Startseite/Rechtliches/Datenschutzerklärung

Your data, your control.

How Frachta collects, uses and protects personal data, and the rights you have under the GDPR.

Zum Abschnitt springen
  1. 01 · Overview
  2. 02 · Data controller identity & contact
  3. 03 · Categories of personal data we collect
  4. 04 · Purposes & legal bases
  5. 05 · Data from bank-statement uploads
  6. 06 · Data sharing & processors
  7. 07 · International transfers
  8. 08 · Retention periods
  9. 09 · Your data-subject rights
  10. 10 · How to exercise your rights
  11. 11 · Automated decision-making
  12. 12 · Complaints to a supervisory authority
  13. 13 · Changes to this policy
  14. 14 · Contact
Zuletzt aktualisiert · 23 July 2026Version 1.0 — draftGilt für · frachta.lv
// Structural draft with working wording. Every clause should be reviewed by qualified counsel / a DPO before being relied on. Blocks marked Placeholder indicate what still needs confirming — they are not legal text.

01Overview

This policy explains what personal data Frachta processes, why, the legal bases we rely on, and how you can exercise your rights. It applies to the Frachta platform and website at frachta.lv, and is written for our business users — freight forwarders, carriers and their staff.

02Data controller identity & contact

SIA "HEIDA LTD", registration No. 40203741048, VAT No. LV40203741048, Spāres iela 3A, Rīga, LV-1002, Latvia is the data controller for personal data processed through the platform (“Frachta”, “we”).

For all privacy matters write to privacy@frachta.lv.

Platzhalter

Appoint and name a Data Protection Officer or confirm with counsel that none is required at the current scale; add the DPO's contact here if appointed.

03Categories of personal data we collect

Depending on how you use Frachta, we may process the following categories:

  • Account & company data — name, work email, phone number, role, company name, registration and VAT numbers.
  • Operational data — loads, orders, freight tasks, e-CMR and invoice records you create, including contact details of drivers and counterparties you enter.
  • Financial data — uploaded bank statements and payment-reconciliation data (see section 05), invoices and payment records.
  • Verification data — company registry and EU VIES VAT lookups used to verify that an account belongs to a genuine business.
  • Usage, device & log data — IP address, browser, and actions taken on the platform (security and audit logs).
  • Communications — support tickets, in-platform chat and correspondence with us.
Platzhalter

Keep this inventory aligned with the data map as features ship. State which fields are mandatory vs optional at registration, and note that some data about you may be entered by other Users (e.g. a counterparty adds you as a contact on a shared order).

04Purposes & legal bases

For each purpose we identify a lawful basis under Article 6 GDPR:

  • Provide & secure the service (accounts, exchange, TMS, documents) — performance of a contract, Art. 6(1)(b).
  • Verify companies, keep records, meet tax and accounting duties — legal obligation, Art. 6(1)(c).
  • Improve the platform, prevent abuse and fraud, secure the marketplace — legitimate interests, Art. 6(1)(f).
  • Optional cookies, analytics and marketing messages — consent, Art. 6(1)(a), managed via the Cookie Policy preference centre.
Platzhalter

For every processing activity, keep a record of the specific purpose, the exact legal basis and — where legitimate interests are relied on — a documented balancing test.

05Data from bank-statement uploads

Frachta lets you upload bank statements to reconcile payments against invoices. These files can contain personal and financial data of third parties (counterparty names, IBANs, amounts, dates and payment references), so this processing is described separately.

We extract only the fields needed for payment matching, store files under randomised names with access restricted to your company workspace, and never use statement contents for any other purpose. By uploading a statement you confirm you are entitled to share it. Statements are deleted with your account or earlier on request.

Platzhalter

Confirm with counsel: the retention period for uploaded statements, whether any parsing sub-processor is involved (none today — parsing is in-house), and the wording of the User warranty.

06Data sharing & processors

We share data with vetted processors under data-processing agreements, and with other Users only as needed to conclude and perform a load or order — for example, your company profile, ratings and the contact details you attach to an offer are visible to counterparties. We do not sell personal data.

  • Hosting & infrastructure — EU-based servers running the platform and database.
  • Email delivery — transactional email (verification, magic links, notifications).
  • Analytics — PostHog (EU cloud), only with your consent.
  • Payments — Montonio, our payment provider for subscriptions, acting for payment data as an independent controller.
  • Error monitoring — crash and error reports to keep the platform stable.
Platzhalter

Name each provider with its legal entity and processing location in the DPA subprocessor list, and keep the two lists in sync. Add disclosures required by law or to authorities.

07International transfers

Data is hosted in the EU. Where any transfer outside the EEA is necessary, we rely on an adequacy decision or Standard Contractual Clauses with appropriate safeguards. You can request a copy of the safeguards at privacy@frachta.lv.

08Retention periods

We keep personal data only as long as needed for the purposes above or as required by law:

  • Account & company data — while the account is active, then deleted or anonymised within 12 months of closure.
  • Invoices & accounting records — the statutory Latvian accounting retention period (currently 5 years, 10 years for certain documents).
  • Security & audit logs — up to 12 months.
  • Uploaded bank statements — until you delete them, and at the latest with account closure.
Platzhalter

Validate each period with counsel against Latvian accounting and tax law and the limitation periods for contract claims; document the criteria for any period not fixed here.

09Your data-subject rights

Under the GDPR you have the right to:

  • Access — obtain a copy of your personal data.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — have data deleted (the “right to be forgotten”).
  • Restriction — limit how we process your data.
  • Portability — receive your data in a portable format.
  • Objection — object to processing based on legitimate interests or direct marketing.
  • Withdraw consent — at any time, without affecting prior processing.

10How to exercise your rights

Email privacy@frachta.lv with your request. We respond within one month, as required by the GDPR, and may ask you to verify your identity. If a request is manifestly unfounded or excessive we may refuse or charge a reasonable fee, explaining why. See also the GDPR page.

11Automated decision-making

Frachta does not make automated decisions that produce legal or similarly significant effects on you. Company verification and abuse prevention involve automated checks, but a human reviews any decision to refuse or block an account.

12Complaints to a supervisory authority

You may lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija) or the supervisory authority in your EU country of residence. We would appreciate the chance to resolve any concern directly first — write to privacy@frachta.lv.

13Changes to this policy

We may update this policy; material changes will be notified in-app or by email, and the “last updated” date and version above will change.

14Contact

Questions about this Privacy Policy? Write to privacy@frachta.lv. The controller is SIA "HEIDA LTD". Related documents: Terms & Conditions, Cookie Policy, GDPR and the Data Processing Agreement.