Data Processing Addendum

Last updated: 2026-09-20

This Data Processing Addendum forms part of the agreement between FreightCMD and a business customer where FreightCMD processes personal data on that customer’s documented instructions. It should be completed with the registered contracting entity details before signature.

1. Roles and scope

The customer is controller for personal data it enters about staff, drivers, clients, recipients and trips. FreightCMD is processor for that data. FreightCMD acts as controller for its own account security, billing, legal compliance, platform integrity and direct marketplace relationships.

2. Processing instructions

FreightCMD will process customer data to host, secure, support and provide the subscribed services, documented integrations and lawful support instructions. It will notify the customer where an instruction appears unlawful unless prohibited from doing so.

3. Confidentiality and security

Access is limited by role and work need. FreightCMD will maintain proportionate technical and organisational safeguards, including access controls, transmission security, logging, recovery measures and personnel confidentiality. No service is completely immune from risk.

4. Subprocessors

The customer authorises the subprocessors listed on the Subprocessor List for the stated purposes. FreightCMD remains responsible for imposing appropriate data-protection duties and will provide reasonable notice of material additions so the customer can raise a substantiated objection.

5. Rights requests and incidents

Taking account of the nature of processing, FreightCMD will reasonably assist the customer with access, correction, deletion, objection and portability requests. FreightCMD will notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available information needed for the customer’s assessment and notices.

6. International processing

Some providers may process data outside Sri Lanka. The parties will use contractual or other lawful transfer measures required by applicable data-protection law. The customer will not instruct a prohibited transfer.

7. Return, deletion and retention

On termination, the customer may request an export during the stated retrieval period. FreightCMD will delete or anonymise customer data after that period except for backups awaiting rotation and records retained for law, security, disputes or financial integrity.

8. Audit cooperation

FreightCMD will provide reasonable security and compliance information. On reasonable notice, it will cooperate with a proportionate audit where documentary assurance is insufficient, subject to confidentiality, security, cost and protection of other customers.

9. Priority

If this addendum conflicts with the general Terms on processing customer-controlled personal data, this addendum prevails. Mandatory law prevails over both.