Legal
Privacy & Cookie Policy
This policy explains how we collect, process and protect your personal data in connection with our automated, zone-based parking services and this website.
Last updated: 25 August 2026
1. Legal framework and GDPR compliance
- Data controllerThe controller responsible for personal data processed through this website is SIA Positronic Parking, Raņķa dambis 34-58, Rīga, LV-1048, Latvia, EU. Email park@geaparkt.com, phone +37120004647.
- Data protection contactIf you have questions about your privacy or personal data processing, or wish to exercise your rights, contact us at park@geaparkt.com.
- Notice of camera surveillanceParking sites may be equipped with CCTV and Automatic Number Plate Recognition (ANPR) cameras. Responsibility for operating these systems and for displaying clear informational signage at entrances and throughout the parking area lies with the parking operator and/or landowner, not with Geparkt.
- Industry-specific applicationIn automated parking, a vehicle number plate is personal data. We process it to perform a contract (GDPR Art. 6(1)(b) — delivering the parking service) and on the basis of legitimate interest (GDPR Art. 6(1)(f) — site security, camera health and enforcement of parking terms).
2. What we collect and how we use it
To operate AI-driven, barrier-free parking zones we process the following categories of personal and technical data:
- Number plates (ANPR data)When a vehicle enters or leaves a monitored zone, our cameras capture the number plate. It is used to register session start and end times, calculate fees, and verify an active permit, subscription or payment.
- Account and subscription dataWhen you purchase a plan we collect only what is needed to enter into and fulfil the agreement: first and last name (or company name), email address, phone number, the country of the parking site, and billing details including VAT number for legal entities.
- Payment informationCard payments are processed by certified PCI-DSS payment providers (Stripe). We never store full card numbers — only tokenised or masked references and transaction IDs needed for billing and recurring charges. You may withdraw consent for recurring payments at any time.
- Enforcement photographs (blurred)If a control sanction is issued for a breach of parking terms, still photographs document the violation. When images are sent with the notice, bystanders and sensitive background details are deliberately blurred.
- Video for diagnosticsLive footage from site cameras is retained for a maximum of 7 days and is never shared with third parties. Its only purpose is technical diagnostics: verifying that cameras function, that recognition succeeded, and analysing recognition errors to improve accuracy.
- Support and communication dataWhen you contact us by email, phone or a website form — for example about an invoice, a complaint or a technical issue — we process your contact details and the content of your enquiry. Legal basis: legitimate interest (GDPR Art. 6(1)(f)) in providing support and resolving disputes.
- Security and fraud-prevention logsTo secure the platform and detect or troubleshoot abuse we log IP address, device and browser information and time of access. Legal basis: legitimate interest (GDPR Art. 6(1)(f)) in protecting our infrastructure.
- Debt and fine collectionWhere unpaid sessions or sanctions are escalated, the minimum data necessary is shared with the collection partner chosen by the operator, acting under a data processing or joint-controller arrangement.
4. Retention, hosting and security
- RetentionRetention periods are configurable per zone and defined in each customer agreement. Diagnostic video is kept for a maximum of 7 days. Session and billing records are kept as long as required by accounting and limitation-period law.
- Hosting and safeguardsData is hosted in the EU by default, encrypted in transit and at rest, and access is restricted by role. Every access and change is written to an audit log, and deletions are soft-deleted with an audit trail before permanent removal.
5. Your rights
Under the GDPR you have the right to:
- AccessRequest a copy of the personal data we hold about you, including parking history, passages and billing data.
- RectificationAsk us to correct inaccurate or incomplete personal data.
- ErasureRequest deletion of your personal data, unless we have an overriding legal obligation to retain it.
- RestrictionAsk us to temporarily suspend processing of your data.
- PortabilityReceive your data in a structured, commonly used, machine-readable format.
- ObjectionObject to processing based on legitimate interests, including direct marketing and certain profiling.
- Human interventionBecause sessions are billed from AI-driven ANPR recognition, you may contest any automated decision and request human review and manual correction of plate data.
- Withdraw consentWithdraw consent at any time where processing relies on it, such as non-essential cookies.
- ComplaintLodge a complaint with your national data protection authority if you believe our processing breaches the law.
To exercise any of these rights, contact us at park@geaparkt.com. We respond within 7 days and in any case within the statutory timeframe. A Data Processing Agreement is available on request — see Trust & Security.