Box16
FeaturesPricingReviews
Log inStart free trial
FeaturesPricingReviewsLog in
Legal

Data Processing Agreement

1.1 · 2026-07-11

Privacy PolicyDPATerms of Service

This is an informational translation. The official English version will follow.

Parties

Processor: Box16 B.V., located at Le Mairekade 77, 1013 CB Amsterdam, the Netherlands (Chamber of Commerce: 42104995).

Article 1. Subject Matter and Duration

1.1 The Processor processes Personal Data on behalf of the Controller for the purpose of neutralising CMR transport documents (removal/masking of carrier identification in Box 16 and Box 23).

1.2 This Data Processing Agreement (DPA) is effective for as long as the Controller uses the Box16 service.

Article 2. Personal Data

The following categories of personal data are processed:

  • Company names, addresses and contact details of carriers (included in CMR documents)
  • Email addresses and names of users of the Box16 application
  • IP addresses and session information (for security and audit purposes)

Processing is limited to what is strictly necessary for the neutralisation process.

Article 3. Obligations of the Processor

The Processor shall:

  1. Process personal data solely on the basis of documented instructions from the Controller;
  2. Guarantee confidentiality of all processed personal data;
  3. Implement appropriate technical and organisational security measures (GDPR Article 32);
  4. Engage sub-processors only with prior written consent;
  5. Support the Controller in complying with data subject rights;
  6. Delete or return personal data upon termination of the service.

Article 4. Sub-processors

The following sub-processors are engaged:

Sub-processorPurposeLocation
Vercel (EU - Frankfurt)Frontend hostingEU
Railway (EU - Netherlands)Backend + database hostingEU
Cloudflare R2 (EU)Document storageEU
Google Gemini (EU API endpoint)OCR processing Tier 2EU
Sentry (EU data residency)Error monitoringEU

Article 5. Security

The Processor applies the following technical measures:

  • Encryption of data in transit (TLS 1.2+)
  • Encryption of data at rest (PostgreSQL + R2 server-side encryption)
  • Access control via JWT RS256 tokens
  • Multi-tenant isolation via PostgreSQL Row Level Security
  • Automatic deletion of uploads after `retention_days` (configurable per organisation, default 30 days)

Article 6. Data Breaches

The Processor will inform the Controller without undue delay (and in any case within 72 hours) after discovery of a data breach involving personal data.

Contact for data breaches: info@box16.nl

Article 7. Governing Law

This Data Processing Agreement is governed by Dutch law. Disputes will be submitted to the competent court in the Netherlands.

Ready for your first batch?

Create an account and get 25 free CMRs right away. No credit card required.

Start with 25 free CMRs

Company

How it worksPricing

Resources

Log inContact

Legal

PrivacyTerms

Stay connected

Box16

Box16 automates the neutralisation of CMR consignment notes.

© 2026 Box16 B.V. · Chamber of Commerce 42104995 · All rights reserved