1. Scope
This policy applies to all web and mobile applications provided by digitLabs, especially applications used to capture and process vehicle, document, image, and customer data.
2. Controller
digitLabs Holding GmbH & Co. KG, Hauptstraße 29, 29353 Ahnsbeck, Deutschland. Email: moc.sbaltigid@ofni
3. Purpose of the applications
Our applications allow business users, such as car dealers, workshops, and service providers, to digitally capture vehicle and customer data, scan vehicle documents, take images, and trigger digital workflows.
This may include submitting captured data to the user’s own systems or APIs, or to external partners for services such as damage appraisal reports.
4. Data processed
- Account data, such as name, email address, and organization affiliation,
- Vehicle and document data, such as data extracted from vehicle registration documents,
- Customer data, where entered, scanned, or submitted by the user,
- Images, such as vehicle, document, or damage photos,
- Usage, session, and security data.
5. Role of business users
Our applications are intended for business users. These users are generally the data controllers under the GDPR for personal data of their own customers that they capture, process, or submit through the applications.
The user is responsible for having a valid legal basis, informing their customers, and only capturing or sharing data within the legally permitted scope.
digitLabs generally processes such data as a processor on behalf of the respective business user.
6. OCR and automated text recognition
We may use OCR services to automatically extract text from documents, such as vehicle registration documents. We currently use Mistral AI for this purpose.
7. Sharing with third parties
Users may actively submit captured data to their own systems, APIs, or external partners.
Where data is submitted to external partners, such as SV Berner for damage appraisal reports, this is done at the user’s request. The respective partner is responsible for any further processing under its own privacy terms.
8. Service providers
- Clerk: authentication and session management,
- Supabase: database, storage, and backend infrastructure,
- Mistral AI: OCR and text recognition.
9. App permissions
Camera permission is used to capture documents, vehicle images, or damage photos. Images are only captured when initiated by the user.
10. Deletion
Users may request deletion of their user account and data stored within the application.
Data already submitted to external partners or subject to statutory retention obligations may need to be retained separately and will be deleted after the applicable retention period expires.
11. Security
- Encrypted data transmission,
- Access restrictions,
- Authentication and session management,
- Secure storage using established infrastructure.
12. Data Processing Agreement
For business users, we provide a Data Processing Agreement under Art. 28 GDPR:
13. Updates
We may update this policy if our services, technology, or legal requirements change.
Last updated: 05.05.2026
digitLabs Legal · AppsNote: This policy does not replace individual legal advice.