Privacy policy
Your privacy is important to us
Last updated: September 3rd, 2026
Your privacy is important to us. This Privacy Policy describes how Generation Impact Global SA (“we”, “us”, “our”, or the “Company”) collects, uses, discloses, and protects Your data when You use our Website, Platform, and Services. It also explains Your rights under applicable data protection laws and how You can exercise them.
By using our Website, Platform, or Services, You acknowledge that You have read and understood this Privacy Policy. This Privacy Policy should be read together with our Terms and Conditions and, where applicable, our Data Processing Agreement, both available at generationimpact.global/legal.
Table of contents
Jump to section
1. Interpretation and definitions
Company refers to Generation Impact Global SA, registered in Geneva, Switzerland (CHE-260.384.863), Rue de Lausanne 82, 1202 Geneva, Switzerland.
Data Protection Laws means, all data protection and privacy laws applicable to the relevant processing of Personal Data, including, where applicable, the Swiss Federal Act on Data Protection of 25 September 2020 (FADP/nDSG), the EU GDPR and the UK GDPR, in each case as amended or replaced from time to time.
Personal Data means any information relating to an identified or identifiable individual, as defined under applicable Data Protection Laws.
Platform means the Generation Impact Global software-as-a-service platform for ESG data management, sustainability reporting, impact analytics, and utility management, together with all products, modules and features made available through it from time to time.
Services means all services provided by us, including the Platform, Website, advisory support, and related materials.
AI Features means all AI-assisted functionalities made available within the Platform from time to time, comprising document and data extraction, classification and mapping, generative text, analysis and insights, and data validation, as described in our AI Transparency Notice.
Website refers to https://generationimpact.global and https://generationimpact.tech and all related subdomains.
You / Your refers to the individual accessing or using the Services, or the company or other legal entity on whose behalf such individual is acting.
2. Data controller and contact details
For the purposes of applicable Data Protection Laws, the Data Controller is:
Generation Impact Global SA
Rue de Lausanne 82, 1202 Geneva, Switzerland
Email: [email protected]
UID: CHE-260.384.863
Commercial register reference: CH-660.4.413.022-2
VAT: CHE-260.384.863 TVA
Where we process Personal Data on Your behalf as a Data Processor (e.g. when You upload data to the Platform that contains Personal Data), the terms of our Data Processing Agreement shall apply in addition to this Privacy Policy.
3. Data we collect
3.1 Data You Provide to Us
| Category | Examples | Legal Basis |
|---|---|---|
| Account registration data | Business name, business email address, name of Authorised User, job title, country | Performance of contract; legitimate interests |
| Subscription and billing data | Billing address, VAT/tax ID, payment method (processed by Stripe; we do not store card details), subscription plan, billing currency, billing frequency | Performance of contract; legal obligation (tax records) |
| Platform content (ESG / utility data) | Sustainability data, ESG metrics, utility consumption data, company information, reports uploaded to the Platform | Performance of contract |
| Communications | Emails, support requests, feedback, survey responses | Legitimate interests; consent (for marketing) |
| Consent and preference records | T&Cs acceptance timestamp and version, withdrawal consent, AI acknowledgement, cookie preferences, marketing opt-in/out | Legal obligation; legitimate interests |
3.2 Data Collected Automatically
| Category | Examples | Legal Basis |
|---|---|---|
| Usage data | Pages visited and features used within the Platform, session duration, clicks, searches, actions, and AI feature usage consumption | Legitimate interests |
| Device and technical data | IP address, browser type and version, operating system, device type, unique device identifiers, screen resolution | Legitimate interests |
| Log data | Access logs, error logs, timestamps of actions, AI feature usage logs | Legitimate interests; legal obligation |
| Geolocation data | Approximate location derived from IP address (country/region level only) | Legitimate interests |
| Website interaction, analytics and session replay data | Website pages viewed, referral and campaign information, clicks, scrolling, mouse movements, device and browser data, approximate location, and interactions with on-screen content; depending on tool configuration, session-replay data may include information displayed on the page or entered into Website forms | Consent for non-essential analytics and session replay |
3.3 Cookies and Tracking Technologies
We use cookies and similar tracking technologies to collect information about Your browsing activity on our Website. For full details, please refer to our Cookie Policy available at generationimpact.global/legal/cookies.
We use the following categories of cookies: (a) strictly necessary cookies (essential for Website functionality; no consent required); (b) functional cookies (remember Your preferences; consent required); (c) analytics cookies (understand usage patterns; consent required); and (d) marketing cookies (targeted communications; consent required).
Google Analytics: We use Google Analytics to analyse Website traffic. Google processes data in accordance with its own privacy policy (https://policies.google.com/privacy). You may opt out by installing the Google Analytics opt-out browser add-on.
Session replay and advertising technologies: Subject to Your consent, we use Hotjar and/or Microsoft Clarity on public Website pages to understand visitor interactions; session-replay tools are not enabled on authenticated Platform pages. We also use Google Ads, LinkedIn Insight Tag and Microsoft/Bing UET for campaign measurement, audience creation, remarketing and advertising optimisation. These technologies may process online identifiers, device and browser information, page content, clicks, scrolling and mouse movements. Depending on configuration, session-replay tools may also process information displayed on the page or entered into Website forms. We apply available masking and suppression settings and do not use these tools intentionally to collect payment credentials or special-category Personal Data.
Cookie consent: Where required by applicable law (including the ePrivacy Directive), we obtain Your consent before placing non-essential cookies. You may withdraw consent at any time through our cookie management tool, accessible via the “Cookie Settings” link in our Website footer.
3.4 Payment Data
Subscription payments are processed by Stripe, Inc. (“Stripe”), and/or its applicable affiliates. When You purchase a Subscription, Your payment information (credit/debit card details) is collected and processed directly by Stripe. We do not receive, store, or have access to Your full card number. We receive from Stripe only: the last four digits of Your card, card type, expiry date, billing address, and transaction confirmations. Stripe’s privacy policy is available at https://stripe.com/privacy. Stripe is PCI-DSS Level 1 certified.
3.5 Newsletter and Marketing Data
If You opt in to receive our newsletter and marketing communications, Your business contact details (name and email address) will be shared with our email marketing platform provider, Intuit Mailchimp (The Rocket Science Group LLC, a subsidiary of Intuit Inc.), for the purpose of sending You newsletters, product updates, event invitations, and other marketing materials. You may unsubscribe at any time by clicking the “unsubscribe” link in every email or by contacting us. Mailchimp’s privacy policy is available at https://www.intuit.com/privacy/statement/. Subscription to marketing communications is voluntary and does not affect Your access to the Services.
4. How we use your data
We use Your data for the following purposes:
(a) To provide, operate, and maintain the Services, including the Platform, user accounts, and Subscriptions.
(b) To process payments, manage billing, and comply with tax obligations (via Stripe).
(c) To communicate with You regarding Your account, Subscription, support requests, service updates, renewal reminders, and security notifications.
(d) To send You marketing communications (only with Your consent; You may opt out at any time).
(e) To analyse and improve the Services, including through usage analytics, A/B testing, and performance monitoring.
(f) To provide AI Features within the Platform (see Section 5).
(g) To comply with legal obligations, including tax, accounting, regulatory reporting, and responses to lawful requests from public authorities.
(h) To enforce our Terms and Conditions, protect our rights, and prevent fraud or misuse of the Services.
(i) To facilitate business transfers, such as mergers, acquisitions, or asset sales.
(j) To maintain audit trails and consent records as required by applicable law (including T&Cs acceptance, withdrawal consent, AI acknowledgement, and cookie consent).
(k) To measure Website use, understand Website interactions, improve usability, measure campaigns, create advertising audiences and conduct remarketing, in each case subject to consent where required.
5. Artificial Intelligence and automated processing
5.1 AI Features
The Platform incorporates AI Features through two distinct products, VitAI (document extraction and analysis) and UtilityIQ (utility bill extraction and data management), as well as general AI-assisted functionalities (data classification, report generation, analytics, data validation, and SDG mapping). These AI Features process Your Content to deliver the Services.
5.2 AI Providers
Our AI Features are powered by third-party large language models, currently including models provided by OpenAI and Meta. These models are hosted by Microsoft within the Microsoft Azure environment; OpenAI and Meta do not receive, access or store Your Content. The model providers in use at any time are identified in our sub-processor list (see Section 8.2), and we will notify You of material changes in accordance with the Data Processing Agreement.
5.3 How Your Data is Used by AI Features
Your Content is processed by AI Features solely to provide the Services to You. No customer data is used to train Microsoft’s, OpenAI’s, or Meta’s foundation models. Prompts and outputs submitted to AI Features are processed by Microsoft as our sub-processor. Microsoft operates automated abuse-detection controls; where content is flagged, a limited number of authorised Microsoft personnel may access it under controlled-access conditions. We do not retain prompts and outputs beyond what is required to deliver the Services and to meet our operational and compliance obligations. Any such retention by Microsoft is in a logically separated data store located within the geography in which the service is deployed. Section 7 of our AI Transparency Notice describes this data flow in full. We may use Your Content, in a irreversibly anonymised and aggregated form, to improve our own Platform-specific features.
5.4 Automated Decision-Making
The AI Features within the Platform do not make automated decisions that produce legal or similarly significant effects on You without human involvement. The AI Features are designed to keep a human in the loop: AI-generated Output is presented to You for review, and You decide whether to accept, amend or reject it before relying on it or incorporating it into Your reports and disclosures. Where applicable under applicable Data Protection Laws (including GDPR Article 22), You have the right not to be subject to a decision based solely on automated processing where such decision produces legal effects concerning You or similarly significantly affects You. If You believe an automated decision has affected You, please contact us.
5.5 AI Transparency
Where applicable and as required under the EU AI Act Article 50, we clearly identify when Output has been generated or materially assisted by AI Features. Further information is available in our AI Transparency Notice at generationimpact.global/legal/ai-transparency.
5.6 AI Usage Data
When You use AI Features, we log usage for operational purposes, including usage tracking, error monitoring, and performance analysis. Logs include: timestamp, user ID, feature used, usage consumed, and error codes. Logs do not include the full Content submitted to the AI model or the full output returned. Logs are retained for twelve (12) months.
6. Legal bases for processing
Where required under applicable Data Protection Laws, we rely on one or more of the following legal bases for processing Personal Data:
| Legal Basis | When We Rely on It |
|---|---|
| Performance of a contract | Processing necessary to provide the Services, manage Your Subscription, and fulfil our contractual obligations |
| Consent | Marketing communications; non-essential cookies; newsletter subscription via Mailchimp |
| Legitimate interests | Service improvement, analytics, security, fraud prevention, and business operations (where not overridden by Your rights) |
| Legal obligation | Tax and accounting records, regulatory reporting, audit trails, consent logging, data breach notification |
Where we rely on consent, You may withdraw it at any time by contacting us or using the relevant opt-out mechanism. Withdrawal does not affect lawfulness of processing prior to withdrawal.
7. Data retention
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data | Duration of account + 12 months after deletion | Contract performance; legitimate interests |
| Platform content (ESG / utility data) | Duration of Subscription + 60 days (data download period per T&Cs) | Contract performance |
| Billing and tax records | 7 years after the end of the financial year | Swiss tax law; applicable tax legislation |
| Consent records (T&Cs acceptance, withdrawal consent, AI acknowledgement, cookies) | Duration of account + 6 years (T&Cs); 3 years (other consents); 13 months (cookies) | Legal obligation (Compliance with applicable legal obligations; establishment, exercise or defence of legal claims) |
| Support communications | 3 years after resolution | Legitimate interests |
| Website analytics and session-replay data | Up to 14 months, depending on the relevant tool and account configuration; aggregated or irreversibly anonymised statistics may be retained for longer | Consent; legitimate interests for aggregated analytics |
| Newsletter subscriber data and marketing consent records | Until unsubscribe or withdrawal of consent; minimal suppression and consent records retained for 3 years thereafter | Consent; compliance with applicable legal obligations; legitimate interests in maintaining suppression records |
| Security and access logs | 12 months | Legitimate interests; legal obligation |
| AI usage data (timestamp, user ID, feature used, usage consumed, error codes) | 12 months | Legitimate interests; operational compliance |
| Website cookie identifiers and advertising / measurement data | Cookie lifespans range from the browsing session to 2 years, as specified in the Cookie Policy. Related provider-side campaign or measurement data is retained according to the configured account settings and no longer than necessary for the stated purpose. | Consent; legitimate interests for strictly necessary cookies |
| Platform usage data (pages and features used, session duration, clicks, searches and actions) | 14 months; aggregated or irreversibly anonymised usage statistics may be retained for longer | Legitimate interests in operating, securing and improving the Services |
Upon expiry of the applicable retention period, data is securely deleted or irreversibly anonymised.
8. Data sharing and sub-processors
8.1 Categories of Recipients
We may share Your data with the following categories of third parties:
(a) Service providers and sub-processors: companies that help us provide the Services, including cloud hosting, email delivery, analytics, customer support, and payment processing. Where they act as our processors or sub-processors, such providers are contractually required to process Personal Data in accordance with our instructions and applicable Data Protection Laws.
(b) Payment processor: Stripe, Inc. (and/or its applicable affiliates) processes payment data in connection with the provision of payment services (see Section 3.4).
(c) AI technology providers: Microsoft Azure hosts the large language models that power the AI Features (see Section 5.2). These providers do not retain Your Content for model training.
(d) Email marketing: Intuit Mailchimp processes newsletter subscriber data (see Section 3.5). Only if You have opted in.
(e) Professional advisors: lawyers, accountants, and auditors, where necessary for legal, tax, or compliance purposes.
(f) Regulatory and public authorities: where required by law, regulation, or court order.
(g) Business transfer parties: in connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.
(h) Website analytics, session-replay and advertising providers: Google LLC (Google Analytics, Google Ads and Google Tag Manager), Microsoft Corporation (Microsoft Clarity and Microsoft/Bing advertising), Hotjar Ltd (Hotjar), LinkedIn Corporation (LinkedIn Insight Tag), and Intuit/Mailchimp for campaign tracking, where the relevant technology is enabled and You have provided any consent required by law.
8.2 Sub-Processor List
A current list of our sub-processors, including their names, locations, and the services they provide, is available upon request by contacting us at [email protected]. We will notify You of any material changes to our sub-processors in accordance with the Data Processing Agreement.
8.3 Sale, Sharing and Targeted Advertising
We do not sell Personal Data for monetary consideration. If You consent to advertising or marketing cookies on our Website, certain third-party providers may receive online identifiers and information about Your interactions with the Website for campaign measurement, audience creation, remarketing or advertising optimisation. Depending on applicable law, this activity may constitute “sharing”, “targeted advertising” or cross-context behavioural advertising. You may withdraw consent through Cookie Settings and, where applicable, opt out by using a recognised Global Privacy Control signal. Further details are provided in our Cookie Policy.
9. International data transfers
Personal Data under our control is stored primarily in Switzerland and the European Economic Area (EEA). Processing locations vary by service, provider and technical configuration. In particular, prompts and responses processed through Microsoft Azure AI services may be processed within a customer-specified geography, within a selected Data Zone, or globally where a Global deployment is used. Data stored at rest remains in the customer-designated geography, subject to the applicable Microsoft terms and configuration. Further information is provided in our AI Transparency Notice. Website analytics, sessionreplay, advertising, payment and email-marketing providers may also process Personal Data outside Switzerland and the EEA, including in the United States.
We do not require customers to upload Personal Data through the Platform except where necessary for the designated Services. However, Customer Content uploaded to or processed through the Platform may contain Personal Data. Where Personal Data is transferred to a country outside Switzerland or the EEA that is not covered by an applicable adequacy decision, we use an appropriate transfer mechanism, which may include European Commission Standard Contractual Clauses, with adaptations where required for Swiss law, or another mechanism recognised by applicable law. US-based recipients certified under an applicable Data Privacy Framework may include Stripe, LLC, Google LLC, Microsoft Corporation, LinkedIn Corporation and Intuit Inc., including its covered Mailchimp entity. We rely on an applicable Data Privacy Framework only where the recipient is an active participant and its certification covers the relevant transfer. Otherwise, or as an alternative or fallback where appropriate, we use contractual safeguards such as Standard Contractual Clauses.
You may request a copy of the safeguards in place by contacting us.
9.1 Territories Where Services Are Not Offered
The Services are not currently offered to customers located in the People’s Republic of China, Saudi Arabia, the United Arab Emirates, or Qatar. Any access from these territories is at the user’s own risk regarding compliance with local law.
10. Data security
We implement appropriate technical and organisational measures to protect Your data, including:
(a) Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
(b) Multi-factor authentication (MFA) and role-based access control (RBAC).
(c) Regular security assessments, penetration testing, and vulnerability scanning.
(d) Firewalls, intrusion detection/prevention systems (IDS/IPS).
(e) Employee security training and access controls.
(f) Incident response procedures and a dedicated security team.
(g) Business continuity and disaster recovery plans.
Our security practices are aligned with ISO 27001:2022 standards. For more detail, please visit generationimpact.global/security.
11. Data breach notification
In the event of a Personal Data breach, we shall: (a) notify the competent supervisory authority where and within the timeframe required by Data Protection Laws, including, where applicable, within 72 hours under GDPR Article 33; (b) notify affected individuals without undue delay where required by applicable Data Protection Laws, including where the breach is likely to result in a high risk to their rights and freedoms; and (c) document the breach, including its effects and remedial actions taken. Where the Swiss FADP applies, we notify the Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible where the breach is likely to result in a high risk to the data subject’s personality or fundamental rights (Article 24(1) FADP), and we inform affected data subjects where this is necessary for their protection or where the FDPIC so requires (Article 24(4) FADP).
If we are acting as a Data Processor, we shall notify You (as Data Controller) without undue delay, and in any event within 24 hours of becoming aware of a breach involving Your data, in accordance with the Data Processing Agreement.
12. Your rights
12.1 Rights Under Swiss Law (FADP)
Under the Swiss FADP, You have the right to: access Your Personal Data and receive information about its processing; request rectification of inaccurate data; request deletion of Your data (subject to legal retention obligations); object to processing; and request data portability. Where we take a decision based exclusively on automated processing that has a legal consequence for You or significantly affects You, You have the right to be informed of that decision, to state Your point of view, and to request that the decision be reviewed by a natural person (Article 21 FADP). You may lodge a complaint with the Federal Data Protection and Information Commissioner (FDPIC): https://www.edoeb.admin.ch.
12.2 Rights Under the GDPR (EU/EEA/UK)
Where the EU GDPR or UK GDPR applies to the processing of Your Personal Data, You have the right to: access (Article 15); rectification (Article 16); erasure (Article 17); restriction (Article 18); data portability (Article 20); object to processing (Article 21); not be subject to automated decision-making (Article 22); and withdraw consent at any time. You may lodge a complaint with Your local Data Protection Authority: https://edpb.europa.eu/about-edpb/about-edpb/members_en. UK: Information Commissioner’s Office: https://ico.org.uk.
12.3 Rights Under US State Privacy Laws (CCPA/CPRA and Others)
If You are a US resident in a state with applicable privacy legislation that applies to the processing of Your Personal Data, You may have the right to: know what data we collect and how it is used; request deletion; opt out of the “sale” or “sharing” of Your data, targeted advertising or cross-context behavioural advertising; and not be discriminated against for exercising Your rights. We do not sell Personal Data for monetary consideration. Certain disclosures through advertising and marketing technologies may constitute “sale”, “sharing” or targeted advertising under applicable US state law, as described in Section 8.3. To exercise these rights, use Cookie Settings, enable a recognised Global Privacy Control signal where supported, or contact [email protected].
Notice at Collection (CCPA): We collect the categories of Personal Data described in Section 3 for the purposes described in Section 4. We do not sell Personal Data for monetary consideration. Subject to Your cookie choices, disclosures to advertising and marketing providers may constitute “sale” or “sharing” under the CCPA/CPRA; see Section 8.3 and our Cookie Policy for the categories of information and recipients involved and how to opt out. We retain data for the periods described in Section 7. We do not collect or process sensitive personal information as defined under the CCPA/CPRA for the purpose of inferring characteristics about You. You may use an authorised agent to submit a request on Your behalf; we may require written proof of the agent’s authorisation and may verify Your identity directly.
12.4 Rights Under Canadian Law (PIPEDA/CPPA)
Where applicable Canadian Data Protection Laws apply to our processing of Your Personal Data, You have the right to: access and request corrections; withdraw consent (subject to legal restrictions); and request data portability (when the CPPA comes into force). You may complain to the Office of the Privacy Commissioner of Canada.
12.5 Rights Under African Data Protection Laws
Where applicable, if You are in South Africa (POPIA), Nigeria (NDPA), Kenya (DPA), or another African jurisdiction with applicable legislation, You have rights including access, rectification, deletion, and objection. Contact us for jurisdiction-specific information.
12.6 Rights Under Latin American Data Protection Laws
Where applicable, if You are in Brazil (LGPD), Mexico (LFPDPPP), Chile, Colombia (Law 1581), Argentina (Habeas Data Law), or another Latin American jurisdiction, You have rights including access, rectification, cancellation, objection, and (where applicable) portability. Brazil: complain to the ANPD. Mexico: complain to INAI. Contact us for jurisdiction-specific information.
12.7 Rights Under Asia-Pacific Data Protection Laws
Where applicable, if You are in Japan (APPI), Singapore (PDPA), India (DPDP Act), or Australia (Privacy Act), You have rights under Your local law including access, correction, deletion, and complaint to Your local authority. Contact us for jurisdiction-specific information.
12.8 How to Exercise Your Rights
To exercise any of Your rights, contact us at [email protected]. We will respond within the timeframe required by applicable law (one month under the EU and UK GDPR, which may be extended by two further months for complex or numerous requests, and generally 30 days under the Swiss FADP). We may verify Your identity before processing Your request.
13. Children’s privacy
Our Services are not directed to individuals under the age of 18. We do not knowingly collect Personal Data from anyone under 18. If You become aware that a person under 18 has provided us with Personal Data, please contact us immediately. We will take steps to delete such data.
14. “Do not track” and Global Privacy Control
We honour Global Privacy Control (GPC) signals as required by applicable law (including the CCPA/CPRA). When we detect a GPC signal, we treat it as a valid opt-out of the sale or sharing of Personal Data. There is no industry-agreed standard for responding to browser “Do Not Track” signals, and our Website does not currently respond to them.
15. Third-party links and services
Our Website and Platform may contain links to third-party websites or integrate with third party services. We are not responsible for the privacy practices of such third parties. We encourage You to review their privacy policies.
Our Website uses the IP2Location LITE database for IP geolocation (https://lite.ip2location.com).
16. Changes to this privacy policy
We may update this Privacy Policy from time to time. We will notify You of any material changes by: (a) posting the updated Privacy Policy on this page with a revised “Last updated” date; and (b) sending You an email notification where the changes are material. Your continued use of the Services after the effective date of any update will be subject to the updated Privacy Policy.
17. Contact us
If You have any questions about this Privacy Policy, wish to exercise Your data protection rights, or wish to make a complaint, please contact us at:
Generation Impact Global SA
Rue de Lausanne 82, 1202 Geneva, Switzerland
Email: [email protected]
Phone: +41 78 222 45 82