Privacy Policy
This policy explains how we process personal data when you use the public website, registration, the Cargos3D platform, payments, communications and security functions.
Last updated: 10.08.2026 Version: 2026-08-10
1. Who is responsible for the data
The controller for data we process for our own purposes is Digital Nomads Ltd., company ID 208417243, registered in Sofia, Bulgaria, operator of Cargos3D.
For privacy questions, rights requests or privacy notices, contact sales@cargos3d.com.
2. Categories of data we process
- Registration and contact data - name, email, phone, organization, company, preferred language and related profile data.
- Account and access data - identifiers, organization, roles, settings, trial, subscription or day-pass status, accepted legal documents and acceptance time.
- Customer-entered operational data - cargo, dimensions, weights, quantities, pallets, groups, shipments, customers, routes, stops, vehicles, plans, layouts, instructions, images and imported CSV/XLSX files.
- Payment and billing data - selected plan, payment status, subscription, transaction identifiers and billing data where applicable. Full card details are normally entered directly with the payment provider.
- Technical and security data - IP address, country, browser/device information, session data, timestamps, system and security logs, errors and actions needed for diagnostics and protection.
- Communications - demo requests, support messages, email correspondence, feedback and business communications.
3. Why we use the data
- to create, manage and protect accounts and organizations;
- to provide Cargos3D functions, including import, planning, 3D visualization, saving, PDFs and work instructions;
- to process trials, day passes, subscriptions, payments and billing;
- to respond to inquiries, support, contractual and operational matters;
- to prevent fraud, abuse, unauthorized access, scraping, technical attacks and breaches of terms;
- to maintain and improve service stability, security and quality;
- to comply with accounting, tax, contractual and other legal obligations and protect legal claims.
4. Legal bases
Depending on the activity, processing may be based on performance of a contract or pre-contract steps, legal obligation, legitimate interests or consent where required. Our legitimate interests include protecting the service, preventing abuse, communicating with business users, diagnostics, service improvement and protecting legal claims, while taking into account the rights and interests of affected individuals.
5. When we act as a processor
Cargo and operational data is normally business information. However, if a customer enters personal data about employees, drivers, customers, recipients or other individuals and determines the purposes and means of that processing, the customer is the controller and Cargos3D acts as processor only to the extent it processes that data on the customer’s behalf to provide the service.
In those cases, our Data Processing Addendum also applies. The customer is responsible for having a valid legal basis for data it provides and for avoiding unnecessary personal data or special-category data.
6. Providers, recipients and subprocessors
We use a limited number of technical providers for hosting, database, authentication, payments, email delivery, edge routing and related operations. We provide only the data needed for the relevant function. The current list and role of the main providers is available on our Subprocessors and service providers.
We may also disclose data where necessary for a legal obligation, a valid request from a competent authority, fraud or abuse prevention, security protection or the establishment and exercise of legal rights. We do not sell personal data to advertisers or data brokers.
7. International transfers
Some of our providers or their subprocessors may process data outside the European Economic Area. Where applicable law requires a transfer safeguard, we rely on applicable contractual and legal mechanisms, such as an adequacy decision, the EU-US Data Privacy Framework for certified recipients or Standard Contractual Clauses, depending on the provider and transfer.
8. Retention
We do not retain personal data longer than necessary for the purposes for which it is processed. The specific period depends on the data type, account activity, contractual period, security and diagnostic needs, deletion requests and applicable accounting, tax or other legal retention periods.
- Account and organization - while active and for a limited period after termination where needed to close the relationship, protect security or legal claims.
- Cargo plans and customer content - while the customer uses them or until deleted, except where temporary retention is needed for backups, security or a legal basis.
- Payment and accounting records - according to applicable legal requirements.
- Security and diagnostic logs - for a period reasonably needed to detect abuse, investigate incidents, maintain stability and protect the service.
9. Security
We apply technical and organizational measures appropriate to the service and risk, including authenticated access, permission controls, organization-level data separation, server-side checks for sensitive operations, security logging and HTTPS/TLS for communications with the service. We continue improving measures as the platform and threats evolve.
No online service can guarantee absolute security. Users should protect access to their email and account and notify us if unauthorized access is suspected.
10. Cookies, language and technical requests
We use strictly necessary cookies, local storage or similar technologies for sessions, authentication, selected language, security and correct platform operation. For automatic language selection, we may use country information from hosting infrastructure and, where unavailable, a limited IP-to-country fallback provider. This is not used for advertising profiling.
If we later add non-essential analytics, advertising or remarketing technologies, we will use them only with an applicable legal basis and consent where required by law.
11. Business communications
We may send service messages related to the account, security, payments, support and material service changes. Separate business or marketing communications are sent only where we have an applicable legal basis. Where a message offers an opt-out, you can use the unsubscribe mechanism or contact us directly.
12. Automated decisions and security measures
Cargos3D may automatically apply technical protection rules, such as blocking clearly disallowed registrations, rate limiting or restricting certain actions. We do not use solely automated decision-making that by itself produces legal effects or similarly significantly affects an individual, unless this is expressly explained and lawfully permitted.
13. Your rights
Where the GDPR or other applicable law provides the relevant right, you may request information and access, correction, deletion, restriction, portability, object to processing based on legitimate interests and withdraw consent for future processing where processing is based on consent.
We may request reasonable information to verify your identity and your entitlement to the requested data. If a request concerns data for which our customer is the controller, we may direct you to that customer or assist the customer as processor.
14. Complaint to a supervisory authority
You have the right to lodge a complaint with the Bulgarian Commission for Personal Data Protection or another competent supervisory authority under applicable law.
15. Persons under 18 and policy changes
Cargos3D is a business-oriented service and is not intended for persons under 18. We do not knowingly collect children’s data through the platform.
We may update this policy when the service, providers, security or applicable law changes. The current version and date are published here. We may provide additional notice for material changes.