Privacy Policy
This Privacy Policy explains how Dubra Solutions ("Dubra Solutions", "we", "us", "our") collects, uses, and protects personal data. Dubra Solutions is a shelf-analytics service operated by its founders, Gustavs Gronskis and Kārlis Dubra, based in Rīga, Latvia. We can be reached at gustavs@dubrasolutions.com.
We take a data-minimising approach by design: our in-store analytics processes images on the device inside the store, stores no video, and transmits only anonymous shelf events. Where we do handle personal data — mainly to run your dashboard account — we do so in line with the EU General Data Protection Regulation (GDPR) and Latvian law.
1. Who is responsible for your data (controller vs. processor)
GDPR distinguishes two roles, and which one we hold depends on the data:
- Data controller — the party that decides why and how data is processed.
- Data processor — the party that processes data on a controller's documented instructions.
Applied to our service:
- Dashboard and website accounts. For the account and login data of the people who use our dashboard, Dubra Solutions is the controller.
- In-store shelf analytics. For the analytics we run on a store's shelves, the store is the controller and Dubra Solutions acts as its processor under a Data Processing Agreement (GDPR Article 28). The store instructs us; we process on its behalf.
2. Scope
This Policy covers: (a) visitors to our website; (b) representatives of stores who hold a dashboard account; and (c) shoppers in stores where our analytics hardware is installed. It does not cover third-party websites we may link to.
3. Information we collect
From website visitors. Basic technical data such as IP address, browser type, and pages viewed, collected through cookies and similar technologies (see Section 8).
From dashboard account users. Name, business email, login credentials, the store you represent, and usage logs (for example, sign-in times and actions taken in the dashboard). This is the personal data you provide to connect to and use the Service.
From shoppers (in-store analytics). Our camera observes interactions with specific shelves (pickups, put-backs, dwell). Images are masked on the device so that only the shelf zones are analysed; no video is stored and no video leaves the store. Only shelf events leave the device, each containing at most: store, camera, zone, event type, timestamp, duration, and confidence. We do not process faces, biometric data, identification, people counting, demographics, or audio. These events are designed to be anonymous: on their own they cannot reasonably be linked to an identifiable person, and we do not combine them with other data to re-identify anyone. We treat them accordingly. Whether specific event data qualifies as fully anonymous under GDPR is assessed on an ongoing basis; where any doubt exists, we apply the protections that would apply to personal data.
4. How we use information and our lawful bases
| Purpose | Data | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Provide and operate your dashboard account | Account data | Performance of a contract, Art. 6(1)(b) |
| Keep the Service and hardware secure | Account, usage, technical data | Legitimate interests, Art. 6(1)(f) |
| Run in-store shelf analytics for the store | Anonymous events | Store's legitimate interests (store is controller), Art. 6(1)(f) |
| Website analytics and non-essential cookies | Technical data | Consent, Art. 6(1)(a) |
| Comply with legal obligations | As required | Legal obligation, Art. 6(1)(c) |
We do not sell personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects.
5. The hardware in the store, and how we keep data safe
Where a store uses our analytics, a small device (a camera and a compact edge computer) is physically installed in the store. Our security measures include:
- Processing happens on the device; raw video never leaves the store and is not written to disk in normal operation.
- Only anonymous events are transmitted. Any masked validation clips recorded during pilot tuning show only shelf zones and are deleted on the schedule in Section 6.
- Cloud data is hosted within the EU/EEA (currently with an EU-based hosting provider located in Frankfurt). The dashboard is accessible only after authentication.
- Remote access to devices is encrypted and restricted to authorised personnel.
We are responsible for the security of the data we process and will notify the relevant controller without undue delay if a personal-data breach occurs.
6. Data retention
- Account data — kept while your account is active and deleted (or anonymised) within a reasonable period after you close it or the pilot ends.
- Masked validation clips — kept for 7 days during pilot tuning, then deleted automatically.
- Anonymous shelf events — retained as aggregated, non-personal statistics.
- On the controller's request, any stored material is deleted without undue delay.
7. Sharing and international transfers
We share personal data only with service providers that help us run the Service (for example, EU-based hosting and infrastructure), under appropriate contracts, and only as needed. We do not transfer personal data outside the EU/EEA. We do not sell or rent personal data to third parties.
8. Cookies
Our website uses essential cookies to function and, with your consent, non-essential cookies for analytics. You can manage non-essential cookies through our cookie banner or your browser settings.
9. Your rights
If you are in the EU/EEA, you have the right to: access your data; correct it; delete it; restrict or object to processing; data portability; and withdraw consent at any time. In particular, if you opt out, you can ask us to delete the personal data we hold about you, and we will do so unless we are legally required to keep it. For anonymous shelf events, we cannot identify a specific individual, so individual requests may not be technically possible for that data.
To exercise your rights for data we control, contact us at gustavs@dubrasolutions.com. For in-store analytics, where the store is the controller, please contact the store; we will assist the store as its processor. You also have the right to lodge a complaint with the Latvian supervisory authority, the Data State Inspectorate (Datu valsts inspekcija, DVI).
10. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children.
11. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where appropriate, notify account users.
12. Contact
Dubra Solutions — gustavs@dubrasolutions.com. Supervisory authority: Data State Inspectorate (DVI), Latvia.
This document is provided for transparency and is kept under review. For questions, contact gustavs@dubrasolutions.com.