Processing on your instructions.
The Data Processing Agreement (Art. 28 GDPR) between your company and Frachta for the data you control on the platform — partners, orders, invoices and bank statements — including our subprocessor list.
Zum Abschnitt springen
- 01 · Scope of this agreement
- 02 · Roles of the parties
- 03 · Subject matter, nature & duration
- 04 · Categories of data & data subjects
- 05 · Instructions & confidentiality
- 06 · Security measures (Art. 32)
- 07 · Subprocessors
- 08 · Assistance to the controller
- 09 · Personal data breaches
- 10 · International transfers
- 11 · Return & deletion of data
- 12 · Audits & information
- 13 · Term & liability
- 14 · How to execute this DPA
- 15 · Contact
01Scope of this agreement
This Data Processing Agreement (“DPA”) governs the processing of personal data that your company (“Customer”) controls and entrusts to Frachta by using the platform. It supplements the Terms & Conditions and applies whenever the Customer stores personal data of its own contacts, partners, drivers or counterparties on Frachta.
02Roles of the parties
For this data the Customer is the controller and SIA "HEIDA LTD" (“Frachta”) is the processor, processing personal data only on the Customer's behalf. For data Frachta collects for its own purposes — accounts, security logs, billing, platform analytics — Frachta is the controller, as described in the Privacy Policy.
03Subject matter, nature & duration
The subject matter is the provision of the Frachta platform: freight exchange, transport management, document generation, invoicing and payment reconciliation. The nature of processing is storage, structuring, display, transmission between authorised users and deletion. Processing lasts for the duration of the Customer's account, plus the deletion period in section 11.
04Categories of data & data subjects
- Data subjects — the Customer's employees and drivers; contact persons of the Customer's partners, shippers and carriers; payers appearing on bank statements.
- Data categories — names, business contact details, roles; order and shipment details; invoice data; bank-statement lines (counterparty name, IBAN, amount, date, reference).
- Special categories — none are intended to be processed; the Customer agrees not to upload them.
05Instructions & confidentiality
Frachta processes this data only on the Customer's documented instructions — using the platform's features is the instruction — unless EU or Latvian law requires otherwise, in which case Frachta informs the Customer before processing (unless the law prohibits it). All personnel authorised to process the data are bound by confidentiality obligations.
06Security measures (Art. 32)
Frachta implements appropriate technical and organisational measures, including:
- Encryption in transit (TLS) for all connections; hashed credentials and single-use, hashed sign-in and verification tokens.
- Tenant isolation enforced at the database layer (row-level security) in addition to application checks.
- Least-privilege access — the application runs under a restricted database role; administrative access is limited and logged.
- Uploaded files stored under randomised names with type and size restrictions; audit logging of security-relevant actions.
- EU-based hosting, backups and environment separation.
Extend with the full security annex when signing bespoke DPAs: backup cadence and restore testing, patching policy, personnel screening, and business-continuity commitments.
07Subprocessors
The Customer authorises the following subprocessors. Frachta will announce changes to this list in advance (in-app or by email), giving the Customer the opportunity to object on reasonable grounds:
- Hosting & infrastructure provider (EU) — runs the servers and database for the platform.
- Transactional email provider — delivers verification, notification and document emails.
- PostHog (EU cloud) — product analytics; engaged only for Customers whose users consent to analytics cookies.
- Sentry — error monitoring, to keep the platform stable.
- Anthropic — AI summaries for the optional Company Check feature, only when the Customer uses it.
- Montonio Finance, UAB (Lithuania) — subscription payments; acts as an independent controller for payment data, not a subprocessor.
Before signing: name each provider's exact legal entity, processing location and DPA/SCC status, and confirm the hosting and email providers' details. Keep this list synchronised with the Privacy Policy sharing section.
08Assistance to the controller
Taking into account the nature of processing, Frachta assists the Customer with appropriate technical and organisational measures in fulfilling data-subject requests (Art. 12–23), and in meeting the Customer's obligations under Art. 32–36 (security, breach notification, impact assessments), insofar as the information is available to Frachta.
09Personal data breaches
Frachta notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, providing the information reasonably required for the Customer's own notification duties under Art. 33–34 GDPR.
10International transfers
Processing takes place in the EU. Any transfer outside the EEA occurs only with an adequacy decision or Standard Contractual Clauses in place, and is reflected in the subprocessor list above.
11Return & deletion of data
On termination of the account, Frachta deletes the Customer's controlled data, unless EU or Latvian law requires longer storage (e.g. accounting records). Before closure the Customer can export its data using the platform's export features. Deletion from backups follows the backup rotation cycle.
Confirm the exact deletion window (e.g. 90 days after closure) and the backup rotation period, and state them here.
12Audits & information
Frachta makes available the information necessary to demonstrate compliance with Art. 28 GDPR and allows for audits — normally satisfied by documentation and third-party attestations; on-site audits require reasonable notice, business-hours access and confidentiality undertakings, at the Customer's cost.
13Term & liability
This DPA applies as long as Frachta processes personal data for the Customer. Liability follows the limitations in the Terms & Conditions, to the extent permitted by Art. 82 GDPR.
14How to execute this DPA
This DPA is incorporated into the Terms and applies automatically to every Customer. Enterprise customers who need a countersigned copy, a bespoke security annex or an audit conversation: email privacy@frachta.lv and we will arrange it.
15Contact
Questions about this DPA? Write to privacy@frachta.lv. The processor is SIA "HEIDA LTD", registration No. 40203741048, VAT No. LV40203741048, Spāres iela 3A, Rīga, LV-1002, Latvia. Related documents: Privacy Policy, Terms & Conditions, Cookie Policy and GDPR.