This version is effective from 01 January 2026.
1. Introduction
This policy outlines how SIA “Fracht”, registration number: 40103253277, address: Vesetas iela 7, Riga, LV-1013 (“Fracht”, “we”, “our”, or “us”) processes your personal data when you engage with our services as a ALCS user or interact with us. For any inquiries or concerns regarding this policy, you can contact us at gdpr@fracht.lv.
We are committed to ensuring the protection and privacy of your personal data. This policy aims to inform you about the types of information we collect, how we use it, and your rights in relation to the processing of your personal data.
2. Definitions
“Agreement” refers to B2B Service Agreement concluded between Fracht and the client, a legal entity, for the use of ALCS.
“ALCS” means the Automotive Logistics Control System operated by Fracht, available at www.alcs.eu upon Agreement conclusion. The ALCS operates on a Software as a Service (SaaS) model.
The terms “personal data”, “controller”, “data subject”, “processor”, “processing” and “supervisory authority” hold the same meaning as defined in the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (“GDPR”).
3. Data controller
3.1. We act as data controllers when processing personal data for the purposes outlined in this privacy policy.
3.2. Our clients act as data controllers for the information uploaded to the ALCS, which may contain personal data. In providing our services, we store, process, and transmit the data uploaded by clients to the ALCS. This data is processed exclusively based on the client’s instructions and in accordance with the terms stipulated in the Data Processing Agreement concluded between us and the client.
4. What personal data we collect, for what purpose and on what legal basis?
4.1. We may process the following categories of personal data:
- Client account information– when a client uses our services, we collect and associate with client’s user account the information the client provides us like client’s company name, registration country, VAT code, client user’s position within the company, language preference, name and surname, email address and mobile phone number. We process this data to provide our services on the basis of the Agreement. The legal basis for this processing is contractual necessity.
- Your usage information– We collect information on how you use our service. We may collect information like IP address and the type of browser you use. We use this information in our legitimate interest to maintain and enhance our service, as well as for improving the overall user experience. For instance, we collect data on your browser type to facilitate troubleshooting and ensure the seamless functionality of our web application across all browsers. Additionally, your IP address information is collected for troubleshooting purposes and threat analysis, especially when we detect suspicious activity.
- Request information – to answer your requests, we process personal data that you provide when submitting request on our website or by other means. This data may include your name, company name, email address, phone number and message content as well as other data that you provide. The legal basis for this processing is our legitimate interest in providing information to prospective clients about our service and onboarding new clients.
4.2. The processing of client account information and other data related to the Agreement is a prerequisite for us to provide you with the service.
5.How long do we store your data?
5.1. We will store the personal information we collect for our own purposes for no longer than necessary for the purposes set out in this policy and in accordance with our legal obligations and legitimate business interests.
5.2. We store users’ personal data, including their name, contact information, position within the company, and phone number, as long as the user remains active and has not been forgotten. A user can be forgotten when there are no business objects related to them. For instance, if a user creates an invoice in ALCS, we retain the invoice for 10 years due to its financial data and relevance to Anti-Money Laundering (AML) regulations. Consequently, the user cannot be forgotten for the duration of these 10 years. Such data as invoices, bank account details, orders, and payments, belongs to the client (legal entity) with which we have concluded the Agreement. This data does not pertain to the individual user.
6. Who may access your data?
6.1. We have implemented various tools and services to enhance our service. Consequently, we may disclose your data to our IT support, payment service providers, and other vendors. A detailed list of all our service providers is available here.
6.2. We may disclose your data to law enforcement, regulators, and other parties for legal reasons. This may include sharing your personal information if we reasonably believe that such action is necessary to:
- comply with the law and the reasonable requests of law enforcement;
- detect and investigate illegal activities and breaches of agreements; and/or
- exercise or protect the rights, property, or personal safety of Fracht, its users or others.
6.3. We may share and/or transfer your personal data in the event of any merger, acquisition, reorganization, sale of assets, or bankruptcy that involves Fracht.
7. Where do we store your data?
We process your personal data within the EU/EEA. When selecting our partners, we make sure they provide us with the possibility to limit data processing to the EU/EEA, if possible. In the event that your data is transferred outside of the EU/EEA by one of our partners, we ensure in our agreements that this happens in accordance with applicable data protection law. Under no circumstances will we transfer your Customer Data outside of the EU/EEA.
8. How do we protect your information?
We maintain physical, technical and administrative safeguards to help protect the privacy of data and personally identifiable information you transmit to us. We restrict access to your personal data only to staff members who require such information to provide services to you. We also train our staff about the importance of confidentiality and ensuring the privacy and security of your information.
9. What are your rights?
9.1. Access. You have the right to obtain confirmation as to whether or not personal data concerning you is being processed and, if so, access to that personal data along with additional information, such as the purposes of processing and the categories of personal data involved.
9.2. Rectification. If the personal data we hold about you is inaccurate or incomplete, you have the right to request rectification. We will make reasonable efforts to ensure that your data is accurate and up-to-date.
9.3. Erasure (Right to be Forgotten). You have the right to request the deletion of your personal data under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, or when you withdraw your consent and there is no other legal basis for processing.
9.4. Restriction of Processing. You have the right to request the restriction of processing of your personal data under certain circumstances, for example, if you contest the accuracy of the data or if the processing is unlawful, and you oppose the erasure of the data.
9.5. Data Portability. You have the right to receive your personal data in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller without hindrance from us, where technically feasible.
9.6. Objection to Processing. You have the right to object to the processing of your personal data, based on grounds relating to your particular situation, unless we have compelling legitimate grounds for the processing that override your interests, rights, and freedoms.
9.7. Withdrawal of Consent. Where we rely on your consent as the legal basis for processing, you have the right to withdraw your consent at any time. This withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
9.8. Automated Decision-Making. You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless such processing is necessary for entering into, or the performance of, a contract, or is authorized by applicable law. We do not employ automated decision-making, including profiling.
9.9. Exercising Your Rights. To exercise any of the rights mentioned above, please contact us using the details provided at the end of this privacy policy. We will respond to your request within a reasonable timeframe and in accordance with applicable data protection laws.
9.10. Please note that certain limitations and exceptions may apply to these rights, depending on the specific circumstances of the processing activities and applicable laws. If you have concerns about the way we handle your personal data, you have the right to lodge a complaint with the relevant supervisory authority. In Latvia the supervisory authority is the Data State Inspectorate, whose contact information can be found here: https://www.dvi.gov.lv/en.
10. Changes to this policy
We may update this policy to reflect changes in our practices. Check this page periodically for the latest information.
11. Contact Us
If you have any questions, concerns, or complaints about this privacy policy, you may contact us by writing to gdpr@fracht.lv.

