The data controller is AXEN Logistics s.r.o., with its registered office at Súľovská 5808/21, 040 11 Košice – Západ district, Company Registration Number: 46 027 289, registered in the Commercial Register of the Košice Municipal Court, Section: Sro, file no.: 27357/V (hereinafter referred to as the „Controller“).
The controller processes the personal data of natural persons in accordance with Regulation (EU) (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR), Act No. 18/2018 Z. z. on the protection of personal data and amending certain acts, as amended, and other generally binding legal regulations.
This Privacy Policy provides information on what personal data the Controller processes, for what purposes it processes it, on what legal grounds it processes it, to whom it may disclose it, for how long it retains it, and what rights data subjects have in relation to the processing of their personal data.
If the data subject has any questions regarding the processing of personal data, they may contact the Controller at:
email address: office@axenlogistics.eu
telephone number: +421 918 863 503
the Operator’s registered office address.
If the Controller has appointed a data protection officer in accordance with the GDPR, the data protection officer’s contact details will be published on the Controller’s website or made available upon request by the data subject.
Article II
Categories of data subjects and the scope of personal data processed
The controller processes personal data only to the extent necessary to achieve the purposes set out in this Privacy Policy and in accordance with the data minimisation principle under the GDPR.
The controller may process personal data relating, in particular, to the following categories of data subjects:
clients and their contact persons,
carriers, sub-carriers and their contact persons,
drivers involved in carrying out the transport,
representatives of business partners and suppliers,
visitors to the Operator’s website,
persons communicating with the Operator via email, telephone, the eCargo system or other means of communication,
job applicants or those seeking other forms of collaboration, where the Controller is recruiting.
The controller may process the following categories of personal data in particular:
personal details, in particular first name, surname, company name, job title or position,
contact details, in particular the address, email address, telephone number and contact details set out in the contractual or commercial documentation,
data relating to the conclusion and performance of contractual relationships, in particular data contained in orders, contracts, transport documents, complaints reports or insurance documentation,
details of drivers and persons involved in carrying out the transport, in particular their first name, surname, telephone number, signature, the details stated in the transport documents and the identification details required for organising the transport,
data on vehicle movements and the transport process, in particular GPS data, location data, route data, data on loading and unloading times, and other data relating to the monitoring of transport,
data contained in communications between the Controller and the data subject, including email correspondence, records of telephone conversations, communications via the eCargo system or other electronic platforms,
information contained in photographs, video recordings, documentation relating to damage claims, insurance claims, complaints or security incidents,
technical and electronic data collected whilst using the Operator’s website, in particular the IP address, device details, details of the web browser used, and data collected via cookies or similar technologies.
As a rule, the controller does not process special categories of personal data as defined in Article 9 of the GDPR. Where the processing of such data is necessary to comply with a legal obligation, to establish, exercise or defend legal claims, or for any other reason permitted by the GDPR, the Controller shall ensure that such data is adequately protected.
The controller does not obtain personal data exclusively from data subjects. Personal data may also be obtained from clients, carriers, sub-carriers, business partners, insurance companies, public registers, public authorities or other lawful sources, where this is necessary to fulfil the Controller’s contractual or legal obligations.
Article III
Purposes and legal bases for the processing of personal data
The controller processes personal data only to the extent necessary to achieve a specific purpose of processing and only on the basis of one of the legal grounds set out in Article 6 of the GDPR or specific legislation.
The controller processes personal data primarily for the following purposes:
the conclusion, fulfilment, record-keeping and management of contractual relationships with clients, carriers, sub-carriers, suppliers and business partners,
the organisation, arrangement, coordination and provision of domestic and international transport and freight forwarding services,
communication with clients, hauliers, drivers, business partners and other parties involved in the transport operation,
recording and managing orders, transport documents, contracts, delivery notes, CMR or eCMR consignment notes and other commercial documentation,
vetting of carriers, sub-carriers, drivers, business partners and other entities to protect against fraudulent behaviour, identity theft, phantom carriers or other security risks,
monitoring the progress of transport, ensuring the security of consignments and the protection of property, and meeting clients’ security requirements through the use of GPS data, location data and other operational data,
handling complaints, claims, insurance claims, recourse claims, legal disputes and the out-of-court enforcement of legal claims,
the protection of the rights, legally protected interests and property of the Controller, its clients or business partners,
compliance with obligations arising from legislation, in particular in the areas of accounting, taxation, transport, document archiving, data protection, the fight against fraud, and the implementation of sanctions or security measures,
the management of user accounts, electronic communications and electronic systems used in the organisation of transport, including the eCargo system or similar platforms,
the operation of the Controller’s website, the management of electronic services, ensuring the website functions properly, and analysing its usage,
marketing communications, the sending of commercial communications or information about the Controller’s services, provided there is an appropriate legal basis for doing so.
The legal basis for the processing of personal data may include, in particular:
the performance of a contract or the taking of steps prior to entering into a contract in accordance with Article 6(1)(b) of the GDPR,
compliance with the Controller’s legal obligation under Article 6(1)(c) of the GDPR,
the legitimate interests of the Controller or a third party pursuant to Article 6(1)(f) of the GDPR,
the data subject’s consent in accordance with Article 6(1)(a) of the GDPR, where required in a specific case.
The Controller’s legitimate interests may include, in particular:
the protection of the Controller’s property, rights and legally protected interests,
protection against fraudulent activity, identity theft, phantom carriers, unauthorised collection of parcels or other security risks,
vetting of carriers, subcontractors, drivers and business partners,
the assertion, substantiation or defence of legal claims,
ensuring the safety of transport, the protection of consignments and the smooth running of freight forwarding processes,
maintaining internal records, managing business relationships and improving the quality of the services provided.
Where the processing of personal data is based on the data subject’s consent, the data subject may withdraw their consent at any time in the manner specified in the relevant notice or by contacting the Controller. Withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal.
Article IV
Recipients of personal data and the disclosure of personal data
The controller may disclose or provide personal data only to the extent necessary to achieve the purpose of the processing and only to authorised recipients who are bound by a duty of confidentiality or another legal obligation to protect personal data.
Personal data may be disclosed or provided, in particular, to:
the Operator’s clients,
carriers, subcontractors, drivers and other persons involved in the provision of transport services,
business partners and service providers involved in the organisation and execution of transport,
insurance companies, reinsurance companies, claims adjusters, insurance brokers and other entities involved in the settlement of insurance claims,
lawyers, tax advisers, auditors, experts, debt collection agencies or other specialist advisers to the Controller,
providers of information systems, cloud services, hosting services, GPS monitoring systems, electronic communications services, the eCargo system or other technological solutions used by the Operator,
banks, financial institutions and payment service providers,
to a public authority, a court, a law enforcement agency, an administrative authority or any other authorised body, where so provided for by law or by a decision of the competent authority.
The controller may also disclose personal data to other entities where this is necessary for:
fulfilment of contractual obligations,
the protection of the rights and legitimate interests of the Controller, its clients or business partners,
handling complaints, claims, insured events or recourse claims,
vetting of carriers, subcontractors, drivers or business partners for the purposes of fraud prevention, protecting consignments and ensuring the safety of transport,
the assertion, substantiation or defence of legal claims.
Where the Controller uses data processors in accordance with the GDPR, it shall ensure that the processing of personal data is carried out on the basis of a written contract or other legal instrument in accordance with Article 28 of the GDPR.
The controller does not disclose personal data to third parties for their own marketing purposes, unless there is a specific legal basis for doing so or the data subject has given their consent.
Every recipient of personal data is authorised to process personal data only to the extent necessary to fulfil the purpose for which the data was made available or provided to them.
Article V
Transfer of personal data to third countries
As a rule, the controller processes personal data within the territory of the Member States of the European Union or the European Economic Area (EEA).
In justified cases, personal data may be transferred to a third country or an international organisation if such a transfer is necessary for the performance of a contract, the provision of international transport, the use of information systems or the provision of services used by the Controller.
Where personal data is transferred outside the European Union or the European Economic Area, the Controller shall ensure that such a transfer is carried out in accordance with the GDPR and that an adequate level of protection of personal data is ensured.
The transfer of personal data to a third country may be carried out, in particular:
to a country which the European Commission has determined ensures an adequate level of protection of personal data,
on the basis of standard contractual clauses approved by the European Commission,
on the basis of other appropriate safeguards or data protection mechanisms under the GDPR,
in cases expressly permitted by the GDPR, where the transfer is necessary for the performance of a contract or the exercise of legal claims.
In connection with the use of email, cloud services, GPS tracking systems, communication platforms, the eCargo system or other information technologies, personal data may be processed by service providers operating outside the European Union or the European Economic Area. In such cases, the Controller takes appropriate measures to ensure the protection of personal data in accordance with the GDPR.
The data subject may request information from the Controller regarding a specific transfer of personal data to a third country, including information on the safeguards in place, provided that disclosure is not restricted by law or by the rights of third parties.
Article VI
Retention period for personal data
The data controller retains personal data only for as long as is necessary to fulfil the purpose for which it was collected, or for as long as required by the relevant legislation.
The retention period for personal data depends primarily on the purpose of the processing, the nature of the data being processed, the Controller’s legal obligations and the need to protect its rights and legitimate interests.
Personal data processed for the purposes of entering into, performing and recording contractual relationships may be retained for the duration of the contractual relationship and, following its termination, for the period necessary to protect the rights and legitimate interests of the Controller, but at least until the expiry of the relevant limitation or preclusion periods.
The Controller retains personal data contained in accounting, tax and related documents for the period specified by the relevant legislation.
Personal data relating to complaints, claims, insured events, recourse claims, court proceedings, arbitration proceedings, administrative proceedings or other disputes shall be retained by the Controller for the duration of the relevant proceedings and subsequently for the period necessary to protect and enforce legal claims.
Personal data processed for the purposes of vetting carriers, sub-carriers, drivers and business partners, as well as for the purposes of fraud prevention, the protection of consignments and transport security, shall be retained by the Controller for the period necessary to achieve the aforementioned purposes and to protect its legitimate interests.
Data relating to the course of transport, GPS data, location data, communication records, photographs, documentation of security incidents, complaints, claims or insurance claims may be retained for as long as necessary to protect the rights of the Operator, its clients or business partners, in particular for the purposes of demonstrating compliance with contractual obligations, handling complaints, insurance claims and recourse claims.
Personal data processed on the basis of the data subject’s consent shall be retained by the Controller for the duration of the consent or until it is withdrawn, unless a specific legal provision or other legal basis permits its further processing.
Once the relevant retention period has expired, the Controller shall erase the personal data, anonymise it or ensure its destruction in a manner appropriate to the nature of the data and in accordance with the requirements of the law.
Article VII
Rights of data subjects
In relation to the processing of their personal data, data subjects have the rights set out in the GDPR, Act No. 18/2018 Z. z. on the Protection of Personal Data and other relevant legislation.
In particular, the data subject has the right to:
to request confirmation as to whether the Controller is processing her personal data,
to access your personal data and obtain information about its processing,
to request the rectification of incorrect or incomplete personal data,
to request the erasure of personal data, provided that the conditions laid down in the GDPR are met,
to request a restriction on the processing of personal data in the cases set out in the GDPR,
to object to the processing of personal data carried out on the basis of the Controller’s legitimate interest,
to receive the personal data they have provided to the Controller in a structured, commonly used and machine-readable format, and to request that it be transferred to another controller, provided that the conditions set out in the GDPR are met,
to withdraw consent to the processing of personal data at any time, where the processing is based on consent; the withdrawal of consent does not affect the lawfulness of processing carried out prior to its withdrawal.
The rights of the data subject may be restricted to the extent permitted by the GDPR or specific legislation, in particular where processing is necessary:
to fulfil the Controller’s legal obligation,
for the purpose of asserting, proving or defending legal claims,
to protect the rights and legitimate interests of the Controller, its clients, business partners or third parties,
for the handling of complaints, claims, insured events, recourse claims or the conduct of judicial, administrative or other proceedings.
The data subject may exercise their rights in writing, electronically or by any other means that allows them to prove their identity.
The controller shall process the data subject’s request without undue delay, and at the latest within the time limit laid down in the GDPR. In justified cases, this time limit may be extended in accordance with the GDPR.
If the data subject considers that the processing of their personal data is in breach of the GDPR or the relevant legislation, they have the right to lodge a complaint or bring proceedings before the Office for Personal Data Protection of the Slovak Republic, or to apply to the competent court.
The exercise of a data subject’s rights is free of charge, unless otherwise provided for in the GDPR or relevant legislation.
Article VIII
Cookies and technologies used on the website
The Controller’s website may use cookies, similar technologies and other technical tools to ensure the website functions correctly, enhance security, analyse visitor traffic, improve the user experience and provide selected electronic service features.
Cookies are small text files that are stored on a user’s device when they visit a website and enable the user’s device to be recognised or certain information about their use of the website to be recorded.
In particular, the operator may use:
essential cookies required for the website to function properly,
analytical and statistical cookies used to analyse website traffic and usage,
functional cookies that enable user settings to be remembered,
marketing or advertising cookies, if these are used on the website.
Cookies that are not essential for the operation of the website are used only on the basis of the relevant legal grounds and, where required by law, only after the user has given their consent.
Users can manage their cookie settings via the cookie banner displayed when they visit the website or via their web browser settings. However, restricting the use of cookies may affect the functionality of certain parts of the website.
Detailed information on the cookies used, their purposes, retention periods and management options is set out in a separate document entitled „Policy on the Use of Cookies and Similar Technologies by AXEN Logistics s.r.o.“ published on the Controller’s website.
Article IX
Processing of personal data for the purposes of security, fraud prevention and vetting business partners
The controller also processes personal data for the purposes of protecting its rights and legitimate interests, protecting customers, safeguarding consignments, preventing fraudulent behaviour, preventing damage and ensuring the security of transport.
For the purposes set out above, the Controller may process the personal data of clients, carriers, sub-carriers, drivers, contact persons and other individuals involved in the organisation or provision of transport services.
To the extent necessary to achieve the aforementioned purposes, the controller may, in particular:
vetting of carriers, subcontractors, drivers and business partners prior to entering into a business relationship or during the course of such a relationship,
verification of identification, registration, contact and operational details,
verification of licences to carry out transport activities and related authorisations,
verifying the validity of insurance cover and insurance-related details,
verifying information available in public registers, lists or databases,
verifying facts relating to suspected fraudulent behaviour, identity theft, unauthorised collection of a consignment, unauthorised use of a vehicle or other security risks,
the recording and assessment of security incidents, damage claims, insurance claims, customer complaints and recourse claims,
monitoring the progress of the consignment using GPS data, location data or other data relating to the vehicle’s movements, where necessary to ensure the safe delivery of the consignment, protect the consignment or fulfil contractual obligations.
The legal basis for the processing of personal data under this Article is the Controller’s legitimate interest pursuant to Article 6(1)(f) of the GDPR, consisting in particular of:
the protection of the Operator’s assets, those of its clients and business partners,
the protection of consignments and the prevention of damage,
protection against fraudulent behaviour, bogus carriers, unauthorised recipients or other forms of abuse,
verifying the reliability of business partners,
the assertion, substantiation or defence of legal claims,
compliance with insurers’ requirements, insurance terms and conditions, and safety standards applied in the transport and logistics sector.
The controller shall take appropriate technical, organisational and security measures to protect the personal data being processed against unauthorised access, loss, misuse, destruction or unauthorised disclosure.
The processing of personal data under this Article shall be carried out only to the extent necessary for the purpose pursued and for the period necessary to protect the rights and legitimate interests of the Controller, its clients and business partners.
Article X
Final Provisions
The Data Controller is entitled to amend or supplement this Privacy Policy as appropriate, in particular in the following cases: (a) changes to legislation, (b) changes to the way in which personal data is processed, (c) changes to the services provided, (d) changes to technical or organisational measures, (e) changes relating to the use of the Operator’s website or electronic systems.
The current version of the Privacy Policy is published on the Controller’s website.
If the Controller uses cookies or similar technologies on its website, details of their use may be set out in a separate document entitled „Rules on the Use of Cookies and Similar Technologies by AXEN Logistics s.r.o.“, which is published on the Controller’s website.
This Privacy Policy applies, as appropriate, to personal data processed in connection with the provision of the Controller’s freight forwarding, logistics and related services, unless otherwise provided for in a separate document or by law.
This Privacy Policy shall come into force and take effect on 24 June 2026.
We help businesses deliver goods quickly, safely and efficiently.
Contact
Get a tailor-made offer
We will prepare a logistics solution according to your needs and provide reliable and efficient transport for your business throughout Europe.