Privacy statement
Which personal data Cargofollow processes, why, for how long, and what your rights are.
This text is a draft. It will be replaced once a lawyer has settled it and until then it is not a binding document.
Who is responsible
Cargofollow is a service of Nytrm. For questions about this statement or about your data, use the contact form on this site.
What we process
From visitors to this site. The site sets no cookies and measures nothing that can be traced to a person. If you fill in the contact form, we process your name, your e-mail address, your company name where you give one, and the text of your message. That message goes straight to our mailbox and is stored nowhere else.
From users of the API. A consignment note contains personal data: names of drivers and contacts, signatures, sometimes a phone number or a photograph of the load. We process that data on instruction from the organisation that creates the shipment. That organisation is the controller; Cargofollow is the processor. What exactly we store and for how long is set out in the data processing agreement and in the API documentation.
Legal basis
For the contact form: your own request to be contacted. For the API: the data processing agreement with the organisation that takes the service.
How long we keep it
Messages from the contact form are kept for as long as the conversation runs and no longer than necessary after that. For data in the API, the retention periods agreed per organisation apply; the consignment note data itself is subject to a statutory retention period that differs per country.
Processors and where the data sits
The service runs on Cloudflare, with storage in the European Union. E-mail goes through Cloudflare Email Routing. Where a shipment is written to an eCMR provider, the data that provider needs goes to that provider.
Your rights
You have the right to access, correct and erase your data, and to object to processing. Where the data sits in a consignment note, that request runs through the organisation that created the shipment — we assist that organisation with it. You may also lodge a complaint with your national data protection authority.
Security
All traffic runs over TLS. Signatures, photographs and documents sit in object storage behind signed links with a short lifetime and a bound audience. Access to the API runs through API keys per organisation.