Privacy Notice
Privacy Notice
Last updated: 4 July 2026 — Beta.
This Privacy Notice explains how [LEGAL ENTITY NAME] ("aclRate", "we", "us")
collects, uses, and protects personal data when you use the aclRate freight
procurement platform and related services (the "Service"). It is written with the EU
General Data Protection Regulation (GDPR) and the UK GDPR in mind.
1. Controller
For personal data about your account and your use of the Service, **[LEGAL ENTITY
NAME], [REGISTERED ADDRESS]**, is the data controller. For the shipment, carrier,
and pricing data you upload to run a tender ("Customer Data"), you are the controller
and we act as your processor, processing it on your instructions to provide the
Service. Our processing as your processor is governed by these terms and, where
applicable, a Data Processing Agreement.
2. Personal data we process
- Account data: name, work email, organisation, role, plan, and authentication
identifiers.
- Usage data: log data, pages and features used, IP address, device and browser
information, and audit records of actions taken in the Service.
- Billing data: where you subscribe to a paid plan, billing contact and
transaction records (payment-card data is handled by our payment processor, not
stored by us).
- Customer Data: the files and content you upload. These may incidentally contain
personal data (for example, a contact name in a shipment record). You control what
you upload; please avoid uploading personal data that is not necessary for the
tender.
- Support and communications: messages you send us and our responses.
3. Why we process it and our legal bases
- To provide the Service and your account — performance of a contract (Art. 6(1)(b)).
- To secure the Service, prevent abuse, and keep audit records — our legitimate
interests (Art. 6(1)(f)) and legal obligations (Art. 6(1)(c)).
- To bill paid plans — performance of a contract and legal obligation.
- To improve the Service using aggregated or de-identified data — legitimate
interests. We do not use your Customer Data to train models for other customers
without your instruction.
- To communicate with you about the Service — legitimate interests or, for
marketing, your consent (Art. 6(1)(a)) where required.
4. Cookies
We use strictly necessary cookies to keep you signed in, prevent CSRF, and remember
your cookie choice. We do not use third-party marketing or advertising cookies on the
core application. See our Cookie Notice for details.
5. Sharing and sub-processors
We share personal data only with:
- Sub-processors who host and support the Service (for example, cloud hosting and
storage, authentication, and payment providers), under contract and only as needed
to provide the Service;
- Authorities where required by law; and
- A successor in the event of a merger, acquisition, or reorganisation, subject to
this Notice.
We do not sell personal data. A current list of sub-processors is available on request.
6. International transfers
Where personal data is transferred outside the EEA or the UK, we rely on appropriate
safeguards such as European Commission adequacy decisions or Standard Contractual
Clauses. Details are available on request.
7. Retention
We retain account and usage data for as long as your account is active and as needed
for the purposes above, then delete or anonymise it within a reasonable period. We
retain Customer Data under your control; you can delete tenders and data in the app,
and we delete or return Customer Data on termination in line with your agreement.
Audit and billing records may be kept longer where required by law.
8. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or
object to the processing of your personal data, to data portability, and to withdraw
consent where processing is based on consent. To exercise these rights, contact us
using the details below. If we process personal data as your processor (Customer
Data), please direct data-subject requests to the controller (your organisation); we
will assist as required.
You also have the right to lodge a complaint with a supervisory authority (for
example, your local Data Protection Authority).
9. Security
We use technical and organisational measures to protect personal data, including
access controls, encryption in transit, tenant isolation, and audit logging. No system
is perfectly secure, but we work to protect your data and to notify you of incidents as
required by law.
10. Children
The Service is intended for business use and is not directed to children under 16. We
do not knowingly collect personal data from children.
11. Changes
We may update this Notice from time to time. Material changes will be notified through
the Service or by other reasonable means.
12. Contact
For privacy questions or to exercise your rights, contact **[PRIVACY / DPO CONTACT
EMAIL]** or the address shown in the app. If we have appointed a Data Protection
Officer or EU/UK representative, their details will be listed here: **[DPO /
REPRESENTATIVE DETAILS]**.