Skip to content

Legal

Data Processing Agreement

Version 2026-09-26 — 26 September 2026. This agreement is between TAGQA PTY LTD (ABN 45 634 337 778) of Melbourne, VIC, Australia ("we", the processor) and the organisation using SCMTR ("you", the controller, or the fiduciary under India's Digital Personal Data Protection Act, 2023). It supplements the Terms of Service and the Privacy Policy, and takes effect when an Org Admin accepts it in Settings → Enterprise.

1. What we process, and why

Subject matter. The personal data inside the customs filings you prepare and the files you upload — CSNs, vessel manifests, acknowledgements and customs' replies, and documents such as bills of lading — and the account data of your organisation's members.

Categories of data subjects. Your members; and the people your filings name — consignors, consignees, notify parties, shipping-line and forwarder contacts.

Categories of data. Names, postal addresses, business identifiers such as PAN and IEC, e-mail addresses and telephone numbers where a filing carries them, and the shipment details around them. SCMTR is not designed for, and you should not upload, special categories of personal data.

Purposes. Only to provide the service you use: preparing, checking and — on your instruction — transmitting filings to ICEGATE; reading customs' replies and linking them to your filings and vessel calls; keeping uploaded files so they can be reopened and matched over time; the alerts, API and webhooks you configure; support you ask for; and securing the service. The privacy policy also describes our use of kept files to improve how SCMTR reads and checks files; we do not sell personal data, advertise with it, or use it to train AI models.

2. Your instructions

We process personal data only on your documented instructions — which are this agreement, the terms, and what your members and your systems do in SCMTR — unless the law requires otherwise, in which case we tell you first where the law allows. A webhook endpoint or API key your Org Admin configures is an instruction to send the events and files it covers to where you point it; what happens to them there is yours.

3. Confidentiality and our people

Everyone at TAGQA with access to your data is bound by confidentiality. A platform super administrator may open a kept file to help you or to keep the service running; every opening is recorded — who, which file, when — and you may ask to see those records.

4. Security

  • Encryption in transit (TLS) and at rest.
  • Row-level isolation between organisations enforced in the database itself, not only in application code.
  • Database-backed sessions that end the moment a member is removed; API keys kept only as hashes; webhook signing secrets and filing credentials kept encrypted.
  • An audit trail of administrative and filing actions, including support impersonation sessions and every read of a kept file.
  • Controls you set: an IP allow-list for your organisation, your own file-retention period, and deletion of your uploaded files on request.

5. Sub-processors

You authorise these sub-processors, each bound by written terms that protect the data at least as this agreement does:

Sub-processorWhatWhere
Google Cloud PlatformThe application, its database and backups, the storage bucket holding uploaded files, and our cacheMumbai, India
Google Cloud LoggingRequest and operational logs, 30 daysNot pinned to a region
Google Vertex AIQuestions typed into the SCMTR assistant, suggestions typed into the roadmap, and feedback our staff review; and bills of lading e-mailed to our bills address, with the e-mail's text, read to draft a checklistIndia (Mumbai, asia-south1) to find matching material; the answer or draft is then written through Google's global endpoint, so it may be processed in any of Google's regions. Bills are read through the global endpoint
AnthropicA second reading of each bill of lading e-mailed to our bills address, to check its critical values against the first; the bill only, and not used to train Anthropic's modelsUnited States
Google WorkspaceE-mail we send you, and files e-mailed to our checking address or our bills addressNot pinned to a region
ZeptoMail (Zoho)A second route for outgoing e-mailAustralia
ExpoPhone notifications: a job number, a vessel name and a one-line status — never a party or a documentUnited States

We will tell your Org Admins at least 30 days before adding or replacing a sub-processor, by changing this list and this agreement's version, which Settings → Enterprise then shows as not yet accepted. If you object on reasonable data-protection grounds and we cannot address it, you may stop using the affected part of the service or end the agreement.

6. Transfers outside India

Your filings and uploaded files are stored in India. The transfers in the table above are the only ones, each for the purpose shown, and are made as India's Digital Personal Data Protection Act permits.

7. Helping you meet your obligations

Taking into account what we process and the information available to us, we help you answer data principals' requests (access, correction, erasure), carry out data-protection assessments, and deal with regulators — chiefly through the service itself: your members can read and correct your filings, your Org Admins can export your audit log where your plan includes it and delete your uploaded files, and your API keys can read your files back. For anything the service does not do, write to support@scmtr.io.

8. Personal data breaches

We notify your Org Admins without undue delay, and in any case within 72 hours of confirming a breach affecting your data, with what we know of its nature, the data and people affected, its likely consequences and what we are doing about it — and keep you updated as we learn more. We do not wait for a complete picture before telling you.

9. Retention, return and deletion

Uploaded files are kept for two years after they were last received, or for the period your Org Admin sets in Settings → Enterprise (90 days to ten years), or for as long as a filing sent from SCMTR still relies on them. Your Org Admin can have every uploaded file deleted at any time; deletion starts 24 hours after the request and removes the stored bytes as well as the records. When the agreement ends, we delete your organisation's personal data within 90 days, except filed declarations and their audit trail, which we keep only as long as customs-law record-keeping requires and then delete. Before then you can take a copy of your files through the API.

10. Audits

We make available the information reasonably needed to show we meet this agreement — including our security measures, sub-processor list and your organisation's audit log — and answer a reasonable written questionnaire once a year, or after a breach. An on-site audit, where the law gives you that right, is by prior arrangement, at your cost, under confidentiality.

11. Liability and precedence

Liability under this agreement is as set out in the Terms of Service. Where this agreement and the terms disagree about personal data, this agreement applies. It is governed by the same law as the terms, without limiting any right your own law gives data principals.

Contact

Data-protection questions and breach reports: support@scmtr.io (mark your message "Data protection").