Data Processing Addendum

  • Terms of Service
  • Privacy Policy
  • Data Processing Addendum
  • Subscription & Billing Terms

Last Updated: August 26, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other agreement between DZX Logistics LLC, doing business as ATREK (“Processor”) and Customer (“Controller”) and applies when ATREK processes Personal Data on Customer’s behalf.

1. Definitions and scope

“Personal Data,” “Controller,” “Processor,” “Service Provider,” “Business,” “Consumer,” and similar terms have the meanings given by applicable data-protection law. “Customer Personal Data” means Personal Data processed by ATREK on Customer’s documented instructions through the Services.

Customer is the Controller or Business, and ATREK is the Processor or Service Provider, except where ATREK independently determines purposes described in the Privacy Policy.

2. Instructions and compliance

Customer authorizes ATREK to process Customer Personal Data as necessary to provide, operate, configure, secure, support, diagnose, enforce, and administer the Services and agreement for Customer; carry out Customer’s documented instructions and authorized requests; use subprocessors; prevent fraud, abuse, and security threats; and comply with applicable law.

ATREK may analyze Customer Personal Data only where reasonably necessary to provide, secure, support, diagnose, or improve the Services within the direct business relationship with Customer and as permitted by applicable law. Broader product analysis or improvement across customers must use aggregated or de-identified information that does not reasonably identify Customer or an individual. Customer Personal Data will not be used for targeted advertising or to train a general-purpose model for unrelated purposes without separate authorization.

To the extent ATREK is legally treated as Customer’s Processor or Service Provider, Customer’s agreement, configurations, support requests, and authorized use constitute documented instructions. ATREK has no duty to evaluate the legality or adequacy of those instructions except where applicable law expressly requires it.

Customer is solely responsible for the lawfulness, accuracy, notices, consents, legal basis, instructions, retention decisions, and use of Customer Personal Data. This includes providing any California or other notice at collection before ATREK collects precise location, driver, employment, communications, financial, health-related, or other sensitive personal information on Customer’s behalf.

3. Processing details

  • Subject matter: provision of ATREK transportation-management, communication, document, accounting-workflow, integration, and tracking software.
  • Duration: the term of the Services plus the deletion and retention period stated in this DPA.
  • Nature and purpose: collection, storage, organization, transmission, retrieval, display, analysis, AI-assisted document recognition, OCR, extraction, classification, support, security, and deletion as needed to provide the Services.
  • Data subjects: Customer users, administrators, employees, applicants, drivers, owner-operators, contractors, brokers, shippers, consignees, business contacts, and other persons whose data Customer submits.
  • Data: identity, contact, employment, licensing, vehicle, insurance, tax, banking, logistics, load, route, precise location, communication, document, extracted text and fields, AI or OCR input and output, device, authentication, usage, billing, and support information.
  • Sensitive data: may include precise location, government identifiers, driver-license information, medical-card data, financial details, credentials, and identity or work-eligibility documents, depending on Customer’s use.

4. Confidentiality and personnel

ATREK limits access to Customer Personal Data to authorized personnel and providers that require access for purposes connected with the Services. Personnel authorized to process Customer Personal Data are subject to confidentiality obligations appropriate to their role and access. These obligations do not require ATREK to disclose personnel records, privileged information, security-sensitive information, or provider-confidential information to Customer.

5. Security

ATREK maintains administrative, technical, and organizational safeguards designed for the nature of Customer Personal Data and the risks presented by the processing, consistent with the Privacy Policy and applicable data-protection law. ATREK may select and modify particular measures, technologies, architecture, locations, and providers as the Services and risks evolve.

No particular control, certification, encryption method, backup schedule, recovery objective, audit standard, or security outcome is promised unless stated in a signed order form. No measure guarantees absolute security. Customer remains solely responsible for permissions, devices, credentials, integrations, lawful collection, internal controls, and secure configuration and use.

6. Security incidents

ATREK provides Customer notice of a confirmed breach affecting Customer Personal Data only to the extent, in the manner, and within the time required by applicable law or a signed order form. ATREK has no broader contractual notification, investigation, reporting, remediation, reimbursement, or cooperation obligation.

Any notice is informational, is not an admission of fault or liability, and may be delayed or limited for security, provider, legal, or law-enforcement reasons. Customer is solely responsible for legal analysis and notices to individuals, counterparties, insurers, and authorities unless mandatory law assigns a specific duty to ATREK.

7. Subprocessors

Customer gives ATREK general authorization to select, replace, and use subprocessors. ATREK determines their identity, location, scope, and technical role and may update the Subprocessors & Third-Party Services notice.

ATREK imposes subprocessor terms only to the extent required by applicable law. Advance notice is provided only where applicable law or a signed order form requires it. Customer may object within 15 days solely on specific, documented legal grounds and must cooperate on a commercially reasonable solution.

If ATREK determines that no reasonable alternative is available, Customer’s sole remedy is to stop using and terminate the affected Service. Termination creates no refund right except where mandatory law requires one. ATREK’s responsibility for subprocessors is limited by the Terms of Service.

8. Individual rights and government requests

Customer is solely responsible for receiving, verifying, evaluating, and responding to individuals and authorities. ATREK may direct any request concerning Customer-controlled data to Customer.

ATREK provides assistance only to the extent mandatory law requires and only when Customer cannot complete the task through standard Service functions. Customer must provide complete instructions and reimburse ATREK’s reasonable time and costs.

ATREK may disclose information it reasonably believes is required or appropriate by law or to protect ATREK, the Services, providers, rights, security, or safety. Notice to Customer is provided only when legally required and not prohibited.

9. Assessments, audits, and compliance assistance

ATREK provides compliance documentation, assessment assistance, consultation support, or audit access only to the extent mandatory law requires.

Documentation and independent reports selected by ATREK are used first and are sufficient where they reasonably address the legal requirement. Any further audit is limited to once in 12 months unless a regulator legally requires more; requires at least 30 days’ notice; occurs during normal business hours; must not disrupt operations; and must use an independent non-competitor approved by ATREK and bound by confidentiality.

No audit may access another customer’s data, source code, security-sensitive details, privileged material, provider-confidential material, or ATREK’s pricing and financial records. Customer pays all audit, assistance, remediation-review, and personnel costs and must provide ATREK the final report.

10. Return and deletion

During the subscription and 30-day limited-access period, Customer may access data using administrator credentials and then-available platform functions. ATREK does not provide a dedicated export, migration, custom extraction, or restoration service. Customer is solely responsible for preserving required information before the deadline.

After that period, ATREK will delete Customer Personal Data from active systems unless law or a valid legal hold permits or requires retention. Backup copies expire through standard rotation, are not available for ordinary customer restoration, and remain protected until deletion. Legal, security, tax, accounting, billing, consent, and dispute records may be retained as ATREK reasonably determines necessary.

11. California service-provider terms

Where the California Consumer Privacy Act applies, ATREK acts as a Service Provider or Contractor for Customer Personal Information and will not:

  • sell or share it;
  • retain, use, or disclose it outside the direct business relationship or for purposes other than the business purposes specified in the agreement, except as permitted by law;
  • combine it with personal information received from another person or collected from ATREK’s own consumer interactions except as legally permitted.

ATREK will provide the same level of privacy protection required by applicable law, notify Customer if it can no longer comply, and allow reasonable steps to stop and remediate unauthorized use.

12. Processing locations and international transfers

ATREK’s production servers are located in the United States. Third-party providers may process Customer Personal Data in other locations as permitted by the agreement and applicable law. If Customer Personal Data is transferred from a jurisdiction requiring a transfer mechanism, the parties will use the applicable standard contractual clauses or other lawful mechanism. The relevant controller-to-processor module applies unless another module is legally required.

13. Order of precedence and liability

If this DPA conflicts with the agreement solely regarding processing Customer Personal Data, this DPA controls. All other terms remain unchanged.

A material new version of this DPA may require acceptance by a Company Administrator or another representative authorized to bind Customer.

All liability arising from this DPA, including subprocessor acts, security incidents, assistance, deletion, and international transfers, is subject to the exclusions and aggregate liability cap in the Terms of Service. The DPA does not create a separate or additional liability cap. Customer’s obligations concerning lawful instructions, consents, Customer Data, indemnification, and violations of law remain subject to the Terms of Service and are not limited by this DPA.

Related documents

See the Subprocessors & Third-Party Services notice for the current provider framework.