Labrax Soluciones, S.L. is committed to protecting the privacy of users and processing their personal data in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018, of 5 December, on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

This policy covers the processing of data arising from browsing and the contact form on this website. The processing of license-plate readings, images and video generated by the OCR-ID system once deployed in a municipality is governed by the data processing agreement signed with each local council, summarised on the Data protection page.

1. Data controller

Company nameLabrax Soluciones, S.L.
Tax IDB-70334529
Registered addressCalle Emilio González López 51, bajo, 15011 A Coruña (España)
Emailinfo@ocr-id.com
Phone+34 981 928 655
Company registrationRegistered with the Commercial Registry of A Coruña.

2. For what purpose do we process your data?

At ocr-id.com we process the data provided by users for the following purposes:

3. What data do we process?

The personal data processed through this website is, as a general rule:

We do not request data belonging to the special categories set out in Article 9 of the GDPR. Please do not include such data, or third-party personal data, in the form.

4. What is the legal basis for the processing?

The legal basis for processing is the data subject's consent when submitting their request (art. 6.1.a GDPR), the performance of pre-contractual or contractual measures (art. 6.1.b), and Labrax's legitimate interest in responding to enquiries received (art. 6.1.f).

5. How long do we keep the data?

Data submitted through the form is kept until the request has been resolved and, at most, for two (2) years from the last contact with the data subject. Any subsequent interaction with that person restarts the period. Once it elapses, the data is deleted from the commercial management system: the record and any logged activities are erased, with no anonymised copy retained.

Where the request gives rise to a contractual relationship, the period applicable to that relationship applies instead: six (6) years from the last entry, under article 30 of the Spanish Commercial Code (Código de Comercio), in addition to any applicable tax and administrative periods.

Regardless of the above, Labrax's systems keep a tamper-evident audit log, required by Spain's National Security Framework (ENS), which evidences that a piece of data existed and was deleted, and which in some entries may record the value of fields from the record. That log is not part of the commercial management system, responds to compliance with a legal obligation (art. 6.1.c GDPR) and is governed by its own retention period.

6. Who receives the data?

Data will not be disclosed to third parties except where legally required. It may be accessed by Labrax's technology providers acting as data processors (hosting, email), with whom the corresponding agreements have been signed, and which provide their services within the European Union or under adequate safeguards.

7. What are your rights?

Any person has the right to obtain confirmation as to whether Labrax is processing personal data concerning them. Data subjects have the right to:

You may exercise these rights by writing to info@ocr-id.com or to the postal address indicated, providing proof of identity. You also have the right to file a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing does not comply with applicable regulations.

Withdrawing consent. Where processing is based on your consent, you may withdraw it at any time, as easily as you gave it and without having to justify your decision. Withdrawal does not affect the lawfulness of processing carried out beforehand. For cookies, you can change your choice at any time from “Cookie preferences” in the footer of the home page.

8. Complaint to the supervisory authority

If you believe that the processing of your data does not comply with the applicable rules, or you are not satisfied with how your rights have been handled, you may lodge a complaint with the Spanish Data Protection Agency:

9. Security measures

Labrax applies appropriate technical and organisational measures to ensure the security of personal data and prevent its alteration, loss, unauthorised processing or access, in accordance with the GDPR and Spain's National Security Framework (ENS, High category).

10. Automated decision-making and profiling

Through this website, Labrax does not make automated individual decisions, nor does it carry out profiling that produces legal effects concerning the data subject or similarly significantly affects them.

Once deployed in a municipality, the OCR-ID system does perform automated licence plate readings, but it does so on behalf of the local authority acting as controller: that processing is not governed by this policy but by the processor agreement summarised on the Data protection page, and the decision on each reading always rests with an officer.

11. Changes to this policy

Labrax reserves the right to amend this Privacy policy, in whole or in part, by publishing any changes on this same page and updating its date. Where changes are substantial, they will be communicated through the Website or, where appropriate, by email.