Legal
Privacy policy
Information on the processing of personal data pursuant to Articles 13 and 14 GDPR.
Draft — to be reviewed by counsel before go-live: The technical descriptions match what this application actually does. The legal classification, open retention periods and particulars of the controller must be checked and completed by a qualified advisor. Square brackets are gaps, not guesses.
Controller
- Controller
- cargo protection gf GmbH
Mitterstraße 287a
8073 Seiersberg-Pirka, Austria - Companies register
- FN 685320 z, Landesgericht für Zivilrechtssachen Graz
- office@cargo-protection.com
- Phone
- +43 316 395334-0
- Data protection contact
- [Not appointed as Data Protection Officer on this page. Counsel to decide whether Art. 37 GDPR requires a DPO. Naming the managing director as DPO would likely conflict with Art. 38 (6) GDPR.]
What this page covers
This statement describes four situations. You can read them independently — depending on how you deal with us.
- You visit this website. Then server logs arise. Necessary cookies and a cookie notice (no marketing or analytics scripts).
- You use the software. Then account, uploaded papers and check reports are added.
- You report a fake. Then we process details of the reported carrier and, if you give them, your own.
- You write to us. Then we process your enquiry.
Visiting the website
When you retrieve pages, your browser transmits technically necessary data to the server. That usually includes IP address, time, requested address, volume transferred, browser and operating system. Legal basis is our legitimate interest in a secure, stable operation of the website (Art. 6 (1) (f) GDPR).
This website and the software are one application, hosted by Railway (servers preferably in the EU — [confirm region]). There is no separate World4You site host.
[For counsel: retention of server logs; Art. 28 DPA with Railway, full legal name, address and seat, and whether seat in a third country could still allow access even if servers are in the EU.]
Encryption
Transmission between your browser and our server is encrypted with TLS. You see that from the lock in the address bar and from https:// before the address.
Fonts
Marketing pages and the signed-in application load Space Grotesk, Inter and JetBrains Mono from this application. They do not contact Google Fonts.
Cookies and site data
We do not load Matomo, Meta, LinkedIn, Plausible, Sentry or other marketing or analytics scripts. Statistics and marketing cookies are not in use. A short notice records that you have seen this (necessary cookies only).
Necessary first-party cookies and local storage run the site and the signed-in product. Legal basis: performance of the contract (Art. 6 (1) (b) GDPR) where you have an account, and legitimate interest in a usable, secure service (Art. 6 (1) (f) GDPR).
| Name | Type | Duration | Purpose |
|---|---|---|---|
cp_lang | cookie | 1 year | Remembers English or German on the public site after you use the language switch. |
sb-<project>-auth-token (and .0 / .1 chunks) | cookie | Session / refresh lifetime (Supabase Auth) | Keeps you signed in. Set only after you create an account or sign in. |
sidebar_state | cookie | 7 days | Remembers whether the signed-in sidebar is open. App chrome only. |
cp_consent / cp_consent_id | cookie | 1 year | Remembers that you saw the cookie notice and stores an anonymous id for the consent record. |
cp_training_locale | localStorage | Until you clear site data | Remembers English or German on the Training tab. |
Other site data (not cookies, but similar):
- Server logs on Railway: IP address, time, requested URL, browser user-agent — needed to operate and secure the site.
- First-visit language default: CDN country header (e.g. CF-IPCountry) or a local IP-to-country table for DE/AT/CH/LI. The address is not sent to a geolocation vendor.
- Signup trial-abuse checks: timezone, language, screen-size class and OS family in the browser. We store an HMAC of the IP and of that device class — not a unique fingerprint.
- Signup IP and user-agent are stored on a server-only record for abuse prevention and GDPR documentation. They are not shown in Settings.
- If you start a paid subscription, Stripe Checkout runs on stripe.com and may set its own cookies there. That happens only when you open Checkout.
The exact Supabase cookie name includes the project reference (sb-…-auth-token). Chunked variants exist when the session value is large.
Using the software
To check carriers you create a user account. What is processed is described here; contractual conditions belong in the Terms.
User account
For the account we process the details you give at sign-up — name, email address, company, access data, and optionally an EU VAT number — plus usage data such as sign-in times and the number of checks run. Legal basis is performance of the contract of use (Art. 6 (1) (b) GDPR).
Free-trial abuse checks
To stop people farming extra free scans with throwaway accounts we compute a signup risk score (not the cargo-document score). It can reduce or set to zero the unverified free quota. It does not refuse the account, and a valid unused EU VAT or a paid plan still unlocks scans. Signals we use: whether the sign-up email looks disposable, role-based or free-mail; how many trial workspaces recently appeared from the same network; whether another sandbox on that network already used its free scans; coarse device class (timezone, language, operating-system family, screen-size class); and automated-browser hints from the user-agent. We store an HMAC of the IP address and of that device class — not the raw IP, not a unique device fingerprint (no canvas/WebGL/audio). Sighting hashes are kept about 30 days; the score stays on the workspace until the account is deleted. Legal basis: legitimate interest in preventing trial abuse (Art. 6 (1) (f) GDPR). [Counsel: confirm Art. 22 — automated quota sizing with VAT/pay/admin override — and whether ePrivacy requires extra notice for the device-class signals.]
If the sign-up mailbox is not on our local free-mail list we may send the address to Bouncer (already a processor for document contact emails) to see if it is disposable or a role/catch-all address.
Uploaded papers
You upload transport offers, freight papers, correspondence or whole emails. Then the following happens:
- Every file is first checked for malware. Legal basis is our legitimate interest in the security of the system and of all users’ data (Art. 6 (1) (f) GDPR). We use attachmentAV (EU) for that. DPA confirmation still open; listed on the subprocessors page. We do not list Sophos.
- OCR reads the data and maps it to check fields. We use Google Cloud Document AI for that.
- The extracted text is evaluated with AI support. We use OpenAI (API, not ChatGPT) for that.
- Individual details are checked with specialist services — domain registration data at WhoisXML, email validity at Bouncer, phone line type at Twilio, VAT existence at VIES (European Commission public API).
- Details are scored under the rules of the four modules. That produces the check report with the cp-score.
The full list of providers and their tasks is on the subprocessors page.
These papers regularly contain personal data of third parties — for example name and signature of driving staff, extensions of contacts, or particulars of sole traders. What is uploaded is your decision. We process these data solely for the check you requested.
[For counsel: whether we are controller or processor for these third-party data. In the second case a data-processing agreement belongs in the Terms.]
Check reports and cp-rating
The report stays in your account and can be used again when the same carrier reappears. Results from checks flow in anonymised form into scoring of future enquiries — without tracing who ran the check.
Retention
Uploaded papers are stored for three years and then deleted. [FAQ publishes this figure; counsel to confirm and to set retention of reports and account data after the contract ends, including tax retention of invoices.]
Hosting of the software
The application runs on Railway; database, sign-in and file storage run on Supabase. Server locations should be in the EU — [confirm each region]. Providers that process content of your papers also include US-parent companies; see Recipients and third-country transfers.
Payments
Card payments are handled by Stripe (Stripe Payments Europe, Ltd., Dublin, when live). You enter payment data at Stripe — full card numbers do not reach us. From Stripe we receive what we need for invoicing: name, billing address, amount, method and payment status. Legal basis is performance of the contract (Art. 6 (1) (b) GDPR). Stripe’s DPA is still open before live keys.
[For counsel: full address of Stripe Payments Europe, the DPA, invoice retention, and whether Stripe transfers to the US parent.]
Reporting desk “Report fakes”
Via the report form you can report a carrier that appeared as a fake. Reporting is voluntary and anonymous if you wish.
What is transmitted
- Details of the reported carrier: company, address, country, register and VAT numbers, licence, website, emails, phone, plates and name of driving staff.
- Details of the incident: type, date, route, load, loss amount, platform, account, and whether a police report was filed.
- Evidence, if you attach any. Files are scanned for malware and stored in a private bucket with the report.
- Your own details — name, company, email, phone. These fields are optional. Without them we cannot follow up; we still take the report.
Legal basis is your consent given expressly on send (Art. 6 (1) (a) GDPR) and our legitimate interest and that of other users in preventing further losses (Art. 6 (1) (f) GDPR).
How the report is sent
Submit posts the form to our server over HTTPS. We store the report (and any evidence files) and notify admin@cargo-protection.com by email. If you left an email address, we set it as Reply-To so the desk can answer you. You do not need to send a separate message from your own mail program.
Evidence files we accept: PDF, JPEG, PNG, and saved emails (.eml / .msg), together at most 25 MB. Office or ZIP files are not accepted.
What happens to the report
- We examine it and match it to known patterns.
- What flows into scoring of future enquiries is first anonymised.
- We publish neither the reported name nor your details and do not pass them to third parties for advertising.
- If you ticked the box, we contact you if further reports on the same carrier arrive.
We cannot withdraw a sent report. You can always have your own contact details deleted — write to the address below.
[For counsel: retention of reports and evidence, timing of anonymisation, and information of the reported person under Art. 14 GDPR where personal data are involved.]
Contact
If you contact us by email or phone, we process your details to handle the enquiry. Legal basis is taking steps prior to a contract or performance of a contract (Art. 6 (1) (b) GDPR) or our legitimate interest in answering (Art. 6 (1) (f) GDPR).
[For counsel: retention of correspondence.]
Recipients of your data
We do not sell data and do not pass them on for advertising. Access is limited to the providers named on the subprocessors page, and only as needed for their task: Railway, Supabase, Google Cloud Document AI, OpenAI, WhoisXML, Bouncer, Twilio, Resend, attachmentAV, Stripe (when live), and VIES as a public EU API.
Added to that are authorities and courts where we are legally obliged to disclose, our tax advisor and, in a dispute, our legal representation within the statutory frame.
[For counsel: for each provider, contracting party, seat, processing region, Art. 28 DPA and subprocessors, plus whether OpenAI and Google may use content for training and whether zero-retention is agreed.]
Transfers to third countries
Hosting is intended to be in the EU. Processing nevertheless involves providers whose parent companies sit in the United States — including the services that read and evaluate text from your papers (Google Document AI, OpenAI, and depending on configuration WhoisXML, Twilio and Stripe).
[For counsel: for each provider, whether a transfer to a third country takes place or access from there is possible, and on which basis — adequacy decision, standard contractual clauses plus supplementary measures, or an Art. 49 GDPR exception. Until that is complete this section cannot be final, and no landing-page claim that “data stay in Europe” is made.]
No automated individual decision
The cp-rating scores companies, not persons, and it decides nothing. Whether a job is awarded is decided solely by the person in dispatch — the score is a decision aid that complements their own check and does not replace it. In our view this is not an automated decision under Art. 22 GDPR.
[For counsel: for sole traders the score can have a personal reference. This view should be confirmed or corrected before go-live.]
Your rights
You have the following rights against us:
- Access to personal data processed about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consents with effect for the future (Art. 7 (3) GDPR)
Write to office@cargo-protection.com. We reply within the statutory one-month period.
Independently of that you may complain to a supervisory authority. In Austria that is the Datenschutzbehörde, Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
There is no self-serve button to delete a company and its files. Email office@cargo-protection.com to request deletion of the workspace, accounts and uploaded files. We handle that as an admin GDPR request.
Status
Draft of 30 August 2026, based on the German structure of 27 August 2026, adapted to this single Railway application. We will update this statement when processing changes — in particular when the reporting desk posts to a server endpoint and when live payments are switched on.