PRIVACY POLICY


1. What is this Privacy Notice about?

This Privacy Notice informs You on how the Pix4D Group collects, processes and shares Your Personal Data and Personal Data that concerns other individuals when You visit our Website www.pix4d.com and our other websites and apps, including our cloud platform at cloud.pix4d.com (collectively the "Website"), when You or our customers use our software solutions, products, applications, web and cloud services (each a "Service", collectively the "Services") and when You interact with us in relation to a contract, communicate with us or otherwise deal with us. This Privacy Notice explains in particular what Personal Data we collect and why we collect it, how and for how long we use it and Your rights in relation to such Personal Data.

If You disclose Personal Data to us or share data with us about other individuals, such as co-workers, we assume that You are authorized to do so and that the relevant Personal Data is accurate. When You share Personal Data about others with us, You confirm that. Please make sure that these individuals have been informed about this Privacy Notice.

For the purpose of this Privacy Notice, "Personal Data" means any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. We use the word "Data" here interchangeably with "Personal Data".

In this Privacy Notice, the terms "we", "us", "our(s)" and "Pix4D" refer to the Pix4D Group. "You" or "Your" means any natural person (i.e. the individual who reads this Privacy Notice or accesses our Services on behalf of a corporation or other legal entity).

This Privacy Notice is aligned with the current and revised Swiss Federal Act on Data Protection (together "DPA") and the EU General Data Protection Regulation ("GDPR"). However, the application of these laws depends on each individual case.


2. Who is the controller for processing Your Personal Data?

Pix4D SA, Route de Renens 24, 1008 Prilly, Switzerland ("Pix4D SA") is the controller for the Pix4D Group’s processing under this Privacy Notice, unless we tell You otherwise in an individual case, for example in additional privacy notices, on a form or in a contract. However, unless we tell You otherwise, this Privacy Notice also applies where a group company of the Pix4D Group is the controller, instead of the Pix4D SA. This applies, in particular, where Your Personal Data is processed by a group company in relation with legal obligations or contracts with such a group company or where Personal Data is exchanged with a group company. In these cases, this group company is the controller and only if it shares Your Personal Data with other group companies for their own processing (see Section 6), will these other group companies also become controllers.

You may contact our Data Protection Officer for data protection concerns and to exercise Your rights under Section 14 as follows:

Pix4D SA

Data Protection Officer

Route de Renens 24

1008 Prilly

Switzerland

E: data_protection@pix4d.com


3. What Personal Data do we collect and how?

The following Section describes the Personal Data that we collect and how we collect it. There are multiple ways in which we collect Personal Data, which can be broadly categorized into:

(a) Personal Data that You freely choose to share with us,

(b) Personal Data that is automatically collected when You use our Website or Services, and

(c) Personal Data we receive or collect from third parties (including public sources) about You in accordance with applicable law.

(d) If you are a member of an organization, your organization may decide to share input photos or photogrammetry data and metadata with Pix4D for internal R&D projects

(a) Personal Data that You freely choose to share with us

We collect the Personal Data that You directly provide to us with, such as when You set up an account on the Website or when You send us an e-mail.

This type of collection often occurs through our business support processes, such as:


(b) Personal Data that is automatically collected when using our Services

Besides the Personal Data that You freely choose to share with us, we collect technical data when You use our Services and the Website. While information collected in this manner is not typically Personal Data, we may combine it in ways that make it personally identifiable. When we do so, we will treat the combined information as Personal Data.

Information collected in this manner may include:


(c) Personal Data we gather from third parties (including public sources) about You

As far as it is not unlawful, we also collect Personal Data from public sources (for example debt collection registers, commercial registers, the media, or the internet including social media) or receive data from other companies within our Group, from public authorities and from other third parties (such as our contractual or business partners, including our customers, credit agencies, address brokers, internet analytics services, etc.).

We receive the following categories of Personal Data from third parties:


4. For what purposes do we collect and process Personal Data?

We will mainly process Personal Data for the conclusion, administration and performance of our contractual and business relationships and the provision of the Website and our Services as well as for otherwise interacting and communicating with You or with third parties.

We further process Personal Data for the following purposes:


5. On what basis do we process Your Personal Data?

Where we ask for Your consent for certain processing activities (for example for the processing of sensitive Personal Data, for marketing mailings, for advertising management and behavior analysis on the Website), we will inform You separately about the relevant processing purposes. You may withdraw Your consent at any time with effect for the future by providing us written notice (by mail) or, unless otherwise noted or agreed, by sending an e-mail to us or, for marketing mailings, by unsubscribing from receiving marketing mailings on the link provided in these mailings; see our contact details in Section 2. For withdrawing consent for online tracking, see Section 13. Where You have a user account, You may also withdraw consent or contact us also through the Website or other Service, as applicable. Once we have received notification of withdrawal of consent, we will no longer process Your Personal Data for the purpose(s) You consented to, unless we have another legal basis to do so. Withdrawal of consent does not, however, affect the lawfulness of the processing based on the consent prior to withdrawal.

Where we do not ask for consent for processing, the processing of Your Personal Data relies on the requirement of the processing for initiating or performing a contract with You (or the entity You represent) or on our or a third-party legitimate interest in particular in pursuing the purposes and objectives set out in Section 4 and in implementing related measures. Our legitimate interests also include compliance with legal regulations, insofar this is not already recognized as a legal basis by applicable data protection law (for example in the case of the GDPR, the laws in the EEA and in the case of the DPA, Swiss law). This also includes the marketing of our products and services, the interest in better understanding our markets and in managing and further developing our company, including its operations, safely and

efficiently.

Where we receive sensitive Personal Data, we may process Your Personal Data on other legal basis, for example, in the event of a dispute, as required in relation with a potential litigation or for the enforcement or defense of legal claims. In some cases, other legal basis may apply, which we will communicate to You separately as necessary.


6. With whom do we share Your Personal Data?

Pix4D does not sell or rent Personal Data to marketers or unaffiliated Third Parties. We share Your Personal Data with trusted entities, as outlined below:

All these categories of recipients may involve third parties, so that your data may also be disclosed to them. We can restrict the processing by certain third parties (for example IT providers), but not by others (for example authorities, etc.).

In addition, we enable certain third parties to collect personal data from you on our website and at events organized by us (for example press photographers, providers of tools on our website, etc.). Where we have no control over these data collections, these third parties are sole controllers. If you have concerns or wish to exercise your data protection rights, please contact these third parties directly. See Section 12 for the website.

Finally, please remember that when You publicly share Personal Data, this information may be seen and used by other people, as well as indexed by search engines.


7. Is Your Personal Data disclosed abroad?

We process and store Personal Data primarily in Switzerland and the European Economic Area (EEA). In some cases, however, we may also disclose Personal Data to service providers and other recipients (see Section 6) who are located outside this area or who process Personal Data outside this area, in principle in any country in the world. These countries may not have laws that protect Your Personal Data to the same extent as in Switzerland or the EEA. If we transfer Your Personal Data to such a country, we will ensure the protection of Your Personal Data in an appropriate manner. In particular, we use the European Commission's standard contractual clauses for this purpose, available at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj? unless the recipient is already subject to a legally accepted set of rules to ensure data protection or we can invoke an exception. We would like to emphasize that these contractual measures partly compensate for less or no legal protection, but do not completely exclude all risks (e.g. the risk of data being accessed by governments abroad). In exceptional cases, we may allow the transfer of Your Personal Data to countries without adequate protection in other cases, for example if You consent, in the context of legal proceedings abroad or if it is necessary for the performance of a contract.

Note that data exchanged via the internet is often routed through third countries. Your data may therefore be sent abroad even if the sender and recipient are in the same country.


8. How long do we process Your Personal Data?

We process Your Personal Data for as long as our processing purposes, the legal retention periods and our legitimate interests in documentation and keeping evidence require it or storage is a technical requirement. You will find further information on the respective storage and processing periods for the individual data categories in Section 3, and for cookies in Section 13. If there are no contrary legal or contractual obligations, we will delete or anonymize Your Personal Data once the storage or processing period has expired as part of our usual processes.


9. How do we protect Your Personal Data?

We take appropriate security measures in order to maintain the required security of Your Personal Data and ensure its confidentiality, integrity and availability, and to protect it against unauthorized or unlawful processing, and to mitigate the risk of loss, accidental alteration, unauthorized disclosure or access. Technical and organizational security measures may include encryption and pseudonymization of data, logging, access restrictions, keeping backup copies, giving instructions to our employees, entering confidentiality agreements, and monitoring. We protect Your Personal Data that is sent through our Website in transit by appropriate encryption. However, we can only secure areas in our control. We also require our data processors to take appropriate security measures. However, security risks can never be excluded completely; residual risks are unavoidable. If You have reason to believe that Your interaction with us is no longer secure (for example, if You feel that the security of Your account has been compromised), please contact data_protection@pix4d.com immediately.


10. What Personal Data do we process on our social network pages?

We may operate pages and other online presences ("fan pages", "channels", "profiles", etc.) on social networks and other platforms operated by third parties and collect the Personal Data about You described in Section 3 and below. We receive this data from You and from the platforms when You interact with us through our online presence (for example when You communicate with us, comment on our content or visit our online presence). At the same time, the platforms analyze Your use of our online presences and combine this data with other data they have about You (for example about Your behavior and preferences). They also process this data for their own purposes, in particular for marketing and market research purposes (for example to personalize advertising) and to manage their platforms (for example what content they show You) and, to that end, they act as separate controllers.

We process this data for the purposes set out in Section 4, in particular for communication, for marketing purposes (including advertising on these platforms) and for market research. You will find information about the applicable legal basis in Section 5. We may disseminate content published by You (for example comments on an announcement), for example as part of our advertising on the platform or elsewhere. We or the operators of the platforms may also delete or restrict content from or about You in accordance with their terms of use (for example inappropriate comments).

For further information on the processing of the platform operators, please refer to the privacy information of the relevant platforms. There You can also find out about the countries where they process Your data, Your rights of access and erasure of data and other data subjects rights and how You can exercise them or obtain further information. We currently use the following platforms:


11. What applies in case of Profiling?

We may automatically evaluate personal aspects relating to You ("Profiling") based on Your data (Section 3) for the purposes set out in Section 4, where we wish to determine preference data, but also in order to detect misuse and security risks, to perform statistical analysis or for operational planning. We may also create profiles for these purposes, i.e. we may combine behavioral and preference data, but also contract and master and technical data relating to You in order to better understand You as a person with Your various interests and other characteristics. If You are our customer, we may, for example, use Profiling to determine which other products are likely to be of interest to You based on Your purchases. We may also use profiling to assess Your creditworthiness before offering You to pay for a purchase by invoice. An automated data analysis may also determine, for Your own protection, the likelihood of a particular transaction being fraudulent. This allows us to suspend the transaction for further clarification. "Profiles" are to be distinguished from Profiling. "Profiles" refers to the combining of different data in order to draw conclusions on essential aspects of Your personality (for example what You like, how You behave in certain situations) from the totality of this data. Profiles may also be used for marketing, for example, or for security purposes. In both cases, we pay attention to the proportionality and reliability of the results and take measures against misuse of these profiles or profiling. Where these can produce legal effects concerning You or similarly significantly affect You, we generally ensure human review.


12. Chatbot

When You interact with our chatbot for general technical support alongside with webinars and technical documentation a chatbot is available to help You to find answers to any technical questions You may have about Pix4D and our products. The chatbot does not deal with questions relating to an individual situation or contractual relationship but it will be able to help You to find the page or contact on the Pix4D websites where You can obtain this information.

When You activate the chatbot by starting the chat, a session ID is generated and stored in a Cookie for technical purposes to provide the service. Entering personal data is not required and will not result in any appropriate response. For example, neither Your name, or information on the company You work for, nor any contractual information will be necessary to process the question You may have, as the chatbot cannot associate technical information with an identity. Therefore, we discourage users from entering any personal data when interacting with the bot. If You are a customer and have any specific technical or contractual issue, You can reach out to www.pix4d.com/contact-support and issue a support ticket.

The chatbot is offered by Eligere Technologies Inc. who uses OpenAI-API and has been trained on our Pix4D Documentation (https://support.pix4d.com/hc/en-us ) only. session IDs, queries and responses will be stored for 5 years on a server from Digital Ocean (DigitalOcean | Cloud Infrastructure for Developers ) in the US. Digital Ocean is certified under the EU-/UK-/Swiss-U.S. Data Privacy Framework. We process this information based on our and Your legitimate interest in providing efficient technical support services for general enquiries, to enrich and improve our knowledge base and to provide more appropriate responses.


13. What kind of cookies and other tracking methods do we use?

Like most websites, we may use cookies to ensure the functionality of the Website and carry out analysis and personalization. Cookies are little files that are stored on Your data storage medium and that memorize, through Your Internet browser, some configurations and data in order to exchange them with our system.

We use these technologies on our Website and may allow certain Third Parties to do so as well. However, depending on the purpose of these technologies, we may ask for consent before they are used. You can set Your browser to block or deceive certain types of cookies or alternative technologies, or to delete existing cookies. You can also add software to Your browser that blocks certain third-party tracking. You can find more information on the help pages of Your browser (usually with the keyword "Privacy") or on the websites of the Third Parties set out below.

We distinguish the following categories of "cookies" (including other technologies):


14. What are Your Rights?

Applicable data protection laws grant You the right to object to the processing of Your data in some circumstances, in particular for direct marketing purposes, to profiling carried out for direct marketing purposes and to other legitimate interests in processing.


To help You control the processing of Your Personal Data, You have the following rights in relation with our data processing, depending on the applicable data protection law:


If You wish to exercise the above-mentioned rights in relation with us (or with one of our group companies), please contact us in writing, at our premises or, unless otherwise specified or agreed, by e-mail; You will find our contact details in Section 2. In order for us to be able to prevent misuse, we need to identify You (for example by means of a copy of Your ID card, unless identification is not possible otherwise).

You also have these rights in relation with other parties that cooperate with us as separate controllers – please contact them directly if You wish to exercise Your rights in relation with their processing. You will find information on our key partners and service providers in Section 6 and additional information in Section 10.

Please note that conditions, exceptions or restrictions apply to these rights under applicable data protection law (for example to protect Third Parties or trade secrets). We will inform You accordingly where applicable.

If You do not agree with the way we handle Your rights or with our data protection practices, please let us or our Data Protection Officer (Section 2) know. If You are located in the EEA or in Switzerland, You also have the right to lodge a complaint with the competent data protection supervisory authority in Your country. You can find a list of authorities in the EEA here: https://edpb.europa.eu/about-edpb/board/members_en You can reach the Swiss supervisory authority here: https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html.


15. Revision to this Privacy Notice

We may revise this Privacy Notice from time to time to reflect new services, changes in our Personal Data practices or relevant laws. The “Last updated” legend at the top of this Privacy Notice indicates when this Privacy Notice was last revised. Any changes are effective when we post the revised Privacy Notice on the Services. We may provide You with disclosures and alerts regarding the Privacy Notice or Personal Data collected by posting them on the Website.

If You have an account with us, we will notify You of any material modifications by sending You an e-mail to the e-mail address associated with Your account, unless You have unsubscribed from all e-mail communications.