Data processing agreement
Last updated 25 September 2026
This agreement applies automatically to every customer as part of the terms of service. If your procurement process needs it signed as a standalone document, write to info@cargease.com and we will sign this text. We will also review a DPA of your own, though it will take longer.
1. Parties, and what this covers
This agreement is between Gonzalo Palazuelos, registered in Mexico as persona física con actividad empresarial, operating Cargease ("Processor", "we"), and the customer named in the order form ("Controller", "you"). Our registered domicile is in Nuevo León, Mexico, and we provide it on request.
It forms part of the terms of service and governs our processing of personal data on your behalf. Where this agreement and the terms of service conflict on a matter of personal data, this agreement wins.
It is written to satisfy the Mexican Ley Federal de Protección de Datos Personales en Posesión de los Particulares (where we are an encargado and you are the responsable) and, where it applies to you, Article 28 of the GDPR.
2. Roles
You decide what personal data goes into Cargease and why. We do not. You are the controller for the shipment records, business contacts and documents in your account. We are your processor for all of it.
We are a controller only for the small amount of data we hold in our own right: the names and email addresses of your users so they can sign in, billing details, and ordinary server logs. That processing is described in the privacy notice, not here.
In practice: when a supplier or broker asks us to delete their details, we will not do it on our own authority, because they are not our data to decide about. We will tell them to ask you, point out that you can do it yourself in the application immediately, and support you in answering.
3. Our obligations
We will:
- Process personal data only on your documented instructions. Using the service is itself an instruction: creating shipments, adding participants, requesting documents and sending reminders are all instructed processing. We will tell you if an instruction appears to breach applicable data protection law.
- Never use your personal data for our own purposes. We do not sell it, we do not share it beyond the subprocessors in section 5, and we do not use it to train artificial-intelligence or machine-learning models.
- Keep it confidential, and ensure anyone we authorise to process it is bound by confidentiality.
- Apply the security measures in section 6, and not materially weaken them during the term.
- Help you with data subject requests, security, breach notification and impact assessments, as set out below.
- Delete or return the data when the agreement ends, as set out in section 9.
4. Your obligations
- You warrant you have a lawful basis for the personal data you put into Cargease, and for instructing us to process it.
- You enter the name and email address of a person at your supplier, customs broker or carrier, and instruct us to email them. You confirm you are entitled to do that, and that those people can reasonably expect to be contacted about a shipment they are party to. We collect nothing from them beyond the files they choose to upload, a timestamp, and ordinary server-log data.
- You are responsible for what your users and your counterparties upload, including any personal data inside a document. A signed bill of lading or a driver's identification carries personal data we never asked for and cannot anticipate.
- Do not put special-category data into Cargease. The service is not designed for health data, biometric data, government identity numbers, or payment card data, and you should not use it to store them.
5. Subprocessors
You authorise the subprocessors below, each engaged under a written contract imposing data protection obligations no less protective than this one.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Neon | Managed PostgreSQL database | All structured data: shipments, contacts, users, costs | United States (AWS us-east-1) |
| Vercel | Application hosting | Data in transit while requests are served; no persistent store | United States |
| Cloudflare R2 | Document storage | Uploaded document files | Cloudflare network |
| Cloudflare | DNS and public website | No customer personal data | Global |
| Resend | Transactional email | Recipient address, and the content of sign-in links, document requests, team invitations and notification emails | United States |
If we add or replace a subprocessor that handles personal data, we will email account administrators at least 30 days beforehand and update this page. If you reasonably object on data protection grounds, tell us within those 30 days and we will work with you to find an alternative. If we cannot, you may terminate and we will refund any period you have paid for but not used.
6. Security
The measures we apply are described in full, including what we do not have, on the security and subprocessors page, which forms part of this agreement. In summary:
- Encryption in transit (HTTPS/TLS) and at rest.
- Tenant isolation is enforced twice. Every read and write is scoped to the account that owns the record, and since September 2026 the database enforces the same rule independently: every table carrying customer data has a row-level security policy, and the application connects as a role that cannot bypass them. One customer cannot reach another's data even with a valid session, and the protection does not rest on every query being written correctly.
- Sign-in is a single-use emailed link, so there is no password store to breach.
- Suppliers, brokers and carriers never hold accounts. They receive an unguessable, upload-only link, scoped to the documents assigned to that one party on that one shipment, expiring after 30 days and revoked when that party is removed.
- Document storage is private. No object is publicly readable; every download is authorised against the caller's account.
- Multi-factor authentication on every provider account, credentials in a password manager or the hosting platform's secret store, automatic scanning for credentials in code, full-disk encryption and automatic locking on machines with production access.
7. Data subject requests
Much of this you can do yourself, immediately. You can correct or delete a contact, remove a participant, revoke an upload link, or delete a shipment and its documents from inside the application without asking us.
Where you cannot, we will help. If a data subject contacts us directly about data we process for you, we will not respond substantively. We will tell them to contact you, and tell you within 5 business days. Taking into account the nature of the processing, we will assist you in responding to requests to access, correct, delete, object or limit, including the ARCO rights under Mexican law.
8. Personal data breaches
We will notify you without undue delay, and in any case within 72 hours of confirming a personal data breach affecting data we process for you. The notification will describe the nature of the breach, the categories and approximate volume of data and data subjects involved, the likely consequences, and the measures taken or proposed.
We will not wait for a complete picture before telling you something is wrong. Where we do not yet know everything, we will say what we know and follow up. Notifying regulators and data subjects is your decision as controller; we will give you what you need to make it.
9. Deletion and return
On request during the term, or within 30 days of it ending, we will provide a machine-readable export of the personal data we process for you. After that 30-day window we delete it from production, including document storage, unless the law requires us to retain something, in which case we will tell you what and why.
Deleting a shipment inside the application already removes its documents from object storage, not merely the reference to them. Deleted documents are held in a private recovery area for 7 days, so a mistake can be undone, and are then removed automatically. Database records remain recoverable through point-in-time restore for the same 7 days, after which they are gone. Documents are also copied nightly to a separate, locked backup; a deleted document's backup copy is removed automatically about 30 days after the deletion, and never more than 35. The same applies to backup copies after the 30-day window above.
10. International transfers
Personal data in Cargease is stored outside Mexico and outside the European Economic Area, principally in the United States, and on Cloudflare's global network for documents. By instructing us to process personal data you accept that transfer.
Where the GDPR applies to your use of the service, transfers are made under the European Commission's Standard Contractual Clauses, which are incorporated into this agreement by reference, with this agreement and its annexes supplying the required descriptions. Under Mexican law we rely on the transfer being necessary for the performance of the contract between us, under Article 37 of the LFPDPPP.
We do not offer data residency options. If your policy requires data to stay in a particular country, Cargease cannot meet that today.
11. Audits
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will answer security questionnaires directly.
Cargease is operated by a very small team and does not hold a SOC 2 or ISO 27001 certification, so there is no audit report to hand you. In place of one, the security page describes the system in specific terms including its gaps, and we will answer questions in writing. An on-site audit is not something we can support at this stage.
12. Liability and term
Each party's liability under this agreement is subject to the limitations in the terms of service. This agreement takes effect when your account is created and continues for as long as we process personal data on your behalf.
13. Governing law
The laws of Mexico, with the courts of Nuevo León having exclusive jurisdiction, as set out in the terms of service. Nothing here deprives a data subject of a right they have under the law applicable to them.
Annex 1. Details of processing
| Subject matter | Provision of the Cargease freight operations service. |
|---|---|
| Duration | The term of the agreement, plus the 30-day deletion window. |
| Nature and purpose | Hosting, storage, transmission and display of shipment records and documents; sending document requests, reminders and notifications on your instruction. |
| Categories of data subject | (a) your own staff who hold accounts; (b) named contacts at your suppliers, customs brokers, carriers and customers; (c) any individual appearing in a document uploaded to your account, such as a signatory on a bill of lading. |
| Types of personal data | Name, business email address, job role and employer; the content of uploaded commercial documents, which may contain signatures, phone numbers and similar details; sign-in and upload timestamps; IP address and browser type in server logs. |
| Special categories | None. The service is not designed for special-category data and you should not put it there. |
Annex 2. Security measures
Set out on the security and subprocessors page, which is incorporated into this agreement and summarised in section 6. That page is maintained as the single description of how the service is secured, so that it cannot drift out of step with a copy kept in a contract.
Contact
info@cargease.com for anything in this agreement, including a request to sign it as a standalone document.