Logivya

Data Processing Agreement

Version: September 2, 2026

This Data Processing Agreement forms part of the service agreement between the customer and Logivya when Logivya processes personal data on the customer's documented instructions. It applies together with the Terms, Privacy Policy and any order form; mandatory data-protection law prevails.

Subject matter, duration and data

Processing covers hosting, securing, transmitting, synchronizing, searching, matching, backing up, supporting and deleting customer data as needed to provide the enabled services for the subscription term and any limited lawful retention period. Data subjects may include customer users, contacts, drivers, carriers, cargo owners, group participants and support correspondents; data categories depend on the features the customer activates.

Roles and customer obligations

For data processed on behalf of customers, Logivya fulfills its obligations as a processor regarding security, confidentiality, and access control.

The customer acts as controller or otherwise warrants lawful authority for its instructions, connected accounts, recipients, content and data. The customer is responsible for notices, legal grounds, data accuracy, access permissions, retention choices and responding to data subjects, and must not instruct processing that violates applicable law.

Documented instructions

Logivya processes customer data only to provide, secure and support the configured service and on documented instructions expressed through the agreement, product controls and authorized support requests. If an instruction appears unlawful, Logivya may suspend it and request clarification; legally compelled processing will be disclosed unless law prohibits notice.

Confidentiality and personnel

Personnel and contractors with authorized access are bound by confidentiality obligations, receive access according to role and need, and are subject to access revocation and security procedures. Customer data is not sold or used for unrelated advertising.

Technical and organizational measures

Measures include tenant and account isolation, least-privilege authorization, encryption in transit and for sensitive stored credentials, secret redaction, protected backups, logging and monitoring, vulnerability and dependency management, incident response, deletion controls and business-continuity procedures proportionate to the risk.

Subprocessors

Logivya may use subprocessors for infrastructure, storage, communications, payments, monitoring and support. Subprocessors receive only necessary data and are bound by written data-protection and security terms. Logivya remains responsible for its processor obligations and will provide legally required notice of material changes.

International transfers

International transfers use a mechanism permitted by applicable law. For Türkiye-origin data this may include an adequacy decision, a notified standard contract or another safeguard under Article 9 of Law No. 6698; statutory exceptional transfers are used only where their conditions are met. The customer will reasonably cooperate with required assessments and filings.

Data-subject requests and compliance assistance

Taking account of the nature of processing and available information, Logivya provides reasonable assistance with verified data-subject requests, security assessments, impact assessments and regulator consultations. The customer remains responsible for determining whether and how to respond unless law assigns that duty to Logivya.

Personal-data incidents

After confirming a personal-data incident affecting customer data, Logivya will notify the customer without undue delay, provide available information needed for legal assessment and take reasonable containment and remediation steps. Notification is not an admission of fault or liability.

Return and deletion

On verified request or termination, Logivya will make available supported export functions and delete or anonymize eligible customer data according to the service lifecycle. Narrow records may be retained where law, security, accounting, dispute or legal-hold duties require it; retained data remains protected and is not processed for another purpose.

Information and audit

Logivya will provide information reasonably necessary to demonstrate compliance. Any additional audit must be proportionate, protect other customers and security-sensitive information, use an independent qualified auditor, follow reasonable notice and confidentiality, and avoid disrupting the service. Costs are borne by the customer unless a material breach by Logivya is established.

Order of precedence and contact

For processor obligations, this Agreement prevails over conflicting general service terms; a mandatory signed transfer instrument prevails for the transfer it governs. Other contractual terms remain effective. Privacy and data-processing notices may be sent to support@logivya.com.