Legal · Linkargo AI
Privacy Policy.
Version 1.3 · Last updated 18 August 2026 · English version is binding · Operator: Cedaris LLC, Las Vegas, NV, USA
1. Controller and scope
Linkargo is operated by:
Cedaris LLC
732 South 6th Street, Suite N
Las Vegas, Nevada 89101
United States
Nevada Entity ID: E51379642025-4
Privacy contact: privacy@cedaris-ai.com
General Linkargo contact: info@linkargo.ai
Cedaris LLC, referred to as Cedaris, we, or us, is the controller for personal data used to operate Linkargo membership, the Linkargo Marketplace, Cedaris communications, platform security, service measurement, marketplace transaction records, and the limited freight-market and price-forecasting analytics described in Section 5.9.
This Privacy Policy explains how Cedaris processes personal data relating to:
- Website visitors and applicants.
- Member representatives and Authorised Users.
- Shipper, Carrier, and Storage Provider contacts.
- Drivers, carrier customers, pickup contacts, and delivery contacts.
- Recipients and users of driver, customer, Quote, or storage links.
- People named, shown, or otherwise identifiable in submitted messages or documents.
Linkargo is a business-to-business service for businesses established in the European Union. It is not directed at consumers or children.
2. Representative in the European Union
Cedaris has appointed the following representative in the European Union under Article 27 GDPR:
Rik Hanssen
Appointed EU Representative for Cedaris LLC under Article 27 GDPR, based in the Netherlands
Email: rik.hanssen@dairy-broker.ai
For formal postal correspondence, the Representative's service address is available on request via privacy@cedaris-ai.com.
People in the European Union may contact the representative or Cedaris about any issue relating to the processing of their personal data under the GDPR.
3. When Cedaris is controller and when Cedaris is processor
The privacy role depends on the workflow.
The role descriptions below reflect the intended allocation for the workflows described. They do not override a role assigned by mandatory law based on the actual purposes, means and circumstances of processing. If a workflow materially changes that allocation, Cedaris will update the applicable notice and agreement before using the workflow under the changed allocation.
3.1 Cedaris as controller
Cedaris is controller for:
- Applications, member review, and account administration.
- Marketplace freight and storage requests, matching, Quotes, Counter-Offers, responses, Awards, and related evidence.
- Marketplace tours created from a Linkargo Award, including Tour Rooms, optional foreground location sharing, calculated
ETAs, chat, documents, and role-based links. 4. Frida, automated translation, AI-assisted document functions, and other service communications where Cedaris determines their purposes and essential means. For External Tour content processed only on the Carrier's documented instructions, Section 3.3 applies instead. 5. Authentication, security, abuse prevention, support, legal compliance, and first-party service measurement. 6. The freight-market and price-forecasting analytics described in Section 5.9. 7. The limited Dairy Broker phone recognition described in Section 8.
3.2 Members as independent controllers
When Members receive each other's business contact and transaction information to evaluate, conclude, or perform a Direct Transaction, each Member normally acts as an independent controller for its own use of that information. Members must provide their own privacy information and comply with applicable law. Cedaris does not control a Member's independent systems or later use of data outside Linkargo.
3.3 Cedaris as processor for External Tours
When a Carrier uses Linkargo Pro to manage an External Tour for its own customer, the Carrier normally determines the purpose and essential means of processing the customer, driver, route, milestone, foreground location, ETA, chat, note, document, and related AI output data. The Carrier is controller and Cedaris is processor under the Linkargo Pro Data Processing Agreement.
For that processor data, this Policy describes Cedaris's platform and providers but does not replace the Carrier's own privacy notice. A data subject can contact the relevant Carrier directly. Cedaris will assist the Carrier as required by the Data Processing Agreement and applicable law.
Cedaris remains controller for its own account, security, billing, and service administration data even when it is processor for External Tour content.
4. Sources of personal data
We receive personal data from:
- You, when you apply, contact Frida or Cedaris, use Linkargo, submit a request or response, update a tour, use chat, share foreground browser location, upload a document, or exercise a right.
- Your employer or the business you represent.
- Another Member, for example when a Carrier enters a driver's phone number, a customer contact, or pickup and delivery information.
- A recipient using a Protected Link.
- The separate Dairy Broker project, only for the limited phone recognition described in Section 8.
- Our infrastructure and communication providers, which supply delivery, security, request, and technical metadata.
- Public business registers or other lawful business sources where a manual membership review requires an additional business check.
Where Cedaris acts as controller and obtains personal data indirectly, we provide the information required by Article 14 GDPR within a reasonable period and no later than one month. If we use the data to communicate with the person or disclose it earlier, we provide the information no later than the first communication or first disclosure, as applicable. The Dairy Broker recognition notice is provided at the start of the Linkargo interaction. For External Tour content processed by Cedaris only as processor, the Carrier Controller is responsible for providing the applicable Article 13 or Article 14 information as described in Section 3.3.
Where Linkargo delivers a first-contact notice, we can retain proportionate evidence of the notice provided, such as its version, channel, destination, time, and available delivery status. The message can use a short layered explanation and a link to the applicable privacy information. Linkargo provides the short notice in a supported contact language where available. A person can contact privacy@cedaris-ai.com if the information is not understandable or an accessible version is needed.
5. Personal data we process
5.1 Website and technical request data
We can process:
1. Requested page or path used by infrastructure for delivery and security, timestamp, referrer hostname, and interaction type.
Before event data is used for separate service measurement, Protected Link values and other direct identifiers are removed or replaced and dynamic pages are reduced to appropriate route or feature categories. 2. IP address, user agent, browser, device category, network and request headers, and an approximate country inferred by infrastructure. 3. Security, delivery, and error metadata created by hosting or communication systems. 4. A short-lived rotating pseudonymous visitor identifier for first-party service measurement.
An IP address and similar request data can be used transiently to create the rotating identifier and can also appear in limited infrastructure or security logs. The Linkargo measurement system does not set an analytics cookie and does not use the identifier for cross-site tracking.
A raw infrastructure request can contain a workflow or Protected Link identifier. We treat such identifiers as restricted credentials. They are not used as analytics dimensions, advertising identifiers, or profiling fields. Where they are unavoidably present in restricted infrastructure or security logs, those logs follow their separate security purpose, access restrictions, and retention period.
5.2 Application and member review data
Depending on the role, we can process:
- Company name, legal form, business address, website, VAT or tax identifier, and registration information.
- Contact name, job role, work email, business phone, and preferred language.
- Requested role and plan.
- Fleet, equipment, operating countries, capacity, storage capabilities, and other business information.
- Evidence of a Carrier's or Storage Provider's licence, operating authorisation, regulatory registration, permissions, relevant insurance, and business registration.
- Application status, review notes, reviewer actions, document status, and related timestamps.
- Submission and verification metadata used to prevent spam, fraud, and abuse.
We do not use the application review as a credit score or payment guarantee. A human makes the final approval, rejection, suspension, or information request decision for a standard Linkargo application. The separate Dairy Broker recognition in Section 8 can create a provisional Linkargo shipper profile. It does not activate Marketplace access. Activation occurs only after Cedaris confirms current EU establishment, the person's authority, and the then-current Linkargo eligibility checks.
For a licence, permit, registration, or insurance document, the application record can show that Cedaris received the document, reviewed basic visible details, assigned a document status, requested a replacement, or took another membership action. These records describe a limited administrative membership control. They do not mean that Cedaris authenticated the document or issuer or completed a legal, regulatory, insurance-coverage, or ongoing-compliance audit. The contractual scope and the direct parties' final counterparty checks are explained in Section 6 of the Linkargo Terms of Service.
5.3 Account and authentication data
We can process account identifier, role, status, plan, work email, phone, hashed one-time credentials, credential expiry, verification attempts, request IP, session information, and account activity needed to secure access.
For a Terms, Data Processing Agreement, paid-plan, price-change, or other material acceptance, we can process the information reasonably needed to show who acted for which Member, which document or commercial choice was presented, when and how it was affirmatively accepted, and proportionate technical evidence of that action. A specific arbitration authorisation is recorded separately from the general Terms acceptance. Quote, Counter-Offer, Storage Response, and Award acceptance evidence follows the relevant Marketplace record.
5.4 Freight Marketplace data
We can process:
- Pickup and delivery country, postcode, town, date, and time window.
- Cargo description, equipment, temperature, pallets, pallet exchange, weight, quantity, and operational notes.
- Dangerous goods, customs, sanitary, food safety, security, or access requirements that a Member chooses or is required to provide.
- Request status, matching criteria, invitations, reminders, and timestamps.
- Carrier company, Quote, currency, validity, pickup information, conditions, and notes.
- Requester Counter-Offer price, currency, changed material terms, validity and submission evidence, and the Carrier's acceptance or rejection status.
- Awarded parties, accepted request, Quote, Counter-Offer or Storage Response fields, acceptance status, timestamp, and available evidence of the action.
Before an Award, freight request information can be visible to active Carrier Members. A Counter-Offer is visible to the Carrier that submitted the related Quote. Members should not include unnecessary personal data or confidential information in pre-Award fields.
5.5 Storage data
We can process storage location, postcode, town, type, temperature range, capacity, availability, services, rate card, handling prices, storage prices, billing unit, minimums, energy surcharge, currency, validity, and notes.
For a storage request, we can process requested area, radius, storage type, pallets, dates, notes, matching responses, calculated price information, and an Award record. After a valid Award, the parties receive the contact information needed to perform the storage contract.
5.6 Tours, drivers, customers, and documents
For a marketplace tour or External Tour, we can process:
- Carrier, shipper, or customer name and business contact details.
- Driver phone number and business email where supplied.
- Pickup and delivery addresses, contacts, time windows, loading reference, and vehicle registration.
- Cargo, equipment, temperature, pallets, weight, and operational notes.
- Milestone status, timestamp, update source, incident notes, calculated ETA, and the information used to calculate it.
- If a driver or other authorised recipient enables foreground location sharing, precise browser location points, timestamps, accuracy information, sharing state, and related technical metadata while the relevant page is open and active.
- Tour chat, original messages, automated translations, language information, sender and recipient role, and related timestamps.
- Uploaded PDF or image files, such as delivery, transport, or other tour documents, and the people identifiable in them.
- Document extraction or checking results, such as recognised fields, apparent omissions, inconsistencies, confidence or readability information, and human confirmation or correction.
- Protected driver and customer link identifiers and access-related technical metadata.
Depending on the workflow and sharing controls then available, an authorised driver, customer, Shipper, or Carrier can see route information, references, milestones, ETA, chat, notes, and documents made available to its account, link, role, or shared Tour Room. The Service or accompanying notice identifies the intended account, recipient group, or shared workspace before or when a document is submitted where reasonably practicable. Where granular audience selection is offered, the selected audience controls access. Where a Tour Room is presented as shared without granular document controls, an uploaded document may be visible to all authorised participants in that shared Tour Room. Members must verify the indicated sharing context and must not upload or share information with a person or role that should not receive it.
Foreground location sharing is optional. Linkargo requests browser permission when the recipient deliberately starts the feature. Location points are received only while the relevant driver page remains open and active and the browser continues to provide them. Sharing stops when the recipient stops it, revokes browser permission, closes or backgrounds the page, loses connectivity, or the device or browser suspends the function. Linkargo does not collect location in the background and does not promise or create continuous live GPS tracking. Declining or stopping location sharing does not prevent a driver from using available milestone functions and does not by itself cause Cedaris to take an adverse action.
Location points can be shown to authorised Tour Room recipients and used to calculate or update an ETA. The ETA can also use route, time-window, milestone, traffic, map, and other available operational information. Cedaris does not use foreground location to score a driver or employee, determine Member eligibility, make an Award, or build freight-market and price forecasts.
A Member can revoke a driver or customer tour link through available account controls or by contacting Cedaris. Protected Links follow the expiry, revocation, or workflow lifecycle shown in the Service or accompanying communication and can be shortened or invalidated for security, legal compliance, or closure of the relevant workflow. Where renewal is available for a continuing legitimate purpose, it requires a deliberate action by an Authorised User. Link recipients must treat every active link as a confidential credential.
5.7 Communications
We can process WhatsApp, email, SMS, and support message content together with sender and recipient details, message identifiers, timestamps, delivery status, button responses, attachments where supported, and workflow references.
5.8 Rights, complaints, and incident data
If you exercise a right, complain, report a security event, or become involved in a dispute, we can process your contact details, request, identity verification information, correspondence, investigation material, decision, and completion evidence.
5.9 Freight-market and price analytics
To understand market development and improve internal freight and storage price forecasts, Cedaris can create a separate analytics dataset only from structured Marketplace records for which Cedaris is controller. External Tour data processed for a Carrier Controller and Dairy Broker data are excluded. Depending on availability, this can include origin and destination region, date or season, distance band, cargo and equipment category, temperature requirement, quantity or weight band, request, response and Counter-Offer status, quoted, counter-offered or awarded price, currency and relevant non-personal service conditions.
Before information enters this dataset, Cedaris removes direct contact details, credentials, Protected Link values, precise foreground location, communications, documents, free text, and other fields that are not needed for the analytics purpose. Any Member or transaction identifier that remains necessary is replaced with a purpose-specific pseudonym and access to additional identifying information is restricted. The dataset is not used to score a person, monitor a driver or employee, determine Member eligibility, reveal an individual Member's confidential pricing to another Member, or make a solely automated decision with legal or similarly significant effects. Any future Member-visible benchmark must use aggregation or broader categories sufficient to protect confidentiality and competition and is reviewed before activation.
Cedaris does not disclose the pseudonymised row-level Marketplace analytics dataset to another Member, make it available to a third party for that third party's own purposes, or sell or license it. Approved service providers can process necessary information for Cedaris only under appropriate instructions, confidentiality, data-protection, and access restrictions. This does not prevent a business transfer under the Terms where the recipient assumes the same restrictions. A Member-visible or other external market output must be aggregated or anonymised so that it does not reasonably identify a person, Member, or individual confidential price and must pass appropriate confidentiality and competition safeguards before release.
Where the resulting statistics are irreversibly aggregated or anonymised so that a natural person is no longer reasonably identifiable, they are no longer personal data. Pseudonymised records remain personal data and continue to be subject to this Policy, security measures, retention limits, objections and other GDPR rights.
5.10 Sensitive and unnecessary data
Linkargo is not designed to collect special categories of personal data, personal data about criminal convictions, consumer payment-card data, or government identity documents, except where a specific legal and operational requirement has been approved. Members must not submit such data merely because a free-text or upload field is available.
Operational documents can incidentally contain signatures, photographs, vehicle information, or other personal data. Members must minimise this content and ensure they have a lawful basis for submitting it.
6. Purposes and legal bases
We use personal data for the following purposes and legal bases:
Purpose Personal data and people Legal basis
Receive and assess an application, review business information, and prepare membership
Applicant and business contact data, submitted evidence, review data
Article 6(1)(b) GDPR where the individual is the contracting party or sole trader. Otherwise Article 6(1)(f), our legitimate interest and the applicant business's interest in establishing a B2B relationship
Administer accounts, roles, plans, authentication, and service access
Member representative, account, authentication, and contact data
Article 6(1)(b) where applicable. Otherwise Article 6(1)(f), performance and administration of the B2B agreement with the represented business
Operate freight and storage requests, matching, Quotes, Counter-Offers, responses, Awards, and marketplace Tour Rooms
Member contacts, operational request data, transaction evidence, route, milestone, chat, document, and other tour data
Article 6(1)(b) where the person is party to the relevant contract. Otherwise Article 6(1)(f), our and the Members' legitimate interests in operating, concluding, documenting, and performing B2B logistics workflows
Provide optional foreground location sharing and calculated ETAs for a Marketplace tour
Driver or recipient location points, time, accuracy and sharing state, route, milestone, traffic, map, and ETA data
Article 6(1)(f), our and the direct parties' legitimate interests in coordinating the requested transport and providing proportionate operational visibility. Safeguards include recipient activation, foreground-only collection, short raw- location retention, a milestone alternative, restricted recipients, and no worker scoring or background tracking
Purpose Personal data and people Legal basis
Provide Frida, automated translation, and AI-assisted document extraction or checking
Contact details, original and translated messages, selected documents or extracted content, AI output, human confirmations or corrections, and technical metadata
Article 6(1)(b) where applicable. Otherwise Article 6(1)(f), efficient and accessible operation of the requested B2B service with human review and no solely automated legally significant decision Send required application, authentication, request, Quote, Counter-Offer, Award, storage, tour, document, security, and support messages
Contact and communication data
Article 6(1)(b) where applicable. Otherwise Article 6(1)(f), operating and securing the requested B2B service
Send optional direct marketing Business contact details and preferences
Consent under Article 6(1)(a) where required. Otherwise Article 6(1)(f) where B2B direct marketing is lawful, always subject to applicable electronic communications law and an unconditional right to object Perform limited administrative membership checks concerning licences, insurance evidence, authority, and misuse concerns
Application, review, business, security, and activity data
Article 6(1)(f), protecting Members, platform integrity, and lawful Marketplace access. Article 6(1)(c) where a specific legal duty applies Secure the Service, prevent fraud and abuse, investigate incidents, and preserve evidence
Request, network, login, account, message, token, and activity metadata
Article 6(1)(f), protecting the Service, Members, data subjects, and legal claims. Article 6(1)(c) where a legal duty applies
Measure first-party website and feature use without an analytics cookie
Page, interaction, device, approximate country, and rotating pseudonymous identifier
Article 6(1)(f), understanding and improving our own Service with limited data and no cross-site advertising profile
Analyse structured freight and storage market data and improve internal price forecasts
Pseudonymised route region, time, cargo, equipment, quantity, request/response/Counter-Offer status, Quote, Counter-Offer, Award, price, currency and limited service-condition fields; no direct contact fields, documents, tokens or free text
Article 6(1)(f), our legitimate interest in understanding market development, improving service planning and producing non-individual business forecasts, subject to data minimisation, confidentiality, the separate balancing assessment and the right to object
Handle rights, complaints, disputes, audits, and regulator or court requests
Contact, request, correspondence, transaction, security, and evidence data
Article 6(1)(c), compliance with legal duties. Article 6(1)(f), establishing, exercising, or defending legal claims
Issue and retain Cedaris subscription invoices and accounting records
Member business and billing contact data, plan, invoice, and payment status
Article 6(1)(c), applicable legal and tax duties. Article 6(1)(b) where the individual is the contracting party. Otherwise Article 6(1)(f), administration of the B2B agreement
Where we rely on legitimate interests, we consider the business context, reasonable expectations, data minimisation, access controls, retention, and the person's rights. You can object as explained in Section 15.
For an External Tour, the Carrier is normally controller for the Tour Room content and decides the applicable legal basis. Cedaris processes that content on the Carrier's documented instructions under the Linkargo Pro Data Processing Agreement and does not use it for its own freight-market analytics.
7. Frida, AI transparency, and human review
Frida is an AI system. Frida identifies itself as AI at or before the first direct interaction unless the AI nature is already obvious from the circumstances. A person can request human assistance through the method offered in the conversation or by contacting info@linkargo.ai.
In this Policy, AI-Assisted Functions means Frida, automated translation, document extraction or checking, and any other Linkargo function that uses an artificial intelligence model to prepare, transform, classify, extract, check, or suggest content.
AI-Assisted Functions can analyse incoming message text, prepare structured draft fields or questions, translate operational chat, and extract or check information in selected transport or delivery documents. A document check can flag apparent omissions, inconsistencies, or readability issues, but it does not certify authenticity, legal compliance, signature validity, cargo condition, or delivery. The relevant Member reviews material information and AI output before submission, acceptance, or operational reliance.
Where an AI-Assisted Function is enabled and used, Cedaris can send the minimum content needed for the requested function to the AI service provider identified in Section 10. The provider processes that content for Cedaris under the applicable business terms, data-protection obligations, and transfer safeguard. Cedaris does not authorise the provider to use Linkargo content for unrelated advertising or general-purpose model training.
Automated translations are provided for convenience and the original message remains available as the authoritative version. Safety-critical, legal, price, route, temperature, deadline, and other material content should be verified with the sender where an error could cause loss or harm.
Frida and the document functions do not autonomously submit or accept a Counter-Offer, accept a Quote, create an Award, approve or reject a Member, or make a decision producing legal or similarly significant effects about a person. Linkargo provides the transparency or labelling required by applicable law for the relevant AI interaction or output. We review the data sent to AI providers and will update this Policy before materially expanding AI purposes or data categories.
8. Limited Dairy Broker phone recognition
Dairy Broker and Linkargo are separate Cedaris projects with separate databases, services, public documents, and processing records. Linkargo does not import Dairy Broker trading positions, prices, contracts, scoring, or commercial history.
When a business contact first contacts Linkargo through a supported phone or WhatsApp channel, Cedaris can compare that business phone number with the separate Dairy Broker customer dataset. If a current matching customer is found, Linkargo can receive only limited recognition data needed to respond, consisting of the relevant company and contact name, preferred language, and a restricted reference showing the Dairy Broker source and current relationship status.
The purposes are to avoid asking an existing Cedaris business contact to repeat basic onboarding details, to respond in the appropriate language, and to create or prepare the correct Linkargo shipper context after the person initiates contact with Linkargo.
If the match succeeds, Linkargo can prepare a provisional shipper profile from that limited recognition data. The profile is marked internally as originating from Dairy Broker. It does not activate Marketplace access. Activation occurs only after Cedaris confirms that the represented business is currently a legally registered business established in the European Union, that the person has appropriate authority, and that the then-current Linkargo eligibility checks are satisfied. The earlier Dairy Broker review is contextual information only and is not a new credit check, payment guarantee, or assessment of current transport requirements.
The Dairy Broker source identifier, match status, and fact of the Dairy Broker relationship are not shown to other Linkargo Members. The recognised profile is not used for Linkargo marketing, billing, scoring, or cross-service profiling. It does not make information visible to another Member or create a request, Award, paid plan, or Direct Transaction unless you confirm the relevant Linkargo request or next step.
The legal basis is Article 6(1)(f) GDPR, Cedaris's and the contact's legitimate interests in an efficient, expected B2B onboarding flow between related Cedaris logistics services. The lookup is initiated only after the person contacts Linkargo. Cedaris provides a Linkargo privacy notice at the start of that interaction and identifies Dairy Broker as the source of the recognition data.
You may object to this recognition at any time by replying "do not link", otherwise telling Frida, or contacting privacy@cedaris- ai.com. An objection does not prevent you from applying to or using Linkargo independently. We will stop using the Dairy Broker link and erase imported recognition data unless another legal basis requires a limited record, including a minimal record needed to respect your objection.
9. What other Members and link recipients receive
Linkargo distributes operational information only as required by the workflow:
- An open freight request can be visible to active Carrier Members with the request fields and notes supplied for quoting.
- A Carrier's Quote and related company information are visible to the relevant Shipper; a Counter-Offer is visible to the Carrier that submitted the related Quote.
- Following an Award, the direct parties receive the business contact and operational information needed to perform and document the Direct Transaction.
- A storage request can be sent to potential Storage Providers, and a Storage Response is visible to the requester.
- Following a storage Award, the direct parties receive the contact information needed to perform the storage contract.
- A Carrier can share a driver or customer link with intended recipients. The relevant Tour Room can show route, reference, milestone, ETA, foreground location, original and translated chat, notes, and documents made available to that account, link, role, recipient group, or shared Tour Room as described in Section 5.6.
- Where the feature is enabled, another active Member can see a limited document or membership status, including the document category, administrative review status, and relevant review or recorded expiry date. The underlying document is not disclosed unless it is separately and lawfully shared through the relevant workflow.
Recipients must use the information lawfully and for the relevant business purpose. Once an independent Member receives data for its own Direct Transaction, that Member is responsible for its further controller processing.
10. Service providers and other recipients
We use providers that process personal data for the purposes described in this Policy. The principal provider categories and, where identified below, current providers are:
Provider Service and data context
Supabase Cloud database, authentication, file storage, and related infrastructure
Vercel Website and application hosting, runtime, security, and technical logs Resend and its authorised email subprocessors Transactional email delivery and related delivery metadata Meta Platforms entities WhatsApp Business messaging and related delivery metadata
Anthropic AI processing needed for enabled Frida, translation, and document-support functions Twilio, where SMS is enabled SMS delivery and related delivery metadata
Routing or map-data provider, where an ETA or routing function requires one
Route and location information needed for the enabled routing or ETA function. The selected provider is available from privacy@cedaris-ai.com
The provider's legal role depends on the actual processing. A provider acts as processor where it handles data on Cedaris's instructions. A communications, network or other provider can act as an independent controller for a limited purpose it determines under applicable law or its service terms, such as network security, abuse prevention or legal compliance, as described in that provider's privacy information. Cedaris does not authorise a provider to use Linkargo data for unrelated advertising.
These providers can use authorised subprocessors under their data processing terms. Cedaris maintains an internal provider and transfer register and reviews material changes.
We can also disclose personal data:
- To professional advisers, auditors, insurers, and financing partners under appropriate confidentiality duties where necessary.
- To a regulator, court, law enforcement body, or other authority where disclosure is legally required or necessary to protect legal rights.
- In connection with a merger, financing, reorganisation, or sale, subject to confidentiality, due diligence limits, and applicable privacy law.
We do not sell personal data. We do not use Linkargo personal data for third-party targeted advertising.
11. International processing and transfers
Cedaris is located in the United States. Personal data can therefore be processed or accessed in the United States in connection with Cedaris's operation of Linkargo. The GDPR applies to Cedaris's processing covered by this Policy, and the EU representative described in Section 2 provides an additional contact in the European Union.
Some providers are established in the United States or use global infrastructure and subprocessors. A provider's use of an EU hosting or email delivery region does not mean that all account, support, metadata, log, or backup processing remains in the European Union.
Where Chapter V GDPR requires a transfer safeguard for a disclosure by Cedaris or one of its processors, we use the available lawful mechanism, which can include:
- An adequacy decision, including the EU-US Data Privacy Framework where the recipient has a current certification covering the relevant data.
- The European Commission's 2021 Standard Contractual Clauses, using the module appropriate to the controller and processor roles.
- Contractual, technical, and organisational supplementary measures where required by the transfer assessment.
- A narrow Article 49 GDPR derogation only where its legal conditions are met and it is appropriate for the specific transfer.
Cedaris maintains the records and assessments required for relevant providers and international transfers. You can request more information or a copy of an applicable safeguard by contacting privacy@cedaris-ai.com. We can redact information needed to protect security, confidentiality, or third-party rights.
For an External Tour, the applicable direct Carrier-to-Cedaris Chapter V safeguard is identified in the executed Linkargo Pro Data Processing Agreement and in the Carrier's privacy notice. Cedaris does not accept production External Tour personal data until that safeguard is valid. The European Commission's 2021 transfer Standard Contractual Clauses are used only where their scope conditions are met. Cedaris's onward transfers to providers are covered separately under the applicable provider arrangement.
12. Retention
We keep personal data only for the period needed for the purpose, applicable legal duties, security, and legal claims. The standard retention schedule is:
Data category Standard retention period or criterion
Rejected, withdrawn, or incomplete application
Up to 90 days after the decision or last activity, unless a longer period is needed for a documented fraud concern, dispute, or legal duty
Approved Member account and business review record
For the active relationship and normally up to 3 years after it ends. Superseded evidence can be deleted earlier where no longer needed
Terms, arbitration, Data Processing Agreement, paid-plan, price- change and other material acceptance evidence
For the relevant agreement, version, plan or change and normally up to 6 years after it ceases to govern, where needed to prove the agreement, authority and affirmative action. Longer retention applies only for a specific legal duty, live claim or legal hold Carrier or Storage Provider licence, operating authorisation, regulatory registration, permission, relevant insurance, and business registration evidence
While current evidence is needed for membership review and normally up to 3 years after replacement or the relationship ends, subject to a dispute or legal hold
One-time login and verification records
Credentials expire after a short period. Related records are deleted or irreversibly minimised within 30 days after expiry unless needed for a security investigation Session cookie Up to 30 days, or earlier on logout or invalidation where available
Protected Link credential and lifecycle
The active credential is retained until its applicable expiry, revocation, or workflow closure and is then disabled or removed from active use. Minimal lifecycle, access, and security evidence can normally be retained for up to 12 months, or longer only where it forms part of a live incident, Award, claim or legal hold Unpublished request draft Up to 30 days after the last activity Closed request, Quote, Counter-Offer, or Storage Response without an Award Normally up to 12 months after closure
Core Award and Marketplace Direct Transaction evidence
Normally up to 6 years after completion, cancellation, or closure where needed to prove the accepted request, Quote, Counter- Offer or response, parties, authority, version, price, currency and time. Supporting operational content follows its shorter category unless a claim, mandatory law or legal hold requires it Marketplace tour milestones, ETA snapshots, original and translated chat, notes, documents, and AI extraction or checking results
Normally up to 3 years after completion or cancellation, with earlier deletion where the operational and evidence purpose has ended
Foreground Location Data
Only the latest point and a short rolling window needed for current display and ETA calculation. Raw points are normally deleted or irreversibly reduced within 24 hours after collection and in all cases within 24 hours after the tour is marked delivered or cancelled. Cedaris does not retain a full raw location trail. Minimal sharing-state events and ETA snapshots can follow the applicable Marketplace tour retention period
External Tour content processed for a Carrier
For the period instructed by the Carrier under the Linkargo Pro Data Processing Agreement. On termination, deletion or return follows that agreement, backups, and applicable law
WhatsApp, email, SMS, and support content
Normally up to 24 months after the last relevant interaction. Content forming transaction, security, complaint, or claim evidence follows the corresponding longer period
First-party event-level service measurement
Up to 24 months after the event, after Protected Link values and other direct identifiers have been removed or replaced and dynamic pages have been reduced to appropriate route or feature categories. Raw request and infrastructure data follow their own shorter or security-specific period
Data category Standard retention period or criterion
Pseudonymised freight-market and price-forecasting dataset
Up to 5 years after the source request, response, Counter-Offer, Award or market event, limited to Marketplace data for which Cedaris is controller, and earlier where an applicable objection, erasure decision, or EU Data Act exit requires deletion or verified irreversible anonymisation. External Tour processor data is excluded. Direct contact data, documents, Protected Link tokens, credentials and free text are excluded before transfer into the dataset
Irreversibly anonymised or aggregated market and service statistics
Up to 10 years for multi-year and seasonal comparison, subject to annual confirmation that re-identification is not reasonably possible. If that standard is no longer met, the data is treated as personal data and the applicable shorter period applies
Security, abuse, delivery, and technical logs Normally up to 12 months, and longer only for an active incident, claim, or legal duty
Rights requests, complaints, and incident records Normally 3 years after closure to demonstrate compliance and handle related claims
Article 13 or Article 14 first-contact notice evidence generated by Linkargo
Normally 3 years after delivery or the last relevant interaction, limited to the notice version, channel, destination, time and available delivery status needed to demonstrate the information provided
Cedaris invoices and required tax or accounting records For the period required by applicable law, which can be up to 10 years
When more than one period applies, we keep only the data needed for the longer applicable purpose and restrict its use. Where the EU Data Act Switching and Portability Schedule requires earlier erasure of in-scope exportable data, that Schedule controls unless Union or national law requires retention. A documented legal hold pauses deletion only for the affected data. Backup copies are removed through the ordinary backup lifecycle and are not restored for ordinary operational use after deletion.
13. Required and optional data
Fields marked as required are needed to assess an application, secure an account, provide the requested workflow, submit or accept a Counter-Offer, form an Award record, or comply with law. Without required business and contact data, Cedaris may be unable to approve or operate an account. Evidence of a Carrier's or Storage Provider's licence, operating authorisation, regulatory registration, permissions, relevant insurance, and business registration can be required for Marketplace access.
Optional notes and documents should be used only where necessary. A Member decides which driver and customer contact details it enters for a tour and is responsible for having a lawful basis and providing required information.
14. Cookies and similar technologies
Linkargo uses only technologies needed for the requested service under the current configuration:
- lk_session, an HTTP-only authentication cookie used to maintain an approved Member session, normally for up to 30 days.
- lk_apply, an HTTP-only short-lived application helper cookie, normally for up to 30 minutes.
- Short-lived link and verification parameters used to complete an application or login.
The three technologies listed above are strictly necessary to provide the service requested by the user and to secure access. Linkargo does not currently set an advertising cookie or a third-party analytics cookie. A browser location permission is a device control, not an analytics cookie, and is requested only when the recipient deliberately starts foreground location sharing.
The separate first-party service measurement is cookieless controller processing based on the limited server-side and static- category event data described in Section 5.1 and the documented legitimate-interest assessment, subject to the applicable national ePrivacy or terminal-equipment rules and the right to object. It does not receive Protected Link values or raw dynamic paths. Freight-market and price analytics are a further separate purpose using only the minimised Marketplace fields and safeguards described in Section 5.9; they do not depend on cookies or Protected Link paths.
If optional cookies are introduced, we will provide an appropriate choice before they are used where consent is required.
15. Your GDPR rights
Subject to the legal conditions and exceptions, you have the right to:
- Obtain confirmation and access to your personal data.
- Correct inaccurate data and complete incomplete data.
- Request erasure.
- Restrict processing.
- Receive data you provided in a structured, commonly used, machine-readable format and transmit it to another controller where the portability conditions apply.
- Object to processing based on legitimate interests, including optional foreground location sharing, AI-Assisted Functions, Dairy
Broker recognition, first-party service measurement, and pseudonymised freight-market or price-forecasting analytics, based on your particular situation. 7. Object at any time to direct marketing. We will stop direct marketing to you after your objection. 8. Withdraw consent at any time where processing is based on consent. Withdrawal does not affect processing that was lawful before withdrawal. 9. Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, where
Article 22 GDPR applies. 10. Lodge a complaint with a data protection supervisory authority in the European Union, particularly in the country of your residence, workplace, or the alleged infringement.
To exercise a right, contact privacy@cedaris-ai.com or the EU representative in Section 2. Please describe the relevant Linkargo account, phone number, email, tour, or request so we can locate the data. We may request proportionate identity verification and authority evidence. We will respond within the period required by law.
If Cedaris holds the data only as processor for an External Tour, we will direct the request to or cooperate with the relevant Carrier.
Where you object to processing based on legitimate interests, we will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or the processing is needed to establish, exercise or defend legal claims. Direct marketing stops after an objection without that balancing test.
16. Security
We use technical and organisational measures appropriate to the nature and risk of the processing. These include measures for protected transmission and storage, credential and access management, role restrictions, logging and monitoring, provider management, backup and deletion, and incident handling. The precise measures can vary by system and risk, and security- sensitive implementation details are not published in this Policy.
Protected Links are credentials. A recipient with a valid link can access the information and actions made available by that link and the current workflow without a separate login. Members and recipients must keep these links confidential and promptly report a lost, misdirected, or compromised link to info@linkargo.ai. After receiving enough information to identify the affected link, Cedaris will invalidate, replace, or restrict it without undue delay as appropriate to the risk.
No online system is completely secure. If a personal data breach creates a notification duty, Cedaris will notify the competent authority and affected people as required by applicable law.
17. Children and consumer use
Linkargo is not intended for children or private consumer use. Authorised Users must be at least 18 years old. If we learn that a child's personal data was submitted without a valid business and legal reason, we will take appropriate steps to remove or restrict it.
18. Changes to this Policy
We can update this Policy to reflect changes in the Service, providers, law, or processing. The current version and date will be shown at the top. We will provide an appropriate notice before a material change takes effect where required.
A new purpose that is incompatible with the purpose for which data was collected will require a new legal basis and any notice or consent required by law.
19. Contact
Privacy requests and questions: privacy@cedaris-ai.com
General Linkargo questions: info@linkargo.ai
Controller postal address: Cedaris LLC, 732 South 6th Street, Suite N, Las Vegas, Nevada 89101, United States
