Privacy & Data Protection

CargoOneX Global Privacy Standards, fully compliant with UK GDPR and the Data Protection Act 2018.

1. Introduction and Data Controller

CargoOne Pro Systems ("we", "us", or "our") acts as the Data Controller for personal data collected through our public websites and as a Data Processor for data managed within the Client Management Portal.

Registered Address: 71-75 Shelton Street, Covent Garden, London WC2H 9JQ.
ICO Registration Number: [Pending Registration].

2. Lawful Basis for Processing

Under the UK GDPR, we process your personal data based on the following legal grounds:

  • Contractual Necessity: To provide the CargoOneX software services per your subscription.
  • Legal Obligation: For financial reporting, tax compliance, and anti-money laundering (AML) protocols.
  • Legitimate Interests: To optimize system performance, ensure network security, and manage operational logistics.
  • Consent: For marketing communications where you have explicitly opted in.

3. Categories of Data Collected

Account Data

Name, corporate email, hashed passwords, and multi-factor authentication metadata.

Usage Metrics

IP addresses, login timestamps, API call logs, and browser fingerprinting for security.

4. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. Our standard retention schedules are:

  • Active User Accounts: Retained for the duration of the subscription term.
  • Financial Transaction Records: Retained for 7 years to comply with HMRC requirements.
  • System Log Files: Automatically purged every 90 days unless flagged for a security investigation.

5. Data Subject Rights

Under UK GDPR, you have the following rights regarding your personal information:

Right of Access
Obtain a copy of your personal data held by us.
Right to Rectification
Correct inaccurate or incomplete information.
Right to Erasure
Request the deletion of data under specific circumstances ('Right to be Forgotten').
Right to Portability
Receive your data in a structured, machine-readable format (JSON/CSV).

6. International Data Transfers

While we primary utilize UK-based infrastructure, some processing may occur via global sub-processors (e.g., AWS, SendGrid). In such cases, we utilize Standard Contractual Clauses (SCCs) and the UK IDTA to ensure an equivalent level of data protection.

Request Data Access

To exercise your GDPR rights or submit a Subject Access Request (SAR), please contact our Data Protection Office.

Email DPO

Last Updated: January 2026 | Document Code: DPP-CX-UK-v4