CMR-JET
  • Product
  • Delivery status
  • Who it’s for
  • Proof & compliance
  • Pricing
  • FAQ
NLENDEFR
Sign in Start free trial
Legal

Privacy Policy — CMR-JET

Last updated: 2026-10-10

Authoritative language: English. Translations (NL/DE/FR) are provided for information; in case of discrepancy the English version prevails.

The current version of this policy is always available at https://cmr-jet.eu/en/privacy.

1. Who we are

Ten Square BV, with registered office at Pater Asteerstraat 56, 3970 Leopoldsburg, Belgium, enterprise number (KBO) / VAT BE 0728.686.863 (“Ten Square”, “we”) provides the CMR-JET software-as-a-service platform (the “Service”).

Data-protection contact: privacy@cmr-jet.eu.

2. Two roles: our data and our customers’ data

Ten Square processes personal data in two distinct capacities under Regulation (EU) 2016/679 (the “GDPR”):

a. As controller — for the personal data we need to provide, bill, support and secure the Service ourselves. Those processing activities are listed in §3 and are what this policy is about.

b. As processor on behalf of the Customer — for everything the Customer enters into its own workspace: the content of CMR consignment notes and related operational data, which may contain other people’s personal data (driver names, signatures, delivery photos, consignee contact details, a reduced-precision delivery location where location capture is used). For that data, the transport company using the Service is the controller, and the Data Processing Agreement (DPA) between Ten Square and that Customer applies.

If you are a driver, consignee or contact person

Your name, and sometimes your signature or a delivery photo, may appear on a consignment note in this Service. In that case the transport company that uses the Service decides what is recorded and why. They are the data controller; Ten Square only hosts and processes the data on their instructions.

If you want your data corrected or erased, please contact that transport company. If you write to us instead, we will forward your request to them without undue delay and tell you who to contact. We will not act on such a request ourselves, because we are not allowed to: we may only act on the controller’s documented instructions.

Note that a consignment note is also an accounting record. The transport company may be legally required to keep it (in Belgium, up to ten years), in which case it may refuse erasure of the document itself. That is their decision to make, not ours.

3. What we process as controller, why, and for how long

# Activity What and why Legal basis (GDPR Art. 6) Retention
1 Account management Name, business e-mail, organisation, role, authentication identifiers, session metadata, IP address and audit-log entries of account holders and authorised users — to create the workspace, identify the contracting Customer and enable sign-in. Where two-step verification is enabled for a workspace, this also includes the one-time codes we e-mail at sign-in (stored only as a cryptographic hash, valid for 10 minutes, single use, with the network part of the IP address from which the code was used, truncated to /24 for IPv4 or /48 for IPv6) and a record of the devices a user has chosen to trust for 30 days (stored only as a hash of the device token, with issue, expiry and last-seen timestamps). Since registration requires a VAT identification number, that number is also account data; for a sole trader it is personal data. Art. 6(1)(b) — performance of the contract For the subscription or trial term. After a terminal end (cancellation, or trial expiry without conversion) the workspace stays exportable for 90 days, after which the data becomes eligible for our deliberate, logged deletion process. One-time sign-in codes expire 10 minutes after issue and trusted-device records after 30 days; expired records are removed by a daily clean-up.
2 Billing, payment and VAT verification Name, billing address, VAT number, the VIES verification result and its consultation reference, payment-instrument token (card numbers are held by our payment provider, not by us) and invoice history — to collect fees, comply with VAT and accounting law and evidence the reverse-charge treatment. Art. 6(1)(b) — contract; Art. 6(1)(c) — Belgian accounting and VAT obligations Invoices and the VIES verification result attached to them: 10 years after issue (Belgian accounting law). Payment tokens: removed at our payment provider when the workspace is deleted (§8).
3 Direct marketing (opt-in e-mail) E-mail address, your opt-in choice with its date and the version of the consent text, and language preference — to send product announcements and our newsletter. Art. 6(1)(a) — consent for prospects; Art. 6(1)(f) — legitimate interest in promoting similar own services to existing customers (soft opt-in under ePrivacy legislation). Every message contains an unsubscribe link. Until you withdraw consent or object to the processing. A suppression entry (your address, marked “do not mail”) is kept to enforce and evidence your withdrawal or objection.
4 Customer support E-mail address, name, message content and any screenshots or logs you send us, plus the technical context the support form adds automatically (the page you were on, your browser, screen size, application version and a technical trace reference) — to answer questions and diagnose problems. Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in operating a support function 24 months from ticket close, then deletion or anonymisation.
5 Security telemetry and audit logs Authentication and access events, IP address, user-agent, request metadata and application telemetry — to detect and investigate security incidents and meet our security obligations. This includes the IP address and access events of guests who open a shared document link. Art. 6(1)(c) — the Art. 32 GDPR security obligation; Art. 6(1)(f) — legitimate interest in service security Application and API logs: 90 days; guest-access records: 90 days after the guest link expires; longer only while an open incident investigation requires it.
6 Recruitment (when a role is open) Name, contact details, CV, cover letter and application notes of job applicants. Art. 6(1)(b) — pre-contractual steps at the applicant’s request 6 months after the role closes, then deletion — unless you explicitly consent to a talent-pool retention of up to 24 months.
7 Product and site analytics See §4. See §4 See §4
8 Evidence of acceptance When a workspace is created: the Terms of Service version accepted, the time, the user account and the full IP address of the person who accepted. Each acceptance of the DPA on behalf of a Customer: the same data. Acknowledgements of later Terms versions: version, time and user account, without IP address. Purpose: to be able to prove which terms and which DPA were agreed, by whom and when. Art. 6(1)(f) — legitimate interest in evidencing the conclusion and content of the contract and the DPA; the documented legitimate-interest assessment is on file Until ten years after the workspace or the customer relationship has definitively ended (the limitation period for contractual claims), also after the workspace is deleted; then permanently deleted.

4. Analytics

This section covers the website cmr-jet.eu and the application. Our information sites ecmr-europe.eu, cmr-vrachtbrief.be and cmr-vrachtbrief.nl describe their own visit counts in their own privacy notice.

cmr-jet.eu: anonymous visit counts (no consent needed). Our website cmr-jet.eu counts page views with PostHog, hosted in the EU. For each page you view, it records one event with the path of the page and its language. When you click a link to the application or to another CMR-JET address, it records one event with the page you clicked on, its language and the address the link points to. As standard, PostHog adds technical details to each event: the full address of the page (including any campaign labels in the link that brought you here), the page you came from, the type of device, the type and version of your browser and operating system, your screen size, your language setting and your time zone. Nothing is stored on your device (no cookies, no local storage). Each page view gets a random identifier that is not linked to an account, a name or an IP address. The analytics service receives your IP address only to handle the request; it does not store it and does not derive a location from it. Because these records cannot identify anyone, they are not personal data, and we keep them without a fixed end date.

In the application: no measurement. We do not measure how the application is used: no feature counts, no usage paths, no analytics scripts or identifiers. Before we switch on any form of measurement in the application, we will update this section and describe what we measure, on which legal basis and for how long we keep it.

5. Cookies

The application uses strictly necessary (functional) cookies and browser storage only: for sign-in sessions and security, to remember your language and display preferences, and to keep a short-lived local copy of data you recently loaded (at most 24 hours, removed when you sign out) so that the application opens faster. These do not require consent under the ePrivacy rules. We use no advertising or cross-site tracking cookies, and analytics stores nothing on your device (§4).

If two-step verification is enabled for your workspace and you choose to trust a device, we set one additional strictly necessary cookie that identifies that device for 30 days. It contains a random device token only; on our side that token is linked to your account, so we treat it as personal data under activity 1 above. It is strictly necessary for the function you chose and therefore likewise consent-exempt.

6. Recipients

We share personal data only with:

  • Sub-processors — hosting, authentication, encrypted off-site backups, e-mail delivery, payment processing, support ticketing and product analytics providers. The current list, with each provider’s function, region and transfer mechanism, is published at cmr-jet.eu/subprocessors. We have a data processing agreement (Art. 28 GDPR) with each of them, and Standard Contractual Clauses or an equivalent transfer mechanism where necessary (§7).
  • VAT-number verification. Where you supply a VAT identification number, we transmit it to the VIES service of the European Commission to verify that it is valid. VIES is a public service of an EU institution and is not a sub-processor of Ten Square; it receives no other personal data from us. We retain the verification result, and the consultation reference VIES returns, together with the invoice it justifies, for the statutory accounting-retention period.
  • Professional advisers (accountant, legal counsel) under confidentiality, and authorities where the law requires it.

We do not sell personal data.

7. International transfers

The Service, its database and backups are hosted within the European Union. A limited number of sub-processors have a US parent or US processing: for those, transfers rest primarily on the EU-U.S. Data Privacy Framework (adequacy decision, Art. 45 GDPR) where the relevant US entity holds an active certification, with the EU Standard Contractual Clauses retained as backstop. The sub-processor list states the mechanism per provider.

8. Retention

Retention periods are stated per activity in the table in §3. In general:

  • We keep personal data no longer than needed for the purpose it was collected for, and then delete or anonymise it.
  • After a terminal subscription end (including a trial that expires without conversion), workspace data remains exportable for 90 days and then becomes eligible for our deliberate, logged deletion process. Deletion is confirmed in writing on request.
  • Copies in operational backups are not actively used and age out automatically under a fixed retention schedule; billing records we must keep by law are retained for the statutory period.
  • CMR document content inside a Customer workspace is kept while the workspace exists and deleted with it as described above. Evidence files linked to delivery events or claims (such as proof-of-delivery photos) are deleted earlier, once a retention period that the Service sets per country when the document is activated (currently five to ten years) has passed, unless an open claim requires a longer hold. The Customer (as controller) remains responsible for the statutory retention duties that apply to transport and accounting documents in its country.

9. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection to processing based on legitimate interest. Where processing is based on consent, you may withdraw it at any time without affecting past processing. Requests: privacy@cmr-jet.eu. We answer without undue delay and at the latest within one month.

Where your request concerns data we process as processor for a transport company (CMR document content), §2 applies: we forward your request to that company and tell you who to contact.

You also have the right to lodge a complaint with a supervisory authority — in Belgium the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels — www.dataprotectionauthority.be).

10. Security

We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit (TLS), server-side encryption of stored files (signature images, delivery photos and uploads), role-based access control, optional two-step verification at sign-in (which a Customer can make mandatory for its workspace), tenant isolation, encrypted off-site backups and security logging. For Customers, the binding measures are set out in Annex II of the DPA.

11. Changes to this policy

We may amend this policy. The current version is always available at https://cmr-jet.eu/en/privacy; the date at the top states the last change. For material changes affecting customers we give notice in accordance with the Terms of Service.

CMR-JET

CMR drafting, signed proof of delivery and archive, without a TMS. For shippers who want their CMR work sorted without the hassle.

NLENDEFR

Product

  • Product
  • Delivery status
  • Proof & compliance
  • Pricing

Company

  • Who it’s for
  • Migrate from desktop
  • FAQ

Legal

  • Privacy
  • Terms
  • DPA
  • Sub-processors
  • Imprint
ten square bv · Pater Asteerstraat 56, 3970 Leopoldsburg · BTW BE 0728.686.863 · ten-square.be
hello@cmr-jet.eu
© 2026 CMR-JET