Privacy policy for XMReality Remote Guidance


PRIVACY POLICY FOR XMREALITY REMOTE GUIDANCETM

Dear User,

Welcome to XMReality Remote GuidanceTM (the “Service”), which is provided by XMReality AB (publ), company registration number 556722-7284 having its registered address at Teknikringen 10, 583 30 Linköping, Sweden (“we” or “us”), offered to companies (with each such legal person having entered into an agreement with us regarding use of said solution being a “Customer”).

You may use the Service acting as an authorized employee or consultant of a Customer and you acknowledge that the Service is not provided to you as a consumer. Reference is also made to our End User License Agreement (the “EULA”).
Under the Swedish Personal Data Act (1998:204), which implements the EU Directive 95/46/EC, and following the 25th of May 2018, the regulation (2016/679/EU) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (collectively “Applicable Data Protection Laws”), it is the entity deciding the purposes and the means of processing that is the personal data controller for the processing. When you use the Service, the Customer having authorized your use is the personal data controller for the processing of your Personal Data (as defined below), and we are the personal data processor of the Customer, processing such data on behalf of and according to the instructions of said Customer. Nevertheless, we collect and process certain and limited information, to the extent necessary for the functioning of the Service and your use thereof, and we are the data controller in relation to this processing of Personal Data. Your privacy is important to us. This document contains a policy statement regarding the collection, use and processing of Personal Data within the Service and your rights in relation to your Personal Data, as well as information about with whom we share such information with. With “Personal Data” we mean information which is directly or indirectly referable to a natural living person, e.g. name and address but also possibly, device ID, location data or IP addresses. We collect the information set out below, which include your Personal Data.

Please read this Privacy Policy before you use the Service.

Processed DATA

The following Personal Data is collected and processed when you use the Service:

  • Your user id, typically your e-mail address.
  • Optionally your name, if entered into the system
  • Your chat conversations
  • Records of calls made, including other parties in the call, time and duration.
  • Technical data, including your unique device ID, IP address, network and device performance and other information about your use of the Service.

PURPOSES OF PROCESSING

Customer

The Customer that has authorized your use of the Service processes the Personal Data for the purpose of carrying out activities involving the use of XMReality Remote GuidanceTM. Use of the Personal Data collected for other purposes, if applicable, are to be communicated to you by each such Customer in their capacity of personal data controllers.

XMReality

We will process the information set out above for the following purposes:

  • to administrate your account, to enable and provide the Service and improve our solution for remote guidance, and to otherwise fulfill our obligations with regard to the agreements entered into with our Customers;
  • to inform you about updates of the Service or our EULA;
  • to improve and develop the Service;
  • to ensure the technical functioning of the Service and to prevent use of the Service in breach of the EULA;
  • to enforce the EULA, including to protect our rights, property and safety and also the rights, property and safety of third parties if necessary; and
  • to fulfil requirements by law.

LEGAL GROUND

The processing of Personal Data is based on our legitimate interests, which serves as the legal ground for the processing.

Our legitimate interests are (i) to provide our services to the Customer; and (ii) to continually offer, improve and develop the Service. We are not able to fulfill our legitimate interests without processing some Personal Data.

In the balancing of interests between our legitimate interests, and your interests and rights and freedoms, it is considered that in your position as an employee of the Customer it is expected of you to use the tools and services that you are directed to use by your employer. Therefore, since you have not objected to such processing of Personal Data, we assume that you are not opposing to our processing of Personal Data when providing the Service. Furthermore, we respect the value and integrity of Personal Data – therefore, we have implemented technical and organizational security measures to ensure the integrity and
confidentiality of the Personal Data. The number of employees that processes Personal Data at XMReality is kept to a minimum, they are trained to process the Personal Data in accordance with our internal data protection policies, and they are subject to confidentiality undertakings. The types and amount of Personal Data that is processed, is the minimum data possible to enable us to fulfil our legitimate interests. The Personal Data will not be used for any other purposesthan what is set out in this Privacy Policy and will not be used for additional purposes in the future. In light of this, we consider that the processing of Personal Data conducted by us does not infringe your rights and freedoms, and that our legitimate interests set out above are not incompatible with your interests. Please note that the Customer’s processing of your Personal Data may be based on other legal
grounds than what we have set out here.

DISCLOSURE OF PERSONAL DATA

We may share and disclose your Personal Data to our sub-contractors within the EU/EEA.

Your e-mail address may be disclosed to other users of the Servicesthat you choose to connect within the Service.

RETENTION OF PERSONAL DATA

The Personal Data is processed for the period during which the Service is provided to you. Upon termination of a user account, the Personal Data relating to such an account will be deleted within 3 months after the termination of the applicable customer agreement or within reasonable time after the 3 months period.

RESPONDING TO LEGAL REQUESTS AND PREVENTING HARM

We can access, preserve and share your information in response to a legal request (like a search warrant, court order or a subpoena or the like), or when necessary to detect, prevent and address fraud and other illegal activity, to protect ourselves, you and other users, including as part of investigations, if we have a good faith belief that the applicable law require us to do so.

This includes responding to legal requests from jurisdictions outside of the EU/EEA when we have a good faith belief that the response is required by law in that jurisdiction, affects users in that jurisdiction, and is consistent with internationally recognized standards.

Information that we receive about you when you use our Service, can be accessed, preserved and retained for an extended period of time when it is the subject of a legal request or obligation, government investigation, or investigations concerning possible violations of our EULA or policies, or otherwise to prevent harm.

SOME OTHER THINGS YOU NEED TO KNOW

Change of Control

If the ownership of our business changes, we will transfer your information to the new owners so they can continue deliver our solution for remote guidance, including the Service. The new owner will still have to honor the commitments we have made in this Privacy Policy.

Notice of changes

If we make changes to this Privacy Policy, we will notify you by publication here in the Service. If the changes are material, we will provide you additional, prominent notice as appropriate under the circumstances and, where required under applicable law, ask for your consent.

Your Privacy Rights under Applicable Data Protection Laws

Applicable Data Protection Laws permits residents of the Member States to request details about what Personal Data is stored with us, the source of the data and the identity of parties to whom the data has been provided free of charge, as well as other information, without indicating any reasons.

You can object to the use of your Personal Data at any time. Nevertheless, please note that the Customer’s processing of your Personal Data may be on other legal grounds than what we have set out in this Privacy Policy. In addition, you can request rectification, erasure or blocking at any time of any Personal Data. However, if we are under legal obligation to save the data, such data can only be blocked. Furthermore, we will assess all requests on a case by case basis and might in some cases not be able to adhere to your request.

To exercise the aforementioned rights in relation to us, or if you have any questions about our sharing practices, your rights under Applicable Data Protection Laws, or wish to have your Personal Data removed, please contact us at the following address: XMReality AB, Teknikringen 10, 583 30 Linköping, Sweden. In order to ensure that you receive a swift response, please state in your letter your full name and, if applicable, your address and user name. Please note that you should sign the request in order to receive information of the processing of your Personal Data, and that you may be asked to verify your identity before any Personal Data is disclosed or information given.