1. Application and definitions
This Data Processing Addendum forms part of the agreement between the Customer and the provider identified in the Legal Notice whenever we process personal data on the Customer's behalf in connection with LogisticsAI. GDPR terms such as controller, processor, personal data, processing and personal data breach have their GDPR meanings. Customer Personal Data means personal data contained in Customer Data that we process as processor.
2. Roles and documented instructions
The Customer is controller and we are processor for Customer Personal Data. Each party remains responsible for its own controller activities. We process Customer Personal Data only on documented instructions contained in the agreement, product configuration and authorized support requests, including transfers needed to provide the service, unless EU or Member State law requires otherwise. If legally permitted, we will inform the Customer before required processing.
We will promptly inform the Customer if, in our opinion, an instruction infringes applicable data-protection law and may suspend the affected processing until the instruction is clarified or lawfully modified.
3. Customer obligations
The Customer is responsible for the lawfulness, fairness and transparency of collection and instructions; accuracy and minimization of Customer Personal Data; responding to data subjects; and configuring access and retention. The Customer will not submit special-category or criminal-offence data unless expressly agreed with documented safeguards.
4. Confidentiality and personnel
We ensure that persons authorized to process Customer Personal Data are bound by confidentiality and receive access only as necessary for their duties.
5. Security measures
Taking account of the state of the art, implementation costs, processing context and risk, we maintain appropriate technical and organizational measures. These include authenticated access, organization-scoped authorization and database policies, private storage, encryption in transit, restricted production credentials, logging and audit trails, backups, dependency and incident processes, and deletion controls. Measures may evolve without materially reducing the overall level of protection.
6. Subprocessors
The Customer gives general authorization to use subprocessors necessary to provide the service. Current categories and providers include Supabase for database, authentication and storage; Vercel for hosting and delivery; OpenAI for enabled AI document and data processing; Sentry for diagnostics; ImprovMX for transactional email and domain forwarding; and PostHog or Crisp only for enabled optional functions where they process Customer Personal Data on our behalf.
Lemon Squeezy or another merchant of record generally acts under its own responsibilities for payment, invoicing, tax and fraud processing and is not treated as our subprocessor for those independent activities. We will impose data-protection obligations on subprocessors as required by Article 28 GDPR and remain responsible for their performance to the extent required by law.
We will provide reasonable notice of a new subprocessor that materially processes Customer Personal Data. The Customer may object on reasonable data-protection grounds before use begins. The parties will seek a practical solution; if none is available, either party may terminate the affected feature without penalty.
7. International transfers
Where Customer Personal Data is transferred outside the EEA without an adequacy decision, we will use the European Commission's Standard Contractual Clauses or another lawful mechanism and apply supplementary measures where appropriate. The applicable SCC module and annexes for each transfer chain are incorporated where required. The Customer authorizes transfers described in the agreement and subprocessor information.
8. Data subject requests
Taking account of the nature of processing, we will provide reasonable assistance through product functionality and support so the Customer can respond to requests under Chapter III GDPR. If we receive a request relating to Customer Personal Data, we will direct it to the Customer and will not respond substantively unless instructed or legally required.
9. Breach notification
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, notice will describe the nature of the breach, likely consequences, affected categories where known, mitigation and a contact point. Notification is not an admission of fault. The Customer is responsible for regulatory and data-subject notifications as controller.
10. Assistance and compliance information
Taking account of the processing and information available to us, we will reasonably assist with security obligations, breach assessments, data-protection impact assessments and prior consultations. We will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR.
11. Audits
The Customer may no more than once annually, and additionally after a substantiated material incident, request relevant compliance information or an audit by an independent qualified auditor. Audits require reasonable advance notice, must avoid access to other customers' data and unnecessary disruption, and are subject to confidentiality. The Customer bears its audit costs unless the audit identifies our material breach. Certifications and recent independent reports may satisfy an audit request where appropriate.
12. Return and deletion
At the Customer's choice, we will return or delete Customer Personal Data after the end of services and delete remaining copies, unless applicable law requires retention. Content-free deletion records, security logs and backups may remain for documented limited periods and will be isolated from ordinary use. The Customer should export required data before account closure.
13. Processing details
Subject matter: hosted logistics document extraction, workflow, evidence and reporting services. Duration: the agreement term plus limited deletion and backup periods. Nature and purpose: upload, storage, organization, extraction, transformation, human review, export, support, security and deletion according to Customer instructions.
Data subjects may include Customer users, employees, drivers, subcontractors, business contacts and persons named in operational documents. Data may include identity and contact details, workplace role, vehicle or permit information, routes, shipment references, document contents, account identifiers, review history and technical metadata. Sensitive data is not intended. Processing frequency depends on Customer use.
14. Liability, priority and termination
Liability under this Addendum follows the agreement, without limiting rights or liabilities that mandatory data-protection law does not permit the parties to limit. If this Addendum conflicts with the Terms on personal-data processing, this Addendum prevails. It ends when we no longer process Customer Personal Data, except provisions intended to survive.
Contact
- Support
- support@logisticsai.eu
- Legal notices
- legal@logisticsai.eu
- Privacy requests
- privacy@logisticsai.eu