This version is effective from 01 January 2026.

1. Definition

“Master Agreements” mean B2B Service Agreement, Carriage Terms and Conditions as well as Standard Terms and Conditions concluded between Fracht and the Customer for the use of ALCS.

“DPA” means this Data Processing Addendum.

“ALCS” means the Automotive Logistics Control System operated by Fracht available at www.alcs.eu that the Customer can access in accordance with the Master Agreements. The ALCS operates on a Software as a Service (SaaS) model.

“ALCS User” means natural person who has ALCS account and performs actions in it on behalf of the Customer.

“Customer” means the legal entity which has concluded the Master Agreements with Fracht for the use of the ALCS.

“Customer Data” means all personal data that the Customer stores and manages in the ALCS.

“Fracht” means SIA “Fracht”, address Skanstres iela 25, Riga, LV-1013, registration number: 40103253277.

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

“Parties” mean a collective reference to Controller and Processor (or Customer and Fracht).

“Sub-Processor” means third parties engaged by the Processor to assist in fulfilling Processor’s obligations with respect to the provision of its services under the Master Agreements. List of Sub-Processors can be found on Fracht’s website.

 

The terms “personal data”, “controller”, “data subject”, “processor”, “processing” and “supervisory authority” shall have the same meaning as set out in the GDPR.

2. Role of the Parties

For the purposes of this DPA, the Customer is the personal data controller (the “Controller”) and Fracht is the personal data processor (the “Processor”) of Customer Data.

3. Processor’s obligations

3.1. The Processor shall process Customer Data only for the purpose of providing the Customer access to the ALCS as described in the Master Agreements or in accordance with the Controller’s written instructions. The Controller shall not use or process personal data for any other purpose, unless required to do otherwise by the applicable laws.

3.2. The Processor shall process the personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by the Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3.3. The Processor shall promptly inform the Controller if, in its opinion, an instruction from Controller infringes GDPR and/or other data protection laws.

3.4. The Processor shall ensure that any person authorized to process personal data on its behalf is subject to appropriate confidentiality obligations.

3.5. The Processor shall assist the Controller in responding to data subject requests, including requests for access, correction, deletion, or data portability. The Processor shall promptly inform the Controller if it receives any requests directly from data subjects.

3.6. The Processor shall assist the Controller in ensuring compliance with the Controller’s obligations under Articles 32 to 36 of the GDPR, considering the nature of processing and the information available to the Processor.

4. Controller’s obligations

4.1. The Controller shall be responsible for ensuring that the processing of personal data complies with applicable data protection laws and regulations, including the GDPR.

4.2. The Controller shall ensure that it has a lawful basis for the processing of personal data and that it has obtained any necessary consents or authorizations required under the data protection laws from the data subjects. The Controller shall provide all applicable notices to data subjects required under applicable data protection laws for the lawful processing of Customer Data by the Processor in accordance with the Master Agreements.

4.3. The Controller shall not instruct the Processor to process personal data in violation to data protection laws.

4.4. The Controller confirms that the Master Agreements along with the ALCS documentation and Customer’s configuration of the Service are Controller’s complete and final documented instructions to the Processor for the processing of Customer Data, unless otherwise agreed in writing.

5. Sub-Processing

5.1. The Controller hereby grants the Processor general authorization to engage Sub-Processors which will process Customer Data on behalf of the Processor according to the scope and purposes specified in this DPA. Up-to-date list of engaged Sub-Processors is available on Fracht’s website.

5.2. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors by making such information available on Fracht’s website no later than 14 (fourteen) days prior to the planned changes, giving the Controller the opportunity to object.

5.3. If the Controller objects to such replacement or engagement of the Sub-Processor, the Controller shall have the right to unilaterally terminate this DPA and the Master Agreements. In this case, the termination of the DPA will be the only measure that can be applied by the Controller and the Processor will not be obliged to compensate damages to the Controller.

5.4. If the Controller withdraws its general authorization to engage or replace a Sub-Processor, the Processor shall have the right to unilaterally terminate the Master Agreements, and such termination shall be considered to have been made for important reasons. The Controller shall be deemed not to have suffered any damage due to such termination.

5.5. If the Controller does not object to replacement or engagement of a new Sub-Processor within 10 (ten) days after being notified by the Processor according to clause 5.2 of this DPA, it shall be considered that the Controller agrees to change of Sub-Processors.

5.6. The Processor shall enter into a written agreement with the Sub-Processors that imposes the same obligations on the Sub-Processors regarding processing of Customer Data as imposed on the Processor under this DPA.

5.7. The Processor shall be liable against the Controller for the performance of obligations of Sub-Processors engaged.

6. Data Security and Audits

6.1. The Processor has implemented appropriate technical and organizational measures to protect the security, integrity, and confidentiality of the Customer Data and to prevent unauthorized access, disclosure, alteration, or destruction of the personal data.

6.2. Technical measures: The ALCS has user identification and authentication to prevent unauthorized access to ALCS. All ALCS Users have a unique username and must comply with Password Security Policy (minimum length check and special characters requirements). Passwords are hashed or encrypted depending on use case. All failed attempts to establish a user session are logged. The Processor implements user activity logging in ALCS to track user actions (requests to ALCS API). ALCS uses HTTPS when transferring Customer Data over public networks.

6.3. Processor’s Data Access Control: The Processor has implemented and maintains access controls that ensure that only authorized personnel can access Customer Data. Access permissions are role-based, and user access is promptly revoked upon termination or change of responsibilities. The Processor ensures that its employees understand their obligations and responsibilities under the data privacy laws when acting on behalf of the Processor.

6.4. Controller’s Data Access Control: The Controller can manage ALCS User’s access to Customer Data through its administrator account. The responsibility for determining who has access and what access is granted, as well as deciding with whom and what Customer Data is shared, lies entirely with the Controller.

6.5. Data Backup and Recovery: The Processor has implemented backup and recovery procedures to ensure the availability and integrity of Customer Data. Data recovery plans are tested periodically.

6.6. Incident Response: The Processor has an incident response plan to address and mitigate any security incidents promptly. The Controller shall be notified of any incidents affecting personal data as per the terms of this DPA.

6.7. Data Retention: Upon termination of this DPA or as otherwise instructed by the Controller, the Processor shall securely delete Customer Data, including backups, in a manner consistent with industry best practices.

6.8. Compliance and Security checks: The Processor from time to time conducts due diligence checks on third-party vendors or Sub-Processors to ensure their compliance with the GDPR and adequate security measures. The Processor conducts penetration testing and vulnerability scans to proactively identify and address security weaknesses.

6.9. Audits by the Controller: The Processor shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller to verify compliance with this DPA. Such audits shall be conducted at the Controller’s expense. The Controller notifies the Processor about the planned audit in writing at one week prior.

7. Data disclosure

7.1. Save as required (or where prohibited) under applicable law, the Processor shall notify the Controller of any request received from a data subject or any third party, whether directly or through a Sub-Processor, regarding personal data processing in accordance with Master Agreements and this DPA.

7.2. The Processor shall notify the Customer of any requests for the disclosure of Customer Data by a governmental or regulatory body or law enforcement authority (including any data protection supervisory authority) unless otherwise prohibited by law or a legally binding order of such body or agency.

7.3. The Processor may disclose Customer Data to data subjects or third parties only after receiving written authorization from the Controller, unless required to do otherwise by applicable laws.

8. International transfers

8.1. The Processor shall not transfer the Customer Data to a recipient in a country or territory outside the European Union unless:

  1. the recipient, or the country or territory in which it processes or accesses the Customer Data, ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of Customer Data as determined by the European Commission; or
  2. the transfer is based on the Standard Contractual Clauses approved by European Commission, or another legally recognised transfer method.

9. Data breach notification

The Processor shall notify the Controller without undue delay upon becoming aware of any personal data breach. The Processor shall provide the Controller with a sufficient information to allow the Controller to meet any obligations to report or inform competent supervisory authorities and data subjects, as required under the GDPR.

10. Duration and Termination

This DPA shall remain in effect for the duration of the Master Agreements. Upon the termination of the Master Agreements or as otherwise directed by the Controller, the Processor shall, at the choice of the Controller, delete or return all personal data to the Controller and delete existing copies, unless applicable law requires retention of the personal data.

11. Governing Law and Jurisdiction

11.1. This DPA shall be governed by and construed in accordance with the laws of Republic of Latvia.

11.2. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Republic of Latvia.