aclRate
Legal

Privacy Notice

Privacy Notice

Last updated: 4 July 2026 — Beta.

This Privacy Notice explains how [LEGAL ENTITY NAME] ("aclRate", "we", "us")

collects, uses, and protects personal data when you use the aclRate freight

procurement platform and related services (the "Service"). It is written with the EU

General Data Protection Regulation (GDPR) and the UK GDPR in mind.

1. Controller

For personal data about your account and your use of the Service, **[LEGAL ENTITY

NAME], [REGISTERED ADDRESS]**, is the data controller. For the shipment, carrier,

and pricing data you upload to run a tender ("Customer Data"), you are the controller

and we act as your processor, processing it on your instructions to provide the

Service. Our processing as your processor is governed by these terms and, where

applicable, a Data Processing Agreement.

2. Personal data we process

  • Account data: name, work email, organisation, role, plan, and authentication

identifiers.

  • Usage data: log data, pages and features used, IP address, device and browser

information, and audit records of actions taken in the Service.

  • Billing data: where you subscribe to a paid plan, billing contact and

transaction records (payment-card data is handled by our payment processor, not

stored by us).

  • Customer Data: the files and content you upload. These may incidentally contain

personal data (for example, a contact name in a shipment record). You control what

you upload; please avoid uploading personal data that is not necessary for the

tender.

  • Support and communications: messages you send us and our responses.

3. Why we process it and our legal bases

  • To provide the Service and your account — performance of a contract (Art. 6(1)(b)).
  • To secure the Service, prevent abuse, and keep audit records — our legitimate

interests (Art. 6(1)(f)) and legal obligations (Art. 6(1)(c)).

  • To bill paid plans — performance of a contract and legal obligation.
  • To improve the Service using aggregated or de-identified data — legitimate

interests. We do not use your Customer Data to train models for other customers

without your instruction.

  • To communicate with you about the Service — legitimate interests or, for

marketing, your consent (Art. 6(1)(a)) where required.

4. Cookies

We use strictly necessary cookies to keep you signed in, prevent CSRF, and remember

your cookie choice. We do not use third-party marketing or advertising cookies on the

core application. See our Cookie Notice for details.

5. Sharing and sub-processors

We share personal data only with:

  • Sub-processors who host and support the Service (for example, cloud hosting and

storage, authentication, and payment providers), under contract and only as needed

to provide the Service;

  • Authorities where required by law; and
  • A successor in the event of a merger, acquisition, or reorganisation, subject to

this Notice.

We do not sell personal data. A current list of sub-processors is available on request.

6. International transfers

Where personal data is transferred outside the EEA or the UK, we rely on appropriate

safeguards such as European Commission adequacy decisions or Standard Contractual

Clauses. Details are available on request.

7. Retention

We retain account and usage data for as long as your account is active and as needed

for the purposes above, then delete or anonymise it within a reasonable period. We

retain Customer Data under your control; you can delete tenders and data in the app,

and we delete or return Customer Data on termination in line with your agreement.

Audit and billing records may be kept longer where required by law.

8. Your rights

Subject to applicable law, you have the right to access, rectify, erase, restrict, or

object to the processing of your personal data, to data portability, and to withdraw

consent where processing is based on consent. To exercise these rights, contact us

using the details below. If we process personal data as your processor (Customer

Data), please direct data-subject requests to the controller (your organisation); we

will assist as required.

You also have the right to lodge a complaint with a supervisory authority (for

example, your local Data Protection Authority).

9. Security

We use technical and organisational measures to protect personal data, including

access controls, encryption in transit, tenant isolation, and audit logging. No system

is perfectly secure, but we work to protect your data and to notify you of incidents as

required by law.

10. Children

The Service is intended for business use and is not directed to children under 16. We

do not knowingly collect personal data from children.

11. Changes

We may update this Notice from time to time. Material changes will be notified through

the Service or by other reasonable means.

12. Contact

For privacy questions or to exercise your rights, contact **[PRIVACY / DPO CONTACT

EMAIL]** or the address shown in the app. If we have appointed a Data Protection

Officer or EU/UK representative, their details will be listed here: **[DPO /

REPRESENTATIVE DETAILS]**.