Privacy Policy

Last updated

This document is a working draft prepared alongside the product and has not yet been reviewed by legal counsel. The bracketed placeholders below still need the registered entity details filled in. Do not rely on it as a binding agreement until it has been signed off.

OTOLAB is a workshop management platform. This policy explains what personal data we handle, why, and what rights you have over it. It covers both the people who use OTOLAB to run a workshop and the vehicle owners whose details a workshop records in the platform.

1. Who we are

OTOLAB is operated by [[LEGAL_ENTITY_NAME]], registered at [[REGISTERED_ADDRESS]], company registration number [[COMPANY_REGISTRATION_NUMBER]].

For questions about this policy or about how your data is handled, reach us through our contact form, choosing the privacy option so your message is routed to the right person.

2. Controller and processor roles

The distinction matters because it determines who you should contact about your data.

For account holders — the workshop owners, managers and technicians who log in to OTOLAB — we act as the data controller for account, billing and platform usage data.

For client and vehicle records entered into the platform by a workshop, the workshop is the data controller and we act as a data processor on its behalf. If you are a vehicle owner asking about data a workshop holds about you, contact that workshop directly; we can only act on their instructions.

3. Data we collect

We collect the following categories of data:

  • Account data — name, email address, phone number, role and permissions, company affiliation, password (stored only as a salted hash, never in readable form).
  • Workshop operational data — job orders, requested services, task assignments, notes, consumables used and order status history.
  • Client and vehicle data entered by workshops — client names and contact details, vehicle make, model, registration plate, VIN, service history and damage records.
  • Media — photographs and video uploaded against orders, inspections and tutorials, including images processed by the plate and VIN recognition feature.
  • Inspection data — damage markers positioned on 3D vehicle models, and the notes attached to them.
  • Time and attendance data — clock-in and clock-out records, time logged per job, and derived performance summaries, where a workshop enables these features.
  • Billing data — subscription tier, billing period, invoice history and payment status. Card details are handled by our payment processor and never reach our servers.
  • Technical data — IP address, browser and device type, session identifiers, and application error diagnostics.
  • Communications — messages sent through in-app chat and support channels, and prompts submitted to the AI assistant.
  • To provide the service — performance of a contract. Without this data the platform cannot function.
  • To bill for the service — performance of a contract and compliance with tax and accounting obligations.
  • To secure the service — legitimate interest in preventing unauthorised access, detecting abuse and maintaining audit trails of sessions and sensitive actions.
  • To support and communicate with users — legitimate interest, and performance of a contract for service-related notices.
  • To improve the product — legitimate interest, using aggregated and de-identified usage patterns.
  • To send marketing communications — consent, which you can withdraw at any time without affecting your use of the service.

5. AI features and automated processing

OTOLAB includes an AI assistant that can create and modify records, answer questions about workshop data and look up vehicle reference information, plus an optical recognition feature that reads registration plates and VIN codes from uploaded photographs.

When you use these features, the relevant content — your prompt, and the specific records or image needed to answer it — is transmitted to a third-party AI provider for processing and returned as a result. We do not permit these providers to train their models on your content.

These features assist rather than decide. Every action the assistant proposes is applied within the permissions of the account that requested it, and no legal or similarly significant decision about any individual is made by automated means alone.

6. Who we share data with

We do not sell personal data. We share it only with service providers who process it on our behalf under contract, and only as far as their function requires:

  • Cloud hosting and database providers, to run the application and store its data.
  • Object storage providers, for uploaded documents, photographs and video.
  • Our payment processor, for subscription billing and invoicing.
  • Our transactional email provider, for account, notification and system emails.
  • AI providers, for the assistant and recognition features described above.
  • Push notification services, where you have enabled browser or device notifications.
  • Professional advisers and authorities, where we are legally required to disclose.

7. International transfers

Some of our providers process data outside the European Economic Area. Where that happens, the transfer is covered by an adequacy decision or by Standard Contractual Clauses approved by the European Commission, together with any supplementary measures the transfer requires.

You can request details of the safeguards applying to a specific transfer through our contact form.

8. How long we keep it

  • Account data — for the life of the account, then deleted or anonymised within 90 days of closure.
  • Workshop operational, client and vehicle data — for as long as the workshop maintains its subscription. On termination the workshop may export its data, after which it is deleted within 90 days unless a longer period is legally required.
  • Billing records — seven years, or as required by applicable tax law.
  • Security and session logs — 12 months.
  • Backups — retained on a rolling schedule and overwritten in the ordinary course; data deleted from the live system persists in backups only until those backups rotate out.

9. How we protect it

Data is encrypted in transit. Passwords are stored as salted hashes and are never recoverable in readable form. Access within the platform is governed by a role and permission system, and each company's data is isolated so one tenant cannot read another's records.

Sessions are tracked and can be reviewed and revoked by the account holder. Sensitive administrative actions require re-authentication. Backups run on an automated schedule and are stored separately from the live system.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours and inform affected users without undue delay.

10. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy of it.
  • Have inaccurate data corrected.
  • Have your data erased, where no overriding legal obligation requires us to keep it.
  • Restrict or object to processing carried out on the basis of legitimate interest.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with a supervisory authority — in Romania, ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal).

11. Exercising your rights

Submit your request through our contact form, choosing the privacy option. We will respond within one month, extendable by two further months for complex requests, in which case we will tell you why within the first month.

If your request concerns data a workshop holds about you as its client, we will forward it to that workshop, which is the controller for those records.

12. Children

OTOLAB is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, tell us through our contact form and we will delete it.

13. Changes to this policy

We may update this policy as the product and the law evolve. Material changes will be announced in the application and by email to account holders at least 30 days before they take effect. The date at the top of this page always reflects the current version.