close-tab-svgrepo-com
Search result
showing 30 result for

    Data protection information Daego®

    Privacy Policy PXL Vision AG for the use of the Daego® Mobile App and the Daego® WebApp

    1. The product

    With the Daego® product, PXL Vision provides you with an option for digital identification with transaction partners independent of PXL, which enables the verification of an ID document based on its security features and the data contained on it, as well as a comparison of the photo contained on the ID document with a selfie video taken by the user. The verified result can then be used by transaction partners to verify the identity at the time of a required identity check.
    Daego® can be used in two different ways: As part of the Daego® Mobile App for installation from a smartphone and via the Daego® WebApp for use via the internet browser.
    As part of the Mobile App, identification is only required once and the app can be used for identification with several transaction partners because the identification data and the validation result are stored in the app. In the case of the WebApp, an ID card comparison must be carried out for each transaction.


     

    2. Secure processing of data

    The verification of ID documents is necessarily associated with the collection and processing of personal data from the scanned document and the video from the identification process. In order to compare the photos, particularly sensitive personal data (biometric data of the user's face) is also collected and processed.
    The processes used by PXL to process this data are subject to strict data protection regulations and are protected by correspondingly secure technical and organizational measures. PXL's servers are located exclusively in Switzerland; no data is transferred to third parties or to other countries (with the exception of the transfer to the specific transaction partners named at the time of identification).


     

    3. Further processing for other purposes (development purposes) pursuant to Art. 13 para. 4 GDPR and your separate consent pursuant to Art. 9 para. 2 GDPR

    The data collected and processed as part of the identification and verification process is generally only processed to provide identification in the respective individual case and is not used for other purposes or even transferred or sold to third parties.
    However, the verification process is based on complex analysis algorithms that require constant improvement in order to enable a reliable analysis result. The processing of this data for this purpose, which differs from the pure identification service, is dependent on the express consent of the user concerned in accordance with data protection laws. PXL therefore requests this consent from the user before using the product. If the user agrees, the collected data is then stored on separate servers, also located exclusively in Switzerland, and is then used to improve the algorithms and the PXL technology on which they are based. Strict technical and organizational security measures naturally also apply here. The employees entrusted with the analysis of the data are separately obliged to strictly comply with data protection and confidentiality.
    To ensure fair and transparent processing, we hereby inform you in accordance with Art. 13 para. 2 GDPR about the processing of this data for this purpose:

    1. Storage period and criteria for the storage period
      In principle, the effective use of machine learning processes requires algorithms with the most comprehensive database possible. It is therefore necessary and sensible to retain the data. Deletion takes place if you request deletion of your data or object to its use, which results in immediate deletion.
    2. Right to object at any time
      You can request your objection to the use of your data for machine learning processes at any time at privacy@pxl-vision.com. This does not affect the lawfulness of the processing carried out on the basis of the consent until revocation.

    3. Right to lodge a complaint with a supervisory authority
      You have the right to lodge a complaint about the processing of your data with a supervisory authority; further information can be found below under section IV.9.d.

    4. Required by law or contract
      The collection and processing of your data in the context of machine learning takes place exclusively on the basis of your voluntary consent.

    5. Automated decision-making and profiling
      The machine learning processes and the associated evaluation of biometric data for the purpose of improving identity verification are not used for profiling purposes. The biometric and identification data of PXL is not used to evaluate the personal aspects of a person who would analyze or categorize you as a data subject with regard to personal characteristics, age, interests, health, economic situation, whereabouts, change of location or behavior and could thus cause legal impairments for you. The data collected and processed with your consent is used exclusively for the algorithmic comparison of your face with the data held in the ID document and for extracting the information relevant for identification for data comparison from the document and verification of the authenticity of the document. As part of an identity check via the app, an automatic decision on verification is made if the comparison is positive, but this is initiated voluntarily by you when using the verification process for use with a transaction partner of your choice. The use of biometric data exclusively for this purpose as part of the machine learning processes is particularly important in order to make this automatic decision as reliable as possible. Your data will not be processed for any other purpose and the automatic decision during verification is based exclusively on the algorithmic comparison of your biometric facial data without any other evaluation of the same.

      PXL thanks you for your willingness to support the improvement of the PXL technology with your consent. Of course, you can revoke your consent at any time by sending an e-mail to privacy@pxl-vision.com. The data will then be deleted immediately.

     

    4. Data protection information obligations

    1. Controller responsible for processing under data protection law

    PXL Vision AG

    Rautistrasse 33

    8047 Zurich, Switzerland

    2. Contact details of the data protection officer

    privacy@pxl-vision.com

    3. Categories of personal data that are processed

    a. When you access the mobile app, we collect and process the following usage data

    • The identification number of your end device (UDID),

    • Type of end device,

    • Operating system of the end device

    • browser version
      b. When you access the WebApp, we collect and process the following usage data

    • The identification number of your end device (UDID),

    • Type of end device,

    • Operating system of the end device

    • browser version

    • Session cookie (for load balancing)
      c. When you initiate and carry out a verification process, we collect and process the following personal data (identification data):

       

      1. Master data: Identity card data

      Surname, maiden name, first names, doctor's degree, date of birth, place of birth, address, nationality, document type, last day of validity, service and card-specific identifier, country code, information on whether a certain age is exceeded or fallen short of, information on whether a place of residence corresponds to the requested place of residence, and religious name, artist name, ID number

      2. Image files

      We collect a photo of both sides of your ID document, your personal photo from the ID document or (if applicable and available) from the NFC data of your ID document and the selfie video of your face

      3. Special types of personal data

      Biometric data such as facial data.

      d. If you contact the contact address provided in the mobile app/web app as part of a user request:

      1. User data:

      Your name and address and, if applicable, e-mail address or telephone number that you provide as part of the user request.

      2. Any identification data provided above,

      if this is necessary to process the user request.

      e. Miscellaneous

      In the event of malfunctions, the app contacts an error reporting tool to rectify the errors and improve the user experience. Data from the end device (browser, operating system) may be transmitted.

     

    5. Purposes for which the personal data is to be processed and the legal basis for the processing

    a. In the following cases, we collect and process data in the context of a legitimate interest in accordance with Art. 6 para. 1 lit. f) GDPR:

    1. Usage / metadata to improve the user experience of the App/WebApp

    2. Usage data to rectify errors in the software or processes

    3. Anonymization of user data for statistical purposes

    4. Identification data and photo files for the purpose of error checking after a completed verification and transaction. Data is also stored in the event of unsuccessful verification in order to be able to follow up on any subsequent errors or complaints.

    b. In the following cases, we collect and process data on the basis of consent pursuant to Article 6(1)(a) or Article 9(2)(a) GDPR

    1. Identification data and biometric data, such as the ID photo and selfie video to carry out the identification and verification process

    2. Identification data and biometric data, such as the ID photo and selfie video, to improve identification procedures in the context of machine learning and artificial intelligence processes.
    For more information on further processing for this purpose, please refer to the detailed explanation above in section III.

    c. In the following cases, we collect and process data for the provision of the contractually agreed service pursuant to Art. 6 para. 1 lit. b)

    1. Collection, processing and transmission of the identification data for comparison with the data record held by the transaction partner. If verification is successful, the data is transmitted to the transaction partner via a secure connection.

    2. Collection, processing and transmission of the photos and the selfie video to compare the ID photo and the person photographed during use and to provide this data to the transaction partner for comparison with their own data to be confirmed by the transaction partner. Once the identification and verification process has been completed, the data is made available to the transaction partner via a secure connection. This also takes place in the event that verification is not successful.
    In addition, machine learning and the use of the data required for its development are also necessary in order to fulfill PXL's contractual obligations and for maintenance and quality assurance purposes.

     

    6. Recipients or categories of recipients of the personal data

    a. No transmission to third parties as part of the verification process

    As part of the verification process, the data will not be transmitted to third parties, but will remain exclusively on PXL's servers in Switzerland until the identity verification has been successfully completed.

    b. Transmission to transaction partners

    After each successfully completed verification, you will be expressly asked by the app or the WebApp for your consent as to whether the result of the verification and the transfer of the collected data for comparison and, if necessary, further storage and processing by the transaction partner may be transmitted to the transaction partner already known to you and expressly and specifically named again during the verification process. Once you have given your consent, PXL transmits this data to the named transaction partner via a secure connection. From this point on, the transaction partner is solely responsible to you for further processing. Please inform yourself about their data protection regulations before giving your consent.

     

    7. Place of data processing / transfer of personal data to a third country

    PXL processes your personal data exclusively on servers in Switzerland, which are protected by state-of-the-art technical and organizational measures and comply with the SOC 2 standard.
    PXL Vision does not transfer your data to third countries unless you have expressly consented to this in the context of a transaction, with the exception of the service providers contractually bound to PXL described in the next paragraph. If a transaction partner is located in a third country that does not belong to the European Economic Area or does not comply with sufficiently recognized data protection regulations, it is up to you to decide whether you agree with the data protection information provided by the specific transaction partner and whether you consent to the transfer by PXL.
    Service providers who process personal data on our behalf outside the European Union (so-called third countries) are only used if an "adequacy decision" of the European Commission (Art. 45 GDPR) exists for this third country, "appropriate safeguards" (Art. 46 GDPR) or "internal data protection rules" (Art. 47 GDPR) are in place at the recipient's premises, if necessary together with additional safeguards. For further information, please contact our data protection officer. Otherwise, your personal data will be processed in third countries if this is necessary to fulfill the contract, if you have given your consent or if there is a legal obligation.
    Employees of our company and service providers who support us in data processing as part of order processing (service providers for IT operations, customer service) have access to your personal data to the extent necessary to fulfill the purposes stated below. Any deviations are expressly indicated below. In individual cases, we are legally obliged to transfer personal data to authorities (e.g. requests for information from investigating authorities) or natural/legal persons (e.g. to assert claims under copyright law).

     

    8. Duration for which the personal data is stored

    a. Operational system

    After completion of a transaction via the MobileApp or WebApp, the data will be deleted immediately in PXL's operational system after retrieval by the transaction partner.

    b. Storage in the mobile app

    The data collected as part of the Mobile App is otherwise stored exclusively on the user's device for as long as the user has installed the app or has not deleted it from the app himself. The data will not be stored by PXL at the same time, but will only be available on the end device.

    c. Storage for machine learning

    With regard to data storage for machine learning purposes, please read section III.

     

    9. Automated decision making

    If the identification and biometric data are successfully matched, an automated decision is made about the identity of the user with the documents scanned by the user. This decision is not based on personal characteristics of the user, such as age, gender, interests, knowledge, etc., but solely on the algorithmic comparison of the image files and the comparison of the identification data. Profiling does not take place.

     

    10. Your rights

    a. Existence of a right to rectification or erasure of personal data concerning you

    With regard to the personal data that you have consented to being used for machine learning purposes, you have the right to object to the processing and erasure at any time, which you can exercise by sending an email to privacy@pxl-vision.com. This does not affect the lawfulness of the processing carried out on the basis of the consent until revocation.

    If you notice an error in the data collected during the verification process via the app or the web app, you should cancel the verification process and inform us of this via the email address support@pxl-vision.com.

    After a successful transaction, the data will be deleted from PXL's operational systems and a correction is no longer possible. With regard to the data stored for auditing purposes in accordance with Section IV.7.b (also in the event of an unsuccessful verification or the termination of the verification process), please also contact the above-mentioned contact details.

    After transmission to the transaction partner following your consent, please contact them directly regarding the correction of the data transmitted to them. PXL no longer has access to this data.

    b. Existence of a right of access by the controller to the personal data concerned

    You can request information about the processing of your personal data from PXL at any time in accordance with Art. 15 GDPR using the contact details provided in sections IV.1 and IV.2 above. We ask for your understanding that in this case we will take appropriate measures to ensure your identity as the correct recipient of the data information.

    c. Right to object to processing and the right to data portability

    You can object to the processing of your data at any time by contacting PXL using the contact details provided in sections IV.1 and IV.2 above. Once the transaction has been completed, your data will no longer be transferred to third parties.

    d. Right to lodge a complaint with the supervisory authority

    You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). You can contact the data protection supervisory authority for this purpose.

    e. Data extract

    You have the right to receive or transfer the personal data concerning you (Art. 20 GDPR). To do so, please use the contact details above.

     

    11. Secure communication

    For the transmission of confidential information, we recommend that you contact us by telephone, post or encrypted contact form. If you contact us by email, social media, messenger services (such as WhatsApp) or other means, we cannot guarantee complete data security.

     

    12. Changes to the data protection regulations

    Since changes to the law or changes to our internal company processes may make it necessary to adapt this privacy policy, which we reserve the right to do accordingly, you can access the current version as well as older versions of the privacy policy at pxl-vision/privacy.

    © PXL-Vision AG, as of April 2023