Privacy & Data Protection Policy.
Effective Version 4.2 • September 2026 • Apex Freight HUB Data Protection Office
Summary of Our Commitment
Apex Freight HUB, together with its European operating subsidiaries (Apex Logistics Germany GmbH, Apex Freight Poland Sp. z o.o., and Apex Baltics UAB), is committed to safeguarding customer commercial confidentiality, cargo manifests, shipment telematics, and personal data. We strictly abide by the General Data Protection Regulation (EU Regulation 2016/679), the UK Data Protection Act 2018, and international data protection standards.01Data Controller Identification
The joint data controllers responsible for your personal and shipment data across the Apex Freight HUB platform are:
Central European Controller:
Apex Logistics Germany GmbH
Gänsemarkt 31, 20354 Hamburg
HRB 184920 Hamburg
Eastern European Controller:
Apex Freight Poland Sp. z o.o.
Al. Niepodległości 214, 00-608 Warszawa
KRS 0000984120
Baltic Operating Controller:
Apex Baltics UAB
Islandijos Plentas, 47446 Kaunas
Reg. 304918290
Data Protection Officer Contact: [email protected] (Ref: DPO Inquiries).
02Comprehensive Categories of Collected Data
To execute multi-modal freight transport, generate compliant transport documents (Bills of Lading, AWBs, CMR waybills), and provide continuous telemetry tracking, we collect and process:
A. Shipper & Consignee Information
Legal company names, authorized booking contact names, email addresses, dispatch desk numbers, tax identification numbers (VAT, EORI, EIN), and physical pickup/delivery addresses.
B. Cargo Manifest & Customs Data
Commercial invoices, packing lists, declared customs value, harmonized system (HS) classification tariff codes, certificates of origin, dangerous goods declarations (MSDS), and import/export licenses.
C. Real-Time Telematics & Operational Events
GPS satellite coordinates from linehaul vehicles, marine AIS transponder feeds, flight telemetry milestone timestamps, temperature and humidity logger records (for cold chain pharmaceutical freight), container seal serial numbers, and digital Proof of Delivery (POD) signatures.
D. Portal Authentication & Financial Records
Encrypted login credentials, audit session logs, IP addresses, credit references, bank account routing details for automated freight settlement, and invoicing records.
03Legal Bases for Processing Under GDPR
We only process your data when a recognized lawful basis exists under Article 6 of the GDPR:
- Contractual Necessity (Art. 6(1)(b)): Essential for booking freight, linehaul execution, customs clearance, tracking telemetry, and freight invoicing.
- Legal & Regulatory Compliance (Art. 6(1)(c)): Mandatory reporting to government customs agencies (EU ATLAS, UK CDS, US CBP), tax accounting, and anti-money laundering (AML) verification.
- Legitimate Interests (Art. 6(1)(f)): Ensuring cargo security, route optimization, fraud prevention, and platform stability.
04Third-Party Carrier & Customs Data Sharing
Because international shipping requires cross-border handoffs, data is transmitted strictly on a need-to-know operational basis to:
- • Integrated Carrier Alliances: Direct API/EDI transmission to UPS, DHL Aviation, FedEx Express, Maersk Line, Flexport, and KLG Europe to schedule pickup, booking, and final-mile delivery.
- • Customs & Border Authorities: Direct electronic declaration transmission to tax and customs clearance systems across 180+ jurisdictions.
- • Terminal & Port Operators: Crane discharge manifests and container chassis release PINs at marine and inland intermodal terminals.
- • Insurance Underwriters: In the event of a formal cargo loss or damage claim filing.
⚠️ Apex Freight HUB will never sell, lease, or monetize customer shipment manifests, pricing records, or supplier details to third-party marketing brokers.
05International Data Transfers & Standard Clauses
For freight shipments moving between the European Economic Area (EEA) and third countries (e.g. United States, United Kingdom, Singapore, UAE), data transfers are governed by:
- • European Commission approved Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914.
- • European Commission Adequacy Decisions for recognized safe third countries (e.g. UK, Switzerland, Japan).
- • Mandatory transfer impact assessments and end-to-end TLS 1.3 encryption in transit.
06Data Retention Schedules
We retain personal and shipment data only as long as necessary to fulfill transportation agreements and satisfy statutory tax and commercial law retention requirements:
Customs Declarations
7–10 Years
Statutory EU / US customs audit mandate
Bills of Lading & PODs
5 Years
Commercial contract limitation period
Live Telematics GPS Logs
12 Months
Archived for dispute & SLA analysis
07Your Statutory Rights Under GDPR
As a data subject under the GDPR, you possess the following enforceable rights:
Right of Access (Art. 15):
Request a complete copy of all personal records we hold regarding your account.
Right to Rectification (Art. 16):
Correct inaccurate address records, contact information, or company details.
Right to Erasure (Art. 17):
Request deletion of non-statutory records when processing is no longer required.
Right to Data Portability (Art. 20):
Export your shipment records and telematics history in a structured CSV/JSON format.
To exercise any of these rights, submit a written request to [email protected]. We respond to all verified requests within 30 calendar days without charge.
08Information Security & ISO 27001 Standards
Our platform employs enterprise-grade technical and organizational security measures:
- • Encryption: TLS 1.3 for all data in transit; AES-256 bit encryption for all database volumes at rest.
- • Access Control: Role-based access control (RBAC), multi-factor authentication (MFA) enforcement for portal operators, and continuous immutable audit logging.
- • Physical Security: Tier-4 certified European data centers with 24/7 biometric security and automatic geo-redundant backups.
09Supervisory Authority & Complaints
If you believe our processing of your personal data infringes data protection laws, you have the right to lodge a formal complaint with a European Data Protection Supervisory Authority:
- • Germany: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI), Ludwig-Erhard-Str. 22, 20459 Hamburg.
- • Poland: Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa.
- • Lithuania: Valstybinė duomenų apsaugos inspekcija (VDAI), L. Sapiegos g. 17, 10312 Vilnius.