Privacy Policy
1. Who we are
UAB NVGroup Legal entity code: 149942553 VAT payer code: LT499425515 Registered office: Elektrinės g. 8, 03150 Vilnius, Lithuania Data protection inquiries: privacy@demurrit.eu
This policy applies to services provided on the domain demurrit.eu (the Service).
2. Our role: two distinct relationships
We process personal data on two distinct bases, and this determines who you should contact regarding your rights.
| Data | Our role | |
|---|---|---|
| Part A | Account, billing and website usage data | Data controller |
| Part B | The content of documents you upload and data extracted from them | Data processor acting on behalf of the client (controller) |
In Part A, we determine the purposes and means. Sections 3–5 apply to this part.
In Part B, the purposes and means are determined by the client – the transport, forwarding or cargo-owning company that uploads the documents. We act only on its instructions and under a data processing agreement concluded with it (GDPR Art. 28). Sections 6–9 apply to this part.
If you are a driver, a contact person, or another individual whose data appears in a document uploaded by a client – please contact the company that employs you or with which you have a contractual relationship regarding your rights. We will help that company respond to your request, but we cannot decide independently on this data.
Part A. Data for which we are the controller
3. Data processed, purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Email, name, organisation name, membership role | Account administration, granting access | Art. 6(1)(b) – performance of a contract |
| Billing and accounting data | Invoicing, bookkeeping | Art. 6(1)(c) – legal obligation |
| Login records, IP address, system logs | Service security, prevention of unauthorised access and abuse | Art. 6(1)(f) – legitimate interest |
| Inquiries submitted via contact forms | Responding to your inquiry | Art. 6(1)(f) – legitimate interest |
Legitimate interest in this case means protecting the Service and the client data it contains from unauthorised access, and the ability to respond to business inquiries. We have assessed that this interest does not override your rights, since only a minimal amount of data is processed and it is not used for profiling or marketing.
4. Retention periods (Part A)
| Data | Period |
|---|---|
| Account data | For the duration of the contract + 12 months |
| Accounting and billing documents | 10 years from the end of the financial year (a requirement of Lithuanian accounting legislation) |
| System and security logs | 30 days |
| Correspondence via contact forms | 24 months |
5. Your rights (Part A)
You have the right to access your data, rectify it, erase it, restrict its processing, port it, and object to processing based on legitimate interest.
Contact us at: privacy@demurrit.eu. We respond within 30 days.
You also have the right to lodge a complaint with the State Data Protection Inspectorate of Lithuania (L. Sapiegos g. 17, Vilnius, vdai.lrv.lt).
Part B. Documents uploaded by clients
6. How documents are processed
The Service processes transport and customs documents – CMR consignment notes, bills of lading, carrier invoices, customs declarations, fuel receipts – and extracts structured data from them: dates, amounts, vehicle registration numbers, countries and route information. Documents may contain data on third parties, for example drivers or contact persons.
6.1 Tiered processing
Documents are processed in tiers, with each document processed at the lowest tier sufficient for the task:
- Structured data (XML, EDIFACT, customs declaration formats) – processed deterministically, exclusively within EU infrastructure.
- Documents with a text layer – recognised using predefined carrier and form templates, exclusively within EU infrastructure.
- Documents requiring interpretation of content – scanned or non-standard documents are forwarded to the processor named in Section 7.
This architecture means that the majority of document traffic is processed without leaving the EU. This is applied as a data minimisation measure (GDPR Art. 5(1)(c)).
6.2 Automated decision-making
Automated extraction does not make decisions that produce legal effects or similarly significantly affect you. All extracted data is reviewed by a human before being used in a claim, declaration or report. GDPR Art. 22 does not apply.
7. Processors
| Provider | Purpose | Data location |
|---|---|---|
| netcup GmbH | Application server, database | Nuremberg, Germany |
| Hetzner Online GmbH | Document storage | Nürnberg, Germany |
| Akenes SA (Exoscale) | Backups | Vienna, Austria |
| Anthropic PBC | Content interpretation (Section 6.1, tier 3) | United States of America |
A data processing agreement under GDPR Art. 28 has been concluded, or is being concluded, with each processor.
Changes. We notify clients of changes to the list of processors no later than 30 calendar days in advance. The client has the right to raise a reasoned objection within 15 days.
8. Transfers of data outside the EEA
8.1 Akenes SA (Exoscale)
Backups are physically stored in Vienna, Austria. The provider is a company registered in Switzerland, so access from Switzerland is possible during technical maintenance.
Switzerland is covered by the European Commission's adequacy decision (26 July 2000), the continuity of which the Commission confirmed in its review report of 15 January 2024. No additional safeguards are required.
8.2 Anthropic PBC
Documents at Section 6.1, tier 3 are transferred to Anthropic PBC (USA).
- tiered processing (Section 6.1), as a result of which most documents are never transferred;
- encryption in transit (TLS) and at rest;
- only the content of the document is transferred, without account, billing, or client-organisation-linkage data.
Impact assessment. A Transfer Impact Assessment has been carried out in accordance with the recommendations of the European Data Protection Board 01/2020. The assessment and a copy of the standard contractual clauses are provided to clients and to the supervisory authority upon reasoned request.
9. Retention periods (Part B)
Periods are set by the client in the data processing agreement. Default periods, unless otherwise agreed in the agreement:
| Data | Period | Basis |
|---|---|---|
| Original documents | 24 months from upload | Limitation periods under the CMR Convention and the Hague–Visby Rules are calculated from delivery, not from upload |
| Customs documents | 40 months from upload | The three-year application period and processing time under Art. 121 of the Union Customs Code |
| Extracted structured data | Same as the associated document | – |
| System logs | 30 days | Technical maintenance |
Legal hold. If a document is related to an unresolved claim or customs procedure, it is flagged for retention and is not deleted until the procedure concludes, even after the stated period has elapsed or the contract has ended. This exception exists in the client's interest – deleting evidence would deprive a claim of its basis.
Upon termination of the contract, data is returned or destroyed at the client's instruction, subject to the exception stated above. In backups, data is destroyed during the backup rotation cycle, no later than within 31 days.
10. Security measures
- Organisation separation at database level (row-level security): one organisation cannot technically access another organisation's data, even in the event of a software error.
- Encryption in transit (TLS) for all connections.
- Encryption at rest in the document store and database.
- Backups are encrypted on the client side before being transferred to storage; the storage provider does not hold the encryption keys.
- Original documents are protected against overwriting and accidental deletion (object lock), while preserving the ability to fulfil a data subject's erasure request.
- Backups are held with a different provider than the production infrastructure, using credentials without delete permission.
- System logs do not store document content – only organisation, document and action identifiers. These identifiers are pseudonymised personal data and are retained for 30 days.
- Access and change log (append-only) for every document.
11. Cookies
The use of cookies is described in a separate Cookie Policy.
12. Changes to this policy
This policy is updated when the list of processors or the purposes of processing change. We notify clients of material changes no later than 30 days in advance. The applicable version and its date are always stated at the beginning of this document.
13. Contacts
Data protection inquiries: privacy@demurrit.eu General inquiries: info@demurrit.eu