Front Carbon
AdvisoryOur PlatformCCS MapAbout
Talk to us
AdvisoryOur PlatformCCS MapAbout
Sign in
PlatformClient sign inMapExplorerTalk to us
Legal

Data Handling and Security Policy

Version 1.1·Last updated July 2026·Front Solutions AS
Contents
1. Purpose2. Data Classification3. Data Isolation and Multi-Tenancy4. Data Storage and Infrastructure5. Data Processing Principles6. Data Retention and Deletion7. Access and Audit8. Incident Response9. Compliance10. Contact

1. Purpose

This policy describes how Front Carbon handles, stores, protects, and processes customer data. It applies to all data submitted through the assessment form, client portal, and consultant planner, as well as all calculation outputs produced by the platform.

2. Data Classification

2.1 Customer Facility Data

Information about the customer's CO2 sources: facility locations, emission volumes, capture rates, industry type, operational timelines. This is the most sensitive category as it may reveal strategic plans and competitive positioning. Handling: Encrypted at rest, organization-scoped access, never shared between customers.

2.2 Commercial and Financial Data

Pricing information: capture costs, storage tariffs, transport budgets, vessel arrangements, negotiated rates. This data has direct commercial value. Handling: Encrypted at rest, organization-scoped access, never used in aggregate reporting without explicit consent.

2.3 Calculation Results

Cost breakdowns, optimized routes, fleet specifications, sensitivity analyses, AI-generated interpretations. These are derived from customer data combined with Front Carbon's models. Handling: Organization-scoped access, retained for the duration of the customer engagement, exportable by the customer via PDF and Excel.

2.4 System and Reference Data

Exchange rates, fuel prices, vessel specifications, storage site public tariffs, regulatory data (EU ETS prices). This data is not customer-specific. Handling: Accessible to all authenticated users, sourced from public market data.

3. Data Isolation and Multi-Tenancy

3.1 Architecture

Front Carbon is a multi-tenant platform. All customers share the same application infrastructure but their data is strictly isolated at the database level.

3.2 Row Level Security (RLS)

Every table in the database (75 tables, 180+ security policies) enforces Row Level Security. The database itself verifies that every query only returns data belonging to the requesting user's organization. This protection operates at the database layer, independent of application code. Seven purpose-built security functions control access based on user role, organization membership, project assignment, and client relationship.

3.3 Role-Based Access

Five user roles with distinct permissions: Admin (full access), Senior Consultant (assigned projects, full configuration), Consultant (assigned projects, cases and calculations), Client (own project results, facility data submissions only), Participant (limited project view, read-only).

3.4 Visibility Controls

Consultants control exactly which data points are visible to each client through a 25-field visibility configuration per project. Sensitive fields (vessel prices, TC rates, OPEX details, fuel consumption, calculation methodology) are hidden by default and must be explicitly enabled.

4. Data Storage and Infrastructure

4.1 Hosting

Application hosted on Vercel (European region available). Database hosted on Supabase (PostgreSQL) with data residency options. File storage via Supabase Storage with server-side encryption.

4.2 Encryption

In transit: All data encrypted via TLS 1.2+ (HTTPS). At rest: Database encrypted using AES-256 (Supabase managed encryption). Backups: Automated daily backups, encrypted.

4.3 Authentication

Email and password authentication via Supabase Auth, with optional multi-factor authentication (TOTP). Token-based invitation system for client onboarding (tokens expire after 7 days). Session management with automatic expiry.

4.4 Monitoring and Analytics

Error monitoring via Sentry, hosted in the EU (Germany). Error reports are minimized: IP addresses and request PII are not attached by default, session replay is disabled except for a small sample (10%) captured when an error occurs, with text masked. Aggregate performance and traffic statistics via Vercel Analytics and Speed Insights, which are cookieless and do not track individual users across sites.

5. Data Processing Principles

5.1 Minimization

We collect only the data necessary to perform the requested analysis. Assessment form fields are optional where possible, and customers choose what to share.

5.2 Purpose Limitation

Customer data is used exclusively for: performing the requested CCS transport analysis, generating reports and visualizations, and improving the accuracy of the customer's specific project. Customer data is never used for: training AI models, benchmarking against other customers (without explicit consent), marketing or advertising, or selling or sharing with third parties.

5.3 AI Processing

Front Carbon uses AI (Claude by Anthropic) for post-calculation analysis. AI never performs calculations: all cost computations are deterministic TypeScript functions. AI receives only the customer's own calculation results as context, never data from other customers. AI-generated content is clearly labeled. AI API calls are made via server-side routes. Anthropic does not use this data to train its models.

5.4 No Hardcoded Values

Every number in a calculation comes from either: the customer's own data, configured project assumptions, or live market data. No calculation parameter is hardcoded in the application. This ensures transparency and auditability.

6. Data Retention and Deletion

6.1 Active Engagements

Customer data is retained for the duration of the active engagement plus 12 months for reference and potential follow-up analysis.

6.2 Completed Engagements

After the retention period, customers may request full data export (PDF, Excel, raw results) or data deletion (removal of all customer-specific data).

6.3 Right to Deletion

Upon written request, Front Solutions will delete all customer-specific data within 30 days. Confirmation of deletion will be provided in writing.

6.4 Assessment Requests

Data from the public assessment form is retained for 12 months. If no engagement follows, the data is deleted by an automated retention routine. Prospects may request deletion at any time.

6.5 Operational Logs

Authentication, audit, and portal activity logs are deleted after 12 months by the same automated retention routine. Each run of the routine is logged, and a watchdog alerts us if the routine stops running.

7. Access and Audit

Only Front Solutions employees with admin or senior consultant roles can access customer projects. All access is logged. The platform maintains activity logs for portal visits, communications, data submissions, and report generation. Customers can view all their data through the client portal and request complete data exports.

8. Incident Response

In the event of a data breach: affected customers will be notified within 72 hours, the scope will be communicated clearly, remediation steps will be implemented immediately, a post-incident report will be provided, and relevant authorities will be notified as required by GDPR.

9. Compliance

9.1 GDPR

Front Solutions AS is a Norwegian company subject to GDPR. Customer data is processed in accordance with all GDPR principles.

9.2 Data Processing Agreement

Enterprise customers may request a Data Processing Agreement (DPA) specifying the terms of data processing, sub-processors, and data transfer mechanisms.

9.3 Sub-Processors

Current sub-processors: Supabase (database hosting and authentication), Vercel (application hosting, cookieless analytics), Anthropic (AI analysis, no customer data retained or used for training), Resend (transactional email delivery), Sentry (error monitoring, EU region, PII minimized), Mapbox (map display and geocoding of facility addresses). Billing and accounting data is additionally processed in Tripletex, our accounting system, to meet Norwegian bookkeeping obligations.

10. Contact

For data handling inquiries, deletion requests, or security concerns, contact Front Solutions AS at post@frontcarbon.com.

This policy is reviewed and updated as the platform evolves. Customers will be notified of material changes.

Front Carbon

Front Carbon is an independent advisory for CCS logistics. Our platform is the engine behind our work; the Map is open to all.

Platform

OverviewCapabilities

Map

OverviewWhat you’ll seeOpen the map

Company

AdvisoryAboutLegal

Get in touch

Contactpost@frontcarbon.comSign in
© 2026 Front Solutions AS, trading as Front Carbon. All rights reserved. Org. nr. 933 375 250.