Data Protection
Last updated: July 30, 2026
1. Purpose of this document
This document is separate from the Privacy Policy, which governs the processing of data belonging to visitors of this website or those who complete the contact form. This document describes how Grafiti-ID, the software developed by Labrax Soluciones, S.L., processes citizens' personal data when the platform is used by public administrations, local police, the Spanish National Police, and other client bodies to identify graffiti offenders.
2. Roles in the processing
In the operational use of Grafiti-ID, the client entity (town council, police force, or public body) acts as the Data Controller for citizens' personal data. Labrax Soluciones, S.L. acts as the Data Processor, in accordance with Article 28 of the GDPR, under the data processing agreement signed with each client.
3. Personal data processed
- Photographs of graffiti and their surroundings, captured by officers, fixed cameras, or the citizen app.
- Biometric signatures extracted from graffiti: 64 interpretable handwriting features and a 512-dimensional visual embedding.
- Capture metadata: geolocation, date and time.
- Third-party data incidentally captured in the image (faces, unrelated vehicle license plates), which is automatically blurred before processing.
4. Purpose of processing
Identification of graffiti and urban vandalism offenders, linking of incidents across municipalities to build case files for continuing offenses, and generation of forensic handwriting reports admissible in court.
5. Legal basis
- Performance of a task carried out in the public interest (Art. 6.1.e GDPR).
- Processing by public administrations and security forces for the purposes of prevention, investigation, and prosecution of criminal offenses and public order infringements (Art. 22 LOPDGDD).
6. Technical and organizational security measures
Labrax Soluciones applies measures aligned with the ENS Alto category (Royal Decree 311/2022): multi-factor authentication (MFA), HSM-based encryption, Network Policies, and an immutable WORM chain of custody with chained SHA-256 hashing. The platform is certified under ISO 9001, ISO 14001, ISO 27001, and ISO 42001 (AI management system). Data is stored in a datacenter located in Spanish territory, with multi-tenant segregation by client entity.
7. Privacy by design
Grafiti-ID incorporates data minimization measures: automatic blurring of faces and license plates of third parties unrelated to the investigation, and generation of non-reversible embeddings that do not allow the original image to be reconstructed. Labrax Soluciones has carried out 4 Data Protection Impact Assessments (DPIAs) on the platform's operation.
8. Retention period
The data retention period is configurable by each controller entity, in accordance with its own records-management rules and the applicable criminal limitation periods for the type of offense.
9. Sub-processors and international transfers
Data is hosted on infrastructure located within the European Union. Labrax Soluciones does not carry out international transfers of personal data outside the European Economic Area.
10. Exercising your rights
Since Labrax Soluciones acts as the data processor, requests for access, rectification, erasure, restriction, portability, and objection must be addressed to the controller entity (the town council, police force, or public body) that uses Grafiti-ID. Labrax Soluciones cooperates with that entity to handle such requests within the legally established deadlines. For general questions about this document, you may write to privacidad@labraxsoluciones.com.
11. Changes
Labrax Soluciones, S.L. reserves the right to modify this document to adapt it to legislative, case-law, or technical developments. Any modification will be published on this page, indicating the date of the last update.