1. Parties, Scope and How It Takes Effect
This Data Processing Agreement (the "DPA") is made between:
The Customer, the company that has signed up to use CargoGauge, acting as the controller; and
CargoGauge, CVR 42423432, Thomas Laubs Gade 23, 2100 Copenhagen, Denmark, acting as the processor.
It applies to all personal data that CargoGauge processes on the Customer's behalf under the Terms of Service (the "Agreement"), and it forms part of that Agreement. Where the two conflict on a question of data protection, this DPA prevails.
It does not cover the data for which CargoGauge is itself the controller: platform logins, the driver sign-in register, our security records and this website. Those are described in section 2.2 of the Privacy Policy and are governed by that notice, not by this agreement.
To have it countersigned, or to ask a question about it before you buy, write to sales@cargogauge.com. For anything to do with its operation once you are a customer, privacy@cargogauge.com.
2. Subject Matter, Duration, Nature and Purpose
| Required by Art. 28(3) | For this agreement |
|---|---|
| Subject matter | Provision of the CargoGauge logistics platform: dispatch, driver communication, live position tracking during a trip, arrival time calculation, proof of delivery and the reporting built on those. |
| Duration | The term of the Agreement, plus the wind-down period in section 11. |
| Nature of the processing | Collection, recording, storage, organisation, consultation, use, transmission to the recipients in section 8, restriction, erasure and destruction, all by automated means. |
| Purpose | Solely to deliver, support and secure the platform for the Customer, and for nothing of CargoGauge's own beyond what section 4 permits. |
| Types of personal data | Annex 1. |
| Categories of data subjects | Annex 1. |
3. Roles
The Customer decides which drivers and users exist in its account, which trips are planned and tracked, and what is recorded against them. The Customer is therefore the controller and is responsible for having a lawful basis for that processing, for informing its own drivers and staff, and for the accuracy and lawfulness of the instructions it gives. CargoGauge acts only as processor for that data.
Where the Customer is itself acting as a processor for someone else, references to "controller" in this DPA are read accordingly and CargoGauge is a sub-processor.
4. Processing Only on Documented Instructions
CargoGauge processes the Customer's personal data only on the Customer's documented instructions, including as to transfers to a third country, unless EU or Danish law requires otherwise. Where such a law applies, CargoGauge informs the Customer before processing, unless that law forbids the notification on important grounds of public interest.
The Customer's documented instructions consist of:
- this DPA and the Agreement;
- the configuration the Customer chooses in the platform, and the actions its users take in it;
- any further written instruction the Customer gives, which CargoGauge will follow where it is within the platform's capability and lawful. Where an instruction requires work outside the ordinary operation of the service, CargoGauge may charge for the effort and will say so in advance.
If CargoGauge considers an instruction to infringe the GDPR or other EU or member-state data protection law, it will say so immediately rather than carry it out quietly (Art. 28(3), final paragraph).
The one thing CargoGauge does with Customer data for its own purposes is described in section 7 of the Privacy Policy: position data is aggregated into statistics about stretches of road, so that arrival time predictions improve. Those statistics carry no driver, vehicle, company or trip and cannot be traced back to an individual or a journey. CargoGauge does not otherwise use Customer data for its own purposes, and does not sell it.
5. Confidentiality of Personnel
CargoGauge ensures that every person authorised to process the Customer's personal data is bound by an obligation of confidentiality, by contract of employment or engagement, and that the obligation survives the end of their engagement. Access to production data is limited to the people who operate the service and is granted on need rather than by role or seniority.
6. Security of Processing (Art. 32)
CargoGauge implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The current measures are listed in section 9 of the Privacy Policy, which is maintained as the single description of them and forms Annex 2 to this DPA. They are summarised there rather than repeated here, so that one description cannot drift out of step with another.
That section also states plainly what CargoGauge does not do, and the Customer should read it as part of its own assessment. CargoGauge may change a measure, but not in a way that materially reduces the overall level of security.
7. Sub-Processors
The Customer gives general written authorisation for CargoGauge to engage sub-processors, on the terms in this section.
- The current list is Annex 3, below, and is the same list published as section 10 of the Privacy Policy, where what each one receives is described in detail.
- CargoGauge imposes on every sub-processor, by contract, data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the sub-processor's performance.
- Change notice. CargoGauge informs the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance, by email to the Customer's administrative contact.
- Objection. The Customer may object on reasonable data protection grounds within those 30 days. CargoGauge will then work with the Customer to find a solution. If none can be found, the Customer may terminate the affected part of the service without penalty, with a pro rata refund of anything paid for a period after termination.
- Where a change is forced on CargoGauge at short notice, for example by a provider withdrawing a service, CargoGauge informs the Customer as soon as it can and the objection right applies from that notice.
8. International Transfers
The Customer's personal data is stored and processed in the European Union. There is one transfer outside it: delivery of push notifications to the driver app through Google's Firebase Cloud Messaging in the United States. What that transfer carries, what it does not carry by default, and the safeguards relied on are set out in section 11 of the Privacy Policy.
CargoGauge will not begin any further transfer outside the EU or EEA without first informing the Customer and putting a transfer mechanism recognised by Chapter V of the GDPR in place.
9. Assistance with Data Subject Rights
Taking into account the nature of the processing, CargoGauge assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to requests under Chapter III of the GDPR (Art. 28(3)(e)).
- Requests that reach us first. Where a data subject approaches CargoGauge about data the Customer controls, CargoGauge does not answer on the Customer's behalf. It identifies the controller, forwards the request to the Customer, tells the data subject that it has done so, and then acts on the Customer's instruction.
- Access and portability. On the Customer's request, CargoGauge produces everything the platform holds about one named person as a single machine-readable file, or the same for the whole account. There is no self-service button for this today: it is produced by us, on request, and that is a deliberate control, because the export discloses personal data and we want a human decision behind each one.
- Rectification. Ordinary corrections are made by the Customer in the platform, which is faster than asking us and leaves the record with the party that owns it.
- Erasure. On the Customer's instruction, CargoGauge removes what identifies a person while keeping the operational record of the work, as described in section 7 of the Privacy Policy. Where the Customer instructs a removal that the platform cannot perform without destroying records the Customer or CargoGauge must keep, CargoGauge says so rather than doing it.
- Restriction and objection. CargoGauge assists by deactivating the subject in the platform so that no scheduling, notification or assignment reaches them, and by recording the restriction so it is visible to anyone looking at the account.
- Each of these actions is recorded in CargoGauge's audit log, so that the Customer can be shown what was done and when, which is what Art. 5(2) asks the Customer to be able to demonstrate.
Assistance with an ordinary volume of requests is included in the subscription. CargoGauge may charge for assistance that is disproportionate in volume or effort, and will say so before doing the work.
10. Assistance with Articles 32 to 36
- Security (Art. 32). CargoGauge maintains the measures in section 6 and provides the information the Customer reasonably needs to assess them.
- Breach notification (Art. 33). CargoGauge notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provides, as it becomes available, the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed. The notification to the supervisory authority is the Customer's to make, as controller; CargoGauge gives the Customer what it needs to make it within the Customer's own 72 hour deadline.
- Communication to data subjects (Art. 34). CargoGauge assists the Customer in making any communication that is required, and will not communicate with the Customer's data subjects about a breach without the Customer's agreement, except where CargoGauge is itself the controller of the data involved.
- Impact assessments and prior consultation (Art. 35 and 36). CargoGauge provides the information about the platform that the Customer needs to carry out a data protection impact assessment and, where required, to consult its supervisory authority. Location tracking of employees is a processing operation that often calls for such an assessment; the Customer should expect to do one and CargoGauge will support it.
11. Deletion or Return at the End of the Contract
At the Customer's choice, CargoGauge deletes or returns all the personal data it processes for the Customer after the end of the Agreement, and deletes existing copies, unless EU or Danish law requires storage (Art. 28(3)(g)).
In practice that means:
- Return. Before deletion, CargoGauge produces a machine-readable export of the Customer's data, on request. Ask for it before the account is purged: after the purge there is nothing to export from.
- Deletion. The account is purged as a single operation that removes the Customer's records across the platform. It reports what it removed, table by table, so the deletion can be evidenced rather than asserted.
- Uploaded files. Images such as driver photographs and company logos live in a file store that the database purge cannot reach. The purge therefore hands back the exact list of stored files to delete, and they are deleted as a second step. This is described here because a purge that quietly left photographs behind would be the easiest thing in the world to miss.
- Timing. Unless the Customer asks for something different in writing, deletion happens within 30 days of the end of the Agreement, after the Customer has had the opportunity to take its export.
12. Audit and Inspection
CargoGauge makes available to the Customer all information necessary to demonstrate compliance with Art. 28, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates (Art. 28(3)(h)).
- CargoGauge will answer a written audit questionnaire and provide its documentation. In many cases that, together with this page and section 9 of the Privacy Policy, is enough, and it is the quickest route for both sides.
- Where it is not enough, the Customer may conduct an inspection on 30 days written notice, during business hours, no more than once in any 12 month period, and without unreasonable disruption to the service. That limit does not apply after a personal data breach affecting the Customer, or where a supervisory authority requires an audit.
- The auditor must not be a competitor of CargoGauge and must be bound by confidentiality. Nothing in an audit entitles anyone to see another customer's data, and CargoGauge will refuse a request that would expose it.
- The Customer bears its own costs and the reasonable cost of CargoGauge's time, except where the audit finds a material breach of this DPA.
13. Liability, Precedence and Governing Law
The limitations and exclusions of liability in the Agreement apply to this DPA, except where the GDPR does not permit them to. This DPA prevails over the Agreement on any question of data protection, and over any conflicting term in a purchase order or other document, unless the parties have agreed otherwise in a signed writing that refers to this DPA.
This DPA is governed by Danish law, and disputes are resolved in the Danish courts, as provided in the Agreement.
Annex 1: Details of the Processing
Categories of data subjects
- Drivers employed by the Customer
- Drivers employed by the Customer's subcontractors, where the Customer works with them in the platform
- The Customer's own staff who use the operator dashboard
- Staff of the Customer's subcontractors who use the partner portal
- The contact person recorded for a subcontractor company, where that contact is an individual
Delivery sites are recorded as a name and an address, not as a named person, so they are not ordinarily personal data. A Customer that types a person's name into one of those fields makes it personal data, and section 3 puts that on the Customer.
Types of personal data
- Identity and contact: name, email address, telephone number
- Driver qualification: driving licence number and expiry date, and driver documents the Customer uploads
- Image: a photograph of the driver, where one has been uploaded
- Employment context: which company or subcontractor the person belongs to, and their role
- Location and telemetry: position, accuracy, speed and heading recorded while a trip is dispatched or running, and the timestamps that go with them
- Work records: trips, stops, planned and actual arrival and departure times, delivery confirmations and the events that make up a trip
- Device and delivery: push notification tokens for the driver app and the record of notifications sent
- Account usage: sign-in times, and records of actions taken in the platform
The platform is not designed for special categories of personal data under Art. 9, and the Customer should not enter any. Free-text fields will accept anything typed into them; what is typed is the Customer's responsibility.
Frequency and duration
Continuous for the term of the Agreement. Position data is recorded at intervals only while a trip is dispatched or running, and the server rejects a position offered against a trip in any other state.
Retention
Per category, as set out in the retention table in section 7 of the Privacy Policy, which is the single published statement of those periods, and subject to section 11 above at the end of the contract.
Annex 2: Technical and Organisational Measures
Section 9 of the Privacy Policy, as amended from time to time, is Annex 2 to this DPA. It is kept there rather than copied here so that there is one description of the measures and not two that disagree. It lists what is in place and, equally deliberately, what is not.
Annex 3: Approved Sub-Processors
The list below is current as at the date at the top of this page. Section 10 of the Privacy Policy carries the same list with a description of what each one receives and on what safeguard.
| Sub-processor | Function | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the servers and the database | Finland (EU) |
| TomTom | Live and historic traffic used to calculate arrival times | Netherlands (EU) |
| MapTiler | Map imagery in the dashboard, and address lookup | Switzerland (adequacy decision) |
| Brevo | Email delivery | France (EU) |
| GatewayAPI | SMS delivery, including driver sign-in codes | Denmark (EU) |
| Push notification delivery to the driver app, through Firebase Cloud Messaging | United States (see section 8) |
Signing, and questions
Before you buy: sales@cargogauge.com
Once you are a customer: privacy@cargogauge.com
We will countersign this document as it stands. If your legal team needs changes, send them and we will read them; we will not pretend that a template we cannot honour is better than an agreement we can.