1. Scope and roles
This Privacy Notice explains how the operator identified in the Legal Notice processes personal data in connection with the LogisticsAI website, accounts, workspaces, support, billing and hosted logistics workflows.
We act as controller for website, account, security, sales, billing and support administration. For personal data contained in documents or operational datasets uploaded by a business customer, the customer normally determines the purposes and means of processing and acts as controller; we process that data on its documented instructions under the Data Processing Addendum.
2. Personal data we process
Depending on use of the service, we process the following categories:
- account and organization data, including name, business email, role, locale, authentication identifiers and workspace membership
- customer content, including permit documents, shipment or vehicle records, sample rows used for field mapping, extracted fields, review decisions, reports, exports and related metadata
- commercial and support data, including enquiries, correspondence, subscription status, invoices, tax information and payment references; we do not receive full payment-card numbers
- technical and security data, including IP address, device and browser details, timestamps, request and audit logs, rate-limit events and error telemetry
- optional analytics and support-chat data where the user has enabled the relevant category in Cookie Preferences
3. Sources of data
We obtain data directly from users and customer organizations, from files and systems they connect or upload, and from authentication and infrastructure providers. A customer must have a lawful basis and provide all required notices or permissions before submitting personal data about drivers, employees, contacts or other individuals.
4. Purposes and legal bases
We process account, workspace, requested workflow and subscription data as necessary to take steps at your request and perform our contract. We process security, fraud prevention, service reliability, limited product administration and the establishment or defence of legal claims on the basis of our legitimate interests, balanced against individual rights. We process invoices and other records where required by tax, accounting or other law.
Optional PostHog analytics, Google Ads conversion measurement and Crisp support-chat storage are activated only after the relevant consent choice. Consent can be withdrawn at any time without affecting prior lawful processing. Where we act as processor for Customer Data, the customer's legal basis applies and our processing is governed by the Data Processing Addendum.
5. Artificial intelligence processing
Selected features use OpenAI to extract structured fields from permit documents, suggest mappings or generate optional operational insights. The necessary input, which may include an entire uploaded permit or limited sample values, is transmitted to the OpenAI API. Requests are configured with response-object storage disabled. OpenAI states that business/API data is not used to train its models by default; provider abuse-monitoring and other limited retention may still apply unless a separately approved configuration provides otherwise.
AI results are probabilistic and may be incomplete or incorrect. They do not constitute a legal opinion, permit approval, certification or compliance decision. Users must review source references and approve results before operational reliance. The service does not make solely automated decisions that produce legal or similarly significant effects on individuals.
The public LogisticsAI AI assistant is separate from optional Crisp support chat. Messages you submit are sent to OpenAI to answer product questions and suggest a workflow. If no current tool fits a concrete request, we keep a short generalized description and category of the requested capability, the interface language and the approximate country derived from the request for about 90 days to understand product demand. We do not keep the conversation transcript or uploaded document content for this purpose, and we do not send chat text to web analytics. Do not include confidential or unnecessary personal information.
6. Recipients and service providers
We disclose data only where needed to provide, secure, support or bill the service, comply with law, or protect legal rights. Depending on enabled features, recipients may include:
- Self-hosted PostgreSQL, authentication and file storage on our VPS
- Zomro for VPS hosting and delivery; application hosting, database, authentication, storage and domain email are managed on our own server
- OpenAI for the AI processing described above
- Sentry for minimized error and security diagnostics
- Our own mail server for transactional email delivery and domain forwarding
- PostHog for optional product analytics, Google Ads for optional advertising attribution and completed lead-conversion measurement, and Crisp for optional support chat
- professional advisers, authorities or transaction counterparties where legally necessary and subject to appropriate confidentiality
7. International transfers
Our primary database region is in the EEA, but some providers or their approved subprocessors may process data outside the EEA. Where required, transfers rely on an adequacy decision, the EU-US Data Privacy Framework for eligible recipients, the European Commission's Standard Contractual Clauses with supplementary measures, or another lawful transfer mechanism. We do not describe the service as universally EU-only.
8. Retention
We retain personal data only for as long as necessary for the relevant purpose, taking account of contractual, security, dispute and statutory requirements. Account and workspace administration data is generally retained for the contract term and a limited period afterwards. Belgian accounting and tax records may be retained for ten years where required. Security and audit records are retained for a proportionate period and may be preserved longer for an active incident or legal claim.
Customer administrators can delete permit records using the product workflow. The source file, generated exports, extracted content and provider payload are then scheduled for purge, while a content-free deletion record and sanitized audit events may remain. Backups and provider systems follow their documented rotation periods. The service does not currently promise a universal automatic deletion period for all Customer Data; customers should configure or agree retention appropriate to their workflow.
Anonymous trial results can be accessed for 24 hours. Expired results are removed by scheduled cleanup or a subsequent reservation. Files are processed transiently rather than saved as workspace documents. Downloaded draft copies remain on your device under your control. Content-free quota and security records may remain.
9. Cookies and similar technologies
Strictly necessary storage supports authentication, security, locale and consent choices. Optional analytics and support technologies are controlled through Cookie Preferences. Details, providers and withdrawal instructions are in the Cookie Policy. A consent preference expires after six months so that the choice can be renewed.
10. Your rights
Subject to the GDPR and applicable exceptions, you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent at any time. Contact the privacy address stated in the Legal Notice. We may verify identity and will respond without undue delay and in principle within one month; this period may be extended by up to two further months for complex or numerous requests, with notice.
For personal data in Customer Data, contact the customer organization that submitted the data first. We will assist that customer as required by the Data Processing Addendum.
11. Complaints
You may lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels, Belgium, or with the supervisory authority of your habitual residence, place of work or the alleged infringement. We encourage you to contact us first so we can investigate.
12. Security and incidents
We use measures designed to protect data, including authenticated access, organization-scoped authorization, private storage, encryption in transit, audit trails, rate limiting and restricted service credentials. No system is completely secure. Customers must minimize uploads, control workspace access and avoid submitting special-category data unless expressly agreed and lawfully supported.
We assess security incidents and notify affected customers or authorities where required by applicable law and the Data Processing Addendum.
13. Business service, changes and contact
The service is intended for business users and not for children. We may update this Notice to reflect product, provider or legal changes. Material changes will be highlighted by an updated date or other appropriate notice. Controller and privacy contact details appear in the Legal Notice.
Contact
- Support
- support@logisticsai.eu
- Legal notices
- legal@logisticsai.eu
- Privacy requests
- privacy@logisticsai.eu