Tratamiento de datos
Vigente desde
Where we handle personal data for a client, a recipient's name and address, for example, we do so as a processor acting on that client's instructions. This document sets out those terms. It supplements our Terms and Conditions and does not replace the services agreement between us.
1. Roles and Scope
-
1.1
This document applies whenever Ecom Logistics ("we", "us", "our") handles personal data on behalf of a client ("you") in the course of providing fulfillment, delivery, freight or related services.
-
1.2
For that personal data you are the controller and we are the processor. You decide why and how it is processed. We process it only to provide the services you have engaged us for, and on your instructions.
-
1.3
Where we decide for ourselves why and how data is processed, for example the contact details of your staff who administer your account, or the information someone submits through a form on our website, we act as a controller. Our Privacy Policy covers that processing, not this document.
-
1.4
This document supplements our Terms and Conditions. Where your signed services agreement with us says something different about data protection, that agreement takes precedence.
2. What We Process
-
2.1
The personal data we process on your behalf is the data your orders contain. In practice that is the recipient's name, delivery address, and the contact details needed to complete or attempt a delivery, such as an email address or telephone number.
-
2.2
The data subjects are your customers and the recipients of shipments you send.
-
2.3
We also process delivery events attached to those shipments: timestamps, status changes, delivery attempts, and proof of delivery, which may include a photograph taken at the delivery point.
-
2.4
We do not ask you for, and you should not send us, special categories of personal data, payment card numbers, or government identification numbers. None of that is needed to fulfill or deliver an order.
3. Our Instructions
-
3.1
We process personal data only on your documented instructions. Your instructions are the services agreement between us, the orders and shipment data you send us, and any further written instruction you give.
-
3.2
We will tell you if, in our opinion, an instruction you give would breach applicable data protection law.
-
3.3
We will not sell personal data processed on your behalf, and we will not use it to build profiles, train models, or for our own marketing.
-
3.4
If we are required by law to process personal data beyond your instructions, we will tell you before doing so unless the law forbids us from telling you.
4. Confidentiality
-
4.1
We treat personal data processed on your behalf as confidential.
-
4.2
Access is limited to the people who need it to deliver the services: the operations, warehouse, driver and support staff working on your account, and the technical staff maintaining the systems that hold it.
-
4.3
Those people are bound by a duty of confidentiality, whether by their employment terms or by contract.
5. Security
-
5.1
We maintain technical and organisational measures appropriate to the risk of processing this kind of data.
-
5.2
Those measures include access control on the systems that hold order and shipment data, encryption of data in transit over public networks, and physical access control at our facilities.
-
5.3
We keep personal data out of our application logs. Diagnostic information about a shipment is recorded against that shipment's own timeline, where it is subject to the same access controls as the rest of the record, rather than written into general system logs.
-
5.4
The specific security commitments that apply to your account, including any that go beyond this document, are set out in your services agreement.
6. Sub-processors
-
6.1
You give us general authorisation to engage sub-processors to help deliver the services.
-
6.2
The categories we engage are: delivery and freight carriers who carry shipments we do not carry ourselves; cloud hosting and infrastructure providers for the systems that hold order and shipment data; and software providers for customer support and communications.
-
6.3
We impose data protection obligations on each sub-processor that are no less protective than those in this document, and we remain responsible to you for their performance.
-
6.4
We will give you notice of any new sub-processor in a category above, or of a change of sub-processor, before that sub-processor begins processing your data. If you reasonably object on data protection grounds, we will work with you to find an alternative; if none is available, either of us may terminate the affected service.
-
6.5
A current list of our sub-processors is available on request from the contact address below.
7. International Transfers
-
7.1
Our network operates in both Canada and the United States, and we hold facilities in both countries. Personal data you send us may therefore be processed in either country, and may cross the border in the course of fulfilling or delivering an order.
-
7.2
Where personal data is transferred out of the jurisdiction it was collected in, we put in place a transfer mechanism recognised by the applicable law, and we apply the same protections set out in this document to the data wherever it is processed.
-
7.3
Personal data processed in the United States may be subject to lawful access requests by United States authorities. We will tell you about any such request that concerns your data unless we are legally prohibited from doing so.
8. Assisting You
-
8.1
If a data subject contacts us directly to exercise a right over data we hold on your behalf, we will not respond to the substance of the request ourselves. We will refer them to you and tell you about the request.
-
8.2
We will give you reasonable assistance, taking into account the nature of the processing and the information available to us, in responding to requests to access, correct, delete or restrict personal data we hold on your behalf.
-
8.3
We will give you reasonable assistance with data protection impact assessments and with consultations with a supervisory authority, where those relate to our processing of your data.
9. Security Incidents
-
9.1
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data we process on your behalf, we will notify you without undue delay.
-
9.2
Our notification will describe what we know at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures we have taken or propose to take.
-
9.3
We will provide further information as our investigation progresses, and we will cooperate with you so that you can meet your own notification obligations.
-
9.4
Any notification period agreed for your account is set out in your services agreement.
10. Retention, Return and Deletion
-
10.1
We retain personal data processed on your behalf for as long as we need it to provide the services, and for any period we are required to retain it by law.
-
10.2
On termination of the services, and at your choice, we will return the personal data we hold on your behalf or delete it, and delete existing copies, unless we are required by law to keep it.
-
10.3
Where we are required to keep personal data after termination, we will keep it only for as long as the law requires, and this document continues to apply to it for that period.
11. Records and Audit
-
11.1
We maintain records of the processing we carry out on your behalf.
-
11.2
We will make available to you the information reasonably necessary to demonstrate compliance with this document, and will allow for and contribute to audits, including inspections, conducted by you or another auditor you mandate.
-
11.3
Audits are to take place on reasonable prior notice, during business hours, no more than once in any twelve month period unless required by a supervisory authority or following a security incident affecting your data, and in a way that does not disrupt our operations or compromise the confidentiality of another client's data.
12. Changes to This Document
-
12.1
We may update this document to reflect changes in our operations or in applicable law. Where a change materially reduces the protections it gives, we will give you notice before it takes effect.
-
12.2
The version in force is the one published on this page.
13. Governing Law
-
13.1
This document is governed by and construed in accordance with the laws of Canada, and the courts of Canada have exclusive jurisdiction over any dispute arising from it. This matches the governing law of our Terms and Conditions.
14. Contacto
-
14.1
Questions about this document, requests for our current sub-processor list, and notices under it should be sent to:
-
14.2
Email: info@ecomlogistics.ca
-
14.3
Address: Ecom Logistics, 945 Wilson Ave, North York, ON M3K 1E8, Canada
-
14.4
Telephone: +1-800-862-3315