Cargease Back to cargease.com

Data processing agreement

Last updated 17 August 2026

This is published rather than kept in a drawer, so you can read it before you ask for it. It applies automatically to every customer as part of the terms of service. If your procurement process needs it signed as a standalone document, write to [email protected] and we will sign this text. We will also review a DPA of your own, though it will take longer.

1. Parties, and what this covers

This agreement is between Gonzalo Palazuelos, registered in Mexico as persona física con actividad empresarial, operating Cargease ("Processor", "we"), and the customer named in the order form ("Controller", "you"). Our registered domicile is in Nuevo León, Mexico, and we provide it on request.

It forms part of the terms of service and governs our processing of personal data on your behalf. Where this agreement and the terms of service conflict on a matter of personal data, this agreement wins.

It is written to satisfy the Mexican Ley Federal de Protección de Datos Personales en Posesión de los Particulares (where we are an encargado and you are the responsable) and, where it applies to you, Article 28 of the GDPR.

2. Roles, and the part people get wrong

You decide what personal data goes into Cargease and why. We do not. You are the controller for the shipment records, business contacts and documents in your account. We are your processor for all of it.

We are a controller only for the small amount of data we hold in our own right: the names and email addresses of your users so they can sign in, billing details, and ordinary server logs. That processing is described in the privacy notice, not here.

The practical consequence, and it is the reason this distinction is worth reading: when a supplier or broker asks us to delete their details, we will not do it on our own authority, because they are not our data to decide about. We will tell them to ask you, point out that you can do it yourself in the application immediately, and support you in answering. We think that is the honest answer rather than the convenient one.

3. Our obligations

We will:

4. Your obligations

5. Subprocessors

You authorise the subprocessors below, each engaged under a written contract imposing data protection obligations no less protective than this one.

SubprocessorPurposeDataLocation
Neon Managed PostgreSQL database All structured data: shipments, contacts, users, costs United States (AWS us-east-1)
Vercel Application hosting Data in transit while requests are served; no persistent store United States
Cloudflare R2 Document storage Uploaded document files Cloudflare network
Cloudflare DNS and public website No customer personal data Global
Resend Transactional email Recipient address, and the content of document requests and sign-in links United States

If we add or replace a subprocessor that handles personal data, we will email account administrators at least 30 days beforehand and update this page. If you reasonably object on data protection grounds, tell us within those 30 days and we will work with you to find an alternative. If we cannot, you may terminate and we will refund any period you have paid for but not used.

6. Security

The measures we apply are described in full, and honestly including what we do not have, on the security and subprocessors page, which forms part of this agreement. In summary:

7. Data subject requests

Much of this you can do yourself, immediately, and that is deliberate. You can correct or delete a contact, remove a participant, revoke an upload link, or delete a shipment and its documents from inside the application without asking us.

Where you cannot, we will help. If a data subject contacts us directly about data we process for you, we will not respond substantively. We will tell them to contact you, and tell you within 5 business days. Taking into account the nature of the processing, we will assist you in responding to requests to access, correct, delete, object or limit, including the ARCO rights under Mexican law.

8. Personal data breaches

We will notify you without undue delay, and in any case within 72 hours of confirming a personal data breach affecting data we process for you. The notification will describe the nature of the breach, the categories and approximate volume of data and data subjects involved, the likely consequences, and the measures taken or proposed.

We will not wait for a complete picture before telling you something is wrong. Where we do not yet know everything, we will say what we know and follow up. Notifying regulators and data subjects is your decision as controller; we will give you what you need to make it.

9. Deletion and return

On request during the term, or within 30 days of it ending, we will provide a machine-readable export of the personal data we process for you. After that 30-day window we delete it from production, including document storage, unless the law requires us to retain something, in which case we will tell you what and why.

Deleting a shipment inside the application already removes its documents from object storage, not merely the reference to them. Residual copies may persist briefly in routine backups and are deleted on the ordinary backup cycle.

10. International transfers

Personal data in Cargease is stored outside Mexico and outside the European Economic Area, principally in the United States, and on Cloudflare's global network for documents. By instructing us to process personal data you accept that transfer.

Where the GDPR applies to your use of the service, transfers are made under the European Commission's Standard Contractual Clauses, which are incorporated into this agreement by reference, with this agreement and its annexes supplying the required descriptions. Under Mexican law we rely on the transfer being necessary for the performance of the contract between us, under Article 37 of the LFPDPPP.

We do not offer data residency options. If your policy requires data to stay in a particular country, Cargease cannot meet that today, and we would rather say so here than three weeks into a procurement process.

11. Audits

We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will answer security questionnaires directly.

We are honest about the shape of this: Cargease is operated by a very small team and does not hold a SOC 2 or ISO 27001 certification, so there is no audit report to hand you. In place of one, the security page describes the system in specific terms including its gaps, and we will answer questions in writing. An on-site audit is not something we can support at this stage, and we would rather tell you that than agree to a clause we could not honour.

12. Liability and term

Each party's liability under this agreement is subject to the limitations in the terms of service. This agreement takes effect when your account is created and continues for as long as we process personal data on your behalf.

13. Governing law

The laws of Mexico, with the courts of Nuevo León having exclusive jurisdiction, as set out in the terms of service. Nothing here deprives a data subject of a right they have under the law applicable to them.

Annex 1. Details of processing

Subject matterProvision of the Cargease freight operations service.
DurationThe term of the agreement, plus the 30-day deletion window.
Nature and purposeHosting, storage, transmission and display of shipment records and documents; sending document requests, reminders and notifications on your instruction.
Categories of data subject(a) your own staff who hold accounts; (b) named contacts at your suppliers, customs brokers, carriers and customers; (c) any individual appearing in a document uploaded to your account, such as a signatory on a bill of lading.
Types of personal dataName, business email address, job role and employer; the content of uploaded commercial documents, which may contain signatures, phone numbers and similar details; sign-in and upload timestamps; IP address and browser type in server logs.
Special categoriesNone. The service is not designed for special-category data and you should not put it there.

Annex 2. Security measures

Set out on the security and subprocessors page, which is incorporated into this agreement and summarised in section 6. That page is maintained as the single description of how the service is secured, so that it cannot drift out of step with a copy kept in a contract.

Contact

info@cargease.com for anything in this agreement, including a request to sign it as a standalone document.