Privacy Policy
Last Updated: June 20, 2026
This Privacy Policy explains how Tax2Cargo, operated by mytax4cargo OÜ, handles, processes, and protects your personal and business data. This policy is structured to maintain strict compliance with both the EU General Data Protection Regulation (EU GDPR) and the UK General Data Protection Regulation (UK GDPR).
At Tax2Cargo, we are committed to ensuring the safety, confidentiality, and integrity of your corporate and personal datasets. This document details our operational mechanics regarding the collection, processing, cross-border transmission, and storage of data across our cloud-based pipelines.
1. Corporate Identity and Data Roles
The Service, application infrastructure, and site domains are owned and operated by:
Legal Entity: mytax4cargo OÜ
Jurisdiction: Registered in the Republic of Estonia
Commercial Registry Number: 17532008
Registered Office Address: Sakala tn 7-2, Kesklinna linnaosa, Tallinn, Harju maakond, 10141, Estonia
Data Protection Contact: privacy@tax2cargo.com
Allocation of Data Protection Roles:
- Data Controller for Platform Accounts: We act as a Data Controller for your user registration records, system preferences, and software login logs.
- Independent Data Controller for Payments: Our Merchant of Record, Paddle (Paddle.com Market Limited and its global affiliates), acts as an Independent Data Controller for your transactional billing information, payment methods, financial geolocation data, and invoice generation metrics.
- Data Processor for Customs & Transit Telemetry: We act strictly as a Data Processor for the specific trade metadata, manifest files, carrier tracking numbers, and declaration fields that you submit through our platform to government gateways. We process this information exclusively under your documented operational parameters.
2. Information We Collect
We harvest and handle the following categories of information to maintain secure technical functionality:
a. Profile and Professional Contact Details
- First and last name, business email addresses, and phone contacts.
- Trading entity names, legal company addresses, and structural tax identifiers.
b. Trade, Border Transit, and Declaration Metadata
- Economic Operators Registration and Identification (EORI) numbers.
- Customs valuation parameters, country of origin tracking fields, and cargo descriptions.
- Harmonized System (HS) commodity classifications.
- Goods Movement References (GMR), vehicle registration numbers, and vessel voyage logs used for CDS, ENS, GVMS, and ICS2 API mapping.
c. Technical Device and Infrastructure Logs
- Origination IP addresses, web browser client data, and device operating system parameters.
- OAuth authorization tokens, technical security login timestamps, and raw API success/failure payload logs from customs endpoints.
d. Financial and Subscription Data
- SaaS subscription plans, payment milestones, and billing references. (Note: Raw credit card details and bank routing pathways are processed directly by Paddle and never hit our software databases).
3. Purpose and Legal Basis for Processing
We process personal and corporate data under the following legitimate legal frameworks defined by the GDPR:
| Processing Purpose | Source System Scope | GDPR Lawful Basis |
|---|---|---|
| Creation and functional maintenance of your software profile | Platform Core | Performance of a contract |
| Technical processing and serialization of trade files to government networks | CDS, ENS, GVMS, ICS2 | Performance of a contract / Compliance with legal duties |
| Managing billing, automatic plan renewals, and handling business invoices | Paddle Infrastructure | Performance of a contract |
| Analyzing threat vectors, tracking API schema injections, and preventing trade fraud | Security Monitoring | Legitimate interests of the Company |
| Retaining immutable transactional verification logs to support third-party safety audits | Audit Ledger | Compliance with legal duties / Legitimate interests |
4. Automated Assistive Features and AI Data Integrity
The Platform implements automated helper tools and generative Artificial Intelligence (AI) models to match commodity descriptions to potential HMRC tariff classifications and simplify forms.
- Contextual Scoping: The AI processes textual entry data only for real-time field validation, code suggestions, and administrative lookup mapping.
- Training Exclusion: Your uploaded commercial invoices, company names, specific financial metrics, and customs declarations are never submitted to public AI repositories or used to train external model systems.
- User Oversight: All automated recommendations are unverified helpers. The final approval and submission verification rests under the absolute legal ownership of the user.
5. Data Distribution and Third-Party API Transmissions
We share trade metadata and platform records only when necessary, using encrypted tunnels. Data is distributed to:
- National Customs Gateways: Information is pushed directly via secure APIs to HMRC (for CDS, ENS, and GVMS networks) and to the European Commission (for central ICS2 safety nodes).
- Merchant of Record Partner: Transaction tracking indexes are shared with Paddle to manage subscription balances, facilitate fraud checks, and resolve accounting tickets.
- Infrastructure Hosting Vendors: We use enterprise cloud environments provided by Amazon (AWS) (located within secure EU data regions) to hold operational application pipelines.
- Logistical Intermediaries: If you choose to share profiles with third-party logistics firms or external freight forwarders, they operate as Independent Data Controllers. We assume no liability for how external agencies use your data.
6. International Data Routing and Safeguards
mytax4cargo OÜ leverages advanced, enterprise-grade cloud architectures to host, process, and secure the Platform.
- Cloud Location Posture: All operational application servers, database environments, and technical serialization tools are deployed and hosted exclusively within the Amazon Web Services (AWS) European Union (EU) Region infrastructure. No transactional customs, vehicle, or safety data is stored on localized office hard drives or physical servers within the Republic of Estonia.
- UK to EEA Data Streams: Personal and corporate data flows dynamically from the United Kingdom directly into our isolated AWS EU cloud environment. The UK Government officially recognizes the European Economic Area (EEA) as providing an adequate data protection framework. Consequently, these direct cloud transfers do not require secondary legal wrappers or individual Standard Contractual Clauses (SCCs).
- Remote Operator Access: Authorized operators and technical systems engineers of mytax4cargo OÜ access the platform securely via encrypted web browsers or secure terminals solely for platform maintenance, troubleshooting, and support ticketing. Data remains resident within the secure AWS EU cloud boundaries at all times, and remote access does not constitute a secondary cross-border data transfer.
7. Data Retention Protocols
We apply explicit limitation timelines to ensure data is deleted when it is no longer operationally necessary:
- Platform Profile Data: Stored for the duration of an active user subscription, and retained for up to six (6) years following account termination to fulfill corporate accounting obligations.
- Customs Data Records: In accordance with statutory record-keeping mandates enforced by border authorities, raw transmission histories for CDS, ENS, GVMS, and ICS2 entries are preserved for five (5) years.
- Security & Network Logs: Raw IP addresses and server communication streams are systematically scrubbed or anonymized after twelve (12) calendar months.
8. System Technical Security
We enforce rigorous physical and digital protocols to insulate your datasets:
- Enforced Transport Layer Security (TLS 1.2 and higher) for all inbound and outbound API requests.
- Complete AES-256 bit encryption models for databases at rest.
- Role-Based Access Controls (RBAC) preventing unauthorized system engineers from viewing multi-tenant client declaration histories.
- Strict multi-factor authentication (MFA) parameters across internal control panels.
9. Your Statutory Privacy Rights
Depending on your legal location, you hold the following data protection choices under the UK and EU GDPR:
- Access & Portability: Request full copies of your registration profile and export your historical transaction lists in structured XML or CSV file formats.
- Rectification: Correct mismatched tax identification records or broken contact details.
- Erasure & Restriction: Request deletion or processing limitations on account metadata, provided the information is not legally required for outstanding customs logs or tax compliance investigations.
- Withdrawal of Consent: Revoke platform access rules at any time, noting that closing connection pathways will instantly terminate your live government API transmission functions.
To act on any of these options, contact us directly at mytax4cargo@tax2cargo.com. We will process and address all valid requests within one (1) calendar month.
10. Cookies and Analytical Trackers
We use cookies to maintain your active account session, securely store your user choices, and monitor application speeds. You can review or adjust your preferences by clicking the "Cookie Settings" link in our site footer. For complete details on tracking elements, see our dedicated Cookie Policy.
11. Regulatory Authority Contact Links
If you believe our platform has mismanaged your privacy data, you have the right to lodge a formal complaint with a national regulatory body:
- In the United Kingdom: Contact the Information Commissioner's Office (ICO) via ico.org.uk.
- In the European Union: You have the right to contact your local Data Protection Authority or the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) directly at aki.ee.