Legal · Version 1.0
Privacy Notice
This notice explains how the Green Energy Transition Tool collects, uses, shares, and protects personal data and port operational data, in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"). It applies to everyone who registers an account or uses the Tool.
1. Who is responsible for your data
The data controller is Klaipėda Science and Technology Park (KSTP), acting as lead partner for the Tool under the DigiTechPort2030 project, co-funded by the European Union through the Interreg South Baltic Programme.
For questions about this notice or to exercise any of the rights below, contact KSTP's data protection contact point at privacy@digitechport2030.eu (placeholder — KSTP to confirm the live contact address and, if appointed, a Data Protection Officer, before launch).
2. What data we collect
- Account data — email address, password (stored hashed by Supabase Auth), and optionally your name.
- Port & membership data — the port name, country, and which user accounts belong to that port.
- Operational questionnaire data — the fuel, energy, equipment, traffic, and infrastructure figures you submit about your port, used to calculate your baseline, Port Score, and scenarios.
- Usage & security logs — sign-in events, AI interpretation requests, exports you generate, and an audit trail of changes made to your account or your port's data.
We do not knowingly collect any special category data (Art. 9 GDPR) and ask that you do not submit any in free-text fields.
3. Why we process your data and the legal basis
- To provide the Tool — create your account, compute your emissions/energy/cost baseline, Port Score, and transition scenarios, and let you export results. Legal basis: your consent (Art. 6(1)(a)) and, once registered, performance of the service you requested (Art. 6(1)(b)).
- To generate plain-language interpretation — an AI layer explains figures already calculated by the Tool; it never calculates results itself. Legal basis: consent (Art. 6(1)(a)).
- Anonymised peer benchmarking — your port's KPIs may contribute to aggregate statistics shown to other ports. Individual port data is never shown to another port, and aggregates are suppressed below a minimum cohort size. Legal basis: legitimate interest (Art. 6(1)(f)) in providing sector benchmarking, balanced against your privacy through anonymisation.
- Security & accountability — audit logging of who changed what, when, to protect the integrity of your data and meet our accountability obligations under Art. 5(2) GDPR. Legal basis: legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)).
4. Automated processing and AI
The Tool's deterministic calculation engine — not an AI model — produces every emissions, cost, and score figure you see. A separate AI layer (Anthropic Claude) only writes plain-language explanations and suggestions from those already-computed figures; it is never given your name, email, or any other directly identifying information, only your port's non-identifying operational results. AI output is always clearly labelled as indicative and does not produce any decision with legal or similarly significant effects on you within the meaning of Art. 22 GDPR — a human at your port always reviews and decides.
6. How long we keep your data
Your account and port data are kept for as long as your account remains active. Draft questionnaires and AI interpretation logs are subject to admin-configured retention periods and are deleted automatically once they expire. Audit log entries that document a GDPR action (export, rectification, erasure) are kept as a compliance record.
7. Your rights
You have the right, at any time, to:
- Access & portability — download a copy of all data held about you.
- Rectification — correct your name or email address.
- Erasure — request deletion of your account and associated data.
- Restriction & objection — ask us to restrict or stop a particular processing activity.
- Withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal.
Signed-in users can exercise the access, portability, and rectification rights directly from Account → Privacy & your data. For erasure, restriction, objection, or any other request, contact us using the details in Section 1.
You also have the right to lodge a complaint with a supervisory authority — in Lithuania, the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija), or the data protection authority in your own EU member state.
8. How we protect your data
Access to port data is restricted at the database level (Supabase Row-Level Security) so that only members of a port, and administrators, can see that port's data. All data in transit is encrypted (HTTPS/TLS).
9. Changes to this notice
If we make a material change to this notice, we will update the version number above and, where required, ask you to re-confirm your consent. This is version 1.0.
