Cargizon Data Processing Agreement (DPA)
Last updated: July 18, 2026
Pending review by qualified privacy counsel (in particular the international-transfer mechanics in §5). The factual details are completed.
This Data Processing Agreement ("DPA") forms part of the agreement between 9485-2068 Québec Inc. ("Cargizon", the "Processor") and the customer identified in the applicable order or account registration ("Customer", the "Controller") governing use of the Cargizon Service (the "Agreement"). It applies to the extent Cargizon processes Personal Data contained in Customer Data on Customer's behalf.
1. Definitions
"Personal Data", "processing", "controller", "processor", "data subject", "supervisory authority" have the meanings in applicable Data Protection Law. "Data Protection Law" means all laws applicable to the processing of Personal Data under the Agreement, including the EU GDPR, UK GDPR, PIPEDA, Quebec Law 25, and applicable US state privacy laws. "Sub-processor" means a third party engaged by Cargizon to process Personal Data on Customer's behalf. "SCCs" means the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). "UK Addendum" means the UK ICO's International Data Transfer Addendum to the SCCs.
2. Scope and Roles
2.1 Customer is the controller (or a processor acting on behalf of another controller, in which case Customer warrants its instructions are consistent with the ultimate controller's instructions); Cargizon is the processor.
2.2 Details of processing (GDPR Art. 28(3)):
- Subject matter & duration: provision of the Service for the term of the Agreement plus the post-termination retrieval/deletion period.
- Nature & purpose: hosting, storage, transmission, display, AI-assisted extraction and classification, analytics, and related support of Customer Data to provide shipment visibility, order management, document management, and freight cost reconciliation.
- Categories of data subjects: Customer's personnel and authorized users; personnel of Customer's vendors, suppliers, carriers, freight forwarders, customs brokers, and consignees; other individuals whose information Customer includes in Customer Data.
- Categories of Personal Data: business contact information (names, emails, phone numbers, job titles, employers, addresses); identifiers appearing in trade documents (e.g., signatures, contact lines on invoices, bills of lading, packing lists); communications metadata from email import; account and usage records. Not intended for the Service: special categories of data (GDPR Art. 9), government IDs, or financial account numbers of individuals; Customer agrees not to submit them.
3. Processor Obligations
Cargizon will: (a) process Personal Data only on Customer's documented instructions (the Agreement, this DPA, and use of Service features constitute instructions), including for international transfers, unless required by law — in which case Cargizon will inform Customer unless legally prohibited; (b) immediately inform Customer if, in its opinion, an instruction infringes Data Protection Law; (c) ensure persons authorized to process Personal Data are bound by confidentiality; (d) implement the technical and organizational measures in Annex II and maintain a level of security appropriate to the risk (GDPR Art. 32); (e) assist Customer, taking into account the nature of processing, in responding to data subject requests (Art. 12–23) and in Customer's compliance with Art. 32–36 (security, breach notification, DPIAs, prior consultation), at Customer's reasonable expense where requests are excessive; (f) notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer's Personal Data, providing information reasonably required for Customer's own notification obligations (including under GDPR's 72-hour rule), and cooperate in remediation; (g) at Customer's choice, delete or return Personal Data after the end of services (export available for 30 days post-termination; deletion from active systems thereafter, with backup copies aging out per schedule), unless law requires retention; (h) make available information reasonably necessary to demonstrate compliance with this DPA and, no more than once per 12 months (or following a material breach), allow audits by Customer or its mandated auditor, under confidentiality, during business hours, with 30 days' notice, at Customer's cost; Cargizon may first satisfy audit requests with recent third-party reports or certifications where available.
4. Sub-processors
4.1 Customer provides general authorization for Cargizon's use of Sub-processors. The current list is published at /subprocessors (as of July 18, 2026: Vercel — hosting; Supabase — database, authentication, storage; Stripe — payments; Resend — transactional email and email import; Anthropic — AI processing; Sentry — error monitoring; AISStream — vessel data; PostHog — product analytics; Google Workspace — business email).
4.2 Cargizon will provide notice (via the sub-processor page and/or email) at least 14 days before adding or replacing a Sub-processor. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected services with a pro-rata refund of prepaid fees.
4.3 Cargizon will impose data protection obligations on Sub-processors materially equivalent to this DPA and remains liable for their performance.
5. International Transfers
5.1 Personal Data is processed in Canada, the United States, and other jurisdictions where Cargizon or its Sub-processors operate.
5.2 For transfers of EEA Personal Data to countries without adequacy: the SCCs Module Two (controller → processor) (or Module Three where Customer is a processor) are incorporated by reference, with: Clause 7 (docking) included; Clause 9(a) Option 2 (general authorization, 14 days); Clause 11 optional redress not selected; Clause 17 governed by the laws of Ireland; Clause 18 courts of Ireland; Annex I completed by Section 2.2 and the parties' details in the Agreement; Annex II completed by Annex II below; Annex III by the sub-processor list.
5.3 For UK transfers, the UK Addendum applies with Table entries completed by the corresponding SCC selections above. For Swiss transfers, the SCCs apply adapted as required by the FADP.
5.4 Quebec Law 25: transfers of Personal Data outside Quebec are subject to Cargizon's assessment confirming adequate protection considering sensitivity, purposes, and safeguards; details available on request.
6. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Law does not permit such limitation.
7. Order of Precedence; Term
This DPA prevails over conflicting terms of the Agreement regarding Personal Data processing; the SCCs prevail over this DPA where they conflict. This DPA remains in force as long as Cargizon processes Personal Data on Customer's behalf.
Annex II — Technical and Organizational Measures
- Access control & tenancy isolation: organization-scoped data model enforced by database row-level security on all customer tables; role-based permissions within organizations; owner/admin-gated administrative actions.
- Authentication: managed authentication (Supabase Auth) with hashed credentials; session-based access; API keys stored as salted hashes with least-privilege scopes.
- Encryption: TLS 1.2+ in transit; encryption at rest for database and storage (provider-managed keys).
- Document security: private storage buckets; documents served via authenticated, short-lived signed URLs; external sharing only via expiring, unguessable tokens.
- Application safeguards: input validation; per-user and per-IP rate limiting; per-organization AI spend safeguards; edge-layer attack mitigation and platform DDoS protection.
- Monitoring & logging: centralized error monitoring (Sentry); audit-relevant operational logs; alerting on anomalous failures.
- Change management: version-controlled infrastructure-as-code database migrations; automated test suites (including row-level-security isolation tests) run before deployment; separation of production credentials.
- Backups & resilience: provider-managed daily backups (7-day retention); documented restore capability.
- Personnel: access limited to authorized personnel bound by confidentiality; least-privilege administrative access with MFA on infrastructure accounts.
- Incident response: documented process for detection, assessment, containment, customer notification, and post-incident review.
- Data minimization & retention: configurable data management by Customer; deletion and export processes as described in Section 3(g).