CMR-JET
  • Product
  • Delivery status
  • Who it’s for
  • Proof & compliance
  • Pricing
  • FAQ
NLENDEFR
Sign in Start free trial
Legal

Data Processing Agreement (DPA)

Version: 2026-10-09

Authoritative language: English. Translations (NL/DE/FR) are provided for information; in case of discrepancy the English version prevails.

Forms part of: the Terms of Service (Schedule A).


1. Parties

This Data Processing Agreement (this “DPA”) is entered into between:

  • Ten Square BV, a company organised under the laws of Belgium, with registered office at Pater Asteerstraat 56, 3970 Leopoldsburg, Belgium and registered in the K.B.O. under number 0728.686.863 (hereinafter “Processor”, “Ten Square”); and
  • the customer organisation identified at signup or in the underlying order form (hereinafter “Controller”, “Customer”).

Hereinafter jointly referred to as: the “Parties” or individually as a “Party”.

The Processor’s privacy contact is privacy@cmr-jet.eu. The Controller’s privacy contact is the contact identified in its account or order form, as updated by written notice to the Processor.

This DPA forms an integral part of the Terms of Service (the “Agreement”) between the Parties. In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails.

2. Definitions

Capitalised terms not defined in this DPA have the meaning as defined in the Regulation (EU) 2016/679 or as derived, in order, from the case law of the European Court of Justice, the Market Court, the Belgian Data Protection Authority, other European data protection authorities and courts or the Agreement. In addition:

  • “GDPR” means Regulation (EU) 2016/679 (General Data Protection Regulation) and any national legislation implementing or supplementing it.
  • “Personal Data” means any personal data (as defined by the GDPR) that the Processor processes on behalf of the Controller in the course of providing the Service.
  • “Processing”, “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings set out in Article 4 GDPR.
  • “Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • “Service” means the CMR-JET SaaS platform as described in the Agreement.
  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.

3. Subject-matter, nature, purpose and duration of Processing

3.1 Subject-matter. The Processor processes Personal Data on behalf of the Controller solely to provide the Service in accordance with the Agreement.

3.2 Nature and purpose. Processing consists of hosting, storing, retrieving, transmitting, displaying, printing, exporting and deleting Personal Data submitted to the Service in connection with the documents and records the Controller creates, manages and exchanges in the Service — principally CMR consignment notes and other transport and logistics documents, including Controller-defined document types — together with the related operational data (e.g. addresses, contact records, document history, attachments and delivery evidence). The permitted content of the Service is governed by the Agreement (including its acceptable-use terms and the special-category prohibition in Annex I.E); this clause describes, and does not expand, what the Controller may submit.

3.3 Categories of Personal Data. Set out in Annex I of this DPA.

3.4 Categories of Data Subjects. Set out in Annex I of this DPA.

3.5 Duration. Processing continues for the term of the Agreement, plus the post-termination retention window described in clause 10 (Return or Deletion of Personal Data).

4. Controller obligations

4.1 The Controller is responsible for the lawfulness of the Personal Data it provides to the Service, including ensuring it has a valid legal basis under Article 6 GDPR (and where applicable Article 9 GDPR) for the Processing performed on its behalf.

4.2 The Controller warrants that it has provided all required notices to, and obtained all required consents from, the Data Subjects whose Personal Data it submits to the Service.

4.3 The Controller’s documented instructions to the Processor with respect to the Processing are: (a) the Agreement (including this DPA); (b) the configuration choices the Controller makes within the Service (e.g. user provisioning, security settings, sub-processor toggles where offered); and (c) any further written instructions consistent with the Agreement.

Each time the Controller gives a new Processing instruction or changes the purpose of the Processing, the Controller will propose an addendum to the Agreement, which may take the form of written instructions. Such an addendum may be concluded in writing, including electronically through the Service in accordance with clause 12.5. The Controller acknowledges and agrees that it is liable if such an addendum is not concluded by the Parties in a timely manner.

4.4 The Controller must not submit special-category Personal Data (Article 9 GDPR), criminal-conviction data (Article 10 GDPR), or data subject to sector-specific protections (e.g. PCI-DSS, HIPAA) to the Service in any form — including, without limitation, free-text fields, uploaded files, images and photos, attachments, and data encoded in machine-readable form (e.g. QR or barcodes). The Service is not designed for and is not certified to process such categories.

5. Processor obligations

5.1 Processing on documented instructions. The Processor processes Personal Data only on the documented instructions of the Controller, including with regard to transfers to a third country or international organisation, except where required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor will inform the Controller of that legal requirement before Processing, unless that law prohibits such notice on important grounds of public interest.

5.2 Confidentiality of personnel. The Processor ensures that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is restricted to those personnel who need it to deliver the Service.

5.3 Security of Processing. The Processor implements the technical and organisational measures set out in Annex II (the “TOMs”) to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.

5.4 Notification of unlawful instructions. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member State data-protection provisions.

5.5 Assistance. Taking into account the nature of the Processing and the information available to it, the Processor assists the Controller, by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the Controller’s obligation to:

  • respond to requests for exercising Data Subject rights under Chapter III GDPR;
  • comply with Articles 32 to 36 GDPR (security, breach notification, DPIA, prior consultation).

Reasonable assistance with audits or DPIAs that exceeds the standard self-service tooling provided in the Service may be charged at the Processor’s then-current professional-services rates, except where that assistance is required as a direct result of a Personal Data Breach caused by the Processor’s failure to comply with its obligations under this DPA.

5.6 Data Subject requests. If the Processor receives a request directly from a Data Subject concerning Personal Data processed under this DPA, the Processor promptly forwards the request to the Controller. The Processor does not respond to the request on the Controller’s behalf unless instructed or legally required to do so.

Following a documented instruction from the Controller, the Processor provides appropriate follow-up promptly and no later than seven (7) working days after receiving that instruction. The Processor will provide the requested information, make the requested adjustment, delete or destroy the relevant Personal Data, or explain why it cannot comply within that period.

The Controller acknowledges that compliance with an erasure instruction does not necessarily require immediate deletion from every backup. Residual backup copies are governed by clause 10.3 and remain protected by the TOMs until they expire under the fixed retention schedule.

6. Sub-processors

6.1 General authorisation. The Controller grants the Processor general authorisation to engage Sub-processors to perform specific Processing activities, subject to the conditions in this clause 6.

6.2 Current Sub-processors. The current list of Sub-processors is maintained by the Processor and, from the public launch of the Service, published on the public page at https://cmr-jet.eu/subprocessors (the “Sub-processor List”); the current text is provided with this DPA. The Sub-processor List names each Sub-processor, its function, and the country or region in which Personal Data is processed.

6.3 Notification of changes and objection. The Processor will notify the Controller of any intended addition or replacement of a Sub-processor at least thirty (30) days before the new Sub-processor begins processing Personal Data, by updating the public Sub-processor List and notifying the Controller (by email to the billing/admin contact, or via in-app notice). The notification includes the information needed to assess the change: the Sub-processor’s name, its function, the processing region and the applicable transfer mechanism.

The Controller may object to the change on reasonable and documented data-protection grounds within fifteen (15) days of notice. Upon a timely objection, the Parties will first seek to resolve the objection in good faith. If the objection cannot reasonably be resolved, the Processor may refrain from using the proposed Sub-processor for the Controller’s Personal Data or offer a commercially reasonable alternative. If neither is feasible, the Controller may terminate the affected Service by written notice before the proposed Sub-processor begins processing Personal Data, without any early-termination charge and with a pro-rata refund of prepaid fees for the unused period after the effective date of termination. Such a termination is not a termination for breach.

Emergency replacement. Where the addition or replacement of a Sub-processor is urgently required for security, service-continuity or legal reasons, the Processor may deviate from the notice period above. In that case the Processor notifies the Controller as soon as reasonably practicable and no later than five (5) working days after the new Sub-processor begins processing Personal Data, and the objection and exit mechanism above applies from that notification.

6.4 Flow-down obligations. The Processor enters into a written contract with each Sub-processor that imposes data-protection obligations no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures so that the Processing meets the requirements of the GDPR.

6.5 Liability for Sub-processors. Where a Sub-processor fails to fulfil its data-protection obligations, the Processor remains fully liable to the Controller for the performance of that Sub-processor’s obligations, subject to the limitations of liability in the Agreement.

7. Personal Data Breaches

7.1 In the event of a Personal Data Breach affecting Personal Data processed under this DPA, the Processor shall notify the Controller by telephone or email without undue delay, and where feasible within seventy-two (72) hours of becoming aware of that Personal Data Breach.

7.2 The notification will, taking into account the nature of the Processing and the information available to the Processor, contain at least:

  • a description of the nature of the breach, including (where possible) the categories and approximate number of Data Subjects and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and to mitigate its possible adverse effects.

7.3 If the information cannot all be provided at the same time, it will be provided in phases without further undue delay.

7.4 The Processor cooperates reasonably with the Controller’s own assessment under Articles 33 and 34 GDPR. The Processor does not notify Supervisory Authorities or Data Subjects on the Controller’s behalf except where required to do so by law.

8. International transfers

8.1 The Processor stores and processes Personal Data within the European Economic Area (“EEA”) by default. The current hosting region(s) are stated in Annex II.

8.2 Where a Sub-processor is established outside the EEA, or where Personal Data is transferred outside the EEA in the course of providing support, the Processor ensures that an equivalent level of protection is maintained for the Personal Data and relies on one of the following transfer mechanisms in this order of preference:

  • an adequacy decision under Article 45 GDPR;
  • the SCCs;
  • any other transfer mechanism permitted by the GDPR.

9. Audit rights

9.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.

9.2 The Processor primarily satisfies its audit-cooperation obligation by providing:

  • the Sub-processor List (published at https://cmr-jet.eu/subprocessors);
  • on request, copies of its most recent third-party security attestations or certifications (where available);
  • on request, completed standard security questionnaires and a description of its TOMs.

9.3 Where the documentation in clause 9.2 is insufficient to address a specific concern, the Controller may request an on-site or remote audit. Such audits:

  • take place at most once per twelve-month period (except where required by a Supervisory Authority or following a confirmed Personal Data Breach affecting the Controller);
  • are scheduled with at least thirty (30) days’ prior written notice;
  • take place during normal business hours, in a manner that does not disrupt the Processor’s operations or the security of other customers’ data;
  • are subject to the auditor’s prior written acceptance of confidentiality obligations no less protective than clause 9 of the Agreement;
  • are conducted by the Controller’s own personnel bound by such confidentiality or by an independent, professionally qualified auditor that is not a competitor of the Processor;
  • are limited in scope to the information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and do not extend to the Processor’s source code, pricing, financial information, trade secrets, or any other customer’s data, except where and to the extent strictly necessary to demonstrate that compliance;
  • are conducted at the Controller’s expense, except where the audit reveals a material breach by the Processor of this DPA.

10. Return or deletion of Personal Data

10.1 Following the terminal termination or expiry of the Agreement, Personal Data remains available to the Controller for export through the Service for ninety (90) days. During this export window, the Controller may retrieve its data but may not create new Customer Data in the Service.

10.2 At the end of the export window in clause 10.1, the Personal Data becomes eligible for the Processor’s deliberate, logged deletion procedure. Unless Union or Member State law requires longer retention, the Processor deletes or anonymises the Personal Data from active production systems within thirty (30) days after the export window closes.

10.3 Personal Data residing in backups is retained for the operational backup-retention period stated in Annex II, after which it is overwritten or destroyed in the ordinary course. During this residual period, the Processor does not actively access Personal Data and its TOMs continue to apply.

10.4 At the Controller’s written request, the Processor provides written confirmation of deletion from active production systems and identifies the applicable residual backup-retention periods.

11. Liability

11.1 Subject to clause 11.3, the liability of the Processor under or in connection with this DPA shall in all cases be limited strictly to direct damages suffered by the Controller, up to the aggregate limitation of liability set out in the Agreement. The Processor shall in no event be liable for any indirect, incidental or consequential damages.

11.2 The Controller shall at all times indemnify and hold harmless the Processor against any claims, losses, damages, liabilities, costs or expenses, including legal fees, brought by third parties or Data Subjects arising out of or in connection with the processing of Personal Data under this DPA, except to the extent that such damage was directly caused by a material breach of this DPA by the Processor.

11.3 Nothing in this DPA limits or excludes either Party’s liability:

  • to a Data Subject under Article 82 GDPR;
  • for fraud or wilful misconduct;
  • for any other liability that cannot be excluded under mandatory applicable law.

11.4 As between the Parties, the apportionment of liability for damage caused to a Data Subject follows Article 82(4)–(5) GDPR.

12. Term, conflict, governing law

12.1 Term. This DPA is effective on the same date as the Agreement and remains in force for as long as the Processor processes Personal Data on behalf of the Controller, including the post-termination periods in clause 10.

12.2 Conflict. In the event of any conflict or inconsistency between this DPA and the Agreement, the order of precedence is: (a) the SCCs (where they apply by virtue of clause 8); (b) this DPA; (c) the Agreement.

12.3 Governing law and jurisdiction. Subject to the SCCs (which have their own governing-law clauses where they apply), this DPA is governed by the laws of Belgium and the courts identified in the Agreement have exclusive jurisdiction.

12.4 Severability. If any provision of this DPA is or becomes invalid or unenforceable, the remainder continues in full effect and the Parties will negotiate in good faith a replacement provision that achieves, to the extent possible, the original economic and legal intent.

12.5 Amendments. Any amendment to this DPA must be in writing (including click-through acceptance of an updated version notified at least 30 days in advance, where the Service is provided on standard terms).


Annex I — Description of the Processing

Scope note — controller vs processor

This Annex describes the Personal Data that Ten Square processes as processor on the Controller’s behalf — principally the content of CMR documents and the related operational data in the Controller’s tenant. Ten Square’s processing of account, billing, support and telemetry data as controller (to administer, bill and secure the Service) is governed by Ten Square’s Privacy Policy, not by this DPA — even where a single data element (e.g. an Authorised User’s name or email) appears in both contexts.

A. Categories of Data Subjects

The Personal Data processed concerns the following categories of Data Subjects:

  • the Controller’s own employees, contractors and agents who have user accounts in the Service (“Authorised Users”);
  • transport drivers identified on consignment notes (name, licence-plate or vehicle reference where the Controller chooses to record it, signature image);
  • the Controller’s commercial counterparties identified on consignment notes (consignors, consignees, freight forwarders) — specifically: name of the organisation, individual contact name, address, and where supplied, phone or email;
  • end-customers (recipients) listed on consignment notes;
  • any other natural person whose Personal Data is included by the Controller in free-text fields, attachments or notes, or who is incidentally visible in uploaded photos or scans.

B. Categories of Personal Data

  • Transport-document and delivery-evidence content: identifiers of drivers, consignors, consignees and recipients; addresses; goods descriptions; weights and quantities; signatures (image); proof-of-delivery photos; scans and other file attachments the Controller or its users upload to a document, including persons or identifying context incidentally visible in such images and any metadata embedded in uploaded files (e.g. EXIF timestamps and GPS coordinates; client-side recompression typically strips embedded metadata from JPEG/PNG photos, but not from all formats and upload routes); timestamps; dispute and event annotations; and a reduced-precision delivery-location point where location capture is used.
  • Authorised-User activity within the Controller’s workspace: the user name or identifier as recorded on documents, document history and workspace audit-trail entries kept on the Controller’s behalf.
  • Guest-access records: guest-token identifier and status, verified destination and expiry timestamps used to provide guest access to the Controller’s documents. The IP-address and access-event log that Ten Square keeps to secure the platform is processed by Ten Square as controller and is described in its Privacy Policy (§3), not in this Annex.

Ten Square’s processing of account and identity data, billing data, operational telemetry and support correspondence takes place in its Controller role (see the scope note above) and is described in Ten Square’s Privacy Policy.

C. Nature and purpose of the Processing

Storage, retrieval, transmission, display, printing, export, structured search, and deletion of the data described above, for the purposes of (a) providing the Service and recording delivery evidence, (b) securing and accounting for access to the Service, and (c) compliance with the Processor’s legal obligations. Account administration, billing and customer support are processed by Ten Square as controller (see the scope note above).

D. Duration of the Processing

For the term of the Agreement, plus the post-termination and backup-retention windows described in clause 10 and Annex II. Evidence files linked to delivery events or claims (such as proof-of-delivery photos) are deleted earlier, once a retention period that the Service sets per country when the document is activated (currently five to ten years) has passed, unless an open claim recorded in the Service requires a longer hold. Guest-token records are retained for ninety (90) days after token expiry.

E. Special categories

The Service is not intended for, or configured to process, special-category Personal Data (Article 9 GDPR) or criminal-conviction data (Article 10 GDPR), and the Controller agrees not to submit such data to the Service. This is a strict prohibition, consistent with clause 4.4 — there is no case-by-case carve-out.


Annex II — Technical and Organisational Measures

The measures stated in this Annex are binding measures and therefore describe only controls represented as implemented. The storage and backup measures were verified on the production system on 2026-10-06, the other infrastructure measures on 2026-07-03.

Change control. The Processor may update the measures in this Annex as technology and operations evolve, provided the overall level of protection does not materially decrease. A change that would materially reduce the level of protection will be notified to the Controller in advance in accordance with the Agreement’s amendment procedure.

Production is hosted by Hetzner in the EU (Germany): the application and the database on a single virtual server, and uploaded files in Hetzner Object Storage in a separate Hetzner data centre in Germany. The authoritative source for the live hosts and regions is the Sub-processor List (published at https://cmr-jet.eu/subprocessors).

A. Pseudonymisation and encryption

  • In transit. All client–server traffic uses TLS 1.2 or higher (Let’s Encrypt certificates) with industry-standard cipher suites; the application is served over HTTPS only.
  • Uploaded files at rest. Uploaded files, signature images and proof-of-delivery photos are stored in Hetzner Object Storage and encrypted at rest with AES-256 using server-side encryption with a customer-provided key (SSE-C): the Service supplies the key with every storage request and the storage provider does not retain it. The key is held in the server configuration with owner-only (0600) permissions, with an escrow copy kept off-host. Object names and object metadata (such as size, content type and timestamps) are not encrypted; object names contain internal identifiers only, never the names of uploaded files. Browsers never access the object store directly: every upload and download passes through the Service, which checks authorisation and issues short-lived signed links.
  • Deletion of files. When a file is deleted, every stored version of it is removed from the object store at once. Earlier versions of a file that is replaced (such as a logo) are removed automatically after 30 days. Copies in backups are governed by clause 10.3.
  • Database at rest. The database runs on a single Hetzner virtual server whose volume is not encrypted at disk level; database records are protected by the access, isolation and backup measures in this Annex.
  • Secrets. Application secrets, including the object-store encryption key, are held in a configuration file with owner-only (0600) permissions on the server, separate from application code and version control, with escrow copies in the company password vault; there is no dedicated secrets-management service at this scale.
  • Hetzner backups. Daily automated whole-server backups of the application server (which does not hold the uploaded files) are retained within the EU (Germany) under the hosting provider’s Article 28 DPA, on a rolling 7-day retention.
  • Off-site backups. Every 30 minutes, a restore point of the database together with the uploaded files is encrypted on the Processor’s server before transfer (AES-256 in counter mode with Poly1305-AES authentication), with the encryption key also held off-server, and stored in a Cloudflare R2 bucket configured for EU jurisdiction. Restore points are kept for 48 hours at one per hour, for 40 days at one per day and for 400 days at one per month; expired restore points are deleted by the Processor’s retention routine, and their data is physically removed within a further seven days.

B. Confidentiality, integrity, availability and resilience of Processing systems

  • Confidentiality. Role-based access control on the Service. Tenant isolation enforced at the database row level. A host firewall restricts inbound traffic to SSH and HTTP/HTTPS only; server access is by SSH key only. Production access for personnel is minimised and controlled; personnel with access are bound by confidentiality undertakings. Multi-factor authentication (an e-mailed one-time code as second factor) is available for all sign-in methods and can be made mandatory for a workspace by the Controller’s users with the owner or administrator role; when enforced, it applies to every sign-in method, the Service withholds the access token until the second factor is verified, and a device may be remembered as trusted for at most 30 days.
  • Integrity. Version-controlled and audited deployment pipeline; application and audit logging.
  • Availability. Hosted on EU-region infrastructure (Hetzner, Germany): a single virtual server for the application and the database, and Hetzner Object Storage for uploaded files.
  • Resilience. Daily Hetzner backups of the application server and encrypted off-site backups every 30 minutes, with retention enforced by the Processor’s backup routine and an alert when no backup has succeeded for 90 minutes (see § A).

C. Restoration after incident

  • Documented recovery procedures for the Hetzner and encrypted off-site backups described in § A. A restore of the off-site database and file backup, with the same backup procedure as in production, was tested successfully in a separate test environment on 2026-10-01.
  • Documented incident-response procedure including the breach-notification flow in clause 7 of this DPA.

D. Regular testing, assessing and evaluating effectiveness

  • Static analysis and security linting on every change.
  • Dependency-vulnerability scanning and patch cadence.
  • Periodic review of access lists, audit logs, and Sub-processor contracts.

E. Hosting locations

  • Application and database: production is hosted by Hetzner in the EU (Germany).
  • Uploaded files: Hetzner Object Storage in the EU (Germany).
  • The current Sub-processor List (published at https://cmr-jet.eu/subprocessors) is the source of truth for the live hosts and regions at any given time.
  • Encrypted off-site backups: Cloudflare R2 bucket configured for EU jurisdiction; Cloudflare, Inc. is identified in the Sub-processor List. The backup payload is encrypted before upload.
  • Identity provider (Auth0): EU tenant; US-parent coverage and the applicable transfer mechanism are stated in the Sub-processor List.
  • Payment processor (Stripe): EU and US processing, relying on the EU-U.S. Data Privacy Framework where the participating US entity is covered, with SCCs retained as backstop.
  • Outbound transactional email: provider and EU region identified in the Sub-processor List; any US-linked transfer relies on the mechanism stated there.

F. Personnel measures

  • Personnel access to production Personal Data is minimised by design (the Service uses tenant-scoped self-service tooling for almost all operational tasks).
  • Production administrative access is limited to authorised personnel and is logged by the host and application infrastructure.
  • All personnel with access to Personal Data are bound by written confidentiality undertakings that survive termination of their engagement.

Annex III — SCC completion options

This Annex applies only where the Standard Contractual Clauses are required under clause 8 of this DPA.

SCC clause / option Selection
Module Module 2 (Controller-to-Processor) by default; Module 3 (Processor-to-Sub-processor) where the Processor relies on a Sub-processor outside the EEA
Docking clause (Clause 7) Applicable
Sub-processor authorisation (Clause 9) Option 2 — General written authorisation, with the notice period and objection mechanism set out in clause 6 of this DPA
Redress (Clause 11(a)) Optional language not included by default
Governing law (Clause 17) The law of Belgium (Member State of the data exporter)
Forum and jurisdiction (Clause 18) The courts of Belgium identified in the Agreement
Annex I.A (Parties) Controller and Processor as identified in clause 1 of this DPA
Annex I.B (Description of the transfer) As set out in Annex I of this DPA
Annex I.C (Competent supervisory authority) The Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de Protection des Données)
Annex II (TOMs) As set out in Annex II of this DPA
Annex III (List of Sub-processors) The Sub-processor List (published at https://cmr-jet.eu/subprocessors)

This Annex is a fallback for cases in which the SCCs are required. Transfers to US organisations currently participating in the EU-U.S. Data Privacy Framework rely first on the applicable adequacy decision; the vendor SCCs are retained as a backstop. The Sub-processor List identifies the mechanism used for each vendor.


CMR-JET

CMR drafting, signed proof of delivery and archive, without a TMS. For shippers who want their CMR work sorted without the hassle.

NLENDEFR

Product

  • Product
  • Delivery status
  • Proof & compliance
  • Pricing

Company

  • Who it’s for
  • Migrate from desktop
  • FAQ

Legal

  • Privacy
  • Terms
  • DPA
  • Sub-processors
  • Imprint
ten square bv · Pater Asteerstraat 56, 3970 Leopoldsburg · BTW BE 0728.686.863 · ten-square.be
hello@cmr-jet.eu
© 2026 CMR-JET