ISO 27001 Certified • GDPR (EU 2016/679) Compliant

Privacy & Data Protection Policy.

Effective Version 4.2 • September 2026 • Apex Freight HUB Data Protection Office

Summary of Our Commitment

Apex Freight HUB, together with its European operating subsidiaries (Apex Logistics Germany GmbH, Apex Freight Poland Sp. z o.o., and Apex Baltics UAB), is committed to safeguarding customer commercial confidentiality, cargo manifests, shipment telematics, and personal data. We strictly abide by the General Data Protection Regulation (EU Regulation 2016/679), the UK Data Protection Act 2018, and international data protection standards.

01Data Controller Identification

The joint data controllers responsible for your personal and shipment data across the Apex Freight HUB platform are:

Central European Controller:

Apex Logistics Germany GmbH

Gänsemarkt 31, 20354 Hamburg

HRB 184920 Hamburg

Eastern European Controller:

Apex Freight Poland Sp. z o.o.

Al. Niepodległości 214, 00-608 Warszawa

KRS 0000984120

Baltic Operating Controller:

Apex Baltics UAB

Islandijos Plentas, 47446 Kaunas

Reg. 304918290

Data Protection Officer Contact: [email protected] (Ref: DPO Inquiries).

02Comprehensive Categories of Collected Data

To execute multi-modal freight transport, generate compliant transport documents (Bills of Lading, AWBs, CMR waybills), and provide continuous telemetry tracking, we collect and process:

A. Shipper & Consignee Information

Legal company names, authorized booking contact names, email addresses, dispatch desk numbers, tax identification numbers (VAT, EORI, EIN), and physical pickup/delivery addresses.

B. Cargo Manifest & Customs Data

Commercial invoices, packing lists, declared customs value, harmonized system (HS) classification tariff codes, certificates of origin, dangerous goods declarations (MSDS), and import/export licenses.

C. Real-Time Telematics & Operational Events

GPS satellite coordinates from linehaul vehicles, marine AIS transponder feeds, flight telemetry milestone timestamps, temperature and humidity logger records (for cold chain pharmaceutical freight), container seal serial numbers, and digital Proof of Delivery (POD) signatures.

D. Portal Authentication & Financial Records

Encrypted login credentials, audit session logs, IP addresses, credit references, bank account routing details for automated freight settlement, and invoicing records.

03Legal Bases for Processing Under GDPR

We only process your data when a recognized lawful basis exists under Article 6 of the GDPR:

  • Contractual Necessity (Art. 6(1)(b)): Essential for booking freight, linehaul execution, customs clearance, tracking telemetry, and freight invoicing.
  • Legal & Regulatory Compliance (Art. 6(1)(c)): Mandatory reporting to government customs agencies (EU ATLAS, UK CDS, US CBP), tax accounting, and anti-money laundering (AML) verification.
  • Legitimate Interests (Art. 6(1)(f)): Ensuring cargo security, route optimization, fraud prevention, and platform stability.

04Third-Party Carrier & Customs Data Sharing

Because international shipping requires cross-border handoffs, data is transmitted strictly on a need-to-know operational basis to:

  • Integrated Carrier Alliances: Direct API/EDI transmission to UPS, DHL Aviation, FedEx Express, Maersk Line, Flexport, and KLG Europe to schedule pickup, booking, and final-mile delivery.
  • Customs & Border Authorities: Direct electronic declaration transmission to tax and customs clearance systems across 180+ jurisdictions.
  • Terminal & Port Operators: Crane discharge manifests and container chassis release PINs at marine and inland intermodal terminals.
  • Insurance Underwriters: In the event of a formal cargo loss or damage claim filing.

⚠️ Apex Freight HUB will never sell, lease, or monetize customer shipment manifests, pricing records, or supplier details to third-party marketing brokers.

05International Data Transfers & Standard Clauses

For freight shipments moving between the European Economic Area (EEA) and third countries (e.g. United States, United Kingdom, Singapore, UAE), data transfers are governed by:

  • • European Commission approved Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914.
  • • European Commission Adequacy Decisions for recognized safe third countries (e.g. UK, Switzerland, Japan).
  • • Mandatory transfer impact assessments and end-to-end TLS 1.3 encryption in transit.

06Data Retention Schedules

We retain personal and shipment data only as long as necessary to fulfill transportation agreements and satisfy statutory tax and commercial law retention requirements:

Customs Declarations

7–10 Years

Statutory EU / US customs audit mandate

Bills of Lading & PODs

5 Years

Commercial contract limitation period

Live Telematics GPS Logs

12 Months

Archived for dispute & SLA analysis

07Your Statutory Rights Under GDPR

As a data subject under the GDPR, you possess the following enforceable rights:

Right of Access (Art. 15):

Request a complete copy of all personal records we hold regarding your account.

Right to Rectification (Art. 16):

Correct inaccurate address records, contact information, or company details.

Right to Erasure (Art. 17):

Request deletion of non-statutory records when processing is no longer required.

Right to Data Portability (Art. 20):

Export your shipment records and telematics history in a structured CSV/JSON format.

To exercise any of these rights, submit a written request to [email protected]. We respond to all verified requests within 30 calendar days without charge.

08Information Security & ISO 27001 Standards

Our platform employs enterprise-grade technical and organizational security measures:

  • Encryption: TLS 1.3 for all data in transit; AES-256 bit encryption for all database volumes at rest.
  • Access Control: Role-based access control (RBAC), multi-factor authentication (MFA) enforcement for portal operators, and continuous immutable audit logging.
  • Physical Security: Tier-4 certified European data centers with 24/7 biometric security and automatic geo-redundant backups.

09Supervisory Authority & Complaints

If you believe our processing of your personal data infringes data protection laws, you have the right to lodge a formal complaint with a European Data Protection Supervisory Authority:

  • Germany: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI), Ludwig-Erhard-Str. 22, 20459 Hamburg.
  • Poland: Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa.
  • Lithuania: Valstybinė duomenų apsaugos inspekcija (VDAI), L. Sapiegos g. 17, 10312 Vilnius.