Privacy Policy
Effective Date: August 2026
1. Who We Are
Veridian Climate Pulse (“Veridian,” “we,” “us,” or “our”) operates a data analytics platform at http://18.222.214.164/ (the “Service”), which collects, processes, and analyzes climate-related data and provides analytics products and insights to users and clients.
We are the data controller for personal information collected directly through the Service, except where we act as a data processor on behalf of a client (see Section 4).
Contact: Veridian Climate Pulse (Veridian Intelligence Group) Email: climateinfo@18.222.214.164
2. Scope of This Policy
This policy covers personal information we collect through the Service, including:
- Our website and account portal
- Our APIs and data ingestion endpoints
- Tracking pixels, SDKs, or other data-collection tools embedded in third-party sites or applications on our behalf
It does not cover information processed solely on behalf of a client under a separate data processing agreement, where that client determines the purposes and means of processing. In that case, the client’s own privacy policy governs, and we act only as a processor.
3. Information We Collect
3.1 Default Data Categories We Process
By default, in the ordinary course of operating the Service, we process the following categories of personal information:
- Identity and contact data — name, email address, organization, job title.
- Account and authentication data — login credentials, account settings, access logs.
- Billing data — payment method details (held by our payment processor, not by us directly), billing address, transaction history.
- Technical and usage data — IP address, device identifiers, browser type, cookies, log data, dashboard usage.
- Climate and environmental data submitted to the platform — sensor readings, geographic coordinates, station or facility identifiers, and associated metadata. This category is not personal information unless it is linked to an identifiable individual (for example, a named field technician or facility contact).
We do not, by default, process special category data (such as health data, biometric data, or government identification numbers). Special category data is processed only when a specific client dataset requires it under a documented Data Processing Agreement with additional safeguards, as described in Section 3.4.
3.2 Information You Provide Directly
- Name, email address, and organization when you create an account, request a demo, or contact us.
- Billing and payment information (processed by our payment provider; see Section 8).
- Content of support requests, comments, or messages you send us.
- Files, datasets, or media you upload to the Service.
3.3 Information Collected Automatically
- IP address, device identifiers, browser type, and operating system.
- Log data: pages visited, timestamps, referring URLs, and actions taken within the Service.
- Cookies and similar technologies (see Section 6).
- Usage and performance data related to our analytics tools and dashboards.
3.4 Data Collected for Analytics Purposes
As a data analytics service, we collect, aggregate, and process data — including data about individuals when it is embedded in datasets we analyze — for the purpose of generating climate-related insights, reports, and analytics products. Where this data includes personal information, we process it:
- Under the legal bases described in Section 5 when we act as controller, or
- Under the terms of our Data Processing Agreement with the client when we act as processor.
3.5 Information We Do Not Knowingly Collect
We do not knowingly collect government identification numbers, health information, or other special category data unless a client dataset requires it under a specific, documented agreement with appropriate safeguards (including, where applicable, explicit consent and a Data Protection Impact Assessment).
4. Our Role: Controller vs. Processor
| Role | Description |
| Controller | We determine why and how we process personal information collected directly from Service visitors, account holders, and website users (Sections 3.2 and 3.3). |
| Processor | When clients supply datasets for analysis that include personal information, we process that data only according to the client’s instructions and our Data Processing Agreement with them. Individuals whose data appears in client datasets should direct privacy requests to that client; we will assist the client in responding as required by law. |
5. Legal Basis for Processing (GDPR / UK GDPR)
Where the UK/EU GDPR applies, we rely on the following legal bases:
| Purpose | Legal Basis |
| Operating your account and providing the Service | Performance of a contract |
| Analytics, product improvement, security monitoring | Legitimate interests (see balancing test below) |
| Marketing communications | Consent (withdrawable at any time) |
| Compliance with law, responding to legal process | Legal obligation |
| Processing client datasets containing personal data | Performance of our contract with the client, per their instructions |
Legitimate Interests Balancing Test When we rely on legitimate interests, we have conducted a balancing test to ensure our interests — including security, fraud prevention, and product improvement — do not override your fundamental rights and freedoms. You have the right to object to this processing at any time by contacting us at climateinfo@18.222.214.164.
6. Cookies and Tracking Technologies
We use the following categories of cookies and similar technologies:
| Category | Purpose | Retention |
| Strictly necessary | Login, security, and core functionality. Cannot be disabled without affecting the Service. | Session / up to 2 days |
| Analytics / Performance | Measure usage of the Service (Google Analytics and Mixpanel). | Up to 26 months |
| Functional | Remember preferences such as display settings. | Up to 12 months |
| Marketing / Targeting | Used only with your explicit consent. | Up to 12 months, or until consent is withdrawn |
You can manage cookie preferences through our cookie banner or your browser settings. Disabling non-essential cookies will not affect your ability to use core account features.
7. How We Use Your Information
We use personal information to:
- Provide, maintain, and improve the Service.
- Process transactions and manage accounts.
- Generate analytics products and reports (in aggregated or de-identified form wherever feasible).
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Communicate with you about your account or, with consent, about products and updates.
- Comply with legal obligations.
We do not use personal information for purposes incompatible with those listed above without providing notice and, where required, obtaining consent.
8. Who We Share Data With
We share personal information only as follows:
| Recipient Category | Purpose | Details |
| Hosting Provider | Cloud infrastructure | Amazon Web Services (AWS) — US-East (Virginia) and EU (Ireland) regions |
| Payment Processor | Billing and subscription payments | Stripe, Inc. |
| Email / Communications | Transactional and marketing emails | SendGrid (Twilio Inc.) |
| Analytics Tooling | Product usage measurement | Google Analytics and Mixpanel (IP anonymization enabled) |
| Spam / Abuse Detection | Security monitoring | Akismet (Automattic Inc.) |
| Clients | Where we act as processor for datasets they submit | Per Data Processing Agreement terms |
| Legal and Safety Disclosures | Where required by law, subpoena, or court order | Or to protect the rights, property, or safety of Veridian, our users, or the public |
| Business Transfers | Merger, acquisition, or asset sale | Affected users will be notified |
Subprocessors We maintain a current list of all subprocessors at http://18.222.214.164/subprocessors. We will notify clients of any new subprocessors and provide an opportunity to object before they are engaged.
We do not sell personal information, and we do not share personal information with third parties for their own independent marketing purposes.
9. International Data Transfers
We may transfer personal information to countries outside your own, including the United States and Ireland (where our infrastructure and key vendors are located).
Where we transfer personal data out of the EU/UK, we rely on:
- The European Commission’s Standard Contractual Clauses (SCCs) (or the UK International Data Transfer Agreement / Addendum),
- Supplementary technical measures including encryption in transit and at rest, access controls, and regular security assessments, and
- Contractual commitments from our vendors to provide an essentially equivalent level of protection.
You may request a copy of the applicable transfer safeguards by contacting us at climateinfo@18.222.214.164.
10. Data Retention
| Data Category | Retention Period |
| Account data | For the life of your account, and up to 5 years afterward for legal, tax, or security purposes |
| Support and communication records | Up to 5 years |
| Log and security data | Up to 12 months, then deleted or aggregated |
| Client-submitted datasets | Per the terms of the applicable Data Processing Agreement; deleted or returned upon contract termination unless law requires longer retention |
| Cookie data | Per the retention periods in Section 6 |
| De-identified / aggregated analytics | Indefinitely (no longer personal information) |
We do not retain personal information indefinitely by default. Any exception is documented and tied to a specific legal or operational requirement.
11. Data Protection Impact Assessments (DPIAs)
For processing that is likely to result in a high risk to individuals — including, where applicable, processing of special category data or large-scale client datasets — we conduct Data Protection Impact Assessments to identify and mitigate risks before processing begins.
12. Your Rights
Depending on your location, you may have the right to:
| Right | Description |
| Access | Obtain confirmation of whether we process your personal data and request a copy |
| Correction | Correct inaccurate or incomplete information |
| Deletion | Request deletion (“right to be forgotten”) |
| Objection / Restriction | Object to or restrict certain processing (including processing based on legitimate interests) |
| Portability | Request a portable copy of your data in a structured, machine-readable format |
| Withdraw Consent | Withdraw consent at any time, where processing is based on consent |
| Lodge a Complaint | File a complaint with your local data protection authority |
California Residents (CCPA/CPRA) You have the right to:
- Know what personal information we collect, use, disclose, and sell or share.
- Delete personal information we hold about you.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information.
We do not sell or share personal information as defined by the CCPA. To exercise your rights, submit a verifiable consumer request to climateinfo@18.222.214.164.
EU/UK Residents (GDPR) You have the right to lodge a complaint with your local data protection authority (e.g., the ICO in the UK or your national supervisory authority).
Response Timeframe We will respond to all privacy requests within 30 days. If we cannot respond within that timeframe, we will notify you within the initial 30-day period and explain the reason for the delay.
13. Global Privacy Control (GPC)
We honor Global Privacy Control (GPC) signals. If you use a browser, browser extension, or device setting that sends a GPC signal, we will treat that as a valid opt-out request regarding the sale or sharing of personal information.
14. “Do Not Sell or Share” Link
A “Do Not Sell or Share My Personal Information” link is available in the footer of every page of our website, providing a direct mechanism for California residents to exercise their opt-out rights.
15. Data Security
We apply administrative, technical, and organizational safeguards appropriate to the sensitivity of the data we hold, including:
- Encryption in transit (TLS 1.2/1.3) and at rest (AES-256).
- Access controls (role-based, least-privilege, multi-factor authentication).
- Regular security reviews, vulnerability scanning, and penetration testing.
- Incident response procedures for data breaches.
No system is completely secure, and we cannot guarantee absolute protection against unauthorized access.
Data Breach Notification In the event of a data breach affecting your personal information, we will notify:
- Affected individuals without undue delay where there is a high risk to their rights and freedoms, and
- Relevant supervisory authorities within 72 hours where required by applicable law (GDPR Article 33).
16. Privacy by Design
We incorporate privacy by design and by default into our systems and product development lifecycle. This includes:
- Data minimization — collecting only what is necessary.
- Purpose limitation — using data only for specified, explicit purposes.
- Pseudonymization and aggregation wherever feasible.
- Privacy risk assessments for all new features and processing activities.
17. Automated Decision-Making
Our analytics products may generate automated insights or scores based on submitted data. We do not use automated processing to make decisions that produce legal or similarly significant effects on individuals without human review, unless otherwise disclosed in a specific client agreement.
18. Data Processing Agreements (DPAs)
We enter into Data Processing Agreements with all clients who submit datasets for analysis. Our standard DPA incorporates the EU Standard Contractual Clauses (SCCs) and includes commitments to:
- Process data only on documented instructions.
- Assist with data subject rights requests.
- Maintain appropriate security measures.
- Notify clients of security incidents.
- Engage subprocessors only with prior notice and an opportunity to object.
A copy of our standard DPA is available upon request at climateinfo@18.222.214.164.
19. Children’s Privacy
The Service is not directed to children:
- Under 13 (consistent with COPPA in the United States)
- Under 16 (consistent with GDPR in the EU/UK)
We do not knowingly collect personal information from children under these age thresholds. If we learn that we have collected personal information from a child in violation of this policy, we will delete it promptly.
Parents or guardians who believe their child has provided us with personal information should contact us at climateinfo@18.222.214.164.
20. Changes to This Policy
We will update the Effective Date at the top of this policy whenever we make changes.
For material changes affecting how we use previously collected personal information, we will provide notice through the Service or by email before the changes take effect.
We encourage you to review this policy periodically for the latest information about our privacy practices.
21. Contact Us
| Purpose | Contact |
| Privacy inquiries, rights requests, and general questions | climateinfo@18.222.214.164 |
| Website | http://18.222.214.164/ |