Search Sustopedia

Privacy policy

Effective date · 3 September 2026

Sustopedia is a public sustainability knowledge platform operated by Climateware. You can read the dictionary and metric library, and start an assessment, without creating an account. This policy explains what the website and assessment service process, including what changes if you unlock a detailed report.

Who operates Sustopedia

Climateware operates Sustopedia.

Climateware
BUDOTEK, No. 8/29
34775 Umraniye, Istanbul, Turkey
Email · [email protected]
Telephone · +90 216 807 06 33

Information Sustopedia processes

Website delivery and search

When you request a page, the delivery and security systems process the technical information needed to return it and protect the service. This can include the requested route and transient use of an IP address and user agent. Sustopedia does not provide visitor accounts.

Dictionary search can place your query in the /dictionary/?q= request URL so the requested A–Z state can load. The query is functional route state. The current local search runs in the browser and does not add raw query text to assessment analytics.

Anonymous assessment sessions

Starting an assessment creates a random run identifier and private bearer token. The assessment service stores the selected methodology version, locale, permitted campaign attribution and referring-site hostname, saved answers, branch-clearing events, timestamps and the deterministic result. The private token authorizes access to that run; it is not an account or identity profile and expires after 24 hours.

Answers are saved on the service after each completed step. The browser stores only the run identifier, private token, assessment name and expiry time—not the answers themselves—so the same browser can resume the assessment during the access period. Do not share that private link or browser storage with someone who should not see the result.

Detailed-report information

The anonymous snapshot appears before the report gate. To open the detailed report, Sustopedia requires a work email, company name, country and agreement to the displayed report-access statement. First name and job title are optional. No phone number is requested. The detailed report opens in the browser immediately after a valid submission.

Sustopedia then sends a one-time verification link to the submitted address. Until that link is used, the pending details do not create or update a contact profile, activate an email-question or result-review request, or activate marketing permission. Verification connects the confirmed details and versioned choice receipts to the completed assessment. They may then be made available to Semtrio to handle only the next step selected. Choosing Report only does not request consultant contact. Marketing permission is separate, optional and is not required to see the report.

Why the information is used

Sustopedia processes the information above to:

  • deliver and protect the website and assessment service;
  • save, resume, validate and complete the assessment path;
  • produce the anonymous snapshot and, when requested, the detailed report;
  • verify ownership of a submitted work-email address before activating a contact record, follow-up request or marketing permission;
  • record the versioned report-access and optional marketing choices;
  • respond to an email question or result-review request when you explicitly select one;
  • measure assessment starts, progress, completion and report use; and
  • audit methodology versions, result integrity and service quality.

Browser storage

sustopedia_consent remembers the Performance & analytics preference, save time and preference-format version for up to 12 months. Assessment pages also use a first-party local-storage record named sustopedia:assessment:v1:<assessment>to hold the run identifier, private token and expiry time. The token stops authorizing access after 24 hours even if an expired browser record has not yet been cleared.

Starting over removes the assessment-session record from that browser and opens a new run. Deleting browser storage removes local access but does not by itself delete the corresponding server-side assessment, consent or integrity records. See the Cookie policy for the current browser-storage inventory.

Limited first-party assessment measurement

The assessment service records first-party events such as landing-page view, assessment start, answer-save counts, completion, report unlock, a selected follow-up request and a CBAM cost-scenario calculation. Event metadata is designed not to contain names, email addresses, phone numbers, company names, messages or answer values. Events can still be linked to the random assessment run and methodology version for funnel and integrity analysis.

These functional assessment records are separate from the optional Performance & analytics preference. No advertising identifier, cross-site tracking pixel, device fingerprint or session-replay technology is used by the assessment implementation.

Access period and record retention

The private assessment token is valid for no more than 24 hours. A pending email-verification link is valid for no more than 30 minutes. Expired, replaced and used verification records containing pending contact details are securely removed by the retention process. A completed anonymous run that is not connected to a verified contact is removed after 30 days.

Identifiable contact details connected to a verified lead are retained for up to 90 days after the latest verified assessment submission and are then anonymized. Selected assessment, methodology, consent and integrity records may be preserved after contact anonymization where needed for the stated purposes and applicable requirements. Encrypted disaster-recovery backups expire after 30 days. Append-only deletion records are retained separately and reapplied before a restored service starts, so a restore does not undo an earlier assessment-run, pending-verification or contact deletion.

Your choices

You can use the public libraries and obtain the anonymous assessment snapshot without providing business contact details. The detailed report is optional and opens immediately after a valid gate submission. At its gate, choose Report only unless you want an email response or result review. Those next-step choices and optional marketing permission remain inactive unless the submitted work email is verified. Marketing is unticked by default, separate from report access and withdrawable at any time by contacting Climateware.

Do not enter confidential data, special-category personal data or another person’s contact details unless you are authorized to do so. Links to methodology sources and service websites leave Sustopedia and are governed by the destination’s own privacy information.

Your privacy rights

Privacy rights depend on the law that applies to you and the relevant processing. You can ask about access, correction, deletion, restriction, objection, portability or withdrawal where the relevant right applies. Withdrawing marketing consent does not affect the lawfulness of earlier processing or access to a report already unlocked. Include enough information to locate the submission, such as the work email and company used at the report gate; never send the private assessment token unless asked through a verified support exchange.

Requests, questions and changes

Contact Climateware at [email protected], telephone +90 216 807 06 33, or BUDOTEK, No. 8/29, 34775 Umraniye, Istanbul, Turkey.

This policy will be updated when Sustopedia’s assessment, storage, delivery or measurement practices materially change. The effective date identifies this version.

Read the Cookie policy →