EcoCheckA BeevR product

EcoCheck connector privacy policy

Last updated October 8, 2026. Applies to the EcoCheck connector for ChatGPT, Claude and other AI assistants (the “connector”). The general EcoCheck privacy policy (Vietnamese) is at /chinh-sach-bao-mat; where they differ for the connector, this policy applies.

Who we are

EcoCheck is operated by BeevR Technology Co., Ltd. (Công ty TNHH Công nghệ BeevR), 125 Hoang Ngan, Trung Hoa, Cau Giay, Hanoi, Vietnam (“we”). Contact: [email protected].

What the connector accesses

  • Account connector (https://ecocheck.ai/mcp/account): only the EcoCheck data the signed-in user can already access on ecocheck.ai — workspaces, organizations, facilities, GHG inventories, activity data, emission results, targets, CBAM data and, for workspace owners, member and AI-access settings. Access is limited by the OAuth scope the user grants and by the AI access level set by the workspace owner.
  • Public connector (https://ecocheck.ai/mcp): no account and no personal data. It answers questions from public reference data (regulations, emission factors, EU CBAM default values) and EcoCheck's public content.

What we collect and why

  • Sign-in: authentication is handled by our identity provider (AWS Cognito). We receive the user's account identifier and email to identify the user. The AI assistant never receives the user's password.
  • Data the user asks the assistant to create or change (for example activity data, emission sources, CBAM data) is stored in the user's EcoCheck workspace exactly as if entered on ecocheck.ai, to provide the service.
  • Audit log: for each tool call we record the user, workspace, AI client identifier, tool name, required and effective access level, whether it was allowed, and the time. This lets workspace owners review AI activity and lets us secure the service. We do not store the text of the user's conversation.
  • Operational logs: standard web-server logs (IP address, time, request path, status) for security and troubleshooting.

We do not collect the user's chat history, prompts or files from ChatGPT or Claude; we only receive the tool calls the assistant makes and their arguments. We do not sell personal data, use it for advertising, or use connector data to train AI models.

Sharing

  • Tool results are returned to the AI assistant the user connected (OpenAI for ChatGPT, Anthropic for Claude, or another provider the user chose). How that provider stores conversations is governed by its own privacy policy and the user's account settings.
  • Infrastructure providers that host EcoCheck (Amazon Web Services, Singapore region; Cloudflare) process data on our behalf under contract.
  • Members of the same EcoCheck workspace see shared workspace data according to their roles, as on ecocheck.ai.
  • We disclose data to authorities only when required by law.

Retention and deletion

  • Access tokens expire after 1 hour; refresh tokens can be revoked by the user (disconnecting the app) or by the workspace owner at any time.
  • Inventory and CBAM data are kept for the life of the workspace subscription and deleted within 90 days of a verified deletion request or the end of the subscription, unless law requires longer retention.
  • Audit-log entries are kept for up to 24 months; operational logs for up to 90 days.
  • To access, export, correct or delete your data, email [email protected] from your account address.

Security

Traffic is encrypted with TLS. Tokens are validated on every request (signature, issuer, audience/client, expiry, scope and revocation). Permissions are enforced on our servers, not by the AI assistant. Destructive actions require explicit confirmation and the Full access level.

Children

The connector is a business service and is not intended for people under 18.

Changes

We will post changes on this page and update the date above. Material changes will be notified to workspace owners by email.