Your data, your control.
How Frachta collects, uses and protects personal data, and the rights you have under the GDPR.
Jump to section
- 01 · Overview
- 02 · Data controller identity & contact
- 03 · Categories of personal data we collect
- 04 · Purposes & legal bases
- 05 · Monitoring at work
- 06 · Data from bank-statement uploads
- 07 · Data sharing & processors
- 08 · International transfers
- 09 · Retention periods
- 10 · Push notifications
- 11 · When we ask you for a review
- 12 · Your data-subject rights
- 13 · How to exercise your rights
- 14 · Automated decision-making
- 15 · Complaints to a supervisory authority
- 16 · Changes to this policy
- 17 · Contact
01Overview
This policy explains what personal data Frachta processes, why, the legal bases we rely on, and how you can exercise your rights. It applies to the Frachta platform and website at frachta.lv, and is written for our business users — freight forwarders, carriers and their staff.
02Data controller identity & contact
SIA "HEIDA LTD", registration No. 40203741048, VAT No. LV40203741048, Spāres iela 3A, Rīga, LV-1002, Latvia is the data controller for personal data processed through the platform (“Frachta”, “we”).
For all privacy matters write to privacy@frachta.lv.
We have not appointed a Data Protection Officer: our processing does not meet the criteria in Art. 37(1) GDPR — we are not a public authority, and neither regular large-scale monitoring of individuals nor large-scale processing of special-category data is a core activity of ours. Privacy matters are handled by our management, at the address above.
03Categories of personal data we collect
Depending on how you use Frachta, we may process the categories below. Some of it is entered not by you but by other Users — for example, a counterparty adding your name and phone number as a contact on a shared order:
- Account & company data — name, work email, phone number, role, company name, registration and VAT numbers.
- Operational data — loads, orders, freight tasks, e-CMR and invoice records you create, including contact details of drivers and counterparties you enter.
- Financial data — uploaded bank statements and payment-reconciliation data (see section 06), invoices and payment records.
- Verification & due-diligence data — company registry and EU VIES VAT lookups used to verify that an account belongs to a genuine business, and — when a user runs a partner check — public registry, financial and EU/UN/OFAC sanctions-list data about the checked company, which may include the names of its owners or board members.
- Usage, device & log data — IP address, browser, and actions taken on the platform (security and audit logs).
- Communications — support tickets, in-platform chat and correspondence with us.
- Driver app data — where a carrier invites its drivers to the Frachta driver app: the driver's name, date of birth, nationality, country of residency, e-mail, phone number and driving-licence categories with their validity dates; sign-ins, the device's IP address and app activity; task events and the documents they submit; an approximate location and photographs as described below.
- Location at a work event — when a driver records a stop, a seal or a proof of delivery, the app attaches the device's position if the driver has allowed it. The app asks the operating system for a balanced-accuracy fix — street level, in the order of a hundred metres, not a precise pinpoint — and only at the moment of that action. There is no continuous or background tracking, the app never follows a driver between events, and an action still completes if the driver refuses or the device cannot get a fix.
- Location verification — the position is compared with where the stop was expected to be, and the outcome is stored with the event: whether it matched, and the distance. It is a record, never a block — no action is refused because of it. Because it is a standing record of whether a worker was where the job placed them, it is set out here on its own rather than left inside “task events”.
- Photographs — checklist, seal, proof-of-delivery and problem-report pictures taken in the app. A photograph at a loading bay or a warehouse door can show people who are not our customers and not our users; those people appear in it only because the picture was taken where the work happened.
- The person who signs for the goods — at delivery the app records the name and role of whoever accepts the consignment, with the place and any remarks. That person is usually neither our customer nor our user: their name is in the record because a proof of delivery is not proof of anything without it.
- Your review of Frachta — if you choose to review the platform: the rating, the words you write, the name and role you ask to be credited under, and whether you agreed to publication. A review is never required, and nothing about your account changes if you ignore or decline the request.
- Device identifiers — where push notifications are switched on. In a browser, accepting the prompt creates a subscription with your browser's own push service, and we store the address it returns so that we can send to it; this is in use today. In the driver app the equivalent is a token identifying an installation on a device; that half is built but not yet switched on, and the service that would carry it is listed among the recipients below before the first notification is sent. Neither is a cookie or an IP address.
- Absence and leave — where a carrier uses the driver app to manage time off: the type of absence (leave, holiday or sickness), the dates, whether it was approved, any note added, and the applications a driver submits through the app (for example holiday, parental leave or resignation).
- Health data (a special category). A sickness absence says something about a person's health, and the law treats it more strictly than the rest of this list. Frachta records only that an absence was of that type and when it ran — it does not ask for, and should not be given, a diagnosis, a medical certificate or any clinical detail. The employer is responsible for the lawful basis under Article 9 for keeping it — in employment, ordinarily an obligation under employment and social-security law — and for not entering more than that law requires into the free-text note.
04Purposes & legal bases
For each purpose we identify a lawful basis under Article 6 GDPR:
- Provide & secure the service (accounts, exchange, TMS, documents) — performance of a contract, Art. 6(1)(b).
- Verify companies, keep records, meet tax and accounting duties — legal obligation, Art. 6(1)(c).
- Improve the platform, prevent abuse and fraud, secure the marketplace — legitimate interests, Art. 6(1)(f).
- Optional cookies, analytics and marketing messages — consent, Art. 6(1)(a), managed via the Cookie Policy preference centre.
05Monitoring at work
Some of what the driver app records is, in substance, monitoring of a person at work: where they were when they completed a stop, whether that matched the plan, and when they drove, worked and rested. We set this out plainly rather than leaving it inside a general list, because a worker is entitled to know it exists.
The carrier decides, not Frachta. Your employer chooses to use the app, chooses whether to connect a telematics account, and is the controller of that data — including any obligation to inform you, to consult employee representatives, or to carry out an impact assessment where local law requires it. Frachta processes it on their instruction and does not use it to make decisions about you.
No automated decision is taken about you from it. A location that does not match is recorded and shown to your employer; nothing is blocked, refused or penalised by the software.
Absence is not monitoring, and is not treated as it. A leave or sickness record exists because somebody has to plan the week and meet an employment obligation. It is visible to the carrier that employs the driver and to nobody else — not to other carriers a driver works for, and not to anyone trading on the exchange.
06Data from bank-statement uploads
Frachta lets you upload bank statements to reconcile payments against invoices. These files can contain personal and financial data of third parties (counterparty names, IBANs, amounts, dates and payment references), so this processing is described separately.
We extract only the fields needed for payment matching, store files under randomised names with access restricted to your company workspace, and never use statement contents for any other purpose. By uploading a statement you confirm you are entitled to share it. Statements are deleted with your account or earlier on request.
07Data sharing & processors
We share data with vetted processors under data-processing agreements, and with other Users only as needed to conclude and perform a load or order — for example, your company profile, ratings and the contact details you attach to an offer are visible to counterparties. We do not sell personal data.
- Hosting & infrastructure — EU-based servers running the platform and database.
- Email delivery — transactional email (verification, magic links, notifications).
- Analytics — PostHog (EU cloud), only with your consent.
- Payments — Montonio, our payment provider for plan payments, acting for payment data as an independent controller.
- Error monitoring — crash and error reports to keep the platform stable.
- Advertising measurement — Google, LinkedIn and Meta conversion tags, only with your consent (see the Cookie Policy).
- SMS delivery — verification codes and operational alerts, sent through our EU SMS provider (Esteria).
- Telematics — if your company connects its telematics account (Mapon, Wialon, Webfleet, an rFMS-compatible manufacturer system, or Ruptela), we receive from it, on your instruction, not only vehicle data such as odometer readings and unit hours but also data about named drivers: driver names and tachograph card numbers, driving, work, availability and rest periods, and the position history of the vehicles they drive. Which of these arrive depends on the provider and on what your telematics contract includes.
- Address lookup — to place a loading or unloading point on a map we send the address text to Nominatim, the geocoding service of the OpenStreetMap Foundation. We send the address, not your identity, and no account or contact details go with it.
- Electronic signing — where a document has to be signed, it is passed to a qualified e-signature provider together with the signer's name; the signer chooses their own method there (for example Smart-ID, eParaksts or an ID card). This is being prepared and is not yet active: until it is, documents are signed only within the platform, and the provider will be named in the Data Processing Agreement before the first document is sent to it.
08International transfers
Data is hosted in the EU. Where any transfer outside the EEA is necessary, we rely on an adequacy decision or Standard Contractual Clauses with appropriate safeguards. You can request a copy of the safeguards at privacy@frachta.lv.
09Retention periods
We keep personal data only as long as needed for the purposes above or as required by law:
- Account & company data — while the account is active, then deleted or anonymised within 12 months of closure.
- Invoices & accounting records — the statutory Latvian accounting retention period (currently 5 years, 10 years for certain documents).
- Security & audit logs — up to 12 months, unless a legal hold applies (for example at the request of the police or a regulator) or the records belong to an active security investigation; they are then kept until the hold is released.
- Uploaded bank statements — until you delete them, and at the latest with account closure.
- Backups — encrypted copies, kept on a rolling schedule of up to six months. What you delete leaves the live platform at once and leaves the backups as those copies rotate out.
- Driver app data — task events, the locations and verification outcomes attached to them, photographs and submitted documents are kept while the driver is linked to the carrier, and then for 24 months, because they are the evidence behind a delivery and a working-time record. A driver who ends their account has it closed at once; the events stay with the carrier whose work they document.
- Reviews — kept while the review stands. Withdrawing consent removes a published quote from the site immediately; asking us to delete the review removes it entirely. We keep no copy of a deleted review beyond the backup rotation described above.
- Absence records — kept while the driver is linked to the carrier and then for the period the carrier must keep employment records under the law that applies to it. Sickness absence is deleted on the same schedule as the rest; it is not kept longer because it is more sensitive.
10Push notifications
If you allow them, we can send notifications about things that need you: a new offer matching your search, a message, a document awaiting signature, an invoice falling due. You are never asked for this at sign-up, nothing is sent unless you accept the browser or device prompt, and refusing changes nothing else about the platform.
In the browser. Accepting creates a subscription held by your own browser's push service — Google for Chrome, Mozilla for Firefox, Apple for Safari — and we store the address it gives us so we can send to it. The message itself is encrypted before it leaves us and can only be read by your browser: the push service carries it without being able to see it. If a subscription stops working we delete it.
In the driver app. The same feature is built but not switched on: no token is registered and no notification is sent today. When it is enabled, the device's push token will be handled by the app-notification service named in the Data Processing Agreement and passed to Apple or Google to reach the handset. That will be listed there before the first notification goes out.
You can withdraw permission at any time in your browser or device settings, without telling us. We are not notified when you do; we simply stop being able to reach you, and the dead subscription is removed the next time we try.
11When we ask you for a review
We ask a company's owner for a review, and only after the platform has actually done something for them: a delivery completed through the freight exchange, or two days after a paid module is taken. The request appears in the app, and the same ask goes once by e-mail to the owner's address — once, and never repeated. We rely on our legitimate interest in learning whether the product works, balanced against how little this asks of you — a card you can close, which stops for good once you have closed it three times.
The same request goes to everyone it reaches, with the same links, whatever we expect them to say. We do not ask only the customers we think are happy, and we do not hide, delay or filter a review because of its score. Closing the card puts it away for six months; the third time you close it, it does not come back. Writing a review stops it at once.
To stop review requests entirely at any time, write to privacy@frachta.lv.
12Your data-subject rights
Under the GDPR you have the right to:
- Access — obtain a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — have data deleted (the “right to be forgotten”).
- Restriction — limit how we process your data.
- Portability — receive your data in a portable format.
- Objection — object to processing based on legitimate interests or direct marketing.
- Withdraw consent — at any time, without affecting prior processing.
13How to exercise your rights
Email privacy@frachta.lv with your request. We respond within one month, as required by the GDPR, and may ask you to verify your identity. If a request is manifestly unfounded or excessive we may refuse or charge a reasonable fee, explaining why. See also the GDPR page.
14Automated decision-making
Frachta does not make automated decisions that produce legal or similarly significant effects on you. Company verification and abuse prevention involve automated checks, but a human reviews any decision to refuse or block an account.
15Complaints to a supervisory authority
You may lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija) or the supervisory authority in your EU country of residence. We would appreciate the chance to resolve any concern directly first — write to privacy@frachta.lv.
16Changes to this policy
We may update this policy; material changes will be notified in-app or by email, and the “last updated” date and version above will change.
17Contact
Questions about this Privacy Policy? Write to privacy@frachta.lv. The controller is SIA "HEIDA LTD". Related documents: Terms & Conditions, Cookie Policy, GDPR and the Data Processing Agreement.