Privacy policy

Controller

Reprorace SL, NIF B75382259, Avda. Montes de Oca, 20, Nave 15, 28703 San Sebastián de los Reyes (Madrid), España. Email for any privacy matter: info@reprorace.com. We have not appointed a data protection officer; we answer directly at that address.

This policy applies to the diaglana.com and remote-obd.com websites, the Diaglana platform (app.diaglana.com), its mobile apps, the online shop and our marketplace sales. For each use we explain which data we process, why, on which legal basis (article 6 of Regulation (EU) 2016/679, GDPR) and for how long.

Contact forms and commercial follow-up

Data: what you give us when you write or use the contact forms (name, email, phone, company, profile, message and the page you write from) and the history of our relationship (messages, notes, calls and emails).

Purpose: answering you and following up commercially on your request in our customer management tool. Basis: steps taken at your request before a contract (article 6.1.b GDPR) and our legitimate interest in handling and following up the enquiries we receive (article 6.1.f). Period: while the enquiry lasts and one more year; if you become a customer, the periods of the relevant section.

Commercial news

Only if you tick the box and then confirm it yourself with the link we send to that address (double opt-in: the link works once and for 7 days; if you do not confirm, we send nothing else), we email you commercial news from our brands, at most one a month. Basis: your consent (article 6.1.a GDPR and article 21 LSSI-CE).

To be able to prove it, we keep the date and the version of the text you accepted on the form and the date of your confirmation, linked to a digest (hash) of your address.

You can withdraw it at any time with the unsubscribe link in each email or by writing to us, without affecting what was sent before. Period: until you unsubscribe; then we only keep proof of your consent and unsubscription for the limitation period of possible infringements (up to three years).

Abuse prevention in the forms

To prevent mass submissions we keep a keyed pseudonymised digest (hash) of the IP address each form is sent from, never the address itself, and count recent submissions. Basis: our legitimate interest in protecting the service against abuse (article 6.1.f GDPR). Period: 30 days.

Platform account

Data: name, email, country, language and time zone; organization and roles; second factor and trusted devices; access logs; and the version of the terms and of this policy you accepted, with its date. The identity service stores your password irreversibly encrypted; the platform never sees it.

If you sign in with Google, Apple or Facebook, that provider sends us your name, your verified email and an identifier; we do not receive your password or your contacts. That provider's processing is governed by its own policy.

Purpose: creating and managing your account, giving you secure access and providing the service. Basis: the contract (article 6.1.b GDPR) and, to keep proof of acceptance, our legitimate interest (article 6.1.f). Period: while the account is active; when closed, the data is blocked (article 32 of the Spanish Data Protection Act, LOPDGDD) and only available to courts, authorities and for our defence during the limitation periods (generally five years), and then erased.

Organizations and workshops

If an organization (for example a workshop or a network) gives you access, its administrators see your name, email, role and activity in it. The organization decides who has access and is responsible for having been entitled to add you; we process that data to provide the service to it. Basis: the contract with the organization and our legitimate interest in managing access securely (article 6.1.b and f GDPR). Period: while you belong to the organization and then that of the security and audit section.

Shop purchases

Data: name or company name, tax or VAT number, shipping and billing addresses, email, phone, order, payment method, order conversation, invoices, returns and warranty cases. Your card or payment account details are processed directly by the payment provider; we only receive the result and minimal transaction data.

Purpose: managing the order, payment, delivery, invoice, withdrawal and warranty. Basis: the contract (article 6.1.b GDPR) and our tax and commercial obligations (article 6.1.c). Period: six years from the last entry (article 30 Spanish Commercial Code) and, for tax, while the authorities may audit it (article 66 Spanish General Tax Act).

If you enter a VAT number from another EU member state, we check it in VIES (European Commission) and keep the answer and its consultation number as evidence of the intra-Community supply. Basis: legal obligation (article 6.1.c GDPR).

Origin of the purchase: if you reach the shop from diaglana.com or from remote-obd.com (authorized distributor), the order records which of the two websites you came from (only its name, never your browsing) so we know which sales each one brings and can settle the distributor's. Basis: our legitimate interest (article 6.1.f GDPR). Period: that of the order. Remembering it between visits requires your consent and is explained in this website's cookie policy (section "Platform and shop: browser storage").

Marketplace sales

If you buy our units on Amazon, eBay, Mercado Libre or AliExpress, the marketplace gives us your name, delivery address and phone and the order so we can ship it, invoice it and handle the warranty; we send back the carrier and tracking number. Basis: the contract and our legal obligations (article 6.1.b and c GDPR). Period: that of shop purchases. The marketplace is responsible for the data it processes on its own site, under its policy.

Remote diagnostics and sessions

Data: unit identifier, VIN, fault codes, live data, battery voltage, session status and unit events. Only processed when the vehicle's owner or user authorises each session with the unit's button or in the app, and they may withdraw the authorisation at any time.

Purpose: providing the diagnostic service the customer asks their workshop for. Basis: the contract and the authorisation of each session (article 6.1.b GDPR). Period: that of the contracted service; signed reports, as long as the workshop must keep them.

When a workshop serves its customers through the platform, the workshop is the controller of that data and we process it on its behalf as processor (article 28 GDPR). If you have questions about what your workshop does with your data, ask them; we will help you too.

Recording of diagnostic communications

During each remote session, the units record the technical communication between the tool and the vehicle (messages, timing and bus); no audio or images are recorded. Purpose: analysing how tools and vehicles communicate, improving the service's compatibility and safety and resolving incidents.

Basis: our legitimate interest in improving and protecting the service (article 6.1.f GDPR). We have balanced it against your rights: recordings are stored encrypted under a pseudonymous identifier; the VIN and customer data are kept separately with restricted access; and the analysis team only works on the pseudonymised version. You can object by writing to us. Period: 5 years.

Usage location (mobile app)

Only while you use the app, when you request a remote session or assistance, and only if you allow it: country, region, city and an approximate area of about 11 km. We never keep your exact position. Your phone gets the place name from its own service (Apple or Google, under their policies). If you don't allow it, we keep only the country and region your connection indicates.

Purpose: applying the rules of the place the service is requested from and statistics. Basis: your consent (article 6.1.a GDPR), which you can withdraw in your phone settings, and our legitimate interest in complying with applicable rules (country and region of the connection; article 6.1.f). Period: 24 months.

Expert marketplace

If you are an expert, we publish on diaglana.com the profile data you choose to show (name, photo, organization, specialties, makes, services, rates, languages and working area), after reviewing it. Those pages are public and search engines may index them. Basis: the contract (article 6.1.b GDPR). Period: while the profile is published; you can withdraw it whenever you want.

If you hire an expert or you are the expert: the job's data (enquiry, quote, messages, attachments, appointment, report, review and payments) and, for the expert's workshop, the data Stripe asks for to verify and pay it (identity, address and account). Basis: the contract (article 6.1.b GDPR) and legal obligation (article 6.1.c: invoicing and article 30 of the Digital Services Act). Period: messages, 2 years after closing; payment and invoicing data, 6 years. Stripe processes payment data as an independent controller.

Community

Data: your profile (@username, name, photo and bio), what you post (texts and photos), likes, who you follow, who you block and your reports. By default your profile is only visible to people with an account; you can make it public. A published expert's profile is always public. Public content can be seen without signing in and may appear in search engines.

Purpose: providing the community service. Basis: the contract (article 6.1.b GDPR). Period: until you delete the post or close your account; backups are renewed within a short period.

Reports and moderation

If you report content, we process your account, the reason and the details you give; if your content is reported, the content, the report and our reasoned decision. Basis: the obligations of the Digital Services Act (article 6.1.c GDPR) and our legitimate interest in keeping the community safe (article 6.1.f). We do not reveal to the reported person who reported them, unless legally required.

Period: as long as needed to handle complaints against the decision and defend ourselves against possible claims. If content gives rise to a suspicion of a criminal offence threatening people's life or safety, we will inform the authorities (article 18 of the Digital Services Act).

Service notices

We send notices in the app and by email about your orders, account, units, sessions and security. Basis: the contract (article 6.1.b GDPR). They are not marketing: we only send marketing with your consent.

Artificial intelligence assistants used by our team

Our team uses artificial intelligence assistants from external providers to work faster: through an internal interface, with keys tied to each person's permissions, they can read contacts, orders and support requests and draft notes or replies.

A person on our team always reviews what they prepare and decides; the assistants send nothing to customers and take no decisions about you, your account, your orders or your content. Basis: our legitimate interest in serving you efficiently (article 6.1.f GDPR). The providers act as processors and, if they process data outside the European Economic Area, they do so with the safeguards described below.

Security and audit

We log access and sensitive operations to protect the service, detect misuse and be able to show who did what. Basis: our legitimate interest and the obligation to apply security measures (articles 6.1.f, 6.1.c and 32 GDPR). Period: as needed for those purposes and the applicable legal periods.

Recipients

Providers that process data on our behalf, under a processing agreement complying with article 28 GDPR: hosting, content delivery network, databases and service protection (Cloudflare); invoicing (Holded); email delivery (Mailgun Technologies, Inc., with the messages on its servers in the European Union); the identity service; and the artificial intelligence assistants our team uses.

Third parties that receive data as independent controllers, only when necessary: payment providers (Stripe, PayPal and Redsys with the relevant bank); carriers (delivery name, address and phone); the marketplaces you buy on; Google, Apple or Facebook if you sign in with them; the European Commission (VIES check); tax and customs authorities, courts and law enforcement where the law requires; and professional advisers bound by confidentiality.

If you are a workshop's customer, that workshop accesses the data of the units and vehicles you authorise. We do not sell your data or share it for advertising.

International transfers

Some providers may process data outside the European Economic Area. Cloudflare, Inc. (United States) is certified under the EU-US Data Privacy Framework and also signs the European Commission's standard contractual clauses with us; where the service allows it, we configure database storage in the European Union, although its network may process traffic on servers in other countries.

Mailgun Technologies, Inc. (United States), which sends our emails, keeps the messages and their logs in its European Union region; should its staff access them from the United States, the transfer relies on its certification under the EU-US Data Privacy Framework and the standard contractual clauses of its processing agreement.

With the other providers that process data outside the European Economic Area (for example, the artificial intelligence assistant providers), the transfer relies on an adequacy decision or on the standard contractual clauses, with supplementary measures where needed. You can ask us for a copy of these safeguards by writing to us.

Automated decisions

We take no decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you (article 22 GDPR). The only exception is the automatic application of the VAT treatment according to the VIES answer, which tax law requires; you can ask a person to review it and express your point of view. We do not profile you for advertising either.

Your rights

You can access your data, rectify or erase it, object to its processing, ask for its restriction or portability, withdraw at any time any consent you gave us and not be subject to automated decisions as described in the previous section (articles 15 to 22 GDPR).

Exercise them free of charge from the platform's privacy centre or by writing to info@reprorace.com or to our registered address, stating which right you exercise. If we have reasonable doubts about your identity, we may ask for additional information. We answer within one month, extendable by two more months for complex requests, in which case we will tell you.

If you consider we have not handled your data properly, you can complain to the Spanish Data Protection Agency (C/ Jorge Juan, 6, 28001 Madrid, Spain; www.aepd.es). We would appreciate you writing to us first so we can try to solve it.

Minors

You must be at least 14 years old to create an account (article 7 LOPDGDD). Purchases and paid services require legal age. If we learn we have collected data of a child under 14 without the consent of their parents or guardians, we will erase it.

Other people's data

If you give us data about another person (for example, a workshop adding its customers or a buyer naming someone else for delivery), you must have informed them and have a legal basis to do so.

How we protect your data

We apply technical and organisational measures appropriate to the risk (article 32 GDPR): encryption in transit, role-based least-privilege access, a second factor for sensitive operations, pseudonymised recordings, backups and an audit log. If a personal data breach occurs, we will notify the Spanish Data Protection Agency within 72 hours and tell you when there is a high risk to you.

Changes

If we change this policy, we will publish the new version here with its date and, if the change is relevant, notify you in the platform or by email before it applies.