PRLX-LEGAL-PP-01 · R1

Privacy policy

Effective: 1 January 2026 Last updated: 5 September 2026 PARALLAX_rc SLU
← llx.info

1. Controller identity (GDPR Art. 13(1)(a))

The controller of personal data collected through llx.info and register.llx.info is PARALLAX_rc SLU, Parque Tecnológico de Andalucía, Málaga, Spain.

Contact: marc.vrk@parallax.software

No Data Protection Officer is required under Article 37 GDPR for the scale of processing described in this Policy. All data protection enquiries are handled directly by the controller.

2. Data collected and purpose (GDPR Art. 13(1)(c) and 13(1)(d))

When you submit an access request, the following personal data is collected: first name, last name, work email address, organisation name, role, and intended use. This is the minimum data necessary to process your request.

No special category data is collected within the meaning of Article 9 GDPR. No demographic data (race, ethnicity, religion, political opinions, trade union membership) is collected, requested or stored.

The purpose of collection is the processing of your access request and, if approved, the provisioning and administration of your licence. No data is used for marketing, profiling or any purpose other than licence administration.

3. Legal basis (GDPR Art. 13(1)(c))

The legal basis for processing is Article 6(1)(b) GDPR — processing necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract.

No consent is relied upon as the legal basis for any processing described in this Policy.

4. Retention (GDPR Art. 13(2)(a))

Personal data is retained for the duration of the active licence and for the period required by applicable Spanish law following termination. Data relating to unsuccessful access requests is deleted within ninety (90) days of the decision.

You may request deletion at any time by writing to the controller at the address above, subject to any overriding legal obligation to retain the data.

5. Recipients and transfers (GDPR Art. 13(1)(e) and 13(1)(f))

No personal data is transferred to any third party for marketing, analytics or any other purpose.

No personal data is transferred outside the European Economic Area (EEA). The platform operates entirely within the Licensee's own infrastructure. No document content, retrieval result or custody record is transmitted to the controller or any third party.

This Privacy Policy does not reference the EU–US Privacy Shield, which was invalidated by the Court of Justice of the European Union in Case C-311/18 (Schrems II) on 16 July 2020, nor any other cross-border transfer mechanism, because no such transfers occur.

6. Automated decision-making (GDPR Art. 13(2)(f))

No automated decision-making, including profiling within the meaning of Article 22 GDPR, takes place. Access decisions are made by the controller based on manual review of each request.

7. Your rights (GDPR Art. 13(2)(b) and 13(2)(c))

You have the right to: (a) request access to the personal data held about you (Article 15); (b) request rectification of inaccurate data (Article 16); (c) request erasure where data is no longer necessary or where consent has been withdrawn (Article 17); (d) request restriction of processing (Article 18); (e) object to processing (Article 21); (f) receive your data in a portable format (Article 20).

To exercise any of these rights, contact: marc.vrk@parallax.software. Requests are handled within one calendar month.

8. Supervisory authority (GDPR Art. 13(2)(d))

You have the right to lodge a complaint with the Spanish data protection supervisory authority:

Agencia Española de Protección de Datos (AEPD)
C/ Jorge Juan, 6, 28001 Madrid, Spain
www.aepd.es

9. Architecture note

PARALLAX RC® processes documents locally within the Licensee's own infrastructure. The controller has no access to, and receives no copy of, any document, finding, custody record or retrieval result processed by the platform. The controller is not a processor of document content under Articles 4(8) and 28 GDPR.

This architectural property — local-only, zero-egress execution — means that the personal data protection obligations of Article 5(1)(c) GDPR (data minimisation) and Article 25 GDPR (data protection by design and by default) are satisfied by construction for document content.

10. Updates

This Policy was last updated on 5 September 2026. Material changes will be communicated by notice on this page with at least thirty (30) days before taking effect.