This is an English translation provided for convenience. In the event of any discrepancy, the Romanian version available at www.routena.com/dpa shall prevail.
This Data Processing Agreement (“DPA”) forms part of the Contract between the Client, as Controller, and SPECTRALAB SOLUTIONS S.R.L. (“Routena”), as Processor, and governs the processing of personal data by Routena on behalf of the Client, in accordance with art. 28 of Regulation (EU) 2016/679 (GDPR).
Scope and roles of the Parties
This DPA applies exclusively to processing in which Routena processes personal data on behalf of and in accordance with the instructions of the Client.
For processing in which Routena independently determines the purposes and means of processing, including, as applicable, the administration of the contractual relationship, its own billing, Platform security, the prevention of fraud and abuse, and compliance with legal obligations, Routena acts as an independent controller, and such processing is described in the Privacy Policy.
Certain categories of data (for example authentication data, IP addresses, access logs and support communications) fall under this DPA only when they are processed by Routena on behalf of and in accordance with the instructions of the Client. When Routena processes such data for Platform security, the prevention of abuse, the administration of the contractual relationship or its own support obligations, Routena acts as an independent controller, in accordance with the Privacy Policy.
1. Subject matter and duration of the processing
Routena processes personal data exclusively for the provision of the Services described in the Contract, for the duration of the Contract and for the deletion/return period provided in section 9. The details are in Annex 1.
2. Nature and purpose of the processing
The nature and purpose of the processing are the provision of the management platform for transport, freight-forwarding and logistics companies (orders, planning, fleet, documents, monitoring, invoicing, reports), as configured by the Client. The details, the categories of data and of data subjects are in Annex 1.
3. The Controller’s documented instructions
Routena processes the data only on the basis of the Client’s documented instructions, including those expressed through the configuration and use of the platform and through the Contract. The documented instructions also apply to any international data transfers and to access to the data from third countries. If a legal requirement obliges Routena to process otherwise, it informs the Client beforehand, unless the law prohibits this.
Routena informs the Client without delay if, in its opinion, an instruction infringes the GDPR or other applicable legal provisions on data protection. In such a case, Routena may suspend the execution of the instruction concerned until the Client confirms, modifies or withdraws it.
4. Confidentiality
Routena ensures that the persons authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security of processing
Routena implements and maintains technical and organizational measures appropriate to the level of risk, taking into account the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of data subjects, in accordance with art. 32 GDPR.
Routena may modify the technical and organizational measures during the Contract, provided that the changes do not materially reduce the overall level of security and protection.
The applicable technical and organizational measures are described in the Annex on technical and organizational measures (Annex 2), which forms part of this DPA.
6. Sub-processors
6.1. The Client grants a general written authorization for the use of sub-processors. The current list is published at https://routena.com/en/subprocessors (Annex 3).
6.2. Routena notifies the Client, as a rule, at least 15 calendar days before activating a new sub-processor, except in urgent situations required by security, continuity or law. The Client may raise a reasoned objection, which must be:
- made in writing;
- based on concrete data-protection grounds;
- submitted within the stated period.
If the parties do not identify a reasonable solution within a reasonable time, the Client may terminate the part of the Services directly affected by the sub-processor concerned. For the affected part terminated on this ground, Routena refunds proportionally any recurring Fees paid in advance for the period after termination, and the remainder of the Contract remains unaffected. This termination does not constitute a voluntary cancellation but reflects the impossibility of finding an acceptable solution to a reasoned data-protection objection.
In urgent situations where a new sub-processor is activated before the notice period expires, Routena notifies the Client as soon as possible, and the Client retains the right to object after the notification, in accordance with this section.
6.3. Routena imposes on each sub-processor the same data-protection obligations, to the extent applicable to the services entrusted, as those provided in this DPA, and remains responsible to the Client for their activity.
7. Assistance with data-subject rights
Taking into account the nature of the processing, Routena assists the Client, through appropriate technical and organizational measures, in fulfilling the obligation to respond to data-subject requests (access, rectification, erasure, restriction, objection, portability). If a data subject addresses a request directly to Routena, Routena redirects it to the Client without undue delay and does not respond directly unless the Client instructs it to do so or the law requires otherwise.
8. Assistance with security, DPIA and consultation of the authority
Routena assists the Client in ensuring compliance with the obligations regarding: the security of processing, the notification of breaches to the authority and to data subjects, the data protection impact assessment (DPIA) and the prior consultation of the authority. As Processor, Routena informs the Client without undue delay after becoming aware of a personal data breach and uses reasonable efforts to send an initial notification as soon as possible.
The notification includes, to the extent the information is available: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences and the measures taken or proposed to remedy it. Information unavailable at the time of the initial notification is communicated subsequently, without undue delay, as it becomes available.
The initial notification does not, in itself, constitute an acknowledgment of liability or of a contractual breach by Routena.
9. Return and deletion of the data
Upon termination of the Services, Routena, at the Client’s choice, returns the Client’s Data or deletes it, unless applicable law requires its retention.
The return of the data and the period during which it can be recovered are carried out in accordance with the Data Portability and Provider Switching Annex.
If the Client requests deletion before the expiry of the recovery period, it confirms that it no longer requests the return or export of that data.
The data is removed from the active systems within a maximum of 60 days from the expiry of the recovery period, from the confirmation of the waiver of return, or from another date agreed by the Parties. Existing copies in the backup systems are removed in accordance with the normal retention and overwriting cycles, provided that they are not restored or processed for purposes other than continuity, security or legal obligations. If a backup is restored, the data that should already have been deleted is subjected again to the deletion process.
At the Client’s reasonable request, Routena confirms the completion of the deletion process.
10. Audit and information
Routena makes available to the Client the information necessary to demonstrate compliance with the obligations under this DPA and allows audits, including inspections, carried out by the Client or by a mandated auditor, with reasonable notice, during working hours and without affecting the security of other clients.
Unless a competent authority or the law requires otherwise, on-site audits are limited, as a rule, to one per calendar year, are announced at least 30 days in advance, are conducted under confidentiality obligations and at the Client’s expense. Routena may also respond to an audit request by making available relevant available documentation, audit reports or attestations, where these reasonably cover the subject matter of the audit.
The limit of one audit per calendar year does not apply: after a significant security incident; where there are reasonable indications of non-compliance; at the request of a competent authority; or where the law requires otherwise.
The auditor mandated by the Client must be independent, must not be a direct competitor of Routena and must comply with the applicable confidentiality and security obligations.
11. International transfers
Any transfer outside the EU/EEA is carried out only with adequate safeguards: an adequacy decision of the European Commission (including the EU-US Data Privacy Framework – “Data Privacy Framework”, recognized by Implementing Decision (EU) 2023/1795 – where the provider is certified) or the standard contractual clauses approved by the European Commission, accompanied, where appropriate, by a transfer impact assessment (TIA) and appropriate supplementary measures. The details regarding the processing region and the transfer mechanism applicable to each provider are indicated in the List of Sub-processors.
12. Monitoring of drivers and employees (Law no. 190/2018)
The GPS location and vehicle monitoring functionalities may constitute a form of employee monitoring when used in relation to the Client’s employees. The Client is responsible, as Controller and, where applicable, as employer, for establishing the legal basis, fulfilling the information and consultation obligations and complying with the conditions applicable to workplace monitoring. To the extent that art. 5 of Law no. 190/2018 is applicable, the Client warrants compliance with the subsidiarity requirement, confirming that other, less intrusive forms and means of achieving the purpose have not previously proven effective. Routena remains responsible for its own obligations as Processor, including compliance with the documented instructions, security and the assistance provided by this DPA.
Routena processes the location data exclusively as Processor and does not determine the purposes of the monitoring. The GPS history currently accessible through the Platform is retained for 7 days. Existing technical copies in the backup systems are subject to the normal retention cycles and are not available for current operational use.
13. Liability and precedence of the documents
With regard to personal data, in the event of a discrepancy between this DPA and the other contractual documents, the DPA prevails. Liability is governed by the Contract and by the applicable data-protection legislation.
No provision of this DPA limits the rights of data subjects or the powers of the supervisory authorities, and none removes liability that cannot be limited under applicable law.
Annex 1 — Details of the processing
- Controller: the Client.
- Processor: SPECTRALAB SOLUTIONS S.R.L. (Routena).
- Duration: for the duration of the Contract + the deletion/return period (section 9).
- Nature and purpose: the provision of the TMS platform, as configured by the Client.
- Processing operations: collection, recording, organization, structuring, storage, consultation, use, modification, correlation, transmission, export, restriction and deletion.
Categories of data subjects (depending on the functionalities used by the Client): account administrators; users and employees of the Client; own or external drivers; collaborators; representatives and contacts of the Client’s clients, suppliers, carriers and partners; persons mentioned in transport, invoicing or order documents.
Categories of data (depending on use): identification and contact data; authentication data; data about drivers and documents (licenses, validities); GPS location data of vehicles and drivers; data about orders, routes, statuses and transport documents; financial and fiscal data (including e-Factura); technical usage data (IP, access logs); national identification numbers; the series and number of the license; copies of uploaded documents; signatures; data about vehicles associated with persons; support communications; the content of the transport documents.
The platform is not intended for the processing of the special categories of data provided in art. 9 GDPR or of data relating to criminal convictions and offences, unless such processing is expressly provided in the Offer or in a contractual annex, and the Client has established an appropriate legal basis and documented instructions.
The Client shall not upload such data into fields, documents or functionalities that are not expressly intended for its processing.
Annex 2 — Technical and organizational measures
Protection of data in transit
Public connections to the Platform use encryption mechanisms in transit, including HTTPS/TLS, provided and configured through the technical infrastructure used by Routena.
Access control
Access to the functionalities and data of the Platform is controlled through roles and permissions. The relevant checks are applied at the level of the server components and, where necessary, at the level of the user interface.
Separation of clients’ data
Routena uses a multi-tenant architecture with mechanisms for the logical separation of each Client’s data. Operations on the data of a Client are subject to controls for the identification and delimitation of the relevant Client.
Logging
Routena keeps technical and audit logs for the relevant activities, for the purposes of security, incident investigation, troubleshooting and compliance with contractual and legal obligations.
Backups and continuity
Routena uses automated and periodic backup processes for the main storage components of the Client’s Data, including the production database and the files or documents stored in the storage services used.
The backups are kept in accordance with internal retention periods established according to the technical component, the continuity needs and the applicable obligations.
Routena maintains reasonable recovery and continuity mechanisms, without guaranteeing the full recovery of all data or recovery up to a specific point in time, in the absence of an express commitment in a separate SLA.
Monitoring and incident management
Routena uses technical monitoring, logging and alerting mechanisms to identify operational problems and certain relevant security events.
Incidents are assessed and managed in accordance with internal procedures, including through investigation, containment, remediation and notification measures, where notification is required by law or by the DPA.
Development and administration
Routena applies reasonable measures to control access to the production environments, change management, supplier administration and the protection of authentication information and technical secrets.
Sub-processors
The providers that process personal data on behalf of Routena are subject to the contractual obligations and checks applicable under the DPA. The current list of sub-processors is available on the Routena legal page.
Annex 3 — Sub-processors
The list of authorized sub-processors is published and maintained at https://routena.com/en/subprocessors, together with the notification and objection procedure.