Privacy Policy — CargoScreen
Controller: social.tech SIA · Reģ.nr. 40203514705 · Augusta Dombrovska iela 75 k-2-8, Rīga, LV-1015, Latvia Service: CargoScreen (cargoscreen.eu) Version: 1.1 · Effective date: 19 Aug 2026 Binding language: Latvian. This English text is the official translation; the Latvian version prevails in case of divergence.
1. Who we are and how to contact us
social.tech SIA ("we", "us", the "Controller") operates CargoScreen and determines the purposes and means of processing personal data described in this Policy.
- Controller: social.tech SIA, Reģ.nr. 40203514705
- Registered office: Augusta Dombrovska iela 75 k-2-8, Rīga, LV-1015, Latvia
- Privacy contact / data protection matters: privacy@cargoscreen.eu
- Data Protection Officer: {DPO — see clause 12: state name/email, or state that no DPO is appointed and why}
This Policy explains what personal data we process, why, on what legal basis, with whom we share it, how long we keep it, and what rights you have, in accordance with Regulation (EU) 2016/679 ("GDPR") and the Latvian Personal Data Processing Law (Fizisko personu datu apstrādes likums).
2. Scope
This Policy applies to personal data we process about: visitors to cargoscreen.eu; registered Users of the Service; individuals whose data appears in Screening Data submitted by Users (e.g. named counterparties); and people who contact us. It should be read together with the Cookie Policy and, for business customers, the Data Processing Agreement.
3. Two roles: when we are controller and when we are processor
This distinction is important and determines your rights.
3.1. We act as controller for: account and billing data; our own analytics and security logging; marketing to prospects; and the operation of the Service generally.
3.2. We may act as processor for personal data contained in Screening Data that a Business User uploads about third parties (for example, names of directors or counterparties in an uploaded manifest or counterparty-screening list). In that case, the Business User is the controller of that data, we process it on their documented instructions to provide the Service, and the processing is governed by the Data Processing Agreement (available on request at privacy@cargoscreen.eu) rather than by this Policy. If you are an individual whose data was uploaded by a business customer, please contact that customer to exercise your rights; we will assist them as required.
3.3. For personal data that a Consumer enters about themselves when using the Service, we act as controller under this Policy.
4. What personal data we process and why
| Category | Examples | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|---|
| Account data | name, email, phone (optional), password (hashed), organisation, role | create and manage your account; authenticate you | Performance of the contract (6(1)(b)) |
| Billing data | billing name/address, VAT number, plan, payment metadata (processed by Stripe; we do not store full card numbers) | process payments, invoicing, accounting | Contract (6(1)(b)); legal obligation for accounting/tax (6(1)(c)) |
| Screening Data (as controller, where about you) | codes, routes, descriptions, uploaded files, counterparty details | run screening, generate Verdicts and reports, maintain the audit-trail snapshot | Contract (6(1)(b)); our legitimate interest and, where applicable, that of the User in compliance record-keeping (6(1)(f)) |
| Audit snapshot (screen_log) | inputs, verdict, reasons, snapshot date/time, disclaimer version | preserve a record of what the Service showed on a given date (a core feature enabling post-audit defence) | Legitimate interest (6(1)(f)) and, for Users, contract (6(1)(b)) |
| Usage and technical data | IP address, device/browser, timestamps, pages/actions, log data | operate, secure, and improve the Service; prevent abuse; ensure availability | Legitimate interest (6(1)(f)); consent for non-essential cookies (6(1)(a) + ePrivacy) |
| Support communications | messages, contact details | respond to enquiries and support requests | Legitimate interest (6(1)(f)); contract (6(1)(b)) |
| Compliance/sanctions screening of Users | identity/beneficial-owner data, sanctions-list match results | comply with sanctions and export-control law; prevent prohibited onboarding (see Terms clause 6) | Legal obligation (6(1)(c)); legitimate interest (6(1)(f)) |
| Marketing | email, preferences | send updates/newsletters to prospects and customers | Consent (6(1)(a)); or legitimate interest for existing customers' similar services, with opt-out |
4.1. We do not intentionally collect special categories of personal data (Article 9 GDPR). Please do not upload such data unless strictly necessary and lawful. Counterparty screening deals with sanctions-list data, which may include data relating to criminal matters; we process it only as needed to provide the screening function and to comply with law.
4.2. Where we rely on legitimate interests, our interests are: providing and securing the Service, preventing fraud and abuse, complying with regulatory obligations, and maintaining an audit trail. We have balanced these against your rights; you may object (clause 9).
5. Where the data comes from
We collect data: (a) directly from you (registration, use, payment, contact); (b) automatically (logs, cookies — see Cookie Policy); (c) from our payment processor (payment status/metadata); and (d) for counterparty screening, from public sanctions lists and, potentially, from Business Users who upload counterparty data (in which case we act as processor — clause 3.2). We also collect: (e) publicly available business contact details published on company websites and in public business registers — used for B2B outreach under legitimate interest (Art. 6(1)(f)). You can object at any time by writing to privacy@cargoscreen.eu or using the unsubscribe link in any message.
6. Who we share data with (recipients and subprocessors)
We share personal data only as necessary and under appropriate safeguards. Our service providers process data on our behalf under data-processing agreements.
| Recipient | Role | Purpose | Location / transfer |
|---|---|---|---|
| Hetzner Online GmbH | Hosting / infrastructure processor | hosts the Service and database | EU/EEA, data centre in Finland (Helsinki); no non-EU transfer |
| Stripe | Payment processor | process card payments, subscriptions, invoicing | EU and US; safeguards per clause 7 |
| Anthropic PBC | AI subprocessor | AI-assisted classification of goods descriptions into commodity codes. Only the goods description you submit is sent; account data, counterparty names and screening history are not. | US; EU Standard Contractual Clauses (clause 7) |
| Resend | Email delivery processor | transactional emails to account holders: confirmation, password recovery, trial notices, alerts | Netherlands (EU) |
| Google Workspace | Email / productivity processor | outbound business correspondence | Ireland (EU) |
| Competent authorities | Recipient | where required by law (e.g. sanctions, court order) | as required by law |
| Professional advisers / successors | Recipient | legal/accounting advice; corporate transactions, under confidentiality | EU |
6.1. A current, itemised list of subprocessors is maintained and available on request, and (for business customers) in the DPA Annex. We will inform business customers of changes to subprocessors as provided in the DPA.
6.2. We do not sell personal data.
6.3. Minimising personal data sent to AI subprocessors. Where the AI classification feature processes free-text goods descriptions, we instruct Users not to include personal data in descriptions and take reasonable steps to limit personal data transmitted to AI subprocessors.
7. International transfers
7.1. Some subprocessors (notably AI providers and Stripe) are located in, or may process data in, the United States. Where personal data is transferred outside the EEA, we rely on an appropriate Article 46 GDPR safeguard: the EU Standard Contractual Clauses (2021) and/or the recipient's certification under the EU-US Data Privacy Framework, supported where required by a Transfer Impact Assessment and supplementary measures.
7.2. As of the effective date, the EU-US Data Privacy Framework remains in force but is subject to ongoing legal review at EU level; we monitor developments and maintain SCCs as a fallback. You may request a copy of the relevant safeguards by contacting privacy@cargoscreen.eu.
8. How long we keep data (retention)
| Data | Retention |
|---|---|
| Account data | for the life of the Account and up to 12 months after closure, then deletion or anonymisation |
| Billing/accounting records | 5 years from the end of the relevant financial year, per Latvian accounting/tax law |
| Screening audit snapshots (screen_log) | retained as an audit trail for 5 years from the date of the screening, then deletion/anonymisation, unless a User account setting or the DPA provides otherwise |
| Usage/technical logs | 12 months, unless needed longer for security investigation |
| Support communications | 24 months |
| Sanctions-screening records of Users | as required to evidence compliance, 5 years |
| Marketing data | until you opt out or after 24 months of inactivity |
8.1. We may retain data longer where necessary to comply with a legal obligation, to establish, exercise, or defend legal claims, or where a competent authority requires it.
8.2. The retention of the screening audit snapshot is a deliberate feature. Screening history and dated PDF reports are kept for 5 years from the date of the screening. These records exist so that you can demonstrate, during a customs audit, what the rules were on the day you shipped.
9. Your rights
Subject to the conditions in the GDPR, you have the right to: access your data; rectify inaccurate data; erase data ("right to be forgotten"); restrict processing; data portability; object to processing based on legitimate interests or to direct marketing; and, where processing is based on consent, to withdraw consent at any time (without affecting prior lawful processing).
9.1. To exercise these rights, contact privacy@cargoscreen.eu. We will respond within one month (extendable by two months for complex requests, with notice). We may need to verify your identity.
9.2. Where we process your data as a processor on behalf of a business customer (clause 3.2), please direct your request to that customer; we will assist them in responding.
9.3. Right to lodge a complaint. If you believe your rights have been infringed, you may complain to the Latvian supervisory authority: Data State Inspectorate (Datu valsts inspekcija), Rīga, dvi.gov.lv, or to the supervisory authority of your EU country of residence. We would appreciate the chance to address your concern first via privacy@cargoscreen.eu.
10. Automated decision-making and profiling
10.1. The screening Verdict is generated by applying public regulatory data and rules to the data you enter. It is a compliance-information output about goods and routes, not a decision that produces legal effects concerning you or similarly significantly affects you as an individual within the meaning of Article 22 GDPR, and it does not profile you.
10.2. Some features use AI to classify goods from descriptions (see Terms clause 11). This assists the User; it does not make an automated decision about any individual. AI-assisted results are labelled with a confidence indicator, and low-confidence results do not produce a Verdict. This supports transparency under the GDPR and Article 50 of the AI Act.
11. Security
11.1. We implement appropriate technical and organisational measures to protect personal data, including: encryption in transit (TLS); access controls and role-based permissions; multi-tenant isolation with row-level security; hashed credentials; secrets management; monitoring and rate-limiting; and backups. Payment card data is handled by our PCI-DSS-compliant payment processor and is not stored by us.
11.2. No system is completely secure. In the event of a personal-data breach that is likely to result in a risk to your rights, we will notify the supervisory authority and, where required, affected individuals, in accordance with Articles 33–34 GDPR.
12. Data Protection Officer and EU establishment
12.1. social.tech SIA is established in Latvia (an EU member state); therefore no Article 27 EU representative is required.
12.2. {If you appoint a DPO, state contact details here. If not, state: "We have assessed Article 37 GDPR and consider that we are not required to appoint a Data Protection Officer, because our core activities do not consist of large-scale monitoring or large-scale processing of special-category data. You may nonetheless contact our privacy team at privacy@cargoscreen.eu for any data-protection matter." — confirm this assessment with your lawyer, given the sanctions-data element.}
13. Children
The Service is not directed to persons under 18 and we do not knowingly process their personal data. If you believe a minor has provided us data, contact privacy@cargoscreen.eu.
14. Cookies
We use cookies and similar technologies as described in the Cookie Policy (https://cargoscreen.eu/legal/cookies), which forms part of this Policy.
15. Changes to this Policy
We may update this Policy. Material changes will be notified by email and/or in-app before they take effect. The current version and its date are always shown at the top. Continued use after the effective date constitutes acknowledgement.
16. Contact
social.tech SIA · Reģ.nr. 40203514705 · Augusta Dombrovska iela 75 k-2-8, Rīga, LV-1015, Latvia · privacy@cargoscreen.eu
Changelog
| Version | Date | Change |
|---|---|---|
| 1.1 | 19 Aug 2026 | Account data extended with optional phone number; hosting data centre, email and AI subprocessors named; retention periods fixed; public business contact details added as a data source. |
| 1.0 | 18 Jul 2026 | Initial version. |