Freight Audit made easy

Freight Audit Hub helps shippers gain full visibility of their freight spending, cut logistical expenditures and improve processes related to freight audit

Get more details
Freight Audit made easy

Our Platforms

Freight Audit

Freight Audit

Robust Freight Audit Services for multinational companies

Freight Spend Insights

Freight Spend Insights

Clean and actionable data from the audit process

Live Demo Request

Request a free live demo session to experience our innovative software solutions in action.

Get demo

Live Demo Request

Request a free live demo session to experience our innovative software solutions in action.

Get demo

Legal notice

Responsible for the content of the website and other media containing a link to this publishing information:

Transporeon GmbH
Heidenheimer Straße 55/1
89075 Ulm
Germany

+49 (0) 7 31 1 69 06 0
info@transporeon.com

Company headquarter:
DE-89075 Ulm
Company registration number: Amtsgericht Ulm
HRB 722056
Tax identification number: DE 25 80 42 133

Authorized Managing Directors:

PR Requests: pr@transporeon.com

Editorial Staff: Peter Read - peter.read@transporeon.com

Privacy Policy (System)

Latest Update: 19.07.2023

This page informs you of our policies regarding the collection, use and disclosure of Personal Information we receive about users of the ControlPay modules.

Privacy Policy
By using the ControlPay web-based modules (also referred to as the "system"), you agree to the collection and use of information in accordance with this policy.

Who does this Privacy Policy apply to?
We act as a data controller for all personal data collected by ControlPay and we may request to perform processing activities from any of ControlPay divisions depending on the business specifics. We process personal data as safely and reasonably as possible and in strict compliance with the applicable data protection legislation, including the EEA’s General Data Protection Regulation 2016/679 (“GDPR”) and Brazil’s Lei Geral de Proteção de Dados, the Brazilian General Data Protection Law, Federal Law no. 13,853/2019 (“LGPD”).

Data protection queries can be sent to the group data protection officer at Transporeon via e mail to dataprotection@transporeon.com or you can send your request by post to the following address:

Transporeon GmbH
Data Protection Officer
Heidenheimer Straße 55/1
89075 Ulm
Germany

What is covered by this Privacy Policy?
This Privacy Policy tells you:

Which personal data do we collect?
While performing business-related activities in the system, we may ask you to provide us with personal data that can be used to contact or identify you in terms of freight audit activities. Your following personal data is collected and processed: your full name; gender (used for salutation); your business contact detail such as e-mail address and phone number, your position («Personal Information»).

How do we obtain your personal data?
We may obtain your personal data:

How we store and process your personal data?
Your personal data will be stored on our server in Europe. The defined ControlPay staff members, in all offices, may have an access to your personal data for the business-related purposes described above.

To achieve the objective of our processing, as described above, we may allow to access your personal data outside the European Economic Area (EEA) or outside Brazil ensuring proper technical and organizational measures for the data protection. This ability is granted to ControlPay staff members, including those in our offices outside the EEA or Brazil. The European affiliated companies of ControlPay and the affiliated companies outside of the European Union or the European Economic Area have implemented and transcribed the EU standard contractual clauses in order to ensure an adequate level of data protection and to ensure compliance with the legal requirements of Art. 44 ff. GDPR. The legal basis for access granting is Art. 6 Para. 1 clause 1 lit. f GDPR. Our legitimate interest results from the possibility to support your use of our service worldwide and in a multitude of languages.

According to Article 5 (e) GDPR and Article 16 LGPD, we only retain the personal data collected as long as the user`s account is active or otherwise for a limited period of time as long as we need it to fulfill a reasonable business purpose.

The legal grounds for processing your personal data
We process your personal data for the purposes mentioned in the previous section relying upon the following legal basis: for the purposes of the legitimate interests of our company (Article 6 (f) GDPR and Article 7 (IX) LGPD). The processing of your first name, last name, and business contact details takes place when using the system (including access to the system, communication with users, remote support and onboarding, information on updates and troubleshooting).In this respect, we will always determine whether our interests are not overridden by your interests, fundamental rights and freedoms.

How is your personal data secured?
We employ strict technical and organizational (security) measures to protect your personal data from an access by unauthorized persons and against unlawful processing, accidental loss, destruction and damage, both online and offline. These measures include:

Our security measures comply with international standards, such as ISO27001 for the data security and availability.

The security of your personal data is important to us, but please note that no method of transmission over the Internet, or method of electronic storage, is 100% secure, thus we cannot guarantee its absolute security.

How do we use your personal data for communication?
We may send you notification letters related to freight audit activities whenever particular changes in the system/related to your account in the system or some informational points appear or in case particular actions are required from your side. We may also use your e-mail or phone number in order to contact you in terms of freight audit related activities within contract obligations fulfillment.

What are your rights regarding personal data?

If your personal data is processed based on legitimate interests in accordance with Art. 6 Para. 1 clause 1 lit. f GDPR, you have the right to file an objection against the processing of your personal data in accordance with Art. 21 GDPR provided that there are reasons for this arising from your particular situation, or the objection relates to direct advertising. In the latter case, you have a general right of objection, which is implemented by us with no requirement to give a specific reason. If you would like to exercise your right of revocation or objection, please send an e-mail to dataprotection@transporeon.com.

Changes to this Privacy Policy
We reserve the right to update or change our Privacy Policy at any time and you should check this Privacy Policy periodically. Your continued use of the service after we post any modifications to the Privacy Policy on this page will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy.

If we make any changes to this Privacy Policy, we will notify you either through the e-mail address you have provided us, or by placing a notice on our website.

How to Contact Us
We hope that this Privacy Policy helps you to understand and feel confident about the way we collect and process your data. If you have any further queries about this Privacy Policy, please contact us:

Download Privacy policy

Privacy Policy (Website)

Privacy policy (Website)

Information on the handling of personal data

We are very pleased about your interest in our website - and thus in our company. The protection of your private rights and freedoms is very important to us; we only use your data for the purposes intended. Since it is important to us that you are aware at all times of the extent to which we collect, use and, if necessary, transfer your data to third parties, we will provide you with the following comprehensive information on the processing of your personal data collected by us or stored by us.

Visiting our website is generally possible without providing (personal) data; if there are exceptions to this for selected services, we will explain these in the following chapters. When processing personal data, we strictly adhere to the requirements of the EU General Data Protection Regulation (GDPR) and any other data protection regulations.

Name and address of the controller

Transporeon GmbH
Heidenheimer Straße 55/1
89075 Ulm
Germany

Phone: +49 (0) 7 31 1 69 06 -0
E-mail: info@transporeon.com
Website: https://www.controlpay.com/

Name and address of the data protection officer

Data protection team for general data protection inquiries:
Team e-mail: dataprotection@transporeon.com

Actuality of the privacy policy

To ensure that we always have up-to-date data protection information in connection with the services of our website, we use the CLOUD Privacy Policy service of Cookiebox GmbH from Münster.

Rights of data subject

The EU General Data Protection Regulation (GDPR) provides for extensive rights for data subjects in Chapter III, which we explain to you accordingly below with regard to the processing of your personal data:

Right to information

This requirement concerns in particular information on the following details of data processing:

  • Processing purposes
  • Data categories
  • Recipients or categories of recipients, if applicable
  • If applicable, the planned storage duration or the criteria for determining this duration.
  • Note on the respective right of correction, deletion, restriction or objection
  • Existence of the right to complain to a supervisory authority
  • If applicable, origin of the data (if not collected from you)
  • If applicable, existence of automated decision-making including profiling, including meaningful information about the logic involved, the scope and the effects to be expected
  • If applicable, (planned) transfer to a third country or international organization
Right to rectification

We will correct any erroneous data immediately, provided that you inform us of the circumstance accordingly.

Right to erasure (right to be forgotten)

Provided that the processing is no longer necessary and one of the following conditions is met:

  • Discontinuation of the purpose of processing
  • Withdrawal of their consent and absence of any other legal basis for processing
  • Objection to processing without an important reason to the contrary
  • Unlawful processing
  • Required to fulfill a legal obligation
  • Data collection was carried out in accordance with Art. 8 (1) GDPR
Right to restriction of processing

Provided that one of the following conditions is met:

  • You dispute the accuracy of your data (restriction can be made for the duration of the review on our side)
  • In the event of unlawful processing and if the data is not to be deleted, restriction of processing shall take the place of deletion
  • If the processing purposes cease to apply, at the same time you need your data for the assertion, exercise or defense of legal claims
  • After you have lodged an objection pursuant to Art. 21 (1) GDPR and for the duration of the examination as to whether our legitimate reasons outweigh yours.
Right to data portability

If it is technically possible and does not affect the rights and freedoms of other persons, we will - at your request - transfer your data to another recipient (responsible party).

Right to object

If we collect or have collected and process personal data from you (on the basis of Art. 6 (1) e or f or Art. 9 (2) a GDPR), you have the right to object to the data processing (including profiling) at any time (with effect for the future). In exceptional cases, the objection may be ineffective, e.g. if we can demonstrate compelling interests worthy of protection for the processing that outweigh your interests or processing serves the assertion, exercise or defense of legal claims. If we process your personal data for the purpose of direct marketing, you have the right to object to such processing at any time. This also applies to profiling, insofar as it is related to such direct advertising. You also have the right to object to processing of your data concerning you which is carried out by us for scientific or historical research purposes or for statistical purposes pursuant to Article 89 (1) GDPR, unless such processing is necessary for the performance of a task carried out in the public interest.

Automated decisions in individual cases including profiling

If we collect or have collected and process personal data from you, you have the right not to be subject to any decision based solely on automated processing - including profiling - which produces legal effects concerning you or similarly significantly affects you. Exceptions to this requirement apply if the decision is necessary for the conclusion or performance of a contract between you and us or you have expressly consented to the processing. In any case, we will take reasonable steps to safeguard your rights and freedoms and legitimate interests, including at least the right to obtain the intervention of a person on our part, to express our own point of view and to contest the decision.

Right to complain to a supervisory authority

A list of the supervisory authorities responsible in Germany can be found on the website of the Federal Commissioner for Data Protection or at the following link: https://www.bfdi.bund.de/EN/Service/Anschriften/Laender/Laender-node.html.

General information on data processing on the website

The following information applies to the data processing on our website in general. If there are exceptions or additions to this information, these are described in detail in the relevant sections.

Data security information

We secure our website and other systems through technical and organizational measures against loss, destruction, access, modification or distribution of your data by unauthorized persons. In addition, we have implemented SSL encryption (SHA256) on our website to protect your data. However, despite regular checks, complete protection against all dangers is not possible.

Our legitimate interest

Our legitimate interest, as defined in Article 6 (1) f GDPR, is based on the performance of our business activities in order to maintain our ability to operate and secure the employment of our employees.

General deadlines for data deletion

After the purpose of storage has ceased, the retention periods are generally at least six or ten years. As a rule, data is deleted immediately in accordance with our deletion concept, provided that this does not conflict with any retention obligation, necessity for contract fulfillment or a legitimate interest.

Deletion or blocking of personal data

We store your personal data only for the period required to fulfill the specified purpose. After the purpose no longer applies and after expiration of any existing retention periods, your data will be deleted immediately. If deletion is not possible, the data will be blocked instead.

Collection of general data and information

As soon as you visit our website, our web server collects some general data and technical information - as shown in the table below:

Data collected

Purpose of the survey

browser types and versions usedcorrect display of the page content
Operating system used, visitor origin (referrer, e.g. Google), subpages clicked onOptimization of our website content as well as our advertising
Date and time of access to the website as well as IP address and internet service provider of the visitorEnsuring the permanent functionality of our IT systems (for the operation of the website) and prevention of misuse

Other data and information for security in the event of attacks

Providing relevant information to law enforcement agencies in the event of a cyberattack

Obligation to provide personal data

Under certain circumstances (e.g. due to legal or contractual regulations), an obligation arises for you to provide us with your personal data. Examples of such processing as follows:

Nature or purpose of the processing

Need

Conclusion of a sales contract (e.g. your address)Fulfillment of the contractual obligation (e.g. delivery of the goods to your address)
In the employee context (e.g. transmission of data to the tax office)Compliance with legal requirements (e.g. tax regulations)
Data security information

We secure our website and other systems through technical and organizational measures against loss, destruction, access, modification or distribution of your data by unauthorized persons. In addition, we have implemented SSL encryption (SHA256) on our website to protect your data. However, despite regular checks, complete protection against all dangers is not possible.

Information about specific data processing on the website

If applicable, in deviation from or in addition to the above-mentioned general information, you will find details of the individual data processing on our website below.

Newsletter
Purpose of processingProvision of information in the form of electronic circulars
Legal basisConsent (Art. 6 para. 1 lit. a GDPR)
Recipient (if applicable)none
If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)A data transfer to a third country does not take place and is not planned.
If known: Duration of data storageSee General deadlines for data deletion
Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessityThere is no obligation to provide personal data. Newsletters are sent exclusively after registration via a double opt-in procedure (voluntarily given and revocable informed consent pursuant to Article 6 (1) a DSGVO) or after a purchase contract has been successfully concluded and the e-mail address has been collected in this process (pursuant to Section 7 (3) UWG).
Consequences of non-compliance (in case of failure to provide the required data)Non-compliance (i.e. not providing the required data) would result in the newsletter not being delivered to you.
If applicable, existence of an automated decision-making processIn this context, we do not use automatic decision-making.
If applicable, origin of the data (if not collected directly from the data subject)The data comes from the data subject himself.
Change of purpose, if applicablenone
Contact form
Purpose of processingProcessing and, if necessary, answering the request of the form sender
Legal basis (according to Art. 6 / 9 GDPR)
  • Protection of legitimate interests (Art. 6 para. 1 f)
  • Implementation of pre-contractual measures (Art. 6 para. 1 b)
  • Recipient (if applicable)The data will not be passed on to third parties and/or to a third country.
    If applicable, intention of forwarding to a third country or int. organization (incl. info on adequacy decision of the Commission or suitable guarantees)Data transfer to a third country does not take place and is not planned.
    If known: Duration of data storageSee General deadlines for data deletion
    Obligation to provide personal data (e.g. due to legal or contractual regulations) / necessityThere is no obligation.
    Consequences of non-compliance (in case of failure to provide the required data)none
    If applicable, existence of an automated decision-making processIn this context, we do not use automated decision-making.
    If applicable, origin of the data (if not collected directly from the data subject)The data originates from the person concerned.
    Where applicable, categories of personal data (if not collected directly from the data subject).Data and categories requested in the respective form.
    Change of purpose if necessarynone
    Cookies

    We use cookies on this website; these are small text files that are stored on your computer via your internet browser (e.g. Google Chrome, Safari, Firefox, Edge). These cookies are used for various purposes: Many cookies are technically necessary to provide you with certain website functions (e.g. shopping cart functions, saving your login information), other cookies are used for the security of your data or the website and some cookies can be used to analyze your user behavior. The latter cookies may contain a so-called cookie ID - a unique identifier consisting of a character string that enables websites and servers to be assigned to the storing browser.
    Cookies that are necessary to carry out the transmission of a message via a public telecommunications network and cookies that are absolutely necessary to provide you with an expressly requested function are referred to as "technically necessary cookies" and may be set without your explicit consent (Section 25 (2) TDDDG). All other cookies are subject to consent (Section 25 (1) TDDDG); where applicable, this is regulated by our consent management platform.
    We use cookies in part only for the duration of your visit to the website, in part for a predefined period and in part permanently. You can delete all these cookies manually or automatically at any time via your web browser.
    It is possible to use our website (although possibly not to its full extent) without cookies. Most browsers are set to accept cookies automatically. However, you can deactivate the storage of cookies or set your browser so that it notifies you as soon as cookies are sent.

    Web tracking technologies - managed with Usercentrics

    To manage all cookies, website and tracking technologies that require consent or opt-out in a privacy-compliant manner, we use the Consent Management Platform of Usercentrics GmbH, Rosental 4, 80331 Munich, Germany, with which we have integrated the following services:

    Terms of use

    This page informs you of our terms of use. By using the site, you agree to the collection and use of information in accordance with this policy

    Download Terms of use