Version: 2026-10-09
Forms part of: the Terms of Service (Schedule A).
This Data Processing Agreement (this “DPA”) is entered into between:
Hereinafter jointly referred to as: the “Parties” or individually as a “Party”.
The Processor’s privacy contact is privacy@cmr-jet.eu. The Controller’s privacy contact is the contact identified in its account or order form, as updated by written notice to the Processor.
This DPA forms an integral part of the Terms of Service (the “Agreement”) between the Parties. In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails.
Capitalised terms not defined in this DPA have the meaning as defined in the Regulation (EU) 2016/679 or as derived, in order, from the case law of the European Court of Justice, the Market Court, the Belgian Data Protection Authority, other European data protection authorities and courts or the Agreement. In addition:
3.1 Subject-matter. The Processor processes Personal Data on behalf of the Controller solely to provide the Service in accordance with the Agreement.
3.2 Nature and purpose. Processing consists of hosting, storing, retrieving, transmitting, displaying, printing, exporting and deleting Personal Data submitted to the Service in connection with the documents and records the Controller creates, manages and exchanges in the Service — principally CMR consignment notes and other transport and logistics documents, including Controller-defined document types — together with the related operational data (e.g. addresses, contact records, document history, attachments and delivery evidence). The permitted content of the Service is governed by the Agreement (including its acceptable-use terms and the special-category prohibition in Annex I.E); this clause describes, and does not expand, what the Controller may submit.
3.3 Categories of Personal Data. Set out in Annex I of this DPA.
3.4 Categories of Data Subjects. Set out in Annex I of this DPA.
3.5 Duration. Processing continues for the term of the Agreement, plus the post-termination retention window described in clause 10 (Return or Deletion of Personal Data).
4.1 The Controller is responsible for the lawfulness of the Personal Data it provides to the Service, including ensuring it has a valid legal basis under Article 6 GDPR (and where applicable Article 9 GDPR) for the Processing performed on its behalf.
4.2 The Controller warrants that it has provided all required notices to, and obtained all required consents from, the Data Subjects whose Personal Data it submits to the Service.
4.3 The Controller’s documented instructions to the Processor with respect to the Processing are: (a) the Agreement (including this DPA); (b) the configuration choices the Controller makes within the Service (e.g. user provisioning, security settings, sub-processor toggles where offered); and (c) any further written instructions consistent with the Agreement.
Each time the Controller gives a new Processing instruction or changes the purpose of the Processing, the Controller will propose an addendum to the Agreement, which may take the form of written instructions. Such an addendum may be concluded in writing, including electronically through the Service in accordance with clause 12.5. The Controller acknowledges and agrees that it is liable if such an addendum is not concluded by the Parties in a timely manner.
4.4 The Controller must not submit special-category Personal Data (Article 9 GDPR), criminal-conviction data (Article 10 GDPR), or data subject to sector-specific protections (e.g. PCI-DSS, HIPAA) to the Service in any form — including, without limitation, free-text fields, uploaded files, images and photos, attachments, and data encoded in machine-readable form (e.g. QR or barcodes). The Service is not designed for and is not certified to process such categories.
5.1 Processing on documented instructions. The Processor processes Personal Data only on the documented instructions of the Controller, including with regard to transfers to a third country or international organisation, except where required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor will inform the Controller of that legal requirement before Processing, unless that law prohibits such notice on important grounds of public interest.
5.2 Confidentiality of personnel. The Processor ensures that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is restricted to those personnel who need it to deliver the Service.
5.3 Security of Processing. The Processor implements the technical and organisational measures set out in Annex II (the “TOMs”) to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
5.4 Notification of unlawful instructions. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member State data-protection provisions.
5.5 Assistance. Taking into account the nature of the Processing and the information available to it, the Processor assists the Controller, by appropriate technical and organisational measures, insofar as this is possible, in the fulfilment of the Controller’s obligation to:
Reasonable assistance with audits or DPIAs that exceeds the standard self-service tooling provided in the Service may be charged at the Processor’s then-current professional-services rates, except where that assistance is required as a direct result of a Personal Data Breach caused by the Processor’s failure to comply with its obligations under this DPA.
5.6 Data Subject requests. If the Processor receives a request directly from a Data Subject concerning Personal Data processed under this DPA, the Processor promptly forwards the request to the Controller. The Processor does not respond to the request on the Controller’s behalf unless instructed or legally required to do so.
Following a documented instruction from the Controller, the Processor provides appropriate follow-up promptly and no later than seven (7) working days after receiving that instruction. The Processor will provide the requested information, make the requested adjustment, delete or destroy the relevant Personal Data, or explain why it cannot comply within that period.
The Controller acknowledges that compliance with an erasure instruction does not necessarily require immediate deletion from every backup. Residual backup copies are governed by clause 10.3 and remain protected by the TOMs until they expire under the fixed retention schedule.
6.1 General authorisation. The Controller grants the Processor general authorisation to engage Sub-processors to perform specific Processing activities, subject to the conditions in this clause 6.
6.2 Current Sub-processors. The current list of Sub-processors is maintained by the Processor and, from the public launch of the Service, published on the public page at https://cmr-jet.eu/subprocessors (the “Sub-processor List”); the current text is provided with this DPA. The Sub-processor List names each Sub-processor, its function, and the country or region in which Personal Data is processed.
6.3 Notification of changes and objection. The Processor will notify the Controller of any intended addition or replacement of a Sub-processor at least thirty (30) days before the new Sub-processor begins processing Personal Data, by updating the public Sub-processor List and notifying the Controller (by email to the billing/admin contact, or via in-app notice). The notification includes the information needed to assess the change: the Sub-processor’s name, its function, the processing region and the applicable transfer mechanism.
The Controller may object to the change on reasonable and documented data-protection grounds within fifteen (15) days of notice. Upon a timely objection, the Parties will first seek to resolve the objection in good faith. If the objection cannot reasonably be resolved, the Processor may refrain from using the proposed Sub-processor for the Controller’s Personal Data or offer a commercially reasonable alternative. If neither is feasible, the Controller may terminate the affected Service by written notice before the proposed Sub-processor begins processing Personal Data, without any early-termination charge and with a pro-rata refund of prepaid fees for the unused period after the effective date of termination. Such a termination is not a termination for breach.
Emergency replacement. Where the addition or replacement of a Sub-processor is urgently required for security, service-continuity or legal reasons, the Processor may deviate from the notice period above. In that case the Processor notifies the Controller as soon as reasonably practicable and no later than five (5) working days after the new Sub-processor begins processing Personal Data, and the objection and exit mechanism above applies from that notification.
6.4 Flow-down obligations. The Processor enters into a written contract with each Sub-processor that imposes data-protection obligations no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures so that the Processing meets the requirements of the GDPR.
6.5 Liability for Sub-processors. Where a Sub-processor fails to fulfil its data-protection obligations, the Processor remains fully liable to the Controller for the performance of that Sub-processor’s obligations, subject to the limitations of liability in the Agreement.
7.1 In the event of a Personal Data Breach affecting Personal Data processed under this DPA, the Processor shall notify the Controller by telephone or email without undue delay, and where feasible within seventy-two (72) hours of becoming aware of that Personal Data Breach.
7.2 The notification will, taking into account the nature of the Processing and the information available to the Processor, contain at least:
7.3 If the information cannot all be provided at the same time, it will be provided in phases without further undue delay.
7.4 The Processor cooperates reasonably with the Controller’s own assessment under Articles 33 and 34 GDPR. The Processor does not notify Supervisory Authorities or Data Subjects on the Controller’s behalf except where required to do so by law.
8.1 The Processor stores and processes Personal Data within the European Economic Area (“EEA”) by default. The current hosting region(s) are stated in Annex II.
8.2 Where a Sub-processor is established outside the EEA, or where Personal Data is transferred outside the EEA in the course of providing support, the Processor ensures that an equivalent level of protection is maintained for the Personal Data and relies on one of the following transfer mechanisms in this order of preference:
9.1 The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller.
9.2 The Processor primarily satisfies its audit-cooperation obligation by providing:
9.3 Where the documentation in clause 9.2 is insufficient to address a specific concern, the Controller may request an on-site or remote audit. Such audits:
10.1 Following the terminal termination or expiry of the Agreement, Personal Data remains available to the Controller for export through the Service for ninety (90) days. During this export window, the Controller may retrieve its data but may not create new Customer Data in the Service.
10.2 At the end of the export window in clause 10.1, the Personal Data becomes eligible for the Processor’s deliberate, logged deletion procedure. Unless Union or Member State law requires longer retention, the Processor deletes or anonymises the Personal Data from active production systems within thirty (30) days after the export window closes.
10.3 Personal Data residing in backups is retained for the operational backup-retention period stated in Annex II, after which it is overwritten or destroyed in the ordinary course. During this residual period, the Processor does not actively access Personal Data and its TOMs continue to apply.
10.4 At the Controller’s written request, the Processor provides written confirmation of deletion from active production systems and identifies the applicable residual backup-retention periods.
11.1 Subject to clause 11.3, the liability of the Processor under or in connection with this DPA shall in all cases be limited strictly to direct damages suffered by the Controller, up to the aggregate limitation of liability set out in the Agreement. The Processor shall in no event be liable for any indirect, incidental or consequential damages.
11.2 The Controller shall at all times indemnify and hold harmless the Processor against any claims, losses, damages, liabilities, costs or expenses, including legal fees, brought by third parties or Data Subjects arising out of or in connection with the processing of Personal Data under this DPA, except to the extent that such damage was directly caused by a material breach of this DPA by the Processor.
11.3 Nothing in this DPA limits or excludes either Party’s liability:
11.4 As between the Parties, the apportionment of liability for damage caused to a Data Subject follows Article 82(4)–(5) GDPR.
12.1 Term. This DPA is effective on the same date as the Agreement and remains in force for as long as the Processor processes Personal Data on behalf of the Controller, including the post-termination periods in clause 10.
12.2 Conflict. In the event of any conflict or inconsistency between this DPA and the Agreement, the order of precedence is: (a) the SCCs (where they apply by virtue of clause 8); (b) this DPA; (c) the Agreement.
12.3 Governing law and jurisdiction. Subject to the SCCs (which have their own governing-law clauses where they apply), this DPA is governed by the laws of Belgium and the courts identified in the Agreement have exclusive jurisdiction.
12.4 Severability. If any provision of this DPA is or becomes invalid or unenforceable, the remainder continues in full effect and the Parties will negotiate in good faith a replacement provision that achieves, to the extent possible, the original economic and legal intent.
12.5 Amendments. Any amendment to this DPA must be in writing (including click-through acceptance of an updated version notified at least 30 days in advance, where the Service is provided on standard terms).
This Annex describes the Personal Data that Ten Square processes as processor on the Controller’s behalf — principally the content of CMR documents and the related operational data in the Controller’s tenant. Ten Square’s processing of account, billing, support and telemetry data as controller (to administer, bill and secure the Service) is governed by Ten Square’s Privacy Policy, not by this DPA — even where a single data element (e.g. an Authorised User’s name or email) appears in both contexts.
The Personal Data processed concerns the following categories of Data Subjects:
Ten Square’s processing of account and identity data, billing data, operational telemetry and support correspondence takes place in its Controller role (see the scope note above) and is described in Ten Square’s Privacy Policy.
Storage, retrieval, transmission, display, printing, export, structured search, and deletion of the data described above, for the purposes of (a) providing the Service and recording delivery evidence, (b) securing and accounting for access to the Service, and (c) compliance with the Processor’s legal obligations. Account administration, billing and customer support are processed by Ten Square as controller (see the scope note above).
For the term of the Agreement, plus the post-termination and backup-retention windows described in clause 10 and Annex II. Evidence files linked to delivery events or claims (such as proof-of-delivery photos) are deleted earlier, once a retention period that the Service sets per country when the document is activated (currently five to ten years) has passed, unless an open claim recorded in the Service requires a longer hold. Guest-token records are retained for ninety (90) days after token expiry.
The Service is not intended for, or configured to process, special-category Personal Data (Article 9 GDPR) or criminal-conviction data (Article 10 GDPR), and the Controller agrees not to submit such data to the Service. This is a strict prohibition, consistent with clause 4.4 — there is no case-by-case carve-out.
The measures stated in this Annex are binding measures and therefore describe only controls represented as implemented. The storage and backup measures were verified on the production system on 2026-10-06, the other infrastructure measures on 2026-07-03.
Change control. The Processor may update the measures in this Annex as technology and operations evolve, provided the overall level of protection does not materially decrease. A change that would materially reduce the level of protection will be notified to the Controller in advance in accordance with the Agreement’s amendment procedure.
Production is hosted by Hetzner in the EU (Germany): the application and the database on a single virtual server, and uploaded files in Hetzner Object Storage in a separate Hetzner data centre in Germany. The authoritative source for the live hosts and regions is the Sub-processor List (published at https://cmr-jet.eu/subprocessors).
This Annex applies only where the Standard Contractual Clauses are required under clause 8 of this DPA.
| SCC clause / option | Selection |
|---|---|
| Module | Module 2 (Controller-to-Processor) by default; Module 3 (Processor-to-Sub-processor) where the Processor relies on a Sub-processor outside the EEA |
| Docking clause (Clause 7) | Applicable |
| Sub-processor authorisation (Clause 9) | Option 2 — General written authorisation, with the notice period and objection mechanism set out in clause 6 of this DPA |
| Redress (Clause 11(a)) | Optional language not included by default |
| Governing law (Clause 17) | The law of Belgium (Member State of the data exporter) |
| Forum and jurisdiction (Clause 18) | The courts of Belgium identified in the Agreement |
| Annex I.A (Parties) | Controller and Processor as identified in clause 1 of this DPA |
| Annex I.B (Description of the transfer) | As set out in Annex I of this DPA |
| Annex I.C (Competent supervisory authority) | The Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de Protection des Données) |
| Annex II (TOMs) | As set out in Annex II of this DPA |
| Annex III (List of Sub-processors) | The Sub-processor List (published at https://cmr-jet.eu/subprocessors) |
This Annex is a fallback for cases in which the SCCs are required. Transfers to US organisations currently participating in the EU-U.S. Data Privacy Framework rely first on the applicable adequacy decision; the vendor SCCs are retained as a backstop. The Sub-processor List identifies the mechanism used for each vendor.