Política de privacidad

Last updated: 31 August 2026

1. About this Privacy Policy

This Privacy Policy explains how EcoCitizenz Ltd, trading as EcoCitizenz ("EcoCitizenz", "we", "us" or "our"), collects, uses, stores, shares and protects personal information when you use or interact with our websites, online store, TrustOps services, ECZ-ID products, Resolver, applications, developer tools, APIs, authentication services, support services, automated or agentic interfaces and related systems.

This Privacy Policy is intended to apply across the EcoCitizenz and ECZ-ID ecosystem unless a particular product or service has a more specific privacy notice. Where a product-specific notice applies, it supplements this Privacy Policy and will explain any material differences.

We aim to collect and use only the information reasonably required to provide, secure and administer our services.

This Privacy Policy should be read together with our Terms of Service and any product-specific terms that apply to the service you use.


2. Data Controller and Contact Details

The data controller is:

EcoCitizenz Ltd
Trading as EcoCitizenz
Company number: 17348848
Registered office:
66 Paul Street
London
EC2A 4NA
United Kingdom

Privacy and support email:

support@ecocitizenz.com

For privacy questions, data-protection requests or complaints, please contact us using the email address above.


3. Services Covered by this Policy

This Privacy Policy applies, where relevant, to:

(a) EcoCitizenz websites and web applications;

(b) the EcoCitizenz online store and commerce services;

(c) TrustOps and associated customer-account services;

(d) ECZ-ID Business Passports and other ECZ-ID identity products;

(e) ECZ-ID Declared, Verified and Assured services;

(f) the ECZ-ID Resolver and other public verification surfaces;

(g) developer, agent, MCP, API, marketplace and machine-facing services;

(h) authentication and account-linking services;

(i) subscription, activation, entitlement and lifecycle services;

(j) support, qualification and onboarding services;

(k) automated, AI-assisted and agentic interaction channels; and

(l) associated security, monitoring, evidence and operational systems.

Different products may process different subsets of the information described below.


4. Personal Information We May Collect

4.1 Identity and Contact Information

Depending on how you interact with us, we may collect:

(a) your name;

(b) business, organisation or trading name;

(c) job title, position or role;

(d) email address;

(e) billing or service address;

(f) telephone or other contact information where provided;

(g) country, jurisdiction or location information relevant to a service; and

(h) other identity or contact information you choose to provide.


4.2 Account and Authentication Information

We may process information needed to create, authenticate, secure and administer an account, including:

(a) internal account identifiers;

(b) login and authentication records;

(c) authentication method;

(d) account status;

(e) organisation memberships;

(f) permissions and access roles;

(g) security and account-recovery information;

(h) login timestamps and security events;

(i) authentication challenges and one-time codes;

(j) session information; and

(k) information required to prevent unauthorised access, replay, impersonation or account takeover.

Passwords, where used, are intended to be stored using appropriate one-way password hashing rather than as readable passwords.


5. Federated Sign-In and Identity Provider Information

We may allow you to sign in to EcoCitizenz or TrustOps using a third-party identity provider such as:

Google, Microsoft, GitHub, or an approved enterprise OpenID Connect provider.

When you choose a federated sign-in method, the identity provider may send us information necessary to authenticate you.

Depending on the provider and configuration, this may include:

(a) a stable provider account identifier;

(b) issuer or tenant information;

(c) email address;

(d) whether an email address has been verified by that provider;

(e) name or display name;

(f) profile image or basic profile information; and

(g) technical authentication information required to complete the sign-in.

We use the provider's stable account identifier, together with the provider or issuer, as the principal basis for recognising a federated identity.

We do not treat an email address alone as proof that two accounts belong to the same person or organisation.

If two authentication providers return the same email address but we cannot safely establish that they belong to the same existing account, we may require an explicit account-linking or recovery process instead of automatically combining the accounts.

This is intended to reduce the risk of account takeover, mistaken identity or unauthorised access to an organisation or ECZ-ID.


6. Google Sign-In and Google User Data

Where you choose Sign in with Google, EcoCitizenz uses Google OAuth/OpenID Connect for authentication.

For ordinary Google sign-in, we request only the basic identity scopes required for authentication:

openid
userinfo.email
userinfo.profile

Depending on Google's response, this may allow us to receive:

(a) your Google account's stable subject identifier;

(b) your email address;

(c) whether Google reports the email as verified;

(d) your name or display name;

(e) basic profile information, such as a profile image; and

(f) authentication metadata necessary to establish the sign-in.

What we use Google user data for

Google user data received through this sign-in process is used only as reasonably necessary to:

(a) authenticate you;

(b) create or recognise your private EcoCitizenz or TrustOps account;

(c) protect your account against unauthorised access;

(d) maintain your chosen authentication method;

(e) support explicit account linking;

(f) establish your permitted organisation memberships;

(g) provide the EcoCitizenz or ECZ-ID services you request;

(h) investigate security, fraud or account-recovery issues; and

(i) comply with applicable legal obligations.

What Google sign-in does not give us access to

Using Google to sign in to EcoCitizenz does not give EcoCitizenz general access to your:

Gmail messages;
Google Drive files;
Google Calendar;
Google Contacts;
Google Photos;
Google Cloud resources;
billing information; or
Google Workspace administration.

We do not request those permissions as part of ordinary Google authentication.

We do not receive your Google password.

Google user data and advertising

We do not use Google sign-in data obtained through these authentication scopes to access unrelated Google services or for unrelated behavioural advertising.

Google user data and account ownership

A Google account, Google email address or successful Google authentication proves control of that Google account at the time of authentication.

It does not, by itself, prove:

(a) legal ownership of a business;

(b) control of an existing ECZ-ID;

(c) authority to act for an organisation;

(d) Verified or Assured ECZ-ID status; or

(e) entitlement to modify another person's or organisation's ECZ-ID.

Additional account, membership, authority or verification checks may therefore be required.

Google API Services User Data Policy

Our use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including applicable Limited Use requirements.

We limit our use of Google user data to the purposes disclosed in this Privacy Policy and the functionality the user has requested.


7. Microsoft, GitHub and Enterprise Identity Providers

Where Microsoft authentication is enabled, we may process the account, issuer, tenant and basic identity information required to authenticate the user.

Where GitHub authentication is enabled, we may process the stable GitHub account identity and basic account or verified/contact email information required for authentication.

Where Enterprise OpenID Connect is enabled for a customer, the relevant identity is normally distinguished using the combination of the approved issuer and the provider's stable subject identifier.

We do not treat email addresses from different providers as interchangeable identity credentials.

Additional provider-specific terms and privacy notices may also apply to the processing performed independently by those providers.


8. Email Possession and One-Time Authentication

Where email-based authentication or account recovery is offered, we may process:

(a) your email address;

(b) one-time verification challenges or codes;

(c) challenge creation and expiry times;

(d) attempt counts;

(e) security and rate-limit information; and

(f) confirmation that possession of the email address has been demonstrated.

Email possession proves access to an email account at that time.

It does not, by itself, establish legal identity, ownership of a business, authority over an existing ECZ-ID, or Verified or Assured status.

One-time authentication codes are designed to expire after a short period and cannot be reused once successfully consumed.


9. Order, Billing and Subscription Information

Where you buy or subscribe to a product or service, we may process:

(a) products or services selected;

(b) order numbers;

(c) subscription tier;

(d) billing period;

(e) order and payment status;

(f) cancellation, refund and renewal information;

(g) transaction references;

(h) discounts or promotional information;

(i) product entitlement information; and

(j) information required to administer or fulfil the contract.

We do not ordinarily receive or store complete payment-card details.

Payments are generally processed by Shopify, payment processors or other authorised commerce providers.

Those providers may process payment information independently under their own privacy notices and contractual terms.


10. Business, Organisation, Agent and Service Information

Depending on the service, we may process information concerning:

(a) a business or organisation;

(b) a principal, operator or authorised representative;

(c) an AI agent or automated system;

(d) an MCP server or other technical service;

(e) an API, software product or platform integration;

(f) a counterparty or supplier;

(g) authority, ownership, control or relationship information;

(h) configuration and binding information;

(i) information submitted for activation, review or verification;

(j) product eligibility and parent-tier information;

(k) service lifecycle information;

(l) evidence or supporting documentation; and

(m) current service or identity state.

Some information relating to businesses or technical systems may not be personal information. This Privacy Policy applies to such information only to the extent that it identifies or relates to an identifiable individual.


11. ECZ-ID, TrustOps and Organisation Membership

An authenticated user account is not automatically equivalent to an ECZ-ID or to authority over an organisation.

Where relevant, TrustOps may maintain private records establishing that a particular authenticated account has an authorised membership or role within a particular organisation.

These records may be used to determine whether a user is permitted to perform an action involving that organisation or its ECZ-ID.

We may distinguish between roles such as owner, administrator or member.

Authentication, payment or possession of an email address does not by itself confer a higher ECZ-ID assurance level.

A free or self-declared ECZ-ID remains Declared unless and until a separate legitimate verification or assurance process changes its state.


12. Public Verification and the ECZ-ID Resolver

Some ECZ-ID information is intended to be publicly verifiable.

Depending on the ECZ-ID product and state, public information may include:

(a) an ECZ-ID identifier;

(b) subject, business or organisation name;

(c) ECZ-ID tier or assurance state;

(d) product, passport or scope information;

(e) current lifecycle or operational status;

(f) effective dates;

(g) expiry, renewal or re-check information;

(h) public reason or state codes;

(i) public authority or relationship information where appropriate;

(j) public verification references;

(k) badges, QR verification or machine-readable verification information; and

(l) information required to distinguish current state from superseded or revoked state.

The Resolver is intended to provide verification of authoritative public state, not to expose private account information.

We do not intend public verification surfaces to display:

(a) account passwords;

(b) private authentication tokens;

(c) private provider subject identifiers;

(d) raw payment-card details;

(e) unnecessary private evidence;

(f) private account recovery information; or

(g) unnecessary personal contact information.

Where personal information is involved, we seek to limit public display to what is reasonably necessary for the relevant verification purpose.

Public state may change following correction, expiry, cancellation, refund, failed renewal, suspension, revocation, supersession, restoration or another legitimate lifecycle event.

Historical references may be retained where necessary to preserve integrity, provenance, fraud prevention and auditability.


13. Communications and Support Information

We may process:

(a) emails;

(b) support requests;

(c) feedback;

(d) complaints;

(e) activation or troubleshooting information;

(f) security reports;

(g) account-recovery communications; and

(h) records of communications with us.

We may retain relevant correspondence where necessary to provide support, protect accounts, administer contracts, resolve disputes or establish an audit trail.


14. Technical, Security and Usage Information

When you use our websites, applications or services, we or our service providers may process:

(a) IP address;

(b) browser information;

(c) device information;

(d) operating system;

(e) timestamps;

(f) requested pages or endpoints;

(g) referring pages;

(h) cookie and consent choices;

(i) authentication events;

(j) diagnostic and performance information;

(k) security, fraud-prevention and abuse signals;

(l) error information; and

(m) audit and operational logs.

We seek to avoid collecting unnecessary technical information and may use aggregation, pseudonymisation or short retention periods where appropriate.


15. AI, Agentic and Automated Interaction Information

You may interact with EcoCitizenz through an AI assistant, agent, marketplace, automated purchasing service or another machine-mediated channel.

Where this occurs, we may receive information such as:

(a) requested product or service;

(b) order or acquisition instructions;

(c) referral or source information;

(d) machine or marketplace context;

(e) technical metadata;

(f) a short-lived handoff token or reference;

(g) information necessary to continue the user's requested journey; and

(h) other information the channel is authorised to transmit.

A machine or marketplace handoff does not, by itself, prove identity, ownership, authority, payment, verification status or entitlement.

The third-party AI, marketplace or platform may independently process information under its own terms and privacy notice.


16. How We Collect Personal Information

We may collect information:

(a) directly from you;

(b) from a person, organisation or authorised representative acting for you;

(c) when you create or authenticate an account;

(d) when you use a federated sign-in provider;

(e) when you place an order or subscribe;

(f) when you contact support;

(g) through Shopify, payment providers and commerce systems;

(h) from our websites, applications, APIs, security systems and logs;

(i) from public registers or public sources where lawful and relevant;

(j) from service providers supporting our operations;

(k) from authorised business or organisation administrators;

(l) through machine, agentic or marketplace handoffs; and

(m) from systems involved in activation, entitlement, verification, lifecycle management and public verification.


17. How We Use Personal Information

We may use personal information to:

(a) operate our websites and services;

(b) create, secure and administer accounts;

(c) authenticate users;

(d) link authentication providers where explicitly authorised;

(e) establish organisation memberships and permitted roles;

(f) provide ECZ-ID and TrustOps services;

(g) create or maintain ECZ-ID records where authorised;

(h) process orders, subscriptions, billing, cancellations and refunds;

(i) administer product entitlement;

(j) assess product eligibility and tier requirements;

(k) complete activation, configuration or binding;

(l) operate Resolver and verification services;

(m) maintain current lifecycle state;

(n) provide support;

(o) prevent fraud, abuse, impersonation and unauthorised access;

(p) investigate security incidents;

(q) maintain appropriate evidence, transaction and audit records;

(r) monitor and improve reliability, usability and performance;

(s) enforce our terms and policies;

(t) comply with legal, tax, accounting, regulatory and lawful-disclosure requirements;

(u) establish, exercise or defend legal claims;

(v) send important service, security, account, billing and policy information; and

(w) send marketing communications where permitted.

We do not use authentication by itself to grant an ECZ-ID assurance level that the authentication method does not prove.


18. Lawful Bases for Processing

Where the UK GDPR applies, we rely on one or more lawful bases.

Contract

We may process personal information where necessary to enter into or perform a contract with you, including account administration, orders, service delivery, subscriptions, support, activation and lifecycle management.

Legal obligation

We may process personal information where necessary to comply with applicable legal obligations, including tax, accounting, fraud prevention, consumer protection, sanctions, regulatory and lawful disclosure requirements.

Legitimate interests

We may process personal information where necessary for our legitimate interests or those of another party, provided those interests are not overridden by your rights and interests.

Our legitimate interests may include:

(a) operating and improving our services;

(b) maintaining account and service security;

(c) preventing fraud, abuse and duplicate or unauthorised identity actions;

(d) maintaining accurate records;

(e) protecting ECZ-ID and Resolver integrity;

(f) supporting customers;

(g) managing and understanding service use;

(h) maintaining auditability;

(i) enforcing contractual rights; and

(j) establishing or defending legal claims.

Consent

We rely on consent where required, including for certain marketing activities, optional cookies or other optional processing.

You may withdraw consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.


19. Special Category, Criminal-Offence and Highly Sensitive Information

We do not intentionally request special-category personal information or criminal-offence information unless it is necessary, lawful and specifically identified as part of an approved process.

Unless we have expressly requested it through an appropriate secure process, please do not submit information about:

health;
racial or ethnic origin;
religious or philosophical beliefs;
political opinions;
trade-union membership;
genetic or biometric identification;
sexual life or sexual orientation;
criminal allegations or convictions; or
other highly sensitive matters.

Do not send us:

passwords;
private cryptographic keys;
seed phrases;
complete payment-card information; or
unrelated confidential information.


20. Automated Processing and Decision-Making

Some service checks, eligibility rules, security controls, fraud controls, routing decisions, lifecycle calculations and technical validations may be automated.

We do not intend to rely on solely automated decision-making that produces legal or similarly significant effects on an individual unless permitted by applicable law and appropriate safeguards are provided.

Where applicable, you may contact us to request information about, challenge, or request human review of a significant automated decision.


21. Sharing Personal Information

We may share personal information where reasonably necessary with:

(a) Shopify and associated commerce providers;

(b) payment processors and financial-service providers;

(c) cloud hosting, infrastructure, storage and database providers;

(d) identity and authentication providers;

(e) email and communications providers;

(f) security, monitoring, fraud-prevention and logging providers;

(g) support and operational service providers;

(h) appropriately vetted contractors or specialists;

(i) professional advisers, including lawyers, accountants and insurers;

(j) regulators, courts, law-enforcement bodies or public authorities where legally required or permitted;

(k) a genuine buyer, investor, financier or successor in connection with a restructuring, merger, acquisition or sale; and

(l) another party where you have instructed or authorised us to disclose the information.

Service providers acting on our behalf are expected to process information only for authorised purposes and subject to appropriate contractual and legal safeguards.

Some providers may act as independent controllers for certain processing, particularly payment providers and external identity providers.

We do not sell personal information for money.


22. Shopify, Payment Providers and External Platforms

Where you purchase through Shopify, Shopify and its payment or commerce partners may process your information independently under their own terms and privacy notices.

Where you authenticate through Google, Microsoft, GitHub or another identity provider, that provider processes the authentication interaction under its own terms and privacy notice.

Where you interact through ChatGPT, Microsoft Copilot, Shop or another AI, marketplace or agentic channel, that channel may independently collect and process your information.

EcoCitizenz is not responsible for processing carried out independently by those third parties.

You should review the relevant third party's privacy information before using its service.


23. International Transfers

Some of our service providers may process personal information outside the United Kingdom.

Where required by applicable data-protection law, we use an appropriate transfer mechanism or safeguard.

Depending on the circumstances, this may include:

(a) UK adequacy regulations;

(b) the UK International Data Transfer Agreement;

(c) the UK Addendum to approved contractual clauses;

(d) other approved contractual safeguards; or

(e) supplementary technical and organisational measures.

You may contact us for further information about safeguards relevant to your personal information.


24. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy and for applicable legal, accounting, contractual, security, audit and dispute-resolution requirements.

Typical periods or criteria include:

Orders, billing, contracts and tax records: normally up to six years after the end of the relevant relationship or financial period, unless a different period is required.

Account and authentication records: while the account is active and afterwards for a reasonable period where necessary for security, recovery, dispute resolution, fraud prevention or legal claims.

Provider identity links: while needed to support the account, provider relationship or security history, and afterwards where retention is reasonably required for fraud prevention, audit or legal claims.

Email-possession codes: short-lived verification codes expire after their stated validity period. Related security metadata may be retained longer where reasonably necessary for fraud and abuse prevention.

Subscription, activation and service records: while the service is active and normally for up to six years afterwards where required for contract administration, audit or legal claims.

Support communications: normally up to three years after the matter is closed unless longer retention is justified.

Technical and security logs: normally up to 12 months, or longer where necessary to investigate fraud, abuse, a security incident or a legal claim.

Marketing records: until you unsubscribe or withdraw consent, with a limited suppression record retained where necessary to respect your preference.

ECZ-ID Resolver and lifecycle records: for as long as reasonably necessary to preserve accurate current state, legitimate audit history, provenance, fraud prevention and the integrity of authoritative identity records.

We may retain information longer where required by law, litigation, investigation, security needs, regulatory requirements or another legitimate and documented reason.

We may anonymise information and retain it in a form that no longer identifies an individual.


25. Security

We use technical and organisational measures designed to protect personal information against unauthorised access, alteration, disclosure, loss, misuse and destruction.

Depending on the service, these measures may include:

(a) access controls;

(b) authentication;

(c) password hashing;

(d) encryption;

(e) short-lived authentication challenges;

(f) replay protection;

(g) separation of public and private information;

(h) role and membership checks;

(i) logging and monitoring;

(j) rate limiting and abuse prevention;

(k) backups and recovery controls;

(l) environment separation;

(m) data minimisation;

(n) security testing; and

(o) change and release controls.

No internet-connected service or information-storage system can be guaranteed to be completely secure.

You are responsible for protecting your devices, accounts, credentials and authentication methods.

Please notify us promptly at support@ecocitizenz.com if you believe an account or information has been compromised.


26. Cookies and Similar Technologies

We and our service providers may use cookies, local storage and similar technologies to:

(a) provide essential site and authentication functions;

(b) maintain secure sessions;

(c) remember preferences;

(d) operate checkout;

(e) prevent fraud;

(f) understand reliability and performance; and

(g) provide analytics or marketing where permitted.

Where required, non-essential cookies are used only after appropriate notice or consent.

You can manage cookies through any available cookie banner, privacy controls or browser settings.

Blocking essential authentication or security cookies may prevent parts of the service from working.


27. Marketing

We may send marketing communications where you have consented or where another lawful basis permits us to do so.

You can unsubscribe using the link provided in the communication or by contacting:

support@ecocitizenz.com

Opting out of marketing does not prevent us from sending necessary:

service;
security;
account;
billing;
renewal;
support; or
policy communications.


28. Your Data-Protection Rights

Depending on the circumstances and applicable law, you may have the right to:

(a) be informed about how your personal information is used;

(b) request access to personal information we hold about you;

(c) request correction of inaccurate or incomplete information;

(d) request deletion of personal information;

(e) request restriction of processing;

(f) object to processing based on legitimate interests;

(g) object to direct marketing;

(h) request data portability;

(i) withdraw consent;

(j) obtain safeguards concerning qualifying automated decision-making; and

(k) complain to a data-protection authority.

These rights are not absolute.

For example, we may need to retain information where necessary for:

legal compliance;
fraud prevention;
security;
contract administration;
legal claims;
auditability; or
the integrity of authoritative ECZ-ID records.

To exercise a right, email:

support@ecocitizenz.com

We may need to verify your identity before responding.

We normally respond within one month, subject to any lawful extension.


29. Disconnecting an Identity Provider and Account Deletion

You may stop using a third-party sign-in method at any time.

For providers such as Google, you may also be able to revoke EcoCitizenz's access through the privacy or security controls provided by that provider.

Revoking a provider's authentication access prevents future use of that authorisation as permitted by the provider, but it does not necessarily delete your EcoCitizenz account or records already lawfully retained by EcoCitizenz.

If you want to:

disconnect a provider;
request deletion of an account;
remove an account link; or
exercise a data-protection right,

contact:

support@ecocitizenz.com

Deletion requests remain subject to legitimate retention requirements described in this Privacy Policy.

Where an ECZ-ID contains public or historical lifecycle information, removing a private account does not necessarily require deletion of legitimate public or audit records if those records must be preserved for integrity, fraud prevention, legal obligations or accurate historical state.


30. Complaints

Please contact us first so that we can investigate and try to resolve your concern.

You also have the right to complain to the UK Information Commissioner's Office (ICO) where UK data-protection law applies.

Information about the ICO is available at:

https://ico.org.uk/

You may also have the right to contact another competent data-protection authority depending on where you live.


31. Children

Our services are intended primarily for adults, professionals and business users.

We do not knowingly offer EcoCitizenz accounts or paid ECZ-ID services directly to children under 18.

If you believe a child has provided personal information without appropriate authority, please contact:

support@ecocitizenz.com


32. Third-Party Links and Services

Our websites and services may contain links to third-party websites, applications or services.

Those parties may operate independently from EcoCitizenz.

We are not responsible for their independent privacy practices, security or content.

Please review the relevant third-party privacy notice before providing information to that service.


33. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect:

(a) changes to our products or services;

(b) new authentication or integration methods;

(c) changes in our processing activities;

(d) legal or regulatory developments;

(e) security or operational changes; or

(f) changes to service providers.

The current version will be published at:

https://www.ecocitizenz.com/policies/privacy-policy

The "Last updated" date at the top of this page identifies the current version.

Where appropriate, we will notify affected users of material changes.

If our use of Google user data changes materially, we will update this Privacy Policy and any associated in-product disclosures before using that data for the new purpose where required.


34. Contact

Questions, requests or complaints about privacy should be sent to:

EcoCitizenz Ltd
Trading as EcoCitizenz
Company number: 17348848

66 Paul Street
London
EC2A 4NA
United Kingdom

Email:

support@ecocitizenz.com