Privacy Policy
Hiili S.L.
Identification of Processing
Data collection from Hiili's proprietary third-party pixel for estimating CO2 emissions from digital advertising.
Exercise of Rights
You may exercise your rights of access, rectification, erasure, right to restriction of processing, data portability, and to object by contacting us at hello@hiili.org.
GDPR
Hiili is fully compliant with the GDPR and respects the privacy of their employers, customers and providers.
All the personal data collected from them is used for the sole purpose of running the regular operation of the company such as: communication, bills generation, pay slips generation, etc.
Our website
Purpose
Our website aims to inform potential customers and stakeholders about the services offered by Hiili S.L. as well as illustrate the impact that digital marketing may have on direct and indirect carbon emissions out of its activity.
Cookies
We use the following cokies on our website for functionality purposes and to analyze our traffic.

Necessary cookies

The following necessary cookies help make a website usable.
The website cannot function properly without these cookies.
cookie duration description type
CookieConsent 1 year Stores the user's cookie consent state for the current domain HTTP

Marketing cookies

The following marketing cookies are used to track visitors across devices and marketing channels.
cookie duration description type
_ga 2 years Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels. HTTP
_ga_# 2 years Used to send data to Google Analytics about the visitor's device and behavior. Tracks the visitor across devices and marketing channels. HTTP
GDPR Compliance
Although we neither collect nor process any personal data our website uses Google Analytics for functionality purposes and to analyze our traffic. Following GDPR requirements we offer the user the possibility of configuring their cookies policies by being able to select: necessary, preferences, statistics, and marketing cookies. We implement an opt-in approach, the most privacy-preserving option, and by default, only necessary cookies are selected. This process allows us to collect the informed consent of the user in case they choose to select the use of another type of cookie beyond the necessary ones.
Carbontag
Purpose
The purpose of this third-party pixel is to collect data from the performance API of JavaScript with the aim of building a model that estimates the amount of CO2 generated in online ads.
Our solution measures the carbon emission and energy consumed by ad impressions.
To this end, we use a script which can be embedded directly inside a regular ad tag.
Upon the rendering process of the ad, the ad from our client calls our domain carbontag.hiili.org to download the ad tag using a specific URL where different parameters are included (e.g., campaign id, ad_id, etc).
These parameters are used for reporting purposes.
Our tag collects several attributes from the browser (none of them including personal data) and sends them to our backend server sitting at server.hiili.org.
Upon receiving these attributes in our backend, our solution uses them to compute the energy consumed by the ad as well as the carbon emissions associated with the ad using our proprietary technology.
Data collection and processing
Our tag collects the following data.
data type purpose
Clicks Estimating the CO2 generated per each click on the ad.
Performance Retrieving duration events, enabling us to compute more accurate CO2 consumption estimations.
performance.getEntries Obtaining a comprehensive dataset that influences CO2 generation estimations.
Navigator Understanding the user's platform helps us report CO2 usage based on the type of device or system being used.
Screen Factoring in the screen size to our estimations.
Size Factoring in the ad format's size contributes to the overall estimation of CO2 emissions.
Parent URL Knowing the webpage where the ad is displayed helps us understand its influence on CO2 generation.
IP prefix Knowing the country where the ad it displayed.
Domains
We use the following Domains to ensure Hiili can provide a reliable service to our clients and end-users.
domain name purpose
carbontag.hiili.org This is the domain from which our script is fetched, whenever an ad containing our Carbontag is loaded.
server.hiili.org This is the end point where the aforementioned data is sent, to be used to compute energy consumptions and resulting carbon emissions.
Data Access
We access the data by inspecting the HTML DOM of the ad, and analyze the requests and responses the ad performs to load the ad's content and track events with third-parties.
Data Storage
The collected information is stored in a secure backend server located at Amazon Web Servers (AWS).
Access to the server is limited to the team working on this project and is protected by user and password credentials.
We want to make it clear that our solution does not engage in any practices that compromise your data privacy.
Specifically, we do not handle any ad targeting, geo-targeting, or buy/sell any data.
We do not collect or use device IDs, employ any methods to track users, or gather information from users across multiple devices.
We also do not gather any personally identifiable information (PII) or utilize PII for any purpose.
Our commitment to your privacy extends to our advertising practices as well, as we do not conduct direct retargeting or contextual targeting.
Furthermore, we do not capture hyperlocal data upon serving the pixel, maintain user profiles or models, use cookies, or access the local storage of the user.
Your trust is important to us, and we take your privacy seriously.
Cookieless
Our Carbontag pixel does not uses cookies nor the local storage to write or read information.
Therefore, it does not manage any personal information linked to cookies or device storage.
GDPR Compliance
We do not collect any personal data.
IAB
We are members of Interesseorganisasjonen for digital markedsføring og kommunikasjon (INMA), the official representative of IAB Europe in Norway.
TCF
We have undergone the IAB Europe's Transparency & Consent Framework verification, and we have been validated and assigned the following TCF Vendor ID: 1247
CarbonAI Web Extension Plugin
Last Updated
22/10/2025
Purpose

This Privacy Policy explains how Hiili ('we', 'our', or 'the Company'), established as a Data Controller in the European Union, collects, uses, shares, and protects personal data when providing its Chrome browser extension and related analytics services. This policy complies with the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and comparable global privacy frameworks.

Scope and Applicability

This policy applies to all users of the Hiili browser extension worldwide. Regional provisions are included for users located in the European Economic Area (EEA), the United Kingdom (UK), the United States (including California, Virginia, Colorado, and Connecticut), and any other jurisdiction with applicable data protection laws. Where local law requires additional rights or disclosures, this policy incorporates them.

Data Controller and Contact Details

Hiili acts as the Data Controller for all processing activities described herein.

Registered Address: [EU Address] AVENIDA GREGORIO PECES BARBA, 1. 28919. LEGANÉS. MADRID: SPAIN
Email: privacy@hiili.org
Data Privacy Representative: Ángel Cuevas Rumín.
Information We Collect

We collect and process the following categories of data when you use our plugin:

Chat Data and Metadata
  • Input and output text processed by Large Language Models (LLMs) such as ChatGPT, Gemini, and DeepSeek.
  • Model name, provider, date and time of interaction, token counts, and generation speed.
  • Conversation titles, chat IDs, and message IDs assigned by the LLM platform.

Hiili does not collect usernames, emails, or other direct identifiers. Where users include personal data in prompts or outputs, such data is pseudonymized and stored under a random UUID.

Energy Consumption Data

Estimated energy usage associated with LLM activities performed through the plugin.

Approximate Geolocation

Continent, country, and region inferred from IP address to estimate CO₂ emissions. IP addresses are not stored or logged.

Technical and Registration Data

Installation date, browser version, preferred language, and user agent for technical support, debugging, and statistical purposes.

Basic demographic data regarding age group, prefessional field and gender for statistical purposes.

Legal Basis for Processing

We process personal data based on the following lawful grounds under Article 6 GDPR:

  • Consent: For collecting and analyzing prompt data or using anonymized inferences for all the elements listed in section 5 “Purposes for processing”.
  • Legitimate Interests: To measure energy consumption, assess environmental impact, and improve Hiili’s offerings, ensuring minimal privacy impact.
  • Contractual Necessity: Where processing is required to provide the plugin’s core functionality.
  • Legal Obligation: Where processing is necessary for compliance with applicable law.

Under the UK, GDPR and US laws, equivalent lawful bases apply. Users may withdraw consent at any time via plugin settings or by contacting Hiili.

Purposes of Processing

We use the data described above for the following purposes:

  • To estimate and analyze energy consumption associated with AI model usage.
  • To conduct scientific research with academic institutions.
  • To conduct environmental research and sustainability reporting.
  • To enhance plugin performance and develop new features.
  • To produce aggregated, anonymized insights into purchase intent and user interests (non-identifiable) for advertising and market research, subject to consent.
  • To produce methodologies, technologies and solutions that allows Hiili to carry out commercial actions to optimize the use of AI solutions for Hilli customers.
  • To comply with legal, security, and regulatory requirements.
Data Sharing and International Transfers

We do not sell, rent, or disclose identifiable personal data. However, we may share anonymized or aggregated insights with research institutions or commercial partners for research purposes, sustainability analytics, optimized use of AI solutions and advertising intelligence.

Where transfers outside the European Economic Area or United Kingdom occur, Hiili ensures compliance through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • The UK International Data Transfer Addendum;
  • Adequacy decisions for approved jurisdictions; and
  • Binding contractual safeguards consistent with GDPR Articles 44–49.
Data Retention

We retain personal data only as long as necessary to fulfill the purposes stated in this policy, or as required by law. Anonymized and aggregated data that no longer identifies any individual may be retained indefinitely for research and statistical purposes.

Security Measures

Hiili applies appropriate technical and organizational measures to protect data from unauthorized access, alteration, loss, or disclosure. This includes encryption in transit (HTTPS) and at rest (AES-256), restricted access, logging, and periodic security audits.

In the event of a data breach, Hiili will notify affected users and relevant authorities in accordance with Articles 33 and 34 GDPR and applicable US state laws.

Data Subject and Consumer Rights

Users have the following rights depending on jurisdiction:

  • Access, rectification, erasure, and restriction of processing (GDPR Articles 15–18);
  • Data portability (Article 20);
  • Right to object (Article 21) and to withdraw consent at any time;
  • Under the CCPA/CPRA: right to know, delete, correct, and opt-out of data sale or sharing;
  • Under the VCDPA and CPA: right to appeal processing decisions.

Requests can be submitted by providing the UUID shown in the plugin interface and contacting: hello@hiili.org.

Children’s Privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from minors. If we learn that such data has been collected, we will delete it promptly.

Updates to This Policy

We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes. The 'Last Updated' date at the top will indicate the latest revision. Significant updates will be communicated through the plugin or our website.

Contact and Redress

If you have any questions, concerns, or wish to exercise your rights, please contact:

Hiili
Registered Address: [EU Address] AVENIDA GREGORIO PECES BARBA, 1. 28919. LEGANÉS. MADRID: SPAIN
Email: privacy@hiili.org
Data Privacy Representative: Ángel Cuevas Rumín.

If you are based in the EU or UK, you may also lodge a complaint with your national data protection authority. In the United States, consumers may contact the relevant state attorney general’s office for privacy complaints.