Data Processing Addendum
This Data Processing Addendum ("DPA") applies when Gant Technology Group LLC d/b/a CargoFlow processes personal data on behalf of a customer in connection with the CargoFlow service.
1. Scope and relationship to the Customer Agreement
This DPA forms part of the Customer Subscription & Services Agreement or other written agreement governing Customer's use of CargoFlow ("Customer Agreement"). It applies only to personal data that CargoFlow processes on Customer's behalf as a processor, service provider, or equivalent role under applicable privacy law ("Customer Personal Data").
If this DPA conflicts with the Customer Agreement on the processing of Customer Personal Data, this DPA controls for that subject. Customer-specific signed privacy terms may modify this DPA.
2. Roles
Customer determines the purposes and means of processing Customer Personal Data and acts as controller, business, or equivalent role under applicable law. CargoFlow acts as processor, service provider, contractor, or equivalent role for Customer Personal Data to the extent the law recognizes those roles.
CargoFlow may separately act as an independent controller for limited information it processes for its own account security, fraud prevention, legal compliance, direct business relationship administration, and service operations as described in the Privacy Policy.
3. Processing instructions
CargoFlow will process Customer Personal Data only on Customer's documented instructions, including the Customer Agreement, authorized configuration, user actions, support requests, and other lawful written instructions, unless law requires otherwise. If legally permitted, CargoFlow will notify Customer before processing required solely by law.
CargoFlow will not sell Customer Personal Data or use it for cross-context behavioral advertising or targeted advertising. CargoFlow will not retain, use, or disclose Customer Personal Data outside the direct business relationship except as permitted by the Customer Agreement, this DPA, Customer's instructions, or applicable law.
To the extent applicable privacy law imposes service-provider or contractor restrictions, CargoFlow will not combine Customer Personal Data received from or on behalf of Customer with personal data received from another person or collected from CargoFlow's own interaction with an individual except where that combination is permitted by applicable law and is necessary for an authorized business purpose or Customer instruction.
4. Nature and purpose of processing
CargoFlow may collect, receive, organize, structure, store, retrieve, display, transmit, secure, back up, delete, and otherwise process Customer Personal Data to provide freight-operations software, shipment workflows, collaboration, documents, alerts, portals, reporting, integrations, account administration, support, security, and related contracted functionality.
5. Processing details and duration
Subject matter. Customer Personal Data processed through the CargoFlow freight-operations service and customer-authorized integrations.
Duration. Processing continues for the subscription or service relationship and any limited post-termination period needed for Customer-authorized export, legal obligations, security, dispute preservation, or backup and recovery cycles, subject to Section 13.
Nature and frequency. Processing may occur on an ongoing basis as authorized users create, view, update, share, upload, download, classify, communicate about, track, bill, report on, or otherwise operate Customer records through the service.
Purposes. Purposes can include shipment management, tracking and milestones, customer portals, document storage and security screening, email and communication workflows, rates and billing readiness, handoffs and collaboration, reporting, account administration, support, fraud and abuse prevention, security, audit history, and other functionality ordered or enabled by Customer.
Smart Paste currently performs supported field recognition through application logic and does not require transfer of the pasted text to a third-party general-purpose AI model. If a future material feature changes that processing model, CargoFlow will update the applicable disclosures and contractual terms before relying on the new processing for Customer Personal Data where required.
6. Categories of data and people
Depending on Customer's use, Customer Personal Data may include business contact information; user identity and account information; logistics contacts; shipper, consignee, carrier, broker, warehouse, customer, and vendor contacts; shipment references and operational notes; communications; uploaded business documents; audit and security events; and similar business records.
Data subjects may include Customer personnel, Customer's customers, suppliers, logistics providers, business contacts, portal users, and other individuals whose business information is included in Customer-authorized records. Customer should not use CargoFlow for highly sensitive personal data that the service is not designed to store unless the parties expressly agree in writing.
7. Confidentiality
CargoFlow will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access restrictions. Access will be limited to personnel and service providers who need the information for authorized service, security, support, or legal purposes.
8. Security measures
CargoFlow will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Personal Data against unauthorized access, acquisition, alteration, disclosure, loss, or destruction, taking into account the nature of the data and service.
Measures may include role and tenant authorization, secure authentication, administrator multi-factor authentication, encrypted transport, restrictive security headers, activity and security-event records, protection of connected-service credentials, backups and recovery controls, vulnerability and dependency management, and access limitation based on legitimate business need.
Customer remains responsible for its own endpoints, networks, identity lifecycle, role assignments, user training, internal policies, and decisions about what information to submit.
9. Security incidents
CargoFlow will notify Customer without undue delay after confirming a security incident that results in unauthorized access to, acquisition of, disclosure of, loss of, or material compromise of Customer Personal Data for which notification to Customer is required under the Customer Agreement or applicable law ("Security Incident"). Where applicable law or a signed customer agreement requires a shorter notification timing, CargoFlow will follow that requirement.
The notice will include information reasonably available to CargoFlow about the nature of the incident, affected data or systems, containment or remediation steps, and a contact for follow-up. Notification is not an admission of fault or liability. Unsuccessful attempts or events that do not compromise Customer Personal Data are not Security Incidents for purposes of this section.
10. Subprocessors
Customer authorizes CargoFlow to use subprocessors needed to provide the service, including providers of cloud hosting, databases, messaging or queue infrastructure, email or communications, security, authentication, support tooling, and Customer-authorized integrations.
CargoFlow will require subprocessors that process Customer Personal Data to protect the data through contractual or other legally appropriate obligations materially consistent with CargoFlow's responsibilities for the services they perform. CargoFlow remains responsible for its subprocessors to the extent required by applicable law and the Customer Agreement.
The current public provider disclosure is available at Subprocessors & Connected Services. Customer may request additional information about material subprocessors by contacting contact@cargoflowdg.com. If a Customer reasonably objects to a new material subprocessor on documented privacy or security grounds, the parties will work in good faith on a commercially reasonable solution.
11. Data subject requests
Taking into account the nature of the processing, CargoFlow will provide reasonable assistance to Customer in responding to legally valid requests by individuals to exercise privacy rights for Customer Personal Data. CargoFlow may direct a requester to Customer when Customer controls the relevant data and instructions.
If CargoFlow receives a request directly concerning Customer Personal Data, CargoFlow may notify Customer and will not independently fulfill the request except on Customer's instructions or where law requires CargoFlow to do so.
12. Compliance assistance
Taking into account the information available to CargoFlow and the nature of the service, CargoFlow will provide reasonable information needed for Customer's legally required data-protection assessments, breach-response obligations, or regulator inquiries relating specifically to CargoFlow's processing of Customer Personal Data.
Assistance that requires substantial custom work beyond normal service and compliance support may be subject to reasonable fees if permitted by the Customer Agreement and agreed in advance.
13. Return and deletion
During the subscription, Customer may use available export and deletion features subject to role, security, and records-integrity controls. After termination, CargoFlow will delete or return Customer Personal Data in accordance with the Customer Agreement, Customer's lawful instructions, and applicable law.
CargoFlow may retain information where required for legal obligations, security records, dispute preservation, fraud prevention, or backup and disaster-recovery cycles. Retained information remains protected and is not returned to ordinary production use solely because it remains in a protected backup.
14. International transfers
CargoFlow is designed primarily for United States business operations. If Customer introduces personal data that requires an international transfer mechanism, the parties will cooperate in good faith to implement legally required safeguards before or as required for that regulated processing. A separate signed addendum may be required for particular jurisdictions.
15. Audit information
Upon reasonable written request, CargoFlow will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, privilege, and protection of other customers. Where documentation is insufficient and applicable law requires an audit or monitoring right, the parties will agree on a reasonable scope, timing, confidentiality protections, and method that minimizes disruption and avoids exposing other customers' information or sensitive security details.
Where applicable privacy law requires it, CargoFlow will notify Customer if CargoFlow determines that it can no longer meet a legally required service-provider or processor obligation relating to Customer Personal Data. Customer may then take reasonable and appropriate steps, consistent with applicable law and the Customer Agreement, to verify, stop, or remediate an unauthorized use of Customer Personal Data.
16. Customer instructions and legality
Customer is responsible for the lawfulness of Customer Personal Data, Customer's instructions, required notices or consents, data minimization, and the legal basis for processing. If CargoFlow reasonably believes an instruction violates applicable privacy law, CargoFlow may pause the affected processing and notify Customer so the parties can address the issue.
17. Term and survival
This DPA remains in effect while CargoFlow processes Customer Personal Data under the Customer Agreement. Confidentiality, security, deletion, and other obligations that by their nature continue after termination survive for as long as CargoFlow retains Customer Personal Data.
18. Contact
Privacy and DPA questions may be sent to contact@cargoflowdg.com. Individual privacy requests may also be submitted through Data & Account Removal or to support@cargoflowdg.com.