עמידה בתקנות GDPR
עודכן לאחרונה: 8 באפריל 2026
Tracktainer Ltd is committed to full compliance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. This page outlines our approach to data protection, our obligations as a data controller and data processor, and the measures we take to protect your personal data.
1. Data Controller
Tracktainer Ltd acts as the data controller for personal data collected through our website, platform, and services. This means we determine the purposes and means of processing your personal data.
- Company: Tracktainer Ltd
- Data Protection Contact: [email protected]
2. Data Processor Role
When our customers use Tracktainer to track shipments on behalf of their clients, we also act as a data processor. In this capacity, we process data strictly in accordance with our customers' instructions and applicable data protection law. We offer a Data Processing Agreement (DPA) to all customers upon request.
3. Lawful Basis for Processing
We process personal data only when we have a valid lawful basis:
- Contract performance (Article 6(1)(b)): To provide the tracking service you have subscribed to.
- Legitimate interests (Article 6(1)(f)): To improve our service, ensure security, and conduct analytics - always balanced against your rights.
- Consent (Article 6(1)(a)): For marketing communications and non-essential cookies. You may withdraw consent at any time.
- Legal obligation (Article 6(1)(c)): To comply with tax, accounting, and regulatory requirements.
4. Your Rights Under GDPR
You have the following rights regarding your personal data. We are committed to responding to all requests within 30 days:
- Right of access (Article 15): Request a copy of all personal data we hold about you, free of charge.
- Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to erasure (Article 17): Request deletion of your data when it is no longer necessary, or when you withdraw consent.
- Right to restrict processing (Article 18): Request limitation of processing while we verify accuracy or assess an objection.
- Right to data portability (Article 20): Receive your data in a structured, commonly used, machine-readable format (JSON or CSV).
- Right to object (Article 21): Object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making (Article 22): Our ETA predictions are AI-generated estimates and do not constitute automated decision-making that produces legal effects.
To exercise any of these rights, email [email protected]. We may ask you to verify your identity before processing the request.
5. Data Protection Measures
5.1 Technical measures
- Encryption in transit using TLS 1.3 for all data transmissions.
- Encryption at rest using AES-256 for stored data.
- Regular penetration testing and vulnerability assessments.
- Automated monitoring and alerting for security incidents.
- Secure API authentication using Bearer tokens and rate limiting.
- Data backups with encryption, stored in geographically separate locations.
5.2 Organisational measures
- Data protection training for all employees.
- Access controls based on the principle of least privilege.
- Documented data processing activities (Article 30 records).
- Data Protection Impact Assessments (DPIAs) for high-risk processing.
- Incident response plan with 72-hour breach notification to ICO where required.
6. International Data Transfers
Where we transfer personal data outside the United Kingdom, we ensure compliance through:
- Adequacy decisions: Transfers to countries recognised by the government as providing adequate data protection.
- Standard Contractual Clauses (SCCs): UK-approved International Data Transfer Agreement (IDTA) or addendum to EU SCCs.
- Transfer Impact Assessments: Conducted for transfers to countries without adequacy decisions.
7. Sub-Processors
We use the following categories of sub-processors to deliver the Service:
- Cloud hosting: Infrastructure providers for data storage and computing (data centres in Europe).
- Payment processing: Stripe (PCI DSS Level 1 certified) for secure payment handling.
- Email delivery: Transactional email providers for alerts and notifications.
- Analytics: Aggregated usage analytics with IP anonymization.
- Carrier data providers: Shipping line APIs for tracking data retrieval.
All sub-processors are bound by Data Processing Agreements and are reviewed regularly for compliance. A full list of sub-processors is available upon request.
8. Data Processing Agreement (DPA)
We offer a DPA to all customers who require one for their own GDPR compliance. The DPA covers the scope of processing, sub-processor obligations, data security measures, breach notification procedures, and data subject rights assistance. To request a DPA, contact [email protected].
9. Data Breach Notification
In the event of a personal data breach, we will:
- Notify the UK Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, where required.
- Notify affected data subjects without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
- Document the breach, its effects, and the remedial actions taken.
10. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is:
- Information Commissioner's Office (ICO)
- Website: ico.org.uk
- Helpline: 0303 123 1113
11. Contact
For any GDPR-related inquiries or to exercise your data subject rights, please contact our Data Protection Officer:
- Email: [email protected]
- Post: Tracktainer Ltd, Data Protection Officer, United Kingdom