Privacy notice

How DocVigia handles the data a fleet puts into it — its units, its documents, and the people named on them.

Version 1.0 · Last updated 10 September 2026 · Under legal review ahead of commercial launch.

Who is responsible

The responsible party

Opalina Technologies S.A. de C.V. ("Opalina", "we") is responsible for the processing of the personal data described in this notice, in its capacity as operator of the DocVigia platform. Contact for privacy matters: [email protected]

This notice is issued under the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) and its Reglamento.

A note on roles. Most personal data in DocVigia is uploaded by a subscribing fleet about its own drivers and staff. For that data the fleet is the responsible party and Opalina is its processor — we act on the fleet's instructions and do not decide what is collected or why. Where we collect data directly, for example from someone who signs up or writes to us, Opalina is the responsible party. Both cases are covered below and each section says which applies.

What we hold

The data, by category

DocVigia is a document platform, so the personal data in it is mostly whatever appears on a document a fleet is required to keep.

Category Responsible party
Account data. Name, work email, telephone, role, employer, password hash. Opalina
Driver and staff data. Name, licence number and class, medical certificate dates, internal employee number, and whatever else appears on a document the fleet uploads. The fleet
Document images and extracted fields. The scan or photograph itself, plus the document type, issue and expiry dates read from it. The fleet
Activity records. Who uploaded, approved, replaced or scanned a document, and when. Gate scans record the unit, the verdict and the operator who performed the scan. The fleet
Technical data. IP address, browser and device type, and timestamps, kept in server logs for security and diagnosis. Opalina

Sensitive data

DocVigia does not ask for sensitive personal data as the LFPDPPP defines it — no racial or ethnic origin, health status, genetic information, religious or philosophical belief, union membership, political opinion or sexual preference. A medical fitness certificate is tracked as a document with a name and an expiry date; the platform does not ask for or store its clinical content. Do not upload documents containing sensitive data into fields that do not call for it.

Why

Purposes

Primary purposes — necessary for the service

  • Operating the platform. Storing documents, computing which ones a unit or a driver is required to hold, and returning a verdict when one is scanned.
  • Expiry notice. Sending alerts to the people a fleet nominates when a document is approaching or past its expiry date.
  • Reading documents. Extracting document type and dates from an uploaded file so a person does not retype them. A person confirms the result before it is saved.
  • Access control. Authenticating users and applying the permissions their role carries.
  • Audit. Keeping a record of who did what, which is the point of the product for an inspection or a dispute.
  • Billing and support. Invoicing the subscribing organization and answering the questions it raises.
  • Security and legal obligation. Detecting abuse, and complying with a requirement lawfully made of us.

Secondary purposes — you may refuse these

Sending product news and commercial information about DocVigia, and inviting an account holder to take part in research about how the product is used. Refusing these is not a reason for us to deny or reduce the service. To refuse, write to [email protected] at any time, or use the unsubscribe link in any message we send.

We do not sell personal data, and we do not use fleet content to train general-purpose AI models. Documents are processed to extract their fields for the fleet that uploaded them, and for nothing else.

Your rights

ARCO rights, and how to exercise them

You may ask to access your personal data, to rectify it when it is inaccurate, to have it cancelled, or to oppose its processing for a particular purpose.

Send the request to [email protected] with: your name and an address for our reply; a document proving your identity, or a power of attorney if you act for someone else; a clear description of the data concerned; and anything that helps us locate it. If the request is to rectify, tell us the correct value and attach what supports it.

We answer within 20 business days of receiving a complete request, and if it is granted we give effect to it within the following 15 business days. Both periods may be extended once, for the same length, where the circumstances justify it; we will tell you if that happens. Exercising these rights is free — you pay only justified shipping or certification costs, if any.

Where the data belongs to a fleet. If you are a driver or an employee and the data was uploaded by the company you work for, that company decides what is held and for how long. Address the request to your employer first. If you send it to us, we will forward it to them and tell you we have done so.

Revoking consent, and limiting use

You may revoke the consent you gave, by the same route. Revocation cannot always be immediate or total: we may need to keep certain records to comply with a legal obligation or to defend a claim, and we will tell you which and why.

To be excluded from our commercial communications you may also register with the Registro Público para Evitar Publicidad, kept by PROFECO.

Where it goes

Transfers and processors

We do not transfer personal data to third parties for their own purposes. We do use suppliers who process data on our behalf and under our instruction — a transfer to a processor of this kind does not require your separate consent under the LFPDPPP, but you should know who they are:

  • Cloud hosting. Amazon Web Services, which runs the servers and the database.
  • Email delivery. The provider that sends alerts and account messages.
  • Document reading. The OCR and language-model services that extract fields from an uploaded document.
  • Payment processing. The processor that handles subscription payments. Card details go to it directly and are never stored by us.

Some of these operate infrastructure outside Mexico, so your data may be processed abroad. Each is bound by contract to process it only on our instruction, to protect it, and to return or delete it when the relationship ends.

We will disclose data without your consent only in the cases article 37 of the LFPDPPP allows — among them a lawful order from a competent authority, or an emergency threatening a person's life.

Handling

Security, retention and cookies

Security

Every record carries the organization it belongs to, and every query is filtered by it at the data layer rather than by each screen remembering to — one company cannot read another's documents. Within a company, what a person sees is bounded by their role and their site. Traffic runs over TLS, passwords are stored as salted hashes and never in readable form, and document access is logged. We do not claim a certification we have not obtained: DocVigia is not, at the date of this notice, ISO 27001 or SOC 2 certified.

No system is immune. If a breach materially affects your rights we will notify you without delay, describing what happened and what you can do, as the Reglamento requires.

Retention

Fleet content is kept for as long as the subscription is active. After it ends the data stays available for export for 30 days, and is then deleted from live systems; backups age out on their own cycle within 90 days. Document versions are kept deliberately — an auditor's question is what was valid on a given date, which cannot be answered if renewals overwrite what they replace. Server logs are kept for up to 12 months. Billing records are kept for the period Mexican tax law requires.

Cookies

The application uses cookies and browser storage to keep you signed in, to remember your language, and to hold the session while you work. These are necessary for it to function; blocking them will sign you out. We do not run advertising trackers or third-party profiling scripts on this site.

Minors

DocVigia is a workplace tool and is not directed at anyone under 18. We do not knowingly create accounts for minors.

Changes and complaints

If this notice changes

We may amend this notice as the product, the law or our suppliers change. The current version always lives at this address, carrying its version number and date at the top. Where a change is material we will also notify account holders by email before it takes effect.

If you believe your right to data protection has been infringed, you may file a complaint with the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI). We would rather hear from you first — write to [email protected] and we will answer.

Related

The commercial relationship — what the service is, how it is billed and who owns what — is set out in the terms of service.