Privacy Policy 2.0

1. Privacy policy

1.1. General

CargoX ("us", "we", or "our") operates the following services (as defined in General Terms and Conditions). By using CargoX services, you agree to this Privacy Policy.

This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our service and the choices you have associated with that data.

We use your data to provide and improve the service. By using the service, you agree to the collection and use of information in accordance with this Policy. Unless otherwise defined in this Privacy Policy, the terms used in this Privacy Policy have the same meanings as in our:

1.2. Definition of terms

Anonymization of data
A data processing technique that removes or modifies personally identifiable information; it results in anonymized data that cannot be associated with any one individual.

CargoX, We, Our, Us
Represents CargoX d.o.o., incorporated in Ljubljana, Slovenia.

Data controller
Data controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information is, or is to be, processed.

Data management
The practice of collecting, organising, and accessing data to support productivity, efficiency, and decision-making.

Data processors, Service providers
Data processor (or service provider) means any natural or legal person who processes the data on behalf of the data controller.

We may use the services of various service providers in order to process your data more effectively.

Data Subject, User, You
Data subject is any living individual who is using our service and is the subject of personal data.

Directive 95/46/EC (General Data Protection Regulation).

Natural person
A natural person is a title used to identify an individual human being.

Personal data
Personal data means data about a living individual who can be identified from that data (or from other information either in our possession or likely to come into our possession).

Usage data
Usage data represents the data on how you use the service and cannot be linked back to any specific individual. The data collected is either completely anonymized or pseudo-anonymized.

Secure usage data
Secure usage data represents information which we collect to improve and monitor security. It may include personally identifiable information, such as email addresses used for login, IP number and similar.

Standard contractual clauses for data transfers between EU and non-EU countries, “pre-approved” by the European Commission.

Service is any service operated by CargoX, as explained above.

2. Information collection and use

We collect several types of information for various purposes to provide and improve our service to you.

2.1. Data controller vs. Data processor

Based on the Service you use, CargoX may be a Data controller or a Data processor. For further enquiries, contact [email protected].

2.2. Types of data collected

2.2.1. Personal data

While using our service, we may ask you or the administrator for your company’s account to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal data”). Personally identifiable information may include, but is not limited to:

  • (Business) Email address,

  • First name and last name, and your title / position within the company,

  • Phone number,

  • Cookies and usage data,

  • IP (Internet Protocol) address.

We may use your personal data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you, if you have opted in for such communication. You may opt out of receiving any, or all, of these communications from us by contacting us.

Your personal data, such as your email, will be used to notify you of system events -- for example when receiving a document through the platform. Other users of the platform from the same company will have access to your personal data and this access cannot be revoked, as it is required for the proper functioning of the platform.

We collect IP addresses and phone numbers for security purposes (to show the log of logins and send confirmation codes).

A natural person’s name and title is used for display purposes to other users of the platform (in the same company) as well as for logging and auditing purposes (e.g. on the audit log of the document).

2.2.2. Uploaded content

We process uploaded content according to the General terms and conditions. Please refer to the GT&C for more information.

2.2.3. Usage data

We may also collect anonymized or pseudo-anonymized information on how the service is accessed and used ("Usage data"). This usage data may include information such as part of or hash of your computer's IP address, browser type, browser version, the pages of our service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

Usage data is data collected automatically. It is either generated by the use of the service or from the service infrastructure itself (for example from server logs). You may opt out of certain data collections by disabling and/or refusing non-essential cookies.

2.2.4. Secure usage data

For security and auditing purposes we may collect personally identifiable information, such as login username, IP address, timestamp, service used, and filenames.

2.3. Use of data

2.3.1. Personal data

CargoX uses the collected data for various purposes:

  • To provide and maintain our service;

  • To notify you about changes to our service;

  • To allow you to participate in interactive features of our service when you choose to do so;

  • To provide customer support;

  • To gather analysis or valuable information so that we can improve our service;

  • To monitor the usage of our service;

  • To detect, prevent and address technical issues;

  • To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information.

Personal data may be transferred to other countries for the purpose of this service. There might be additional limitations on the transfer of personal data based on your local jurisdictions.

CargoX may not rent, barter, trade, sell, loan or lease your individual information.

2.3.2. Uploaded content

CargoX may use your uploaded content to provide you with services and in conjunction with the services. Further details are available in our General terms and conditions.

3. Legal basis for processing personal data under the General data protection regulation (GDPR)

If you are from the European Economic Area (EEA), CargoX's legal basis for collecting and using the personal information described in this Privacy Policy depends on the personal data we collect and the specific context in which we collect it.

CargoX may process your personal data because:

  • You have given us permission to do so to provide the services;

  • We need to perform a contract with you;

  • To comply with the law or public interest and requirements of jurisdictions;

  • The processing is in our legitimate interests, and it is not overridden by your rights.

4. Data retention

4.1. Personal data

Personal data entered as business relationship data between your company and CargoX will be stored for 5 years after termination of business relationship or until all business obligations are settled, whatever comes later.

When acting as a data controller, CargoX will delete your personal data at most 30 days after you close your account or request deletion or storage of your data. CargoX will delete personal data when acting as a data processor 30 days, at most, after being instructed by the Data Controller.

CargoX may retain personal data in backups for up to 180 days for security and compliance purposes.

CargoX may retain and use your personal data longer, to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes and enforce our legal agreements and policies.

Invoices, agreements, and other documents relating directly to our business relationship will be stored up to 10 years after you close your account or request deletion, due to legal requirements.

4.2. Uploaded content

CargoX guarantees that during the currency of your account the uploaded content is available on the platform for 10 years after creation. CargoX will delete the uploaded content from its servers 30 days after you close the account. CargoX might keep the uploaded content after you have deleted your account in case of legal requirements and/or if you have shared the document with another party, which has not closed the account. In other words, the uploaded content retention plan follows the lifecycle of the document and not the lifecycle of the uploader.

Business content related to the agreement and tax purposes can be stored for up to 10 years, while other business content is stored for 5 years.

4.3. Usage data

CargoX will keep the usage data for 1 year after it has been collected.

4.4. Secure usage data

CargoX will keep the secure usage data for 1 year after it has been collected. Audit log data (e.g. audit log on login and documents) might be kept longer and will follow the lifecycle of the related entity (e.g. Personal login or uploaded content).

4.5. Aggregated data

CargoX reserves the right to keep the aggregated data indefinitely.

5. Transfer of data

CargoX will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your personal data will take place to an organisation or a country unless there are adequate controls in place including the security of your data and other personal information.

Your information, including personal data, may be transferred to — and maintained on — computers located outside your state, province, country or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

If you are located outside the EU and choose to provide information to us, please note that we transfer the data, including personal data, to European Union countries and process it there. Based on local regulations, this provision might not apply to you and your personal data might be stored in your country of residence and transferred to other countries for the purpose of using this service. Check your local laws and regulations.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

6. Disclosure of data

6.1. Business transaction

If CargoX is involved in a merger, acquisition or asset sale, your data (e.g. Personal data, Tracking cookies data, Uploaded content, Usage data, Secure usage data and Aggregated data) may be transferred. We will provide notice before your data is transferred and becomes subject to a different Privacy Policy.

6.2. Disclosure for law enforcement

Under certain circumstances, CargoX may be required to disclose your data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

6.3. Legal requirements

CargoX may disclose your data in the good faith belief that such action is necessary to:

  • To comply with a legal obligation;

  • To protect and defend the rights or property of CargoX;

  • To prevent or investigate possible wrongdoing in connection with the service;

  • To protect the personal safety of users of the service or the public;

  • To protect against legal liability.

7. Our policy on "Do not track" signals

We do not support Do not track ("DNT"). Do not track is a preference you can set in your web browser to inform websites that you do not want to be tracked.

You can enable or disable Do not track by visiting the preferences or settings page of your web browser.

8. Your data protection rights under the General data protection regulation (GDPR)

If you are a resident of the European Economic Area (EEA), you have certain data protection rights. CargoX aims to take reasonable steps to allow you to correct, amend, delete or limit the use of your personal data.

If you wish to be informed about what personal data we hold about you and if you want it to be removed from our systems, please contact us ([email protected]).

In certain circumstances, you have the following data protection rights:

  • The right to access, update or delete the information we have on you. Whenever made possible, you can access, update, or delete your personal data directly within the settings section of the application. If you are unable to perform these actions yourself, your company administrator can do it on your behalf. Failing that, please contact us to assist you. If you have (only) subscribed to our marketing communication, you may request opt-out or removal by following a link in an email or contacting us directly.

  • The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.

  • The right to object. You have the right to object to our processing of your personal data.

  • The right of restriction. You have the right to request that we restrict the processing of your personal information.

  • The right to data portability. You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.

  • The right to withdraw consent. You also have the right to withdraw your consent at any time where CargoX relied on your consent to process your personal information.

Please note that we may ask you to verify your identity before responding to such requests.

You have the right to complain to a Data protection authority about our collection and use of your personal data. For more information, please contact your local data protection authority in the European Economic Area (EEA).

Processing of personal data within service providers may imply transfer of your personal data to third countries according to chapter V of Regulation (EU) 2016/679.

9. Service providers

We may employ third party companies and individuals to facilitate our service (“Service providers”), provide the service on our behalf, perform service-related services or assist us in analysing how our service is used.

These third parties have access to your personal data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Service providers are defined in Standard Contractual Clauses, which are an integral part of this Privacy Policy.

10. Links to other sites

Our service may contain links to other sites that are not operated by us. If you click a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility whatsoever for the content, privacy policies or practices of any third party sites or services.

11. Children's privacy

Our service does not address anyone under the age of 18 (“Children”).

We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian, and you are aware that your child has provided us with personal data, please contact us. If we become aware that we have collected personal data from children without verification of parental consent, we take steps to remove that information from our servers.

12. Changes to this privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes at least 30 days before the new policy takes effect.

13. Contact us

If you have any questions about this Privacy Policy, please contact us by email at [email protected]. Data Processing Officer may be contacted at [email protected].

Effective date: February 19th, 2024