D&D Audit

Legal

Privacy Policy

Effective: 2 September 2026

1. Who we are

The website demurrit.eu and the Demurrit Cargo Intelligence portal at cargo.demurrit.eu are operated by:

UAB NVGroup

Company registration number: 149942553
Registered address: Elektrinės g. 8, 03150 Vilnius, Lithuania
VAT number: LT499425515
Email: info@demurrit.eu

We have not appointed a Data Protection Officer, as our activities do not meet the criteria in Article 37 GDPR. For any data protection matter, write to info@demurrit.eu. We respond within 30 days, usually sooner.

2. When we are a controller and when we are a processor

This is the most important section of this policy.

We act as CONTROLLER for:

We act as PROCESSOR for the documents you upload: CMR consignment notes, fuel receipts, SMGS/CIM rail waybills, bills of lading, D&D invoices and carriage contracts. Personal data contained in those documents — driver names and signatures, contact persons, vehicle registrations — belongs to you. You are the controller; we process it only on your documented instructions under a Data Processing Agreement (DPA) pursuant to Article 28 GDPR, which we provide to every client on request.

What this means in practice. If you are a driver, forwarder or employee of another company and your data appears in a document uploaded by one of our clients, please contact that company. If you contact us, we will forward your request to the relevant client within 5 working days and let you know.

Specific note on the Fuel module. Fuel consumption anomaly detection may amount to employee monitoring. The client, as controller, must have a lawful basis for it, inform its employees, and where necessary carry out a Data Protection Impact Assessment (DPIA). We do not perform that assessment on the client's behalf, but we supply the technical information needed to prepare one.

3. What we process, on what basis, and for how long

Category Data Legal basis Retention
Website visits IP address, browser type, request time, pages viewed (server logs) Legitimate interest — site security and operation (Art. 6(1)(f)) 30 days
Enquiries and call bookings Name, email, phone, company, message content Pre-contractual steps (Art. 6(1)(b)) 24 months from last contact
Cargo Intelligence account Email (account identifier), name, role, password hash, login logs, activity audit trail Performance of contract (Art. 6(1)(b)); security logs — legitimate interest (f) Duration of the account + 90 days; security logs 12 months
Uploaded documents and extracted data Document originals and their structured content Processed on client instructions under an Art. 28 DPA Original 12 months from upload; extracted data while the service is active, deleted within 30 days of termination
Travel expense documents Fuel receipts and invoices, toll invoices, ferry tickets, repair documents Processed on client instructions under an Art. 28 DPA 5 years from upload
Customs declarations and related documents Declarations, origin proofs, customs decisions Processed on client instructions under an Art. 28 DPA 40 months from upload
D&D audit case file Invoices, contract extracts, container movement data, correspondence with the carrier Performance of contract (b); establishment and defence of legal claims (f) 5 years from closure of the case
Accounting and payments Invoices, payment data, VAT number Legal obligation (Art. 6(1)(c)) 10 years (Lithuanian accounting and tax law)
Newsletter / marketing Email address Consent (Art. 6(1)(a)) or legitimate interest for existing clients Until consent is withdrawn

We do not knowingly process special categories of data under Article 9 GDPR and ask you not to upload them.

4. Where your data is held

Most data is processed within the European Union — our servers are in the netcup GmbH data centre in Nuremberg, Germany. In two specific cases, data is transferred outside the EU/EEA:

Sub-processors:

Sub-processor Purpose Location Transfer basis
netcup GmbH Servers, storage, backups Germany (EU)
Proton AG Email delivery, encrypted backups Switzerland Art. 45 GDPR adequacy decision
Anthropic PBC AI-based document data extraction USA Art. 46 GDPR Standard Contractual Clauses

We do not use a payment processor — invoices are settled by bank transfer.

The current sub-processor list is annexed to the DPA. We notify clients at least 30 days before adding a new sub-processor.

5. Automated processing and artificial intelligence

We use automated recognition systems to extract data from documents. This is not automated decision-making within the meaning of Article 22 GDPR: the system makes no decision producing legal effects concerning you. It proposes structured data, which a person confirms or corrects. The content of a D&D claim is finally approved by a member of our staff.

We do not use your documents to train artificial intelligence models, and we do not pass them to third parties for that purpose.

6. Who we disclose data to

We do not sell data and do not use it for advertising.

7. Your rights

You have the right to: access your data; have it rectified; have it erased; restrict processing; data portability; object to processing based on legitimate interest; and withdraw consent at any time.

Send requests to info@demurrit.eu. We may ask you to verify your identity. We reply within one month; for complex requests we may extend by a further two months and will tell you if we do.

8. Complaints

If you believe we have infringed your rights, please contact us first. You also have the right to lodge a complaint with a supervisory authority.

Our lead supervisory authority is:

State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
ada@ada.lt · vdai.lrv.lt

You may also complain to the supervisory authority in the EU country where you live or work.

9. Security

We use TLS in transit, encryption at rest, role-based access control, two-factor authentication for administrator accounts, activity audit logging and regular backups (retained 30 days). We report personal data breaches to the supervisory authority within 72 hours and notify affected clients without undue delay where the breach is likely to result in a high risk to them.

10. Children

Our services are for business customers only. We do not knowingly process data of anyone under 16.

11. Changes

We may update this policy. We notify registered users of material changes by email at least 30 days in advance. The effective date is always shown at the top.

Cookie Policy →