Privacy Notice
1. Controller Information
The controller of personal data is CargoX d.o.o., Ameriška ulica 2, Ljubljana, 1000 Ljubljana.
Data Protection Officer (DPO): [email protected]
CargoX ("us", "we", or "our") operates the following services (as defined in the General Terms and Conditions). This Privacy Notice informs you of our practices regarding the collection, use and disclosure of personal data when you use our services, and of the rights available to you
Unless otherwise defined in this Privacy Notice, the terms used in this Privacy Notice have the same meanings as in our:
General Terms and Conditions (accessible from https://cargox.io),
Special Terms and Conditions (available at https://cargox.digital), and
Standard Contractual Clauses (available at https://cargox.digital).
2. Definitions
GDPR: means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) – terms defined in the GDPR also apply to this Privacy Notice.
ZVOP-2: means the Slovenian Personal Data Protection Act (Official Gazette of the Republic of Slovenia, No. 163/22).
3. What are my rights and how can I exercise them?
In relation to your personal data, you may exercise the following rights at any time:
Your rights include the right:
of access to your personal data (Article 15 GDPR),
to rectification or completion of your personal data (Article 16 GDPR),
to erasure of your personal data where the legal basis for processing no longer exists or, as applicable, where the statutory retention obligation has expired, or where you have withdrawn your consent (Article 17 GDPR),
to restriction of processing (in certain circumstances) (Article 18 GDPR),
to object – where processing is carried out on the basis of legitimate interests (Article 21 GDPR),
to data portability – where processing is based on a contract or consent and is carried out by automated means (Article 20 GDPR),
to withdraw your consent at any time, where processing is based on consent (Article 7(3) GDPR). The withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
You may exercise your rights by writing to the controller's address or by sending an email to [email protected]. In certain cases, we may contact you in order to verify your identity.
Right to lodge a complaint: If you believe that your rights are not being properly exercised, we would appreciate it if you first contact us directly via [email protected]. If that does not resolve the matter, you may lodge a complaint with the Information Commissioner of the Republic of Slovenia.
4. Processing Purposes
4.1. If you visit our website
When you visit our website, we temporarily store your IP address for the duration of your session. If our system determines that no activities are being performed that could jeopardize the functioning of our website, this data is automatically deleted at the end of the session.
However, if our system detects activities that are clearly unlawful or evidently aimed at disrupting or disabling the operation of the website, your IP address will be stored permanently. In such cases, it will be added to our IP “blacklist,” and you will be prevented from further accessing or using the website.
------
Details
Legal basis for the processing of personal data: Based on its legitimate interests (Article 6(1)(f) of the General Data Protection Regulation), the controller processes personal data for the purposes of ensuring the security of the website and preventing unlawful activities on it (e.g. intrusions, phishing, etc.).
Categories of recipients: The website hosting provider and the provider of security solutions.
Transfers to third countries: USA, Commission (EU) Implementing Decision 2023/1795 of 10 July 2023
Retention period: Until the end of the session at the latest (general rule), or permanently (in cases of attempted misuse).
4.2. Provision and operation of the B2B platform services
Processing of platform user business contact and account data to create and administer company user accounts and enable core service functionality (e.g. business email, name, title/position, phone, login username).
------
Details
Legal basis: Art. 6(1)(f) GDPR (legitimate interests – conducting and managing B2B service relationships and providing the service)
Categories of recipients: Internal authorized staff, service providers/processors supporting hosting, maintenance and service delivery, other users within the same company account (as part of platform functionality).
Transfers to third countries: USA, Commission (EU) Implementing Decision 2023/1795 of 10 July 2023
Retention period: Business relationship personal data: 5 years after termination of the business relationship or until all obligations are settled (whichever is later), when acting as controller: erasure within max. 30 days after account closure/erasure request, backups up to 180 days, invoices up to 10 years due to legal requirements.
4.3. Service communications and system event notifications
Use of contact details to send operational communications and system notifications related to platform use (e.g. email notifications about system events such as receiving a document).
------
Details
Legal basis: Art. 6(1)(f) GDPR (legitimate interests – ensuring reliable operation of the service and informing users about service events)
Categories of recipients: Internal authorized staff, email/communication service providers, other users within the same company account where notifications relate to shared workflows.
Retention period: Communication data is retained for the duration of the business relationship and for 1 year thereafter. System logs are retained for 1 year after creation. Logs tied to specific documents (e.g. document audit trails) are retained for the duration of the document retention period.
4.4. Customer support and handling enquiries
Processing of business contact data and account-related information to respond to support requests and provide assistance (e.g. email, name, phone, account identifiers and related service information).
------
Details
Legal basis: Art. 6(1)(f) GDPR (legitimate interests – providing support and maintaining customer relationships in a B2B context)
Categories of recipients: Internal support staff, service providers assisting with support tooling and communications.
Retention period: Support records are retained for 1 year after resolution of the relevant enquiry, or until the end of the business relationship (whichever is later), plus up to 180 days in backup systems.
4.5. Security, authentication and fraud/abuse prevention
Processing of security-related identifiers to secure access, verify logins and prevent misuse (e.g. IP address, phone number for confirmation codes, login username, timestamps).
------
Details
Legal basis: Art. 6(1)(f) GDPR (legitimate interests – ensuring network and information security and preventing unauthorized access)
Categories of recipients: Internal security/IT staff, service providers supporting security, hosting and authentication systems.
Transfers to third countries: USA, Commission (EU) Implementing Decision 2023/1795 of 10 July 2023
Retention period: Secure usage data retained for 1 year after collection, audit log data may be kept longer and follows the lifecycle of the related entity (e.g. personal login or uploaded content). Backups up to 180 days.
4.6. Audit Logging and Accountability within the platform
Processing of user identifiers for logging and auditing actions in the platform to ensure traceability and accountability (e.g. name, title, login username, IP address, timestamps, filenames, document audit log entries).
------
Details
Legal basis: Art. 6(1)(f) GDPR (legitimate interests – maintaining audit trails, accountability and integrity of platform operations)
Categories of recipients: Internal authorized staff, service providers supporting logging and infrastructure, other users within the same company account where audit trails are visible as part of platform functionality.
Retention period: Audit log data is retained for up to 3 years after the date of the relevant action, or for the duration of the retention period of the related document (whichever is longer). General website visit data: until the end of the session. In cases of detected abuse or attempted abuse, IP addresses and related security data are retained permanently.
The retention periods stated above apply where CargoX acts as controller. Where CargoX processes audit log data on behalf of a customer as a processor, such data is deleted or returned upon termination of the relevant agreement, in accordance with the customer's instructions and the applicable data processing agreement.
4.7. Analytics and Service Improvement (Usage Monitoring)
Collection and analysis of usage and diagnostic data to monitor service performance and improve the service (e.g. cookie data, usage data such as hashed/partial IP address, browser type/version, pages visited, time/date, time spent, device identifiers).
------
Details
Legal basis: Art. 6(1)(f) GDPR (legitimate interests – measuring usage, improving service quality and performance)
Categories of recipients: Internal product/engineering staff, analytics and infrastructure service providers.
Retention period: Usage data retained for 30 days after collection, aggregated and anonymized data may be retained indefinitely.
4.8. Marketing communications (newsletters and promotional messages)
Use of contact details to send newsletters, marketing or promotional materials and information about goods, services and events (e.g. email, name), where the recipient has given consent.
------
Details
Legal basis: Art. 6(1)(a) GDPR (consent)
Categories of recipients: Internal marketing staff, email marketing/communication service providers, mass email providers.
Retention period: Until withdrawal of consent. All other marketing-related personal data is erased within 30 days of withdrawal.
4.9. Processing of Uploaded Content to Deliver Services
Processing of uploaded content and associated metadata to provide platform services and enable document-related workflows (content may include personal data depending on what users upload).
------
Details
Legal basis: Art. 6(1)(f) GDPR (legitimate interests – providing B2B document and workflow services and operating the platform)
Categories of recipients: Internal authorized staff (as needed for service delivery), service providers/processors supporting hosting and storage, parties with whom documents are shared through the platform.
Retention period: Uploaded content available on the platform for 10 years after creation during the account term, erasure from servers 30 days after account closure, but may be retained longer due to legal requirements and/or where shared with another party that keeps an account, business content for agreement/tax purposes up to 10 years, other business content 5 years.
4.10. Legal Compliance and Responding to Lawful Requests
Processing and disclosure of personal data to comply with legal obligations and respond to valid requests by public authorities (e.g. disclosures for law enforcement, court orders).
------
Details
Legal basis: Art. 6(1)(c) GDPR (legal obligation)
Categories of recipients: Public authorities (e.g. courts, government agencies), legal advisors and relevant service providers as necessary.
Transfers to third countries: Personal data may be transferred to public authorities, courts or law enforcement bodies located outside the European Economic Area where such transfer is required to comply with applicable legal obligations or to respond to valid and lawful requests from competent authorities. Such transfers will take place only where permitted under applicable data protection laws and, where required, appropriate safeguards will be applied in accordance with Chapter V of the GDPR.
Retention period: As required by applicable law. Invoices, agreements and related tax/accounting documents: up to 10 years (Article 86 of the Slovenian Tax Procedure Act). Data required for ongoing legal proceedings or regulatory investigations: for the duration of such proceedings plus 1 year following final resolution. Other data: for the period specified by the applicable legal obligation.
4.11. If you Contact Us via the Contact Form
We welcome every message from you. In such a case, our communication will be conducted on the basis of our legitimate interest, namely the controller’s interest in communicating with the public. If you do not wish to disclose your personal data to us, we will unfortunately not be able to respond to your enquiry. You may discontinue communication at any time (by notifying us accordingly), which will consequently also mean that we will erase your personal data.
------
Details
Legal basis: legitimate interest (communication with the general public) – Article 6(1)(f) GDPR.
Categories of recipients: website hosting provider.
Retention period: until the conclusion of communication. You may request the discontinuation of communication at any time – consequently, we will irreversibly destroy your personal data (provided that no further legal basis exists for their continued processing).
4.12. Web Analytics and Marketing
We carry out web analytics and marketing on our websites through the use of cookies and exclusively on the basis of your explicit consent.
Information about cookies and their settings can be found on our website.
------
Details
Legal basis: consent (Article 6(1)(a) GDPR) – exclusively on the basis of your explicit consent to the placement of cookies.
Categories of recipients: web analytics provider, advertising platform provider.
Retention period: until consent is withdrawn.
5. Service Providers
We may employ third party companies and individuals to facilitate our service (“Service providers”), provide the service on our behalf, perform service-related services or assist us in analysing how our service is used.
These third parties have access to your personal data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
6. Children's Privacy
Our service does not address anyone under the age of 18 (“Children”).
We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian, and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from children without verification of parental consent, we take steps to remove that information from our servers.
7. Links to Other Sites
Our service may contain links to other sites that are not operated by us. If you click a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility whatsoever for the content, privacy policies or practices of any third party sites or services.
8. Changes to this Privacy Notice
We may update our Privacy Notice from time to time. We will notify you of any changes at least 30 days before the new Privacy Notice takes effect.
9. Contact Us
If you have any questions about this Privacy Notice, please contact us by email at [email protected]. The Data Protection Officer may be contacted at [email protected].
Effective date: November 10th, 2026
As of the date on which this Privacy Notice enters into force, Privacy Policy 2.0 ceases to apply.