Privacy Policy Introduction
Effective Date: 17 May 2025 Version: 1.0
1. Introduction
Welcome to FAGi Logistics ("FAGi", "we", "our", or "us"). This Privacy Policy explains how FAGi Logistics collects, uses, stores, protects, shares, and processes personal information when individuals and organizations use our services. Protecting privacy is a fundamental part of our business operations and corporate governance. FAGi Logistics is committed to maintaining the confidentiality, integrity, availability, and security of personal information through responsible data management practices and internationally recognized privacy principles. This Privacy Policy applies to all FAGi websites, mobile applications, driver platforms, business platforms, customer platforms, administrative systems, payment services, APIs, customer support channels, and any other products or services operated by FAGi Logistics. By accessing or using our services, you acknowledge that you have read and understood this Privacy Policy. Where required by applicable law, we will request your consent before processing personal information for specific purposes. This chapter establishes the foundation of the FAGi Logistics Privacy Policy. Subsequent chapters describe in detail how personal data is collected, processed, protected, retained, shared, and securely deleted throughout the lifecycle of our services.
2. Corporate Privacy Commitment
At FAGi Logistics, privacy is a core business value and an essential component of our governance framework. We recognize that customers, business partners, drivers, employees, suppliers, and visitors entrust us with their personal information. We are committed to handling that information responsibly, securely, and transparently throughout every stage of its lifecycle.
Our objective is to build and maintain trust by applying consistent privacy standards across all products, services, technologies, and business operations. Privacy considerations are incorporated into business planning, software development, operational procedures, vendor management, and information security practices.
FAGi Logistics is committed to:
• Processing personal information lawfully, fairly, and transparently.
• Collecting only information that is necessary for legitimate business purposes.
• Protecting personal information through appropriate administrative, technical, and physical
safeguards.
• Limiting access to authorized personnel based on business need.
• Maintaining accurate and up-to-date information where reasonably possible. • Responding promptly to privacy requests and security incidents.
• Continuously improving our privacy and information security programme.
Every employee, contractor, consultant, and approved third-party service provider acting on behalf of FAGi Logistics is expected to comply with this Privacy Policy and applicable data protection laws. Failure to do so may result in disciplinary action, contractual remedies, or other appropriate measures.
3. Scope of Application
This Privacy Policy applies to all products, services, systems, applications, websites, platforms, technologies, and business activities operated by or on behalf of FAGi Logistics unless a separate privacy notice explicitly states otherwise.
The Policy governs the processing of personal information relating to customers, business clients, merchants, drivers, job applicants, employees, contractors, suppliers, website visitors, and other individuals who interact with FAGi Logistics.
This Policy applies to, including but not limited to:
• The FAGi Driver App
• The FAGi Business App
• Customer-facing digital services
• Administrative and dispatch platforms
• Official websites and web portals
• Customer support communications
• Payment processing and billing activities
• Marketing and promotional communications
• Logistics, delivery, and transportation operations
• APIs, integrations, and connected services approved by FAGi Logistics.
All employees, officers, directors, temporary staff, consultants, contractors, and authorized third-party service providers who process personal information on behalf of FAGi Logistics are required to comply with this Privacy Policy, internal security standards, confidentiality obligations, and all applicable privacy and data protection laws.
Where local legislation imposes additional privacy requirements, FAGi Logistics will apply those requirements alongside this Privacy Policy to ensure the highest appropriate standard of protection for personal information.
4. Definitions
For the purposes of this Privacy Policy, the following terms shall have the meanings set out below. These definitions are intended to ensure consistent interpretation throughout all FAGi Logistics products, services, and business operations.
Account
A registered profile created to access one or more FAGi services.
Personal Data
Any information relating to an identified or identifiable natural person, whether collected directly or indirectly.
Processing
Any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, restriction, deletion, or destruction.
Customer
Any individual requesting, receiving, or interacting with FAGi Logistics services.
Business Customer
Any company, merchant, organization, or institution using FAGi Logistics for logistics, transportation, commerce, or related business services.
Driver
An approved delivery professional authorized to provide services through the FAGi Driver App.
Controller
The organization that determines the purposes and means of processing Personal Data.
Processor
A third party that processes Personal Data on behalf of FAGi Logistics under a contractual obligation.
Applicable Law
All privacy, data protection, cybersecurity, and related legislation applicable to FAGi Logistics in jurisdictions where it operates.
Unless the context requires otherwise, words in the singular include the plural, and
references to persons include individuals, companies, partnerships, government authorities, and other legal entities. Additional definitions may be introduced in future revisions of this Privacy Policy where necessary.
5. Privacy Principles
FAGi Logistics processes Personal Data in accordance with internationally recognized privacy principles and applicable data protection legislation. These principles guide every stage of the information lifecycle and are integrated into our governance, technology, operational processes, and business decision-making.
5.1 Lawfulness, Fairness and Transparency
Personal Data is processed lawfully, fairly, and transparently. Individuals are informed about how their information is collected, used, shared, retained, and protected.
5.2 Purpose Limitation
Personal Data is collected only for specified, explicit, and legitimate purposes and is not processed in a manner incompatible with those purposes unless required or permitted by law.
5.3 Data Minimization
FAGi collects only the Personal Data that is necessary, relevant, and proportionate to provide services, comply with legal obligations, improve operations, and protect users.
5.4 Accuracy
Reasonable steps are taken to ensure that Personal Data remains accurate, complete, and up to date. Individuals may request corrections where information is inaccurate.
5.5 Storage Limitation
Personal Data is retained only for as long as necessary to fulfil business, contractual, legal, and regulatory obligations. Information is securely deleted or anonymized when retention periods expire.
5.6 Integrity and Confidentiality
Administrative, technical, and physical safeguards are implemented to protect Personal Data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
5.7 Accountability
FAGi Logistics maintains internal governance, documented policies, employee training, risk assessments, audits, and continuous monitoring to demonstrate compliance with applicable privacy and data protection requirements.
Legal Basis for Processing
6. Legal Basis for Processing
FAGi Logistics processes Personal Data only where a valid legal basis exists under applicable privacy and data protection laws. We are committed to ensuring that every processing activity is supported by an appropriate legal justification and carried out in a lawful, fair, and transparent manner.
6.1 Performance of a Contract
We process Personal Data when it is necessary to provide our logistics services, create and manage accounts, assign deliveries, process payments, communicate with users, and fulfil contractual obligations.
6.2 Legal Obligations
We may process Personal Data where required to comply with applicable laws, regulations, court orders, tax requirements, accounting obligations, anti-fraud measures, or lawful requests from competent authorities.
6.3 Legitimate Interests
Where appropriate, we process Personal Data to support legitimate business interests, including improving our services, maintaining platform security, preventing fraud, conducting internal analytics, managing business operations, and protecting the rights, property, and safety of FAGi Logistics and its users.
6.4 Consent
Where consent is required by law, we will obtain clear and informed consent before processing Personal Data. Individuals may withdraw their consent at any time where permitted by applicable legislation. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.
6.5 Protection of Vital Interests
In limited circumstances, Personal Data may be processed where necessary to protect the life, health, or safety of an individual or another person.
FAGi Logistics regularly reviews its processing activities to ensure that each activity continues to be supported by an appropriate legal basis throughout the information lifecycle.
7. Categories of Personal Data
FAGi Logistics collects and processes Personal Data only where it is necessary to provide services, fulfil contractual obligations, comply with legal requirements, improve platform performance, maintain security, and protect the interests of our customers, business
partners, drivers, employees, and the public.
7.1 Identity Information
This may include names, usernames, profile photographs, dates of birth where required, government-issued identification, and other information used to verify identity.
7.2 Contact Information
We may collect telephone numbers, email addresses, billing addresses, collection and delivery addresses, emergency contact details where applicable, and preferred communication methods.
7.3 Account Information
Account credentials, authentication records, security preferences, account status, and records relating to registration, login, and account management may be processed to maintain secure access to our services.
7.4 Transaction Information
Information relating to orders, deliveries, invoices, payments, refunds, delivery history, customer support interactions, and service requests may be processed to operate our logistics platform.
7.5 Technical Information
We may collect device identifiers, operating system information, browser type, application version, IP address, network information, diagnostics, crash reports, and security logs to improve reliability and protect our systems.
7.6 Location Information
Where permitted or required for service delivery, GPS and location data may be processed to assign deliveries, provide live tracking, optimise routes, enhance operational efficiency, and improve user safety.
7.7 Communications
We may retain records of communications with customer support, operational notifications, service-related emails, in-app messages, and other business communications where necessary for quality assurance, dispute resolution, and regulatory compliance.
8. Customer Personal Data
FAGi Logistics processes Personal Data relating to customers in order to provide safe, reliable, and efficient logistics and delivery services. The information we collect depends on the services requested, the method of interaction, and applicable legal requirements.
8.1 Information We Collect
Customer information may include full name, email address, mobile telephone number, billing address, collection and delivery addresses, account credentials, payment references, delivery instructions, communication preferences, and customer support records. Additional verification information may be requested where required by law or for fraud prevention purposes.
8.2 How We Use Customer Information
Customer Personal Data may be processed to create and manage accounts, process orders, coordinate deliveries, communicate service updates, verify identity, process payments, respond to enquiries, provide customer support, resolve disputes, improve our services, detect and prevent fraud, comply with legal obligations, and maintain the security of our platforms.
8.3 Sharing Customer Information
Customer information may be shared only where necessary with authorized drivers, business customers, payment service providers, technology providers, customer support providers, regulatory authorities, or other trusted service providers acting on behalf of FAGi Logistics under appropriate contractual and confidentiality obligations.
8.4 Retention
Customer Personal Data is retained only for as long as necessary to fulfil contractual, operational, legal, tax, accounting, regulatory, and dispute resolution requirements. When retention is no longer required, information is securely deleted or anonymized in accordance with our internal retention standards and applicable law.
8.5 Customer Rights
Subject to applicable law, customers may request access to, correction of, deletion of, or restriction of the processing of their Personal Data, object to certain processing activities, or request a copy of their information in a portable format where legally available.
9. Business Customer Personal Data
FAGi Logistics processes Personal Data relating to business customers, merchants, corporate clients, suppliers, and other commercial partners to establish and maintain professional relationships, provide logistics services, fulfil contractual obligations, and comply with applicable legal and regulatory requirements.
9.1 Information We Collect
Business-related information may include the name of the organization, registered business details, contact persons, job titles, business email addresses, telephone numbers, billing and operating addresses, tax and registration information, payment references, service history, and communications relating to the use of our services.
9.2 Business Operations
Personal Data may be processed to create business accounts, verify authorized representatives, manage contracts, coordinate deliveries, provide reporting, facilitate invoicing, process payments, deliver customer support, monitor service quality, and maintain secure access to business platforms.
9.3 Compliance and Due Diligence
Where required, FAGi Logistics may process information to perform identity verification, anti- fraud checks, sanctions screening, risk assessments, audit activities, and other compliance measures necessary to satisfy legal, financial, or regulatory obligations.
9.4 Information Sharing
Business Customer Personal Data is shared only with authorized personnel, contracted service providers, payment partners, technology providers, regulatory authorities where legally required, and other parties necessary to provide our services. Appropriate contractual, technical, and organizational safeguards are implemented to protect such information.
9.5 Retention
Business Customer Personal Data is retained only for the period necessary to support contractual relationships, satisfy legal and financial record-keeping requirements, resolve disputes, enforce agreements, and protect the legitimate interests of FAGi Logistics. Upon expiry of applicable retention periods, information is securely deleted or anonymized in accordance with our internal data retention procedures.
10. Driver Personal Data
FAGi Logistics processes Personal Data relating to drivers to recruit, onboard, verify, manage, support, and monitor delivery operations in a safe, secure, and compliant manner. Driver information is processed only for legitimate business, operational, contractual, legal, and regulatory purposes.
10.1 Information We Collect
Driver information may include full name, date of birth where required, residential address, email address, mobile telephone number, government-issued identification, driver's licence, vehicle information, insurance documentation, profile photograph, bank or payment details, emergency contact information, and records relating to training, performance, and communications.
10.2 Verification and Onboarding
FAGi Logistics may verify the authenticity of documents, qualifications, licences, identity, and eligibility to provide delivery services. Additional background or compliance checks may be performed where permitted or required by applicable law.
10.3 Operational Processing
Driver Personal Data is used to assign deliveries, calculate earnings, process payments, provide navigation and route optimisation, communicate operational updates, investigate incidents, respond to customer enquiries, improve platform performance, and maintain service quality and safety.
10.4 Location Data
During active service, location information may be processed to facilitate order assignment, live tracking, delivery verification, fraud prevention, emergency response, and operational analytics. Location processing is limited to legitimate business purposes and subject to applicable law.
10.5 Retention and Protection
Driver Personal Data is protected through appropriate administrative, technical, and physical safeguards. Information is retained only for as long as necessary to meet contractual, operational, financial, legal, regulatory, and dispute resolution requirements, after which it is securely deleted or anonymized in accordance with our retention procedures.
11. Employee Personal Data
FAGi Logistics processes Personal Data relating to employees, temporary workers, interns, consultants, and other members of its workforce for employment, administrative, operational, legal, and security purposes. Personal Data is processed only where necessary to manage the employment relationship, comply with applicable laws, and support the safe and efficient operation of the business.
11.1 Information We Collect
Employee information may include identification details, contact information, employment records, payroll information, tax documentation, emergency contact details, attendance records, training history, qualifications, performance records, and business communications required for employment administration.
11.2 Employment Administration
Personal Data may be processed to recruit personnel, administer employment contracts, manage payroll and benefits, monitor attendance, provide training, manage business travel, administer information technology resources, and support workforce planning and compliance activities.
11.3 Security and Compliance
FAGi Logistics may process employee information to protect company assets, maintain information security, investigate misconduct, respond to legal requests, comply with employment legislation, and fulfil health and safety obligations where applicable.
11.4 Confidentiality
Access to Employee Personal Data is restricted to authorized personnel with a legitimate business need. Appropriate administrative, technical, and physical security measures are implemented to protect confidentiality, integrity, and availability of employee information.
11.5 Retention
Employee Personal Data is retained only for the period required by contractual, employment, tax, accounting, legal, and regulatory obligations. At the end of the applicable retention period, information is securely deleted, archived, or anonymized in accordance with internal retention procedures and applicable law.
12. Location, GPS & Tracking Data
FAGi Logistics uses location, GPS, and tracking technologies to operate its logistics platform safely, accurately, and efficiently. Location information is processed only where necessary to deliver services, improve operational performance, enhance user safety, prevent fraud, and comply with applicable legal obligations.
12.1 Collection of Location Information
Location information may be collected from mobile applications, connected devices, vehicle systems, and other technologies used to access FAGi services. Depending on the service, location data may include real-time GPS coordinates, route history, pickup and delivery locations, timestamps, and estimated arrival information.
12.2 Operational Use
Location information may be used to assign delivery requests, optimise routes, provide live order tracking, verify completed deliveries, calculate travel distances, estimate delivery times, improve dispatch operations, investigate service incidents, and provide customer support.
12.3 Safety and Security
Location information may also be processed to support emergency response, investigate suspected fraud or misuse of the platform, protect drivers and customers, maintain service integrity, and comply with lawful requests from competent authorities where required.
12.4 User Controls
Users may manage certain device location permissions through their mobile device settings. However, disabling location services may limit or prevent access to features that depend on real-time positioning, including delivery assignment, navigation, and live tracking.
12.5 Retention and Protection
Location and tracking information is protected using appropriate administrative, technical, and organizational safeguards. Such information is retained only for as long as necessary to fulfil operational, contractual, legal, regulatory, and security requirements before being securely deleted or anonymized in accordance with FAGi Logistics' data retention procedures.
13. Payment Information & Financial Data
FAGi Logistics processes payment and financial information to facilitate secure transactions, manage customer accounts, pay drivers and business partners, comply with legal obligations, and maintain accurate financial records. Payment information is handled in accordance with applicable laws and recognized security standards.
13.1 Information We Process
Financial information may include payment references, transaction identifiers, billing details, invoices, receipts, account balances, payout information, bank account details where required, and records necessary to process refunds or resolve payment disputes. Sensitive payment credentials are processed only where necessary and, where possible, through trusted payment service providers.
13.2 Payment Processing
Payments may be processed by authorized third-party payment providers. These providers are contractually required to protect personal information and implement appropriate technical and organizational security measures. FAGi Logistics does not retain payment card information beyond what is necessary for lawful business, operational, or regulatory purposes.
13.3 Fraud Prevention
Financial information may be analysed to detect suspicious activity, prevent fraud, verify transactions, investigate unauthorized payments, and protect customers, drivers, business partners, and FAGi Logistics from financial crime or abuse of the platform.
13.4 Compliance
Payment information may be retained and disclosed where required to comply with tax, accounting, anti-money laundering, financial reporting, sanctions, or other legal and regulatory obligations applicable to FAGi Logistics.
13.5 Security and Retention
Payment and financial information is protected using appropriate administrative, technical, and physical safeguards. Records are retained only for the period required to fulfil contractual, accounting, tax, legal, and regulatory obligations, after which they are securely deleted or anonymized in accordance with our data retention procedures.
14. Cookies, Analytics & Tracking Technologies
FAGi Logistics uses cookies, software development kits (SDKs), analytics tools, and similar technologies to operate, secure, improve, and maintain its digital platforms. These technologies help us understand how users interact with our services, enhance system performance, prevent fraud, and deliver a consistent user experience across our websites and mobile applications.
14.1 Cookies
Cookies are small text files stored on a user's device that enable essential functions such as authentication, session management, language preferences, security, and website functionality. Certain cookies may also assist with performance measurement and user experience improvements.
14.2 Analytics Technologies
FAGi Logistics may use analytics services to measure application performance, identify technical issues, understand usage patterns, monitor service quality, and improve products and services. Analytics information is processed in accordance with applicable law and contractual safeguards.
14.3 Mobile Technologies
Our mobile applications may use SDKs and similar technologies to support push notifications, crash reporting, fraud detection, authentication, mapping, navigation, and other operational features necessary for service delivery.
14.4 User Choices
Users may manage certain cookie preferences through browser settings and device controls. Disabling specific technologies may affect the availability, performance, or functionality of certain features or services provided by FAGi Logistics.
14.5 Data Protection
Information collected through cookies, analytics, and tracking technologies is protected using appropriate administrative, technical, and organizational measures. Such information is retained only for as long as necessary to support legitimate business, operational, legal, and security purposes.
15. Information Security
FAGi Logistics is committed to protecting Personal Data and confidential business information through a comprehensive information security programme designed to maintain the confidentiality, integrity, availability, and resilience of our systems, applications, and services. Security measures are implemented using a risk-based approach and are reviewed regularly to address evolving threats, business requirements, and legal obligations.
15.1 Administrative Safeguards
FAGi Logistics maintains internal security policies, employee awareness programmes, confidentiality obligations, access approval procedures, vendor risk assessments, and governance processes to promote responsible handling of information and reduce security risks across the organisation.
15.2 Technical Safeguards
Appropriate technical controls may include encryption of data in transit and at rest, secure authentication mechanisms, role-based access controls, network segmentation, vulnerability management, security monitoring, logging, backup procedures, and regular software updates to help protect information against unauthorised access, disclosure, alteration, or destruction.
15.3 Physical Safeguards
Where applicable, physical security measures may include controlled access to offices and operational facilities, visitor management procedures, secure storage of records and equipment, environmental protections, and measures designed to prevent theft, loss, or unauthorised access to company assets.
15.4 Security Monitoring and Incident Response
FAGi Logistics monitors its systems for indicators of security threats, suspicious activity, and potential vulnerabilities. Security incidents are investigated, documented, and managed in accordance with established response procedures. Where required by applicable law, affected individuals and competent authorities may be notified of qualifying personal data breaches.
15.5 Continuous Improvement
Information security is subject to ongoing review. FAGi Logistics periodically assesses risks, evaluates security controls, conducts testing where appropriate, and updates its policies and procedures to strengthen the protection of Personal Data and support compliance with applicable privacy and cybersecurity laws.
16. Data Sharing & Third-Party Service Providers
FAGi Logistics shares Personal Data only where it is necessary to provide services, fulfil contractual obligations, comply with applicable laws, protect legitimate business interests, or where the individual has provided consent when required. We do not sell Personal Data to third parties.
16.1 Authorized Service Providers
FAGi Logistics may engage carefully selected third-party service providers to support payment processing, cloud hosting, mapping and navigation, customer support, communications, identity verification, fraud prevention, analytics, information technology, and other operational functions. These providers are required to process Personal Data only on documented instructions and to maintain appropriate confidentiality and security safeguards.
16.2 Business Partners
Where necessary to fulfil a requested service, limited Personal Data may be shared with business customers, merchants, delivery partners, or other authorized parties. Information shared is limited to what is reasonably required for operational purposes and service delivery.
16.3 Legal and Regulatory Disclosures
FAGi Logistics may disclose Personal Data where required by law, court order, regulatory requirement, or lawful request from a competent authority. We may also disclose information where necessary to establish, exercise, or defend legal claims or to protect the rights, safety, property, or security of FAGi Logistics, our users, employees, or the public.
16.4 Corporate Transactions
If FAGi Logistics is involved in a merger, acquisition, investment, restructuring, or sale of assets, Personal Data may be transferred as part of that transaction, subject to appropriate confidentiality obligations and applicable legal requirements.
16.5 Accountability
Where Personal Data is shared with third parties acting on behalf of FAGi Logistics, we take reasonable steps to ensure that appropriate contractual, technical, and organizational measures are in place to protect Personal Data and to support compliance with applicable privacy and data protection laws.
17. International Data Transfers
FAGi Logistics may process and transfer Personal Data across national borders where necessary to provide its services, support business operations, maintain technology infrastructure, or comply with legal obligations. As an international logistics company, we are committed to ensuring that cross-border transfers are conducted in accordance with applicable privacy and data protection laws.
17.1 Cross-Border Processing
Personal Data may be processed by FAGi Logistics or authorized service providers in countries where we operate or where our trusted technology partners maintain secure systems and infrastructure. Such processing is limited to legitimate business, operational, contractual, security, and regulatory purposes.
17.2 Appropriate Safeguards
Where required by applicable law, FAGi Logistics implements appropriate safeguards for international transfers. These safeguards may include contractual commitments, technical security controls, organizational measures, and other legally recognized transfer mechanisms designed to provide an equivalent level of protection for Personal Data.
17.3 Security and Accountability
All recipients of Personal Data are expected to maintain appropriate confidentiality, information security, and privacy standards. FAGi Logistics performs reasonable due diligence and contractual oversight to help ensure that third parties protect Personal Data in accordance with applicable legal and contractual requirements.
17.4 Data Subject Rights
International transfers do not reduce or remove the privacy rights available to individuals under applicable law. Where required, individuals may request information regarding the safeguards applied to international transfers of their Personal Data.
17.5 Continuous Review
FAGi Logistics periodically reviews its international data transfer practices to reflect changes in applicable legislation, regulatory guidance, operational requirements, and industry best practices, ensuring that Personal Data remains appropriately protected throughout its lifecycle.
18. Data Retention & Secure Disposal
FAGi Logistics retains Personal Data only for as long as necessary to fulfil the purposes for which it was collected, to comply with contractual obligations, applicable laws, regulatory requirements, legitimate business needs, and to protect the rights of our customers, business partners, drivers, employees, and the Company.
18.1 Retention Principles
Retention periods are determined by considering the nature of the information, the purpose of processing, legal and regulatory obligations, operational requirements, limitation periods for legal claims, and information security considerations. Personal Data will not be retained longer than necessary unless required or permitted by law.
18.2 Business Records
Operational records, financial documentation, customer communications, service history, and other business records may be retained for the periods necessary to support contractual performance, accounting, tax compliance, dispute resolution, fraud prevention, and business continuity.
18.3 Secure Disposal
When Personal Data is no longer required, FAGi Logistics implements appropriate procedures to securely delete, destroy, or anonymize the information. Disposal methods are designed to prevent unauthorized recovery, disclosure, or misuse of Personal Data.
18.4 Backup and Archive Systems
Certain information may remain within secure backup or archive systems for a limited period as part of disaster recovery, business continuity, or legal compliance requirements. Access to archived information is restricted and subject to appropriate security controls.
18.5 Periodic Review
FAGi Logistics periodically reviews its retention schedules and disposal procedures to ensure continued compliance with applicable privacy legislation, regulatory guidance, contractual obligations, and industry best practices.
19. Individual Privacy Rights
FAGi Logistics respects the privacy rights of individuals and is committed to handling requests relating to Personal Data in accordance with applicable privacy and data protection laws. Depending on the jurisdiction and the circumstances, individuals may exercise one or more of the rights described below.
19.1 Right of Access
Individuals may request confirmation of whether FAGi Logistics processes their Personal Data and, where applicable, obtain access to that information together with details regarding the purposes of processing, categories of data, recipients, and applicable retention periods.
19.2 Right to Rectification
Individuals may request that inaccurate, incomplete, or outdated Personal Data be corrected or updated without undue delay where appropriate.
19.3 Right to Erasure
Subject to legal and contractual obligations, individuals may request the deletion of Personal Data where there is no longer a lawful basis for continued processing or where applicable law provides such a right.
19.4 Right to Restrict or Object to Processing
Individuals may request that processing be restricted or may object to certain types of processing where permitted by applicable law. FAGi Logistics will assess such requests on a case-by-case basis and respond in accordance with legal requirements.
19.5 Right to Data Portability
Where required by applicable law, individuals may request a copy of certain Personal Data in a structured, commonly used, and machine-readable format, or request that such information be transferred to another controller where technically feasible.
19.6 Withdrawal of Consent
Where processing is based on consent, individuals may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out before the withdrawal became effective.
19.7 Exercising Your Rights
Requests relating to privacy rights may be submitted through the contact channels identified in this Privacy Policy. FAGi Logistics may request additional information to verify identity before responding to a request in order to protect Personal Data and prevent unauthorized disclosure.
20. Data Breach Management & Incident Response
FAGi Logistics maintains an incident response framework designed to identify, contain, investigate, mitigate, document, and remediate actual or suspected personal data breaches. Our objective is to minimize harm, restore normal operations promptly, and comply with all applicable legal and regulatory requirements.
20.1 Detection and Reporting
Employees, contractors, and authorized service providers are expected to report suspected security or privacy incidents immediately through approved internal reporting channels. Automated monitoring systems may also detect unusual activity, unauthorized access attempts, or other indicators of compromise.
20.2 Investigation and Containment
Upon identification of a potential incident, FAGi Logistics will assess the nature, scope, and impact of the event. Appropriate containment measures may include restricting access, isolating affected systems, preserving evidence, and implementing temporary safeguards to reduce further risk.
20.3 Notification
Where required by applicable law, FAGi Logistics will notify the relevant supervisory authorities and, where appropriate, affected individuals within the timeframes prescribed by law. Notifications will include available information regarding the nature of the incident, likely consequences, and recommended protective actions.
20.4 Remediation
Corrective actions may include restoring systems, strengthening technical and organizational controls, updating procedures, providing additional staff training, and implementing measures to reduce the likelihood of recurrence.
20.5 Continuous Improvement
Following each significant incident, FAGi Logistics conducts a post-incident review to evaluate the effectiveness of its response, identify lessons learned, and improve its information security and privacy management practices.
21. Regulatory Compliance & Privacy Governance
FAGi Logistics maintains a privacy governance framework designed to ensure that Personal Data is processed responsibly, lawfully, and consistently across all business operations. Privacy governance forms an integral part of our corporate governance, risk management, and compliance programmes and supports our commitment to protecting the rights and freedoms of individuals.
21.1 Compliance Framework
FAGi Logistics seeks to comply with applicable privacy, cybersecurity, consumer protection, employment, financial, and sector-specific legislation in every jurisdiction in which it operates. Internal policies and operational procedures are reviewed periodically to reflect changes in legal requirements and industry best practices.
21.2 Governance Responsibilities
Management is responsible for establishing appropriate privacy controls, allocating resources, promoting accountability, and ensuring that employees, contractors, and authorized third parties understand and comply with this Privacy Policy and related internal standards.
21.3 Risk Management and Audits
Privacy and information security risks are assessed on a regular basis. FAGi Logistics may perform internal reviews, compliance assessments, vendor evaluations, and audits to verify that privacy controls remain effective and proportionate to identified risks.
21.4 Training and Awareness
Employees and other authorized personnel may receive privacy and information security training appropriate to their roles. Awareness initiatives are intended to promote responsible handling of Personal Data and support ongoing compliance with legal and organizational requirements.
21.5 Continuous Improvement
FAGi Logistics regularly evaluates its governance framework, privacy programme, policies, procedures, and security controls to improve operational resilience, strengthen regulatory compliance, and respond to evolving legal, technological, and business developments.
22. Changes to this Privacy Policy & Contact Information
FAGi Logistics may update this Privacy Policy from time to time to reflect changes in applicable laws, regulatory requirements, business operations, technologies, security practices, or the services we provide. We encourage users to review this Privacy Policy periodically to remain informed about how we protect Personal Data.
22.1 Policy Updates
Where material changes are made, FAGi Logistics will take reasonable steps to inform affected individuals through appropriate communication channels, which may include our website, mobile applications, email notifications, or other service communications where required by applicable law.
22.2 Effective Date
The Effective Date shown at the beginning of this Privacy Policy indicates when the current version became applicable. Previous versions may be retained for regulatory, legal, audit, or historical purposes where appropriate.
22.3 Contact Us
Questions, concerns, requests, or complaints relating to this Privacy Policy or the processing of Personal Data may be submitted to FAGi Logistics through our official support channels. We will make reasonable efforts to acknowledge and respond to privacy-related enquiries within the timeframes required by applicable law.
Privacy Contact
FAGi Logistics
Email: privacy@fagilogistics.com
Support: support@fagilogistics.com Website:
www.fagilogistics.com
FAGi Logistics remains committed to maintaining the highest standards of privacy, security, transparency, and accountability across all of its operations and will continue to strengthen its privacy programme through ongoing governance, innovation, and regulatory compliance.
Data Retention Schedule (General
Principles) Purpose of this Appendix
This Appendix provides the general principles applied by FAGi Logistics when determining appropriate retention periods for Personal Data. Specific retention periods may vary depending on contractual obligations, operational requirements, applicable legislation, regulatory guidance, litigation holds, or legitimate business needs.
General Retention Principles
Personal Data is retained only for as long as necessary to fulfil the purposes for which it was collected. Retention decisions take into account legal, financial, operational, tax, accounting, fraud prevention, dispute resolution, information security, and business continuity requirements.
Where Personal Data is no longer required, FAGi Logistics will securely delete, destroy, or anonymize the information using methods designed to prevent unauthorized access, recovery, disclosure, or misuse.
Backup copies may remain available for a limited period where necessary to support disaster recovery, business continuity, legal preservation obligations, or regulatory compliance. Access to archived information is strictly controlled and limited to authorized personnel.
Retention schedules are reviewed periodically to ensure continued compliance with applicable privacy legislation, internal governance requirements, and industry best practices. Changes to retention practices are documented and implemented through FAGi Logistics' information governance programme.
Data Subject Request Procedure
This Appendix describes the general process followed by FAGi Logistics when receiving, assessing, responding to, and documenting requests from individuals regarding their Personal Data. The objective is to ensure that requests are handled consistently, securely, and in accordance with applicable privacy and data protection laws.
Receiving Requests
Requests may be submitted through official communication channels, including customer support, designated privacy contact points, or other approved methods made available by FAGi Logistics. Requests should contain sufficient information to allow identification of the requester and the nature of the request.
Identity Verification
Before disclosing, modifying, deleting, or otherwise acting upon Personal Data, FAGi Logistics may request additional information to verify the identity of the requester. This verification
process helps prevent unauthorized disclosure and protects the privacy and security of all individuals.
Assessment and Response
Each request is reviewed to determine the applicable legal requirements, the scope of the request, and any exemptions or limitations permitted by law. Where appropriate, FAGi Logistics will respond within the timeframes required by applicable legislation and provide reasons where a request cannot be fulfilled in whole or in part.
Record Keeping
FAGi Logistics maintains appropriate records of privacy requests, verification activities, responses, and decisions in order to demonstrate compliance, support audits, improve internal processes, and monitor the effectiveness of its privacy programme.
Information Security Controls
This Appendix outlines the general information security controls implemented by FAGi Logistics to protect Personal Data, confidential information, and critical business systems. These controls support the confidentiality, integrity, availability, and resilience of our operations and are reviewed periodically to address evolving legal, operational, and cybersecurity requirements.
Administrative Controls
FAGi Logistics maintains documented policies, employee confidentiality obligations, security awareness training, risk assessments, vendor due diligence, access approval procedures, and governance processes to promote responsible handling of information throughout the organisation.
Technical Controls
Technical safeguards may include strong authentication, role-based access control, encryption of data in transit and at rest, secure software development practices, network protection, vulnerability management, logging, security monitoring, malware protection, backup procedures, and regular system updates where appropriate.
Physical Controls
Physical security measures may include controlled access to offices and operational facilities, visitor management, secure storage of equipment and records, environmental protections, and procedures designed to reduce the risk of theft, loss, damage, or unauthorised access.
Continuous Improvement
Security controls are reviewed and enhanced on a regular basis. FAGi Logistics may conduct internal reviews, security testing, audits, and risk assessments to evaluate the effectiveness of existing controls and to support ongoing compliance with applicable laws, contractual obligations, and recognised industry practices.
International Privacy Laws & Regulatory Framework
This Appendix provides an overview of the privacy and data protection principles that guide the global operations of FAGi Logistics. As our business expands into multiple jurisdictions, we are committed to aligning our privacy programme with applicable legal and regulatory requirements while maintaining consistent internal standards for the protection of Personal Data.
Regulatory Compliance
FAGi Logistics designs its privacy programme to support compliance with applicable privacy, cybersecurity, consumer protection, employment, financial, and electronic communications legislation in the jurisdictions where it operates. Compliance requirements may vary between countries and are monitored on an ongoing basis.
Cross-Border Operations
Where Personal Data is processed across international borders, FAGi Logistics implements appropriate legal, contractual, technical, and organisational measures to safeguard Personal Data and to support lawful international transfers in accordance with applicable legislation.
Regulatory Monitoring
Privacy laws continue to evolve. FAGi Logistics periodically reviews legal developments, regulatory guidance, enforcement trends, and recognised industry standards to strengthen its privacy governance framework and maintain effective compliance practices.
Continuous Improvement
This regulatory framework is reviewed regularly and updated where necessary to reflect legislative changes, operational developments, technological innovation, and recognised best practices for responsible data protection.
Glossary of Privacy Terms
This Appendix provides a glossary of commonly used privacy and data protection terms referenced throughout this Privacy Policy. These definitions are intended to promote consistent interpretation of privacy concepts across all FAGi Logistics operations, services, and documentation.
Personal Data
Information relating to an identified or identifiable natural person.
Processing
Any operation performed on Personal Data, including collection, storage, use, disclosure, transmission, restriction, deletion, or destruction.
Data Subject
The individual to whom Personal Data relates.
Controller
The organization that determines the purposes and means of processing Personal Data.
Processor
A person or organization that processes Personal Data on behalf of a Controller under documented instructions.
Personal Data Breach
A security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
Consent
A freely given, specific, informed, and unambiguous indication of an individual's agreement to the processing of Personal Data where required by applicable law.
Anonymization
The process of permanently removing or transforming identifying information so that an individual can no longer be identified from the data.
Encryption
A security technique that converts information into a protected format to help prevent unauthorized access during storage or transmission.
This glossary may be expanded and updated as FAGi Logistics introduces new services, technologies, or privacy requirements.
Revision History
This Appendix records the revision history of the FAGi Logistics Privacy Policy. Maintaining a documented revision history supports accountability, transparency, regulatory compliance, and effective document governance. Every material update to this Privacy Policy should be reviewed, approved, version controlled, and recorded before publication.
Version Control Principles
Each approved revision should include, where applicable:
• Version number
• Effective date
• Approval date
• Author or document owner • Approving authority
• Summary of changes
• Reason for the revision
Current Published Version
Version: 1.0
Effective Date: 17 May 2025 Status: Initial Release
Future Revisions
Future amendments may be introduced to reflect changes in applicable legislation, business operations, technology, information security practices, regulatory guidance, or organizational requirements. Significant revisions should be communicated through appropriate channels in accordance with applicable law.
FAGi Logistics is committed to maintaining an accurate, controlled, and up-to-date Privacy Policy that reflects current legal obligations and recognized industry best practices.
Privacy Governance Contacts & Reporting
This Appendix describes the governance and communication framework used by FAGi Logistics for privacy-related enquiries, incident reporting, regulatory communications, and internal escalation. It supports consistent handling of privacy matters across the organisation.
Privacy Enquiries
Individuals may contact FAGi Logistics regarding questions about this Privacy Policy, requests relating to Personal Data, or concerns regarding privacy practices through the official communication channels published by the Company.
Internal Reporting
Employees, contractors, and authorised representatives are expected to report suspected privacy incidents, unauthorised disclosures, or potential policy violations without undue delay using approved internal reporting procedures. Reports are assessed confidentially and investigated where appropriate.
Regulatory Communications
Where required by applicable law, communications with supervisory authorities or other competent regulators will be coordinated by authorised representatives of FAGi Logistics to ensure accurate, timely, and consistent responses.
Governance Review
This Appendix is reviewed periodically together with the Privacy Policy to ensure that contact information, reporting procedures, and governance arrangements remain current and effective.
Corporate Privacy & Data Protection Policy Version: 1.0
Effective Date: 17 May 2025
Document Classification: Public Privacy Policy Document Owner: FAGi Logistics Management
This document contains the official Privacy Policy of FAGi Logistics and describes the principles governing the collection, use, protection, retention, disclosure, and management of Personal Data across our services.
© FAGi Logistics. All Rights Reserved.