top of page
Privacy Policy
Privacy Policy
AUREXO Cargo OÜ · Lõõtsa 5-11, 11415 Tallinn, Estonia · Registry code 17548340
Version 1.0
1. Who we are
AUREXO Cargo OÜ ("AUREXO", "we", "us") is a freight forwarding company registered in the Republic of Estonia under registry code 17548340, with its registered office at Lõõtsa 5-11, 11415 Tallinn, Estonia.
We act as the data controller for the personal data described in this policy, within the meaning of Regulation (EU) 2016/679 (the "GDPR").
For any question about this policy or about how we handle your personal data, contact us at privacy@aurexo.eu.
2. Scope
This policy explains how we collect and use personal data relating to:
-
visitors to our website;
-
individuals who contact us or request a quotation;
-
employees, officers and representatives of our clients, suppliers, carriers and agents;
-
individuals identified in shipping documentation, such as shippers, consignees, notify parties and drivers.
This policy does not apply to the websites of third parties that we may link to.
3. What personal data we collect
Contact and identification data. Name, job title, company, email address, telephone number, and postal address.
Commercial and transactional data. Quotation requests, instructions, correspondence, order references, contract terms, and payment records.
Shipping documentation. Information contained in transport and customs documents, including bills of lading, air waybills, packing lists, commercial invoices, certificates of origin, EORI numbers and tax identification numbers.
Compliance data. Information required for identity verification, sanctions and export-control screening, and anti-money-laundering obligations, including copies of identity or company documents where legally required.
Website data. IP address, browser type and version, device information, pages visited, referring page, and the date and time of access. See section 8 on cookies.
We do not intentionally collect special categories of personal data (such as health, religious or biometric data). Please do not include such information in correspondence with us unless it is strictly necessary and we have asked for it.
4. Why we use it, and on what legal basis
We process personal data for the following purposes, on the legal bases set out in Article 6 of the GDPR:
Performance of a contract, or pre-contractual steps taken at your request — Article 6(1)(b)
-
Providing quotations and arranging freight forwarding services.
Compliance with a legal obligation — Article 6(1)(c)
-
Preparing and submitting customs declarations and transport documents.
-
Invoicing, accounting and tax records.
-
Sanctions, export-control and anti-money-laundering screening.
Our legitimate interests — Article 6(1)(f)
-
Managing the relationship with clients, suppliers, carriers and agents.
-
Preventing fraud and securing our systems and communications.
-
Establishing, exercising or defending legal claims.
Your consent — Article 6(1)(a)
-
Sending commercial communications where you have asked to receive them.
-
Non-essential cookies and analytics.
Where we rely on legitimate interests, we have assessed that our interest in operating and protecting our business does not override your rights and freedoms. You may object to such processing as described in section 9.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Who we share it with
Freight forwarding cannot be performed without disclosing certain data to the parties involved in moving the goods. We may share personal data with:
-
Carriers and transport operators — shipping lines, airlines, road hauliers, rail operators.
-
Customs brokers, port and terminal operators, warehouse keepers and stevedores.
-
Overseas agents and correspondents in the countries of origin and destination.
-
Customs, tax, port and border authorities, where required by law.
-
Insurers and insurance brokers, where insurance is arranged at your instruction.
-
Banks and payment providers.
-
Professional advisers — accountants, auditors and lawyers.
-
IT and communications providers who host our website, email and business systems.
We do not sell personal data, and we do not share it for third-party advertising.
6. International transfers
Our services are international by nature. Personal data will be transferred to the countries of origin, transit and destination of the goods, which include Bolivia, Chile and Ecuador as well as other countries worldwide, depending on the shipment.
Some of these countries have not been recognised by the European Commission as providing an adequate level of data protection.
Where we transfer personal data to such countries, we rely on:
-
Article 49(1)(b) GDPR — the transfer is necessary for the performance of the contract between you and us, or for pre-contractual steps taken at your request. This is the case, for example, when we pass consignee details to a destination agent so that the goods can be cleared and delivered.
-
Article 49(1)(c) GDPR — the transfer is necessary for the conclusion or performance of a contract concluded in your interest with a third party, such as a carrier.
-
Standard Contractual Clauses adopted by the European Commission, where we have such clauses in place with the recipient.
-
Article 49(1)(e) GDPR, where the transfer is necessary for the establishment, exercise or defence of legal claims.
You may request further information about the safeguards applicable to a specific transfer by contacting us at privacy@aurexo.eu.
7. How long we keep it
-
Accounting and tax records, invoices and source documents — 7 years from the end of the financial year, under Estonian accounting legislation.
-
Customs and transport documentation — as required by applicable customs legislation, and in any event not less than the accounting retention period.
-
Contracts and commercial correspondence — duration of the relationship plus the applicable limitation period for claims.
-
Compliance and screening records — as required by anti-money-laundering legislation.
-
Quotation requests that did not result in a contract — 24 months.
-
Marketing contact data — until consent is withdrawn.
-
Website and cookie data — see section 8.
When a retention period expires, we delete the data or anonymise it irreversibly.
8. Cookies and the website
Our website uses cookies and similar technologies.
Strictly necessary cookies are required for the website to function — for example, security, load balancing and session management. These are set on the basis of our legitimate interest and cannot be switched off.
Analytics and performance cookies help us understand how the website is used. These are only set with your consent, given through the cookie banner.
You can withdraw or change your cookie preferences at any time through the cookie settings on our website, and you can block or delete cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the website from working.
Our website is hosted by a third-party platform provider, which processes technical data such as IP addresses on our behalf in order to deliver and secure the site.
9. Your rights
Under the GDPR you have the right to:
-
Access the personal data we hold about you, and receive a copy of it.
-
Rectify inaccurate or incomplete data.
-
Erase your data, where one of the grounds in Article 17 applies.
-
Restrict processing in the circumstances set out in Article 18.
-
Object to processing based on our legitimate interests, on grounds relating to your particular situation, and at any time to processing for direct marketing.
-
Data portability — receive data you provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
-
Withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us at privacy@aurexo.eu. We will respond within one month of receiving your request. That period may be extended by two further months where the request is complex, in which case we will tell you within the first month.
Please note that some rights are limited where we are under a legal obligation to retain data — for example, customs, accounting and anti-money-laundering records — or where the data is needed to establish, exercise or defend legal claims.
Right to complain. If you believe we have not handled your data lawfully, you may lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tallinn, Estonia — www.aki.ee. You may also complain to the supervisory authority of your habitual residence or place of work.
10. Data protection officer
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Data protection matters are handled by our management, reachable at privacy@aurexo.eu.
11. Security
We apply technical and organisational measures appropriate to the risk, including access controls, encryption of data in transit, restricted access on a need-to-know basis, and contractual confidentiality obligations on our staff, subcontractors and service providers.
No transmission over the internet can be guaranteed to be completely secure. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority, and you where required, in accordance with Articles 33 and 34 of the GDPR.
12. Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
13. Changes to this policy
We may update this policy from time to time. The current version is always published at www.aurexo.eu/privacy, with the effective date shown at the top. Where changes are significant, we will take reasonable steps to inform you.
bottom of page