Data Processing Agreement
last updated July 10, 2026 · v1.0
This Data Processing Agreement ("DPA") forms part of the agreement between Freyt ("Processor", "we") and the customer identified on the applicable order form ("Controller", "you") governing Freyt's processing of personal data on your behalf when you use the Service. It supplements our Terms of Service and Privacy Policy. By continuing to use the Service after accepting this DPA (including electronically, e.g. by requesting a copy below), you agree to its terms.
1. Scope & roles
You act as the data controller for personal data contained in documents you upload or forward to Freyt (e.g. names, contact details, and other information appearing on rate confirmations or bills of lading). Freyt acts as a data processor, processing that data solely to provide the Service — extracting the fields you request and returning them to you or your configured TMS.
2. Subject matter & duration
The subject matter of processing is the extraction of shipment data from documents you submit. Processing continues for as long as your account is active, or as required to comply with the retention periods described in Section 6 of our Privacy Policy.
3. Nature & purpose of processing
- Receiving documents you upload or forward for extraction
- Running extraction (including via third-party AI sub-processors — see Section 6)
- Returning structured data to you as CSV, dashboard records, or TMS-formatted exports
- Retaining records per your plan's history window
4. Categories of data subjects
Typically your employees, carrier contacts, shippers, and consignees named in the documents you submit for processing.
5. Categories of personal data
Names, business contact details (email, phone), and business addresses appearing on rate confirmations, bills of lading, and related shipment documents. Freyt does not intentionally collect special categories of data (e.g. health, biometric data) and asks that you avoid including such data in submitted documents.
6. Sub-processors
You authorize Freyt to engage the sub-processors listed in our current sub-processor list (available on request), which includes cloud infrastructure (AWS), third-party AI providers used for document extraction, and payment processors (Stripe, PayPal). Freyt imposes data protection obligations on each sub-processor consistent with this DPA and remains responsible for their performance. We'll notify you of material changes to this list with reasonable advance notice, and you may object on reasonable data-protection grounds.
7. Security measures
Freyt maintains technical and organizational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest (AES-256), access controls restricting data to employees on a need-only basis, and regular vulnerability assessments. Further detail is available on our security page.
8. Sub-processing of international transfers
Where personal data is transferred outside the EEA/UK, Freyt relies on Standard Contractual Clauses or another valid transfer mechanism with the relevant sub-processor.
9. Assistance & data subject requests
Freyt will provide reasonable assistance to help you respond to data subject requests (access, correction, deletion) and to fulfil your obligations relating to data protection impact assessments and consultations with supervisory authorities, to the extent required by applicable law.
10. Breach notification
Freyt will notify you without undue delay after becoming aware of a personal data breach affecting your data, and will provide information reasonably necessary for you to meet any notification obligations you may have.
11. Deletion & return
On termination of the Service, Freyt will delete or return personal data processed on your behalf in accordance with the retention terms in our Privacy Policy, except where retention is required by law.
12. Audit rights
Freyt will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, including inspections, conducted by you or an auditor you designate, subject to reasonable notice and confidentiality obligations.
13. Requesting a signed copy
This page constitutes our standard DPA terms. For an executed, counter-signed copy (e.g. for your own vendor-review process), email privacy@freyt.spacewith subject line "DPA Request" and we'll return a signed PDF, typically within 3 business days.
14. Contact
Questions about this DPA: privacy@freyt.space