Processing on your instructions.
The Data Processing Agreement (Art. 28 GDPR) between your company and Frachta for the data you control on the platform — partners, orders, invoices and bank statements — including our subprocessor list.
Jump to section
- 01 · Scope of this agreement
- 02 · Roles of the parties
- 03 · Subject matter, nature & duration
- 04 · Categories of data & data subjects
- 05 · Instructions & confidentiality
- 06 · Security measures (Art. 32)
- 07 · Subprocessors
- 08 · Assistance to the controller
- 09 · Personal data breaches
- 10 · International transfers
- 11 · Return & deletion of data
- 12 · Audits & information
- 13 · Term & liability
- 14 · How to execute this DPA
- 15 · Contact
01Scope of this agreement
This Data Processing Agreement (“DPA”) governs the processing of personal data that your company (“Customer”) controls and entrusts to Frachta by using the platform. It supplements the Terms & Conditions and applies whenever the Customer stores personal data of its own contacts, partners, drivers or counterparties on Frachta.
02Roles of the parties
For this data the Customer is the controller and SIA "HEIDA LTD" (“Frachta”) is the processor, processing personal data only on the Customer's behalf. For data Frachta collects for its own purposes — accounts, security logs, billing, platform analytics — Frachta is the controller, as described in the Privacy Policy.
Telematics providers. The Customer holds the contract with its telematics provider and chooses to connect it; the provider is the Customer's own processor, not one Frachta engages. What Frachta does is receive that data on the Customer's instruction and process it as a subprocessor of the Customer. The Customer should therefore satisfy itself that its agreement with the provider, and any notice it gives its drivers, covers the transfer into Frachta. Frachta does not read telematics data for its own purposes and does not make it available to other Customers.
03Subject matter, nature & duration
The subject matter is the provision of the Frachta platform: freight exchange, transport management, document generation, invoicing and payment reconciliation. The nature of processing is storage, structuring, display, transmission between authorised users and deletion. Processing lasts for the duration of the Customer's account, plus the deletion period in section 11.
04Categories of data & data subjects
- Data subjects — the Customer's employees and drivers; contact persons of the Customer's partners, shippers and carriers; payers appearing on bank statements.
- Data categories — names, business contact details, roles; order and shipment details; invoice data; bank-statement lines (counterparty name, IBAN, amount, date, reference).
- Driver identity and licences — name, date of birth, nationality, country of residency, contact details, driving-licence categories and their validity dates, for drivers the Customer invites to the driver app.
- Work events with location — stops, seals and proofs of delivery, each with the approximate position of the device at that moment (street-level accuracy, captured only at the event, never continuously), the comparison against the expected place, and the distance between them.
- Photographs taken in the driver app, which may incidentally show people who are neither the Customer's staff nor Frachta's users.
- Names of people who sign for consignments — the name and role recorded on a proof of delivery, and any remarks made at handover.
- Telematics data about named drivers — where the Customer connects a telematics account: driver names, tachograph card numbers, driving, work, availability and rest periods, and vehicle position history.
- Absence and leave records — type (leave, holiday or sickness), dates, approval status, any note, and applications submitted through the driver app.
- Special categories (Art. 9). A sickness absence is data concerning health. It is the only special category the platform holds, and it is limited to the fact and the dates of that type of absence — the platform does not ask for a diagnosis or a medical certificate. The Customer is the controller and is responsible for the Art. 9(2) condition it relies on, and for what its staff type into the free-text note. Customers should assess whether this, together with the location and working-time records above, requires a data-protection impact assessment under Art. 35.
05Instructions & confidentiality
Frachta processes this data only on the Customer's documented instructions — using the platform's features is the instruction — unless EU or Latvian law requires otherwise, in which case Frachta informs the Customer before processing (unless the law prohibits it). All personnel authorised to process the data are bound by confidentiality obligations.
06Security measures (Art. 32)
Frachta implements appropriate technical and organisational measures, including:
- Encryption in transit (TLS) for all connections; hashed credentials and single-use, hashed sign-in and verification tokens.
- Tenant isolation enforced at the database layer (row-level security) in addition to application checks.
- Least-privilege access — the application runs under a restricted database role; administrative access is limited and logged.
- Uploaded files stored under randomised names with type and size restrictions; audit logging of security-relevant actions.
- EU-based hosting, separation of environments, and encrypted off-site backups — encrypted on our own servers before they are transferred, so the storage provider holds only ciphertext.
07Subprocessors
The Customer authorises the following subprocessors. Frachta will announce changes to this list in advance (in-app or by email), giving the Customer the opportunity to object on reasonable grounds:
- Hosting & infrastructure provider (EU) — runs the servers and database for the platform.
- Transactional email provider — delivers verification, notification and document emails.
- PostHog (EU cloud) — product analytics; engaged only for Customers whose users consent to analytics cookies.
- Sentry — error monitoring, to keep the platform stable.
- Anthropic (United States) — the model behind the platform's optional AI features, engaged only for the feature the Customer actually uses. It receives what that feature sends it and nothing else: the company and public-source material in a Company Check; an uploaded repair invoice, to read the lines off it; a support ticket, to translate it for our staff; a route and its stops, to plan them; and news or instruction text, to draft and translate it. It is not used to make decisions about a data subject, and its output is advisory.
- Montonio Finance, UAB (Lithuania) — plan payments; acts as an independent controller for payment data, not a subprocessor.
- SMS delivery provider (Esteria, EU) — delivers verification and notification SMS.
- Backblaze (B2 Cloud Storage, EU Central — Amsterdam) — stores our off-site backups. The data is encrypted before it leaves our servers, so Backblaze cannot read it.
- OpenStreetMap Foundation (Nominatim) — converts an address into map coordinates. Receives the address text only; no name, account or contact details are sent with it. Used only as a fallback when the HERE service above is unavailable.
The following are engaged for features that are built but not yet switched on. They receive nothing today. They are listed here in advance so that the notice and objection right above is real — Frachta will not enable any of them without giving the Customer the opportunity to object first.
- App notification service (Expo / 650 Industries, United States) — would carry push notifications to the driver app, passing them to Apple or Google to reach the handset. Receives a device push token and the notification text. Not yet configured; no token is registered and nothing is sent.
- Qualified e-signature provider (Dokobit, Lithuania) — would receive a document to be signed together with the signer's name, and would offer the signer their own choice of method (Smart-ID, eParaksts, ID card). Not yet configured; documents are currently signed within the platform only.
- HERE Global B.V. (Netherlands) — converts addresses into map coordinates, plans truck routes and serves the map itself. Receives the address text and the route's points only; no name, account or contact details are sent with it. The map is loaded through our servers, so a visitor's browser never contacts HERE directly.
08Assistance to the controller
Taking into account the nature of processing, Frachta assists the Customer with appropriate technical and organisational measures in fulfilling data-subject requests (Art. 12–23), and in meeting the Customer's obligations under Art. 32–36 (security, breach notification, impact assessments), insofar as the information is available to Frachta.
09Personal data breaches
Frachta notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, providing the information reasonably required for the Customer's own notification duties under Art. 33–34 GDPR.
10International transfers
Processing takes place in the EU. Any transfer outside the EEA occurs only with an adequacy decision or Standard Contractual Clauses in place, and is reflected in the subprocessor list above.
11Return & deletion of data
On termination of the account, Frachta deletes or anonymises the Customer's controlled data within 90 days, unless EU or Latvian law requires longer storage (for example accounting records) or a legal hold applies. Before closure the Customer can export its data using the platform's export features, and during those 90 days our support can still restore the account on the Customer's written request.
Encrypted backups are taken several times a day and rotate on a rolling schedule of up to six months. Data deleted from the live platform is gone from it immediately; the last backup copy disappears as that schedule rotates. Backups are restored only for disaster recovery, never to revive individual deleted records.
12Audits & information
Frachta makes available the information necessary to demonstrate compliance with Art. 28 GDPR and allows for audits — normally satisfied by documentation and third-party attestations; on-site audits require reasonable notice, business-hours access and confidentiality undertakings, at the Customer's cost.
13Term & liability
This DPA applies as long as Frachta processes personal data for the Customer. Liability follows the limitations in the Terms & Conditions, to the extent permitted by Art. 82 GDPR.
14How to execute this DPA
This DPA is incorporated into the Terms and applies automatically to every Customer. Enterprise customers who need a countersigned copy, a bespoke security annex or an audit conversation: email privacy@frachta.lv and we will arrange it.
15Contact
Questions about this DPA? Write to privacy@frachta.lv. The processor is SIA "HEIDA LTD", registration No. 40203741048, VAT No. LV40203741048, Spāres iela 3A, Rīga, LV-1002, Latvia. Related documents: Privacy Policy, Terms & Conditions, Cookie Policy and GDPR.