1. Introduction
CargoMind is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your personal and business information when you use the CargoMind platform and related services, including our AI-powered Outlook email extension (CargoMind Enhance & Elevate), our CargoMind Business Intelligence (BI) dashboard, and our logistics outsourcing services. We adhere to all relevant data protection laws, including the UK Data Protection Act 2018 and the EU & UK General Data Protection Regulation (GDPR), to ensure your information is handled lawfully, fairly, and transparently. We also comply with Australia's Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), which regulate how organisations collect, use, disclose and manage personal information in an open and transparent manner.
By using CargoMind's services ("Services"), you agree to the collection and use of your information in accordance with this Privacy Policy. If you do not agree with any part of this Policy, please discontinue use of our Services.
2. Information We Collect
We may collect and process various types of information in order to provide and improve our Services:
- Account and Contact Information: When you register for a CargoMind account or contact us (for example, to request a demo or support), we collect information such as your name, company name, email address, phone number, job title, and any other details you provide to us.
- Email Content and Communications: Our Outlook add-in connects with your email inbox to assist with freight operations. With your authorisation, the add-in can access certain content of emails and attachments in your mailbox to perform automated actions (for example, identifying a delivery order email, extracting relevant data, and attaching the order document to the corresponding job in CargoWise). The add-in processes only the minimum information necessary from your emails to carry out these functions. We do not use the content of your emails for any purpose unrelated to the Services, and communications content is not stored on our servers longer than needed to complete the automation tasks or as described in this Policy.
- CargoWise and Logistics Data: When you integrate CargoMind with CargoWise or other third-party logistics management systems, we collect and process data from those systems on your behalf. This may include operational information (such as job numbers, shipment statuses, container numbers, tracking events, and documents like delivery orders or arrival notices) and financial information related to jobs (such as charges, invoices, gross profit and margin data, and associated customer or vendor details). We retrieve and update this data through secure API connections or other authorised methods to provide our BI dashboard and automation features.
- Usage Data: We collect information about how you and your users interact with our platform and add-ins. This may include IP addresses, device type, browser type, time zone, operating system, unique device identifiers, the pages or features of the Services that you access, and the dates/times of use. We may also log actions taken within the platform (e.g., creating a report, using the chat feature, or uploading a document) for troubleshooting and analytics purposes.
- Cookies and Similar Technologies: Our web-based Services (like the BI dashboard) use cookies and similar technologies to enhance user experience. For example, we use cookies to maintain your session (so you remain logged in), remember your preferences, and collect analytics about how you use our site. You can control or disable cookies through your browser settings. Note that some cookies are essential for the platform's operation – for instance, to secure your session – and the Services may not function properly if they are disabled. Where required by law, we will request your consent before using non-essential cookies.
If you provide us with personal data about others (for example, personal information about your customers or colleagues contained in emails or CargoWise records), you must ensure that you have the authority or consent to do so, and that sharing such data with us is in line with any privacy obligations you have towards those individuals.
3. How We Use Your Information
CargoMind uses the collected information for the following purposes:
- Service Delivery: To operate and provide the core functionalities of our Services. For instance, we use your email data to perform automated tasks such as updating CargoWise records with information from your emails or attachments, and we use data from CargoWise to display real-time shipment statuses, financial metrics, and operational dashboards in the BI platform. In our outsourcing service, our trained staff use your provided information and systems (e.g., CargoWise access) to carry out freight forwarding and logistics tasks as per your instructions.
- Service Improvement: To understand and enhance the performance and reliability of our Services. We analyse aggregated usage patterns and feedback to fix bugs, optimise workflows, and develop new features. For example, we might track how frequently a particular dashboard visualisation is used or how often the automated email processing encounters an unrecognised format, in order to improve our algorithms and user interface.
- Communication: To send you important updates and information. This includes administrative emails (for example, to confirm your account creation, inform you of subscription renewals or changes to these Terms or the Privacy Policy, and critical service or security updates). If you have opted in, we may also send you newsletters or marketing communications about new features, promotions, or industry insights. You can opt out of marketing emails at any time by using the unsubscribe link in those emails or contacting us.
- Customer Support: To provide and improve customer support. When you contact us with a question or for assistance, we will use your contact information and any relevant content you've provided (like screenshots or error details) to help resolve the issue. We may also use support communications to improve our Services by capturing and addressing recurring problems or requests.
- Compliance and Protection: To enforce our Terms of Use, to prevent fraud, spam, abuse, or other wrongful activities, and to comply with legal obligations. For example, we may monitor use of the platform for security purposes, such as detecting suspicious sign-in attempts or ensuring our automated processes are not misused to send unauthorised communications. If required by law or legal process, we may process and disclose information to respond to government requests, court orders, or to establish or exercise our legal rights. We will also use and disclose information as necessary to protect our rights or to prevent harm (for instance, to investigate suspicious activities on the platform that could threaten our infrastructure or other users).
We will not use personal data for any purpose that is incompatible with the purposes described above unless we obtain your consent or are required or permitted by law to do so. We do not engage in selling personal information to third parties for their marketing or other independent use.
4. Legal Bases for Processing (EEA/UK users)
(This section applies if you are in the European Economic Area or the United Kingdom.) Under the EU and UK GDPR, we must have a valid "legal basis" to process your personal data. CargoMind relies on the following legal bases:
- Contractual Necessity: We process personal data that is necessary to provide our Services under our contract with you. For example, we need to access certain email data and CargoWise information in order to perform the automated updates and to generate the BI dashboards as per our contractual service offering.
- Legitimate Interests: We process some data as needed for our legitimate business interests – for example, improving and securing our Services, understanding how clients use our platform, and communicating with you about product updates. When we rely on legitimate interests, we ensure that our interest is not overridden by your data protection rights and interests.
- Legal Obligation: Where applicable, we process and retain certain data to comply with our legal obligations – for instance, maintaining accurate financial records for accounting and legal compliance, or adhering to data protection regulations such as recording your preferences (e.g., opt-outs from marketing communications).
- Consent: In certain cases, we rely on your consent. For example, we may ask your consent before collecting certain analytics cookies, or before accessing specific data that is not strictly required to deliver the core Services. When consent is our basis for processing, you have the right to withdraw your consent at any time.
5. Data Storage and Security
We understand that the data you entrust to us may include highly sensitive business and personal information. We have implemented robust technical and organisational measures to protect your data:
- Secure Infrastructure: CargoMind's platform is built on secure cloud infrastructure. All data is stored on servers that employ strong security measures, including firewalls, intrusion detection systems, and regular security audits. We use reputable cloud service providers that comply with industry security standards and certifications (such as ISO 27001).
- Encryption: We use encryption to protect data in transit and at rest. All network communications between your device (or Outlook add-in) and our servers are encrypted using HTTPS/TLS. This means that information like email content or shipment data is transmitted securely and cannot be easily intercepted. Data stored in our databases (including backups) is encrypted at rest.
- Access Controls: Access to systems that store or process personal data is restricted to authorised personnel who need access to perform their job duties. All our staff and contractors undergo background checks where appropriate and are bound by confidentiality obligations. We employ multi-factor authentication, role-based access controls, and session logging to prevent and detect unauthorised access.
- Training and Policies: We regularly train our team (including outsourced logistics staff and engineers) on data protection best practices, confidentiality, and security protocols. Our internal policies ensure that personal data is handled in compliance with our legal obligations and this Policy.
- Third-Party Security: When we use third-party sub-processors or integrate with other services (such as CargoWise or Microsoft's Office 365 platform), we ensure that they meet appropriate security standards. For instance, our Outlook add-in runs within Microsoft's secure Office add-in framework which sandboxes the add-in from accessing anything on your computer outside of Outlook itself. We also review the data protection practices of significant partners like WiseTech (CargoWise) for alignment with privacy requirements.
- Data Minimisation: We aim to collect and retain only what is necessary for the purposes of our Services. We design our systems in line with the principle that personal data should be adequate, relevant, and not excessive for its purpose.
- Breach Notification: We have a data breach response plan. In the unlikely event of a data breach that affects your personal data, we will notify you and the appropriate regulatory authorities as required by law (for example, the UK Information Commissioner's Office or the Australian Information Commissioner, as applicable).
While we strive to protect your information, no method of transmission over the Internet or method of electronic storage is completely secure. Therefore, we cannot guarantee absolute security. However, we follow the data security requirements of applicable law – for instance, the UK Data Protection Act mandates that personal data must be kept no longer than necessary and be processed securely – and we continually improve our safeguards to meet or exceed industry best practices.
6. Data Retention
We retain personal and business data only for as long as necessary to fulfil the purposes outlined in this Policy or as required by law or contractual agreement. Retention periods vary depending on the type of data and context:
- Account Data: Information such as your account registration details and contact information is kept for as long as you maintain an account with us. If you terminate your account, we will delete or anonymise this information within a reasonable period after account closure (except to the extent we need to retain it for legal, accounting, or compliance purposes).
- Operational Data in CargoWise/Emails: Our automation processes may create records or logs (for example, a log entry that a particular email was processed and a delivery order was attached to a CargoWise job). We keep these logs for a limited duration to ensure we can audit and support the Service, and then we securely delete or anonymise them. We do not store the contents of your emails or uploaded documents longer than necessary to perform the integration or support tasks, unless you explicitly save such content within our platform.
- BI and Analytics Data: The BI dashboard may store historical operational and financial data (e.g., job counts, revenue figures, shipment volumes) to provide trend analysis over time. This data is retained while you remain a customer so that you can access historical reports. You may have the ability to delete certain data via the interface; otherwise, you can contact us to request deletion of specific records. If you stop using the BI Service, we will remove or anonymise your data after a set period as per our internal retention schedule.
- Backups: Like most software-as-a-service providers, we perform regular backups of our database to ensure business continuity and disaster recovery. These backups are encrypted and stored securely. Backup data is retained for a limited time (after which it is overwritten or deleted) and is only accessed if needed for disaster recovery or integrity verification.
Where required by law, we will dispose of or de-identify personal data in a secure manner. For example, the UK and EU data protection law requires that personal data not be kept for longer than necessary. The Australian Privacy Principles also oblige us to destroy or de-identify personal information when it's no longer needed for the purpose for which it was collected, unless an exception applies (such as if retention is required by law).
7. Your Rights and Choices
We respect your rights to your personal information. Your rights will depend on your location and the applicable data protection law, but we intend to honour any applicable rights regardless of jurisdiction. These may include:
- Access and Correction: You have the right to request access to the personal information we hold about you, and to request correction of any inaccuracies. We will promptly assist you in accessing your data and correcting any errors. (In many cases, you can review and update basic profile information yourself through your account settings.)
- Erasure (Right to be Forgotten): You may request that we delete your personal data under certain circumstances. For example, if the information is no longer necessary for the purposes for which it was collected; if you withdraw your consent (where the processing was based on consent); or if you object to processing and there are no overriding legitimate grounds for us to continue. We will assess and act on deletion requests in line with applicable laws. Note that we may need to retain certain information if required for legal obligations or legitimate business purposes (we will inform you if so).
- Restriction of Processing: You have the right to ask us to suspend or restrict the processing of your personal data, for example if you contest the accuracy of the data or object to our processing. We will temporarily restrict processing in such cases while we review your request.
- Data Portability: For information you have provided to us, you may have the right to request a copy in a structured, commonly used, machine-readable format, and/or to request that we transmit it to another service provider where technically feasible. This right applies when processing is carried out by automated means and is based on your consent or is necessary for the performance of a contract.
- Objection to Processing: You have the right to object to our processing of your personal data in certain situations. In particular, you can object to processing for direct marketing at any time, and we will stop sending you marketing communications. You can also object when we are processing your information based on legitimate interests or for a task in the public interest. We will consider your objection and whether our processing should cease (unless we have a compelling reason to continue that relates to our operation or legal obligations).
- Automated Decision-Making: We do not make any decisions about you that have legal or similarly significant effects based solely on automated decision-making (without human involvement). The AI features in CargoMind are intended to assist human users, not to replace human decision-making that would have a significant impact on individuals. If we introduce automated decision-making processes, we will ensure compliance with applicable laws regarding such processing and provide you with any required information or rights (such as the right to request human review).
- Withdrawing Consent: Where we rely on your consent to process data (for example, for optional features or marketing emails), you have the right to withdraw that consent at any time. You can do this by changing your settings in the platform (if available) or contacting us. Withdrawal of consent will not affect the lawfulness of any processing we conducted prior to your withdrawal.
- Lodging Complaints: If you have concerns about how we are handling your personal data, we encourage you to contact us so we can resolve your issue. However, you also have the right to lodge a complaint with a data protection authority. The appropriate authority may depend on your location. For example, in the United Kingdom you can contact the Information Commissioner's Office (ICO), and in Australia you can contact the Office of the Australian Information Commissioner (OAIC), if you believe your data has been mishandled and we have not adequately addressed your concerns.
To exercise any of your rights, please contact us using the information in the "Contact Us" section below. We will respond to your request in accordance with applicable law (generally within one month for UK/EU requests, and within a reasonable time for Australian requests) and will let you know if we need additional information from you to verify your identity. Note that some rights may be subject to exceptions or limitations; if we cannot fulfil a request for lawful reasons, we will provide an explanation.
8. International Data Transfers
CargoMind is a global service and your data may be transferred to, and stored on, servers located in countries other than your own. In particular, your personal data may be stored or processed on servers located outside your country of residence – for example, in data centres in the United States, the European Union, or other regions where we or our cloud service providers operate.
When we transfer personal data out of the country where it was collected, we ensure appropriate safeguards are in place to protect it. If you are in the UK or European Economic Area (EEA), this means that we will rely on approved transfer mechanisms such as standard contractual clauses or an adequacy decision to ensure your data receives a level of protection essentially equivalent to that in your home jurisdiction. If you are in Australia, we will take reasonable steps to ensure that any overseas recipient of your personal information does not breach the Australian Privacy Principles in relation to that information, as required by the Privacy Act 1988 (for example, by only transferring data to organisations under an enforceable privacy law or binding scheme, or with your consent).
If you would like more information about our data transfer practices or to obtain a copy of the safeguards in place for overseas transfers of your data, please contact us.
9. Third-Party Services and Links
Our Services may contain links to, or integrations with, third-party websites and services that are not operated by CargoMind. For example, our platform provides integration with CargoWise, a third-party logistics management system owned by WiseTech Global, and operates as an add-in within Microsoft Outlook. Please note:
- Third-Party Platforms (e.g., CargoWise, Outlook): When you enable integration with a third-party platform, any information you share with that platform is governed by their terms and privacy policy. For instance, data transmitted to or from your CargoWise system is subject to the agreements between you and WiseTech Global. Similarly, our Outlook add-in operates within Microsoft's Office 365 environment, and your use of Outlook and Office 365 is governed by Microsoft's terms. CargoMind is not responsible for the privacy, security, or functionality of third-party services. We recommend reviewing the user terms and privacy policies of those services to understand how they handle your data.
- Service Providers: CargoMind uses certain third-party service providers to support our own operations (for example, cloud hosting providers, data analytics services, and customer support tools). We share data with these providers only to the extent necessary for them to perform services on our behalf – for instance, our cloud hosting provider stores the databases containing your information, and our email service may process the emails we send to you. All such providers are contractually obliged to protect your data, maintain confidentiality, and use it only for the purposes we specify (and not for their own purposes).
- Links: Our website or BI dashboard might contain links to external websites for informational purposes (for example, to external tracking websites or relevant industry resources). If you click a third-party link, you will be directed to that third party's site. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. We encourage you to review the privacy policies of every site you visit via links from our Service.
10. Children's Privacy
Our Services are intended for use by businesses and adult professionals in the logistics and freight industry. They are not directed to children under the age of 16. We do not knowingly collect personal information from individuals under 16. If you are under 16, please do not use the CargoMind Services or provide any personal information to us. If we discover that we have inadvertently collected personal information from a child under 16 without proper consent, we will promptly delete that information. If you believe we might have any information from or about a minor under 16, please contact us so that we can take appropriate measures.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices or legal requirements. If we make material changes, we will provide prominent notice – for example, by email notification or through a message in our platform. The "Last Updated" date at the top of this Policy indicates when the latest changes were made. We encourage you to review this Policy periodically. By continuing to use the Services after such changes take effect, you agree to the revised Policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
NextGen BPO Solutions Pty Ltd (trading as CargoMind) – Privacy Officer
Address: Sydney, NSW, Australia
Email: privacy@cargomind.com
We will be happy to answer your questions and address any concerns you have about your privacy.