Privacy Policy
Last updated: June 26, 2026
This privacy policy of the website available at www.carrierguard.eu (hereinafter the “Service” or the “Website”) is for information purposes only, which means that it is not a source of obligations for users of the Service. The privacy policy sets out, above all, the rules for the processing of personal data by the Controller within the Service, including the legal bases, purposes and periods of processing and the rights of data subjects, as well as information on the use of cookies and analytics tools within the Service.
The controller of personal data collected through the Service and its owner is Aleksander Jędrosz, a private individual (hereinafter the “Controller”). To contact the Controller quickly: e-mail: help@carrierguard.eu; phone: +48 503 101 110 (call charged as a standard call in accordance with your provider's tariff).
Personal data within the Service is processed by the Controller in accordance with applicable law, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) — hereinafter the “GDPR”. Official text of the GDPR: http://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679
General provisions
Use of the Service is voluntary. Likewise, providing personal data by a user of the Service is voluntary, except where it is necessary to use certain functionalities of the Service, such as creating an account, using the carrier registry, saving check history, the newsletter or contacting us. Failure to provide the personal data required for a given functionality results in the inability to use that functionality.
The Controller takes particular care to protect the interests of the data subjects, and in particular ensures that the data it collects is: (1) processed lawfully; (2) collected for specified, lawful purposes and not further processed in a manner incompatible with those purposes; (3) accurate and adequate in relation to the purposes for which it is processed; (4) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes of processing; and (5) processed in a manner that ensures appropriate security of the personal data.
The Controller applies appropriate technical and organisational measures to prevent the acquisition and modification of personal data transmitted electronically by unauthorised persons. These measures are reviewed and updated where necessary.
Legal bases for processing
The Controller is entitled to process personal data where — and to the extent that — at least one of the following conditions is met: (1) the data subject has given consent to the processing of their personal data for one or more specific purposes; (2) processing is necessary for the performance of a contract to which the data subject is party, or to take steps at the request of the data subject prior to entering into a contract; (3) processing is necessary for compliance with a legal obligation to which the Controller is subject; or (4) processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.
The specific legal bases for the processing of users' personal data are indicated in the next section of this privacy policy, in relation to each purpose of processing.
Purposes, legal bases and retention periods
In each case, the purpose, legal basis, period and recipients of personal data processed by the Controller result from the actions taken by a given user within the Service. The Controller may process personal data for the following purposes:
Creating and maintaining an account and providing the Service
Basis: Article 6(1)(b) GDPR (performance of a contract). Processing is necessary to create and maintain a user account and to provide the services available within the Service (including access to the carrier registry, search and checking of entities). Authentication and account management are supported by an authentication service provider (Clerk). Data (e.g. e-mail address, name or company name, login credentials) is stored for the duration of the account and, after its deletion, for the period necessary to settle the service and no longer than the limitation period for claims.
Verifying eligibility and granting registry access
Basis: Article 6(1)(b) and (f) GDPR (performance of a contract and the Controller's legitimate interest in making the registry available only to verified freight forwarders and in preventing abuse). The Controller may process data provided when requesting access (e.g. forwarder name, tax ID/NIP) in order to verify and activate access. Data is stored for the duration of use of the service and the limitation period for claims.
Saving carrier-check history
Basis: Article 6(1)(b) and (f) GDPR. As part of the “My checks” feature, the Controller stores the checks performed by the user (including the searched identifier, entity name, risk-assessment result and, if provided, the data supplied for the check) so the user can return to them. Data is stored for the duration of the account or until deleted by the user.
Operating the carrier-risk registry
Basis: Article 6(1)(f) GDPR (the legitimate interest of the Controller and of third parties — freight forwarders — in preventing fraud and abuse in road transport and in the security of commercial transactions). Within the Service, the Controller processes data concerning carriers and related entities sourced from public registers and from reports submitted by forwarders. Such data may include personal data where the carrier is a natural person (e.g. a sole trader) or where the data concerns persons related to an entity (e.g. company officers). Details are described in the section “Data concerning carriers and related persons”.
Sending commercial information and the newsletter
Basis: Article 6(1)(f) GDPR (the Controller's legitimate interest in direct marketing) and, as regards sending via electronic communications end-devices (e.g. e-mail), on the basis of prior consent. Data is processed until an effective objection is raised or consent is withdrawn, without affecting the lawfulness of processing carried out before withdrawal.
Handling enquiries and contact
Basis: Article 6(1)(b) and (f) GDPR. Data provided when contacting us (e.g. by e-mail) is processed in order to respond and handle the matter. Data is stored for the period necessary to handle the enquiry and the limitation period for any claims.
Establishing, pursuing or defending claims
Basis: Article 6(1)(f) GDPR. Data is stored for the duration of the Controller's legitimate interest, but no longer than the limitation period for claims provided for by law, in particular the Civil Code.
Operating the Service, its security and statistics
Basis: Article 6(1)(f) GDPR (the Controller's legitimate interest in running, maintaining and securing the Service and in keeping statistics and analysing traffic to improve its functioning). Data is stored for the duration of the legitimate interest, but no longer than the limitation period for claims.
Data concerning carriers and related persons
The essence of the Service is to provide risk signals about carriers. To this end, the Controller collects and processes data from publicly available registers and sources (including the National Court Register (KRS), CEIDG, REGON/GUS, the VAT taxpayers' “white list”, VIES, the Central Register of Beneficial Owners (CRBR), MSiG/KRZ, sanctions lists and open web sources) as well as data from reports submitted by verified freight forwarders.
To the extent that such data constitutes personal data (e.g. where the carrier is a natural person conducting business activity, or where the data concerns persons related to an entity, such as board members, partners or beneficial owners), the legal basis for processing is Article 6(1)(f) GDPR — the legitimate interest of the Controller and of forwarders in preventing fraud, cargo theft and other abuse in transport and in ensuring the security of commercial transactions.
Data subjects are entitled to the rights described in the section “Rights of the data subject”, including the right to object to processing and the right to request rectification. An entity that believes an entry or data concerning it is inaccurate may contact the Controller at help@carrierguard.eu to have it reviewed.
Recipients of data
For the proper functioning of the Service, the Controller needs to use the services of external entities. The Controller uses only processors that provide sufficient guarantees to implement appropriate technical and organisational measures so that processing meets the requirements of the GDPR and protects the rights of data subjects.
Users' personal data may be transferred to the following categories of recipients:
- the authentication and account-management service provider (Clerk);
- providers of infrastructure, hosting and the database in which the Service's data is stored;
- providers of e-mail and tools for communication and handling enquiries;
- providers of analytics tools (where used);
- providers of legal and advisory services supporting the Controller.
Data is transferred only where it is necessary to achieve a given processing purpose and only to the extent necessary to achieve it.
Transfers outside the EEA
Some service providers used by the Controller (e.g. the authentication provider) may process data outside the European Economic Area. In such cases, the Controller ensures that the transfer is made to a country ensuring an adequate level of protection consistent with the GDPR or, for other countries, on the basis of appropriate safeguards, in particular standard data protection clauses approved by the European Commission. The data subject may obtain a copy of those safeguards by contacting the Controller.
Profiling and automated decisions
The Controller does not take decisions in relation to users of the Service based solely on automated processing (including profiling) that would produce legal effects concerning them or similarly significantly affect them.
Within the service, however, the Service applies automated analysis and risk assessment concerning carriers (e.g. computing risk indicators based on register data and reports). This assessment is auxiliary and informational — the final decision on whether to work with a given carrier is made independently by the user. To the extent that such analysis concerns a natural person, that person is entitled to the rights arising from Article 22 GDPR.
Rights of the data subject
Right of access, rectification, restriction, erasure or portability — the data subject has the right to request from the Controller access to their personal data, its rectification, erasure (“right to be forgotten”) or restriction of processing, and the right to object to processing, as well as the right to data portability. The detailed conditions for exercising these rights are set out in Articles 15–21 GDPR.
Right to withdraw consent at any time — a person whose data is processed on the basis of consent has the right to withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
Right to object — the data subject has the right to object at any time, on grounds relating to their particular situation, to processing of their data based on Article 6(1)(f) GDPR, including profiling on that basis. Where data is processed for direct marketing purposes, the data subject has the right to object at any time to the extent that processing is related to such marketing.
Right to lodge a complaint with a supervisory authority — a person whose data is processed has the right to lodge a complaint with a supervisory authority. In Poland, the supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
To exercise the above rights, you may contact the Controller at: help@carrierguard.eu.
Cookies and analytics
Cookies are small pieces of text information sent by a server and stored on the device of a person visiting the Service. The Service uses cookies necessary for its proper operation, in particular for authentication, maintaining a signed-in user's session and ensuring security.
The Service may also use cookies and tools for anonymous statistics and traffic analysis in order to improve its functioning. The Service does not use cookies for advertising purposes or to display behavioural ads.
By default, most browsers accept cookies. Every user can set the conditions for the use of cookies through their browser settings, including blocking or deleting them. Restricting cookies may affect some functionalities of the Service, in particular the ability to sign in.
External links
The Service may contain links to other websites. The Controller encourages you to read the terms and privacy policy established there after navigating to other sites. This privacy policy applies only to this Service.
Contact
If you have any questions or doubts regarding the processing of personal data or the use of the Service, please contact the Controller: e-mail: help@carrierguard.eu; phone: +48 503 101 110.