International Privacy Notice — TMS
1. Introduction & Identity of the Data Controller
This International Privacy Notice ("Notice") describes how Joyner Transportation & Logistic Services LLC ("Joyner," "we," "us," or "our"), a Georgia limited liability company with its principal place of business in Atlanta, Georgia, USA, processes personal data in connection with the Joyner Transportation Management System ("Joyner TMS") for subscribers and authorized users located outside the United States.
Joyner acts as the data controller with respect to account registration and platform administration data, and as a data processor with respect to customer data that subscribers input into the Joyner TMS platform in connection with their transportation management operations. The allocation of controller and processor responsibilities is further described in the Joyner TMS Data Processing Agreement (DPA).
2. Scope & Applicability
This Notice applies to the following categories of data subjects outside the United States:
- Joyner TMS subscribers — the legal entities and individuals who have entered into a Joyner TMS subscription agreement
- Authorized users — employees, contractors, and agents of TMS subscribers who access and use the Joyner TMS platform on behalf of the subscriber
- Contacts — individuals whose contact information is entered into the Joyner TMS platform by subscribers in connection with their logistics operations (e.g., shipper contacts, carrier contacts, delivery contacts)
This Notice covers personal data processed in connection with Joyner TMS and does not apply to other Joyner services, which are currently available in the United States only.
3. Personal Data We Collect & Process
3.1 Account & Subscriber Data (Controller)
Joyner collects and processes the following personal data as data controller for account management and platform administration purposes:
- Account registration data: subscriber organization name, billing address, country, and VAT/tax identification number
- Primary contact data: name, job title, email address, and phone number of the subscriber's primary contact and billing contact
- Authorized user data: name, email address, job title, and system access role for each authorized user added to the TMS account
- Authentication data: login credentials (passwords stored in hashed form), multi-factor authentication data, and session tokens
- Usage and activity data: log data, feature usage statistics, and platform interaction data generated by authorized users' use of Joyner TMS
- Support and communication data: records of support requests, communications with Joyner customer success and technical teams, and feedback submissions
- Billing and payment data: subscription tier, billing cycle, invoice records, and payment confirmation data (raw payment card data is processed by Joyner's payment processor and not stored by Joyner)
3.2 Customer Data Processed on Behalf of Subscribers (Processor)
Subscribers may input personal data into the Joyner TMS platform in connection with their transportation management operations. This data is processed by Joyner as a data processor acting on the subscriber's documented instructions. Such data may include:
- Shipper, carrier, and broker contact information (names, addresses, phone numbers, email addresses)
- Driver and carrier personnel data entered for load assignment and dispatch purposes
- Consignee and delivery recipient contact information
- Any other personal data subscribers choose to enter into the platform in connection with their logistics operations
Subscribers are responsible for ensuring they have a lawful basis for providing personal data about third parties to Joyner TMS, and for providing appropriate privacy notices to those individuals. Joyner's obligations with respect to customer data are governed by the Joyner TMS Data Processing Agreement.
4. Legal Bases for Processing (EEA, UK & Other Jurisdictions)
For subscribers and authorized users located in the European Economic Area (EEA), United Kingdom (UK), and other jurisdictions that require identification of a lawful basis for personal data processing, Joyner relies on the following legal bases:
- Performance of a contract: Processing of account, subscriber, and authorized user data is necessary for the performance of the Joyner TMS subscription agreement between Joyner and the subscriber
- Legitimate interests: Processing for platform security, fraud prevention, abuse detection, product improvement, and business analytics — where these interests are not overridden by the data subject's interests or fundamental rights
- Legal obligation: Processing necessary to comply with applicable legal obligations, including tax, accounting, and data protection law requirements
- Consent: Where Joyner seeks consent for specific processing activities (e.g., marketing communications), such processing is based on consent, which may be withdrawn at any time
For customer data processed as a data processor on behalf of subscribers, Joyner relies on the subscriber's documented instructions and the subscriber's legal basis for the processing.
5. How We Use Personal Data
Joyner uses personal data collected as data controller for the following purposes:
- Provisioning, operating, and maintaining Joyner TMS accounts and subscriptions
- Authenticating and authorizing user access to the platform
- Billing and invoicing subscribers for their TMS subscriptions
- Providing customer support, onboarding assistance, and technical support
- Sending transactional communications (account notifications, security alerts, service status updates)
- Sending product updates, feature announcements, and marketing communications — subject to applicable consent requirements and opt-out rights
- Improving Joyner TMS functionality and user experience through anonymized usage analytics
- Detecting, preventing, and responding to security incidents, fraud, and abuse
- Complying with applicable legal obligations and enforcing Joyner's agreements
6. International Data Transfers
Joyner is headquartered in the United States. When Joyner processes personal data of individuals located in the EEA, UK, Switzerland, or other jurisdictions with data transfer restrictions, personal data is transferred to and processed in the United States. Joyner relies on the following transfer mechanisms, as applicable:
- Standard Contractual Clauses (SCCs): For transfers from the EEA and Switzerland, Joyner uses the European Commission's Standard Contractual Clauses (Module 1: Controller-to-Controller; Module 2: Controller-to-Processor, as applicable) as the transfer mechanism
- UK International Data Transfer Agreements (IDTAs): For transfers from the United Kingdom, Joyner uses the UK IDTA or the UK Addendum to the EU SCCs as the transfer mechanism
- Other mechanisms: For transfers from other jurisdictions with specific transfer requirements, Joyner implements appropriate safeguards as required by applicable law
To request a copy of the applicable transfer mechanism, contact privacy@myjoyner.com.
7. Data Sharing & Sub-Processors
Joyner shares personal data with the following categories of recipients:
- Sub-processors: Third-party service providers that process personal data on Joyner's behalf in connection with the delivery of Joyner TMS, including cloud infrastructure providers, email delivery services, payment processors, customer support platforms, and analytics providers. A current list of Joyner TMS sub-processors is available at myjoyner.com/legal/sub-processors/.
- Professional advisors: Joyner's legal, accounting, and compliance advisors, under appropriate confidentiality obligations
- Regulatory and governmental authorities: As required by applicable law, court order, or governmental authority
- Business transferees: In connection with a merger, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality protections
Joyner does not sell personal data to third parties and does not share personal data for third-party advertising purposes.
8. Data Retention
Joyner retains account and subscriber personal data for the duration of the active TMS subscription plus one (1) year following subscription termination or expiration, after which it is deleted or anonymized, unless a longer retention period is required by applicable law. Usage logs and platform activity data are retained for up to two (2) years. Customer data processed as a data processor is deleted or returned to the subscriber upon subscription termination in accordance with the Joyner TMS Data Processing Agreement.
9. Your Data Subject Rights
Depending on your location and applicable law, you may have the following rights with respect to personal data Joyner holds about you:
- Right of access: The right to obtain confirmation of whether Joyner processes your personal data and to receive a copy of that data
- Right to rectification: The right to have inaccurate or incomplete personal data corrected
- Right to erasure ("right to be forgotten"): The right to request deletion of your personal data, subject to applicable legal retention obligations and other exceptions
- Right to restriction of processing: The right to request that Joyner restrict processing of your personal data in certain circumstances
- Right to data portability: The right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where technically feasible
- Right to object: The right to object to processing based on legitimate interests, including profiling, and the right to object to direct marketing at any time
- Right to withdraw consent: Where processing is based on consent, the right to withdraw consent at any time, without affecting the lawfulness of processing prior to withdrawal
- Right to lodge a complaint: The right to lodge a complaint with your local data protection authority (see Section 11)
To exercise any of these rights, submit a written request to privacy@myjoyner.com. Joyner will respond within the timeframe required by applicable law (typically 30 days for GDPR requests, with the possibility of a 60-day extension for complex requests).
10. Country-Specific Supplements
In addition to this Notice, the following country-specific provisions apply to subscribers and users in the indicated jurisdictions, as detailed in the applicable schedules to the Joyner TMS SaaS Terms of Service (International):
- European Union / EEA: GDPR (Regulation (EU) 2016/679) applies. The applicable supervisory authority is the data protection authority in your EU member state of residence or establishment.
- United Kingdom: UK GDPR and the Data Protection Act 2018 apply. The applicable supervisory authority is the UK Information Commissioner's Office (ICO): ico.org.uk.
- Canada: PIPEDA (Personal Information Protection and Electronic Documents Act) and applicable provincial privacy laws apply. The applicable authority is the Office of the Privacy Commissioner of Canada: priv.gc.ca.
- Australia: The Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply. The applicable authority is the Office of the Australian Information Commissioner (OAIC): oaic.gov.au.
- India: The Digital Personal Data Protection Act, 2023 (DPDPA) applies upon its entry into force. Joyner will update this Notice as implementing rules are finalized.
- Brazil: The Lei Geral de Proteção de Dados (LGPD) applies. The applicable authority is the Autoridade Nacional de Proteção de Dados (ANPD): www.gov.br/anpd.
- South Africa: The Protection of Personal Information Act (POPIA) applies. The applicable authority is the Information Regulator: inforegulator.org.za.
- Germany / Netherlands: GDPR applies, enforced by the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) for Germany and the Autoriteit Persoonsgegevens (AP) for the Netherlands.
- Singapore: The Personal Data Protection Act 2012 (PDPA) applies. The applicable authority is the Personal Data Protection Commission (PDPC): pdpc.gov.sg.
- UAE: Federal Decree-Law No. 45 of 2021 on Personal Data Protection applies. The applicable authority is the UAE Data Office.
- Mexico: The Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) applies. The applicable authority is the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI).
- China: The Personal Information Protection Law (PIPL) applies. Cross-border data transfers require compliance with PIPL Chapter III requirements. Joyner is working with qualified China legal counsel on PIPL compliance for Chinese TMS subscribers.
11. Data Protection Authority Complaints
If you are located in the EEA, UK, or another jurisdiction with a data protection authority, you have the right to lodge a complaint with your local supervisory authority if you believe Joyner has processed your personal data in a manner that does not comply with applicable data protection law. Joyner encourages you to contact us first at privacy@myjoyner.com so that we may have the opportunity to address your concern directly.
12. Security
Joyner implements appropriate technical and organizational security measures to protect personal data processed in connection with Joyner TMS against unauthorized access, disclosure, alteration, destruction, and loss. These measures include encryption of data in transit and at rest, access controls and authentication requirements, regular security assessments, and incident response procedures. See the Joyner TMS Service Level Agreement for additional information about platform security and availability commitments.
13. Changes to This Notice
Joyner may update this Notice at any time to reflect changes in applicable law, regulatory guidance, or our data processing practices. Material changes will be communicated to TMS subscribers via email or in-platform notification with at least thirty (30) days' advance notice. The current version of this Notice is always available at myjoyner.com/legal/international-privacy-notice-tms/.
14. Contact & Data Protection Officer
For questions about this Notice or to exercise your data subject rights, contact:
- Privacy inquiries: privacy@myjoyner.com
- Mailing address: Joyner Transportation & Logistic Services LLC, Attn: Privacy — TMS International, Atlanta, Georgia, USA
For EEA and UK data subjects, Joyner's designated EU/UK Article 27 representative contact information will be published at this page once appointed prior to Joyner TMS's international commercial launch.
© 2026 Joyner Transportation & Logistic Services LLC. All rights reserved.