and rules take effect.
- The personal data: your email address, if you submit the early-access form; and, if you allow it, aggregated analytics about your visit. Both are itemised in section 2.
- The purpose: to respond to your request and tell you about the launch; and to understand which pages are useful.
- How to withdraw consent: open for analytics, or email privacy@ghgbook.com to be removed from the early-access list. It is as easy to withdraw as it was to give, and we will not make you justify it.
- How to exercise your rights: the same address. Subject to the provisions in force, these include the right to access a summary of your data, to have it corrected or erased, and to nominate another person to exercise these rights if you die or become incapacitated.
- How to complain: write to us at privacy@ghgbook.com. You may also complain to the Data Protection Board of India in accordance with the Act, once the relevant provisions are in force.
Grievance redressal. Grievances reach us at privacy@ghgbook.com, addressed to the Grievance Officer, Laymansoft India Pvt Ltd, New Delhi, India. We aim to respond promptly, and within any period prescribed under the Act once that requirement commences.
We do not currently consider ourselves a Significant Data Fiduciary. If we are notified as one, or if our processing changes such that the classification applies, this policy will change with it and we will name the officers the Act then requires.
11. Children
The website is intended for business and professional users and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has sent us personal data, tell us and we will delete it.
12. Changes to this policy
When we change this policy we update the version and dates at the top. If a change affects what we do with data you have already given us, we will ask again rather than assume the old answer still stands, and the consent banner will reappear.
13. Contact us
- Privacy and data protection
- privacy@ghgbook.com
- Grievance officer (DPDP Act s.13)
- privacy@ghgbook.com
- Postal
- Laymansoft India Pvt Ltd, New Delhi, India