GXO Logistics Privacy Policy
1. Scope
Protecting your information online is of the utmost importance to GXO Logistics, Inc., its affiliates, subsidiaries, directors, officers, agents, and employees (together, “GXO ”, we, “us”, or “our”).
This Privacy Policy applies to information collected through the GXO website located at https://gxo.com (the “Site”), any mobile applications associated with the Site or otherwise offered by GXO (the “Mobile Applications”), all interactive features, applications, widgets, blogs, social networks and social network “tabs”, and other online or wireless offerings that post a link to this Privacy Policy, whether accessed via computer, mobile device or other technology or any associated content, material, software or functionality contained on the Site or Mobile Applications (collectively the “Software” and, together with the Mobile Applications and the Site, the “System”).
This Privacy Policy describes how we treat personal data when we provide our supply-chain management and other services to our business customers (B2B), as well as to end customers of our business customers on the latter’s behalf (B2B2C) (the “Services”).
This Privacy Policy only applies to the processing of personal data of natural persons whose personal data we process in the course of providing our Services and website visitors. This Privacy Policy does not apply to data which is not “personal information” or “personal data” as defined by applicable privacy laws.
GXO Logistics, Inc., with its seat at Two American Lane, Greenwich, CT 06831, United States of America and its subsidiaries (“GXO Group”), is responsible for the lawfulness of the processing of your personal data.
2. Definitions
The following terms are used within this Policy and are defined here for clarification:
(a) “controller” means the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by applicable data protection laws or regulations;
(b) “data subject” is an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity;
(c) “personal data” means any information relating to a data subject;
(d) “processing” means any operation or set of operations performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction;
(e) “processor” shall mean a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the data controller.
(f) “GXO Group” shall mean in relation to GXO, that company, any subsidiary or holding company from time to time of that company, and any subsidiary from time to time of a holding company of that company
3. How We Collect Personal Data
We collect personal data in a variety of ways. The means of collection are as follows:
3.1. Personal Data Collected Directly from You
GXO generally collects personal data directly from you (electronically, in writing, or verbal) in the course of our business relationship or by way of website-based inquiry forms. You also provide new or updated or corrected personal data to GXO from time-to-time.
This information includes:
(I) Business information, such as company name and your position in the company; and
(I) Your inquiries, our responses and other related information, such as subject matter of the query, service type you are interested in, requirements for the service you wish to consult with us (including pick-up and delivery addresses and cargo specifications).
3.2. Personal data collected automatically
We use technology to provide the Services and the System which automatically collect certain categories of information from you via the technology you use. Some of this information is personal data, and some of it is not. Where any unattributable information is combined with personal data, or where enough unattributable information is combined together to make it attributable, we consider such information personal data. GXO we collect personal data by automated means, including, but not limited to:
Computer and connection information, browser type and version, operating system and platform details and the time of accessing the website. This technology helps us to improve the Site and to deliver a better and more personalized service. It helps us:
(I) To estimate our audience size and usage pattern.
(ii) To store information about your preferences, and so allow us to customize our site according to your individual interests.
(iii) To speed up your searches.
(iv) To recognize you when you return to our site.
Browsing information, such as your Internet protocol (“IP”) address, how you were directed to the website, which specific pages you access on the website, how long you view each page, the time and date you access our website, features you use, preferences you set, and the general physical location of your computer or device.
We also use “cookies” and other web or mobile technologies to collect information and support certain features of the System. Some cookies and similar technologies will maintain Personal Data. Some do not. We occasionally carry out market research and business development. A third party might help us to do this and they may send a cookie or web beacon.
You may refuse to accept cookies by changing the settings on your browser. However if you change the settings to refuse cookies you may be unable to access certain parts of the site.
The system may also use web beacons which are similar but not identical to cookies in the way they operate.
3.3. Personal Data Collected from the GXO Group
We collect personal data from other GXO Group companies. For example, we collect information regarding our services, business relationship and your inquiries made vis-à-vis other GXO Group companies but which are appropriate to be handled by another GXO Group company. In this circumstance, the two GXO Group companies involved act as joint controllers. Additionally, as discussed in Sections 5 and 6 below, GXO Group companies share personal data among themselves, for the purposes defined in the Section 4 below.
3.4. Personal Data Collected from Third Parties
Finally, we may receive the categories of personal data listed in Section 3.1 above from third parties who provide services to the GXO Group, in particular search engine optimization services, hosting services, social media services and web mastering services, as well as from our business partners and customers.
4. How We Use Your Personal Data
4.1. Legal Basis for Processing
The legal basis we use for the processing of your Personal Data is usually our legitimate interest in operating out business, or as is necessary to enter into, or fulfill obligations under, a contract we have with you or your employer.
Where we use consent as a legal basis for processing, we will ask for such consent prior to the processing. As such, if we do not ask for your consent, we are using another legally permissible basis for such processing.
4.2. In addition to the other uses mentioned or described elsewhere in this Privacy Policy, GXO and our third party service providers may use the information we collect for various purposes, including:
(a) providing requested Services to you;
(b) providing regulatory required communications;
(c) opening, maintaining, and closing accounts;
(d) processing payments;
(e) marketing or promoting our services;
(f) performing fulfillment functions;
(g) engaging third party service providers to perform supply-chain management services;
(h) conducting satisfaction and other surveys;
(I) sending you information that you request from us, promotional materials regarding GXO’s services and facilities, and any other communication for any other legitimate and lawful business purposes;
(j) improving the System’s content, materials, and services; and
(k) more effectively and efficiently responding to both current and future customer (or potential customer) inquiries; and
(l) analyzing and improving the content, features, Software, Site, and Mobile Applications that we make available on the System.
(m) To protect the integrity of our System, our Services, and our reputation.
(n) To prosecute or defend legal claims.
(o) To protect other users of our websites, and to ensure no unlawful or unethical activity occurs through our systems.
5. How We Disclosure or Share Your Personal Data
GXO takes precautions when sharing personal data with other GXO Group companies (i.e., Intra-Group) or with Third Parties.
5.1. Intra-Group
We may share your personal data with other GXO Group companies and for all the purposes specified above. A list of GXO Group companies is available by writing to [email protected].
5.2. Third Parties
We may share your personal data with our service providers who perform services on our behalf for the purposes described in Section 4 of this Privacy Policy. In particular, we share personal data with providers of hosting services and IT support. The service providers are bound by law and/or contract to protect the confidentiality and security of personal data, and to only use personal data to provide requested services to GXO in accordance with applicable law.
We may share your personal data with other companies, vendors and business partners that perform certain functions for us, whereby these companies are themselves responsible to determine the purposes and/or means of the processing and for the lawfulness of the processing,
We will disclose personal data to buyers, lawyers or professional advisors, courts, tribunals, opposing or other related parties to the proceedings and to their professional advisors, where needed, to affect the sale or transfer of business assets, to defend or enforce our rights, protect our property, assets or safety of others. We will also disclose personal data when required to do so by law, such as in response to a subpoena, including to law enforcement agencies, tribunals and courts in countries where GXO operates.
5.3. Sweepstakes, Promotions, Contest and Surveys
On the System, you may wish to participate in online polls, surveys, contests, sweepstakes and other promotions that we may offer from time to time. Participation in these polls, surveys, contests, sweepstakes and promotions is completely voluntary. In addition, as noted above, we may share this information with our affiliates, and other organizations or entities. Through these online polls, surveys and promotions, you may choose to participate in activities such as sharing information found on the System with others and sending email invitations. In connection with any online polls, surveys, contests, sweepstakes and other promotions that we may offer from time to time via the System, we use the information you provide to administer the polls, surveys, contests, sweepstakes and other promotions. Subject to applicable contractual or legal restrictions, we also may use the information to communicate with you, or the other people you select, about our services or our marketing partners may use such information to communicate with you about the online polls, surveys, contests, sweepstakes or other promotions or their products and services.
6. Third Party Links
Certain portions of the System may include links to other internet sites or other third party applications or systems as a convenience to System users. The inclusion of any link, or third party applications or materials, does not imply our endorsement of any other company, its products, services or privacy practices. GXO is not responsible for personal information disclosed by you to third parties that you reach through links on the System. If you initiate a transaction on a linked website or third party application, even if you reached such site or application through the System, the information that you submit to complete that transaction becomes subject to the privacy practices of the operator of the applicable website or third party application.
7. Cross-Border Transfers
Given that GXO Group companies are located and provide services all over the world, we may need to transfer your personal data internationally. In particular, personal data collected by us may be transferred to and processed in countries which may not have the same level of personal data protection as your country of residence.
7.1. Intra-Group
The transfer of your personal data outside your country of residence takes place on the basis of our intra-group Data Sharing Agreement, which is based on the European Commission’s standard contractual clauses for data transfers, and in accordance with applicable data protection laws.
7.2. Third Parties
Third parties with whom we share personal data may be located outside your country of residence. Transfers to third parties located in other countries outside your country of residence take place using an acceptable data transfer mechanism, such as the EU standard contractual clauses for data transfers, Binding Corporate Rules, approved Codes of Conduct and certifications, or in exceptional circumstances on the basis of permissible statutory exceptions.
8. How We Keep Your Personal Data Secure
GXO takes commercially reasonable measures to secure and protect information transmitted via or stored on the System. However, no data transmission over the internet can be guaranteed to be 100% secure. As a result, we cannot ensure or warrant the security of any information transmitted to the System. You agree to immediately notify us of any breach of the System’s security, this Privacy Policy, or the Terms of Use of which you become aware.
9. How Long We Keep your Personal Data For
We keep the personal data that we obtain about you through this website for no longer than is reasonably necessary for the purpose(s) for which they were collected. In certain cases, personal data may be kept for an extended period of time in order to comply with legal obligations, or for the establishment, exercise or defense of a legal claim, in accordance with applicable laws.
If you have further questions regarding our retention of your personal data, you can contact us at [email protected].
10. Your Rights in Relation to Your Personal Data
Various countries’ data protection laws afford particular rights to individuals. These rights include the following:
10.1. Access
You may have the right to obtain from us confirmation if your personal data are being processed, relevant information about such processing as provided by applicable data protection laws of your country of residence, and a copy of the personal data undergoing processing. Where your personal data is intermingled with other data subject’s personal data, or confidential data of a third party, we will take reasonable steps to protect the rights of such third parties. This may include redacting information from the information we provide you, or even not providing the requested information.
10.2. Rectification
You may have the right to obtain from us the rectification of inaccurate personal data concerning you and to have incomplete personal data completed.
10.3. Objection
You may have the right to object to the processing of your personal data on grounds relating to your particular situation.
You may also object at any time to the processing of your personal data for marketing purposes. (Please note that even if you object to your use of personal data for direct marketing purposes, we will still send you transactional messages in relation to services that you have purchased from us. These include responses to your questions and information about a service you have purchased from us.)
10.4. Portability
You may have the right to receive the personal data concerning you which you have provided to the controller in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller. Where your personal data is intermingled with other data subject’s personal data, or confidential data of a third party, we will take reasonable steps to protect the rights of such third parties. This may include redacting information from the information we provide you, or even not providing the requested information.
10.5. Restriction
You may request to restrict processing of your personal data where the applicable law provides you the right for such restriction.
10.6. Erasure
You may request to erase (delete) your personal data subject to GXO’s need to retain data to comply with its own legal obligations. However, if GXO has a permissible need to retain Personal Information, we are not under an obligation to delete such information, even when requested. Generally, we retain Personal Information to complete the transaction for which the personal information was collected, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between us and you; detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity; debug to identify and repair errors that impair existing intended functionality of our online properties; enable solely internal uses that are reasonably aligned with your expectations based on your relationship with GXO; comply with a legal obligation; or otherwise use your personal information in a lawful manner compatible with the context in you provided it.
10.7. Right to Lodge a Complaint
You may have the right to lodge a complaint with a supervisory authority, in particular in the country of your residence, your place of employment, or the location where the issue that is the subject of your complaint occurred.
10.8. Right to Withdraw Consent
Where GXO uses consent as the legal basis for processing, you are free to withdraw (with effect for the future) your previously provided consent to the processing at any time without any adverse negative consequences. The lawfulness of any processing of your personal data that occurred prior to the withdrawal of your consent will not be affected.
In instances where GXO Group companies act as joint controllers, you can exercise these rights in respect of and against each of them. Please see Section 12 on how to exercise your rights.
11. Updates to our privacy policy
This Privacy Policy describes GXO’s current data protection policies and practices. The most recent version of the Privacy Policy is reflected by the version date located at the bottom of this Privacy Policy. We expressly reserve the right to update this Privacy Policy periodically and without prior notice to you to reflect changes in those policies and practices. This Privacy Policy is not intended to and does not create any contractual or other legal right in or on behalf of any party other than GXO Logistics.
12. Contact
If you have such rights under applicable law, and would like to exercise any such rights, you may do so by contacting us by emailing [email protected].
Please address any other questions or comments about or arising from this Privacy Policy to:
GXO Logistics, Inc.
Attn: Chief Compliance Officer
Two American Lane
Greenwich, CT 06831
Effective August 2, 2021