Surgewave

Privacy Policy

Homeprivacy

Privacy Policy

Effective: August 30, 2025

Last Updated: August 30, 2025
1

Introduction

At Surgewave, we prioritize the privacy and security of your personal data in accordance with global data protection regulations including GDPR, CCPA, and Global's NDPR. This policy explains how we handle information related to your shipments, payments, and account management.

As an international logistics provider, we process personal data across borders while maintaining strict confidentiality standards. By using our services, you consent to the practices described in this policy.

2

Data We Collect

Personal Information

  • Contact Details: Name, email, phone, address of shippers and recipients
  • Business Information: Company name, tax ID, import/export licenses
  • Identification: Government-issued ID for customs clearance when required

Shipping Data

  • Shipment Details: Contents, value, weight, dimensions, HS codes
  • Tracking Data: Location history, delivery confirmation signatures
  • Customs Documentation: Commercial invoices, certificates of origin

Financial Information

  • Payment Details: Card tokens (processed through PCI-compliant gateways)
  • Transaction Records: Payment history, refund requests
3

How We Use Data

Shipment Processing

To prepare customs declarations, calculate duties, and arrange transportation

Compliance

To meet export control, sanctions screening, and regulatory requirements

Service Improvement

To optimize routes, estimate delivery times, and enhance our platform

Communication

To send shipment updates, invoices, and service notifications

We retain shipment data for 7 years to comply with customs regulations and financial reporting requirements. Account data is retained for 3 years after last activity unless legally required otherwise.

4

Legal Basis for Processing

  • Contractual Necessity: Processing required to fulfill shipping contracts
  • Legal Obligation: Compliance with customs, tax, and transport laws
  • Legitimate Interest: Fraud prevention and service improvement
  • Consent: For marketing communications and non-essential cookies
5

Data Sharing

We share minimum necessary data with:

Carriers & Agents

Only contact and address details needed for pickup/delivery

Customs Authorities

Commercial invoices and regulatory documents as required by law

Fraud Prevention Services

Limited payment data for transaction verification

Cloud Service Providers

Encrypted data stored in GDPR-compliant facilities

We never sell customer data. Third-party access is governed by strict data processing agreements.

6

International Data Transfers

As an international logistics provider, your data may be transferred to and processed in:

  • Origin and destination countries for customs clearance
  • Transit countries where shipment tracking occurs
  • Our regional offices in Lagos, London, and Dubai

All transfers utilize Standard Contractual Clauses or other approved mechanisms under GDPR. Sensitive data is encrypted in transit.

7

Data Security

Technical Measures

  • • AES-256 encryption for data at rest
  • • TLS 1.3 for all data transmissions
  • • Regular penetration testing

Organizational Measures

  • • Strict access controls (role-based)
  • • Employee confidentiality agreements
  • • Annual privacy training

We maintain ISO 27001 certification and undergo regular SOC 2 Type II audits. Despite our measures, no internet transmission is 100% secure.

8

Your Rights

Access & Portability

Request a copy of your data in machine-readable format

Correction

Update inaccurate or incomplete information

Deletion

Request erasure where no legal retention requirement exists

Restriction

Limit processing while disputes are resolved

To exercise these rights, contact our Data Protection Officer at dpo@hotmail.com. We respond within 30 days and may request verification.

9

Cookies

We use cookies to enhance your experience on our platform:

  • Essential Cookies: Required for website functionality and security
  • Analytics Cookies: Help us understand user behavior to improve services
  • Marketing Cookies: Used for personalized ads, with your consent

You can manage cookie preferences through our cookie banner or browser settings. Essential cookies cannot be disabled.

10

Changes to This Policy

We may update this policy to reflect changes in our practices or legal requirements. Significant changes will be communicated via email or website notifications at least 30 days before they take effect.

Continued use of our services after changes constitutes acceptance of the updated policy.

11

Contact Us

For privacy concerns or data requests:

Data Protection Officer

dpo@hotmail.com

Privacy Hotline

(+0123) 2345 56789

Mon-Fri, 9AM-5PM WAT

Postal Address

Data Protection Office
265 New Ave, California City-1001, USA

Supervisory Authority

Global Data Protection Bureau
complaints@ndpb.gov