Privacy Policy & Data Protection
LHZ Shipping BV is committed to safeguarding the privacy and confidentiality of our clients, suppliers, and website visitors in accordance with European and Dutch data protection legislation.
1. Principles of Data Processing
LHZ Shipping BV (KvK 73378763) and operating carrier Warber Scheepvaart B.V. (KvK 60819626) process personal data in strict adherence to the General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming - UAVG). We adhere strictly to the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and confidentiality.
2. Categories of Data We Collect
Depending on how you interact with our web portal and logistics services, we collect:
- Transport & Storage Inquiries: Contact name, corporate email address, business telephone number, company designation, cargo characteristics (mineral oil, liquid chemicals, pressurized LPG gases, biofuels), estimated volume, loading port / origin, discharge terminal / destination, and custom freight notes.
- Commercial Contract & Billing Information: Corporate VAT identification numbers, chamber of commerce registration (KvK), bank account details, and authorized signatory records.
- Technical Telemetry & Log Data: Anonymized IP addresses, browser types, operating systems, referring URLs, date/time stamps, and page navigation patterns collected to maintain cybersecurity and load balance server resources.
- Cookie Preferences: Choice tokens stored via local storage (`lhz_cookie_consent`) recording your consent choices.
3. Legal Bases for Processing (GDPR Art. 6)
Processing transport inquiries, calculating barge/rail freight quotations, issuing charter confirmations, and managing cargo delivery.
Compliance with ADN dangerous goods manifests, Dutch Customs declarations, river port authority reporting, and statutory commercial book-keeping.
Ensuring website and network security, preventing fraudulent inquiries, and optimizing corporate operational workflows.
Where you voluntarily grant consent for optional analytical cookies via our cookie preferences banner.
4. Third-Party Data Processors & Subcontractors
We do not sell, rent, or trade your personal data under any circumstances. Personal information is only disclosed to trusted third-party service providers under binding Data Processing Agreements (DPAs) conforming to GDPR Art. 28:
- Transactional Email Delivery: Inquiries submitted via our web portal are processed and securely routed via Resend, Inc., utilizing TLS 1.3 encryption and Standard Contractual Clauses (SCCs).
- Cloud Infrastructure & Hosting: Our web servers and static assets are hosted in certified European data center facilities adhering to ISO/IEC 27001 security standards.
- Port & Regulatory Authorities: Where mandated by law, cargo manifests and vessel crew lists are transmitted to the Dutch Human Environment and Transport Inspectorate (ILT) and Port of Rotterdam Harbor Master authorities.
5. Data Retention Schedules
We retain personal data only as long as necessary to fulfill the purposes for which it was gathered:
- General transport inquiry emails: Retained for 24 months, unless a commercial contract ensues.
- Executed transport, carriage, and storage agreements: Retained for 7 years in accordance with the mandatory statutory record-keeping period under Dutch tax law (Burgerlijk Wetboek & Algemene wet inzake rijksbelastingen).
- Technical server logs: Retained for a maximum of 30 days and purged automatically.
6. Your Rights Under the GDPR
As a European data subject, you hold comprehensive rights regarding your personal information:
To exercise any of these statutory rights, please contact our Data Privacy Office at info@lhzshipping.com. We will respond within 30 calendar days free of charge.
7. Technical & Organizational Security Measures (TOMs)
LHZ Shipping BV enforces state-of-the-art technical protections, including end-to-end TLS 1.3 encryption for all web communications, strict cryptographic hashing of passwords, multi-factor authentication (MFA) for administrative dispatch panels, network firewalls, and regular vulnerability audits to protect against unauthorized access, loss, or alteration.
8. Right to Lodge a Regulatory Complaint
If you consider that our processing of your personal data infringes applicable data protection laws, you have the right to lodge a formal complaint with the Dutch supervisory authority:
Looking for Information About Web Cookies?
Read our dedicated Cookie Policy for a granular itemization of local storage tokens and tracking technologies.