GDPR · Switzerland · Europe

Privacy Policy

How AVA-X AG collects, uses, and protects personal data under the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).

AVA-X AG

1. Controller and Contact

The controller responsible for the personal data described in this Privacy Policy is:

AVA-X AG

Switzerland

Rychenbergstrasse 67

8400 Winterthur

Switzerland

Privacy contact

Inquiries relating to this Privacy Policy, data subject requests, or data protection compliance should be directed to:

Postal: AVA-X AG, attn. Privacy, Rychenbergstrasse 67, 8400 Winterthur, Switzerland.

2. Applicable Law

This Privacy Policy is issued for AVA-X AG under applicable European and Swiss data protection law, including the General Data Protection Regulation (GDPR) where it applies to our processing, the Swiss Federal Act on Data Protection (FADP), and, where relevant to our products, the EU Artificial Intelligence Act and sector-specific rules governing biometric processing.

Where our processing affects individuals in the European Economic Area (EEA), UK, or Switzerland, we process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.

AVA-X AG is the contracting entity for customers in Europe and Switzerland. Our sibling entity AVA-X, Inc. serves the United States market under separate terms and privacy notices.

3. Personal Data We Collect

We generally process personal data that you provide to us, that is generated through use of our website or services, or that is collected in the course of our business relationships, always for a defined, lawful purpose.

3.1 Identity and contact data

  • Name, organisation, job title, postal or physical address, email address, and telephone number
  • Contract documents, billing and payment information (for example bank details and invoice data)
  • Other information you provide when communicating with us (including demo or contact form submissions)

3.2 Technical and usage data

  • IP address, browser type, operating system, device type, and access times
  • Log data when using our website, portals, or cloud-connected services

3.3 Publicly available information

Information from official registers or generally accessible sources, where necessary for business purposes, due diligence, or identification, processed only as permitted by law.

3.4 Customer / end-user operational data

Where we supply video analytics, access control, or related systems to customers, the customer is typically the controller for personal data processed in their environment. We may act as a processor under written instructions and appropriate data processing agreements.

4. How We Use Personal Data

We use personal data only for the purposes set out below, and as otherwise disclosed at collection or permitted by applicable data protection law.

Contract and service delivery

  • Entering into and performing contracts for our products and services (delivery, installation, support, licensing)
  • Customer service, communication, and invoicing

Basis: performance of a contract (Art. 6(1)(b) GDPR); legitimate interests where applicable.

Legal obligations

  • Compliance with statutory retention, tax, and company-law requirements
  • Responding to lawful requests from Swiss, European, and other competent authorities

Basis: compliance with legal obligations (Art. 6(1)(c) GDPR).

Business operations and security

  • Operating, securing, and improving our website and services (including IT security and fraud prevention)
  • Establishing, exercising, or defending legal claims

Basis: legitimate interests (Art. 6(1)(f) GDPR), balanced against your privacy rights.

Consent / marketing

  • Marketing communications (newsletters, campaigns) where consent or another lawful basis is required
  • Non-essential analytics or tracking technologies on our website

Basis: consent (Art. 6(1)(a) GDPR) where required; you may opt out of marketing at any time.

5. Biometric and Special Category Data

Under the GDPR, biometric data used for unique identification (such as facial templates for recognition) is generally treated as special category personal data. Processing requires an appropriate legal basis under Art. 9 GDPR (for example explicit consent, substantial public interest where authorised by law, or safeguards for employment and security) and must comply with the EU AI Act where our products fall within its scope.

Where we process biometric or other special category personal data in connection with our products or services (for example facial recognition or video analytics), we do so only as permitted by applicable law, with appropriate technical and organisational safeguards, and, where we act as a processor, under customer instructions and data processing agreements.

Customers deploying AVA-X technology remain responsible for ensuring their own compliance with applicable European and Swiss data protection law in respect of individuals in their environments (including notice, consent or other required authorisations, data protection impact assessments where required, and retention limits).

6. Processors and Third Parties

We only share personal data with third parties where this is necessary and lawful, including where:

  • required for contract performance (for example payment providers or logistics partners),
  • required to comply with a legal obligation (for example regulators or law-enforcement agencies),
  • provided to processors under written agreements that impose data protection and security duties consistent with the GDPR and Swiss FADP, or
  • you have consented to the disclosure.

We do not sell personal data. We do not share personal data for cross-context behavioural advertising.

Typical recipients include:

  • Swiss, European, and other competent authorities where required by law
  • IT, hosting, cloud, and communications service providers
  • Banks and payment processors
  • Professional advisers (legal, accounting, insurance)

7. International Transfers

Personal data collected in Switzerland or the EEA may be processed by AVA-X AG and affiliated entities or service providers in other countries. Where transfers occur outside Switzerland or the EEA to jurisdictions without an adequacy decision, we implement appropriate safeguards such as Standard Contractual Clauses, binding corporate rules, or other mechanisms recognised under the GDPR and Swiss FADP.

Our product architecture emphasises on-premises and sovereign deployment options so that customer operational data can remain within Switzerland, the EEA, or another chosen jurisdiction.

8. Cookies and Tracking

We use cookies and similar technologies (for example local storage) on our website to:

  • ensure essential functionality and security of the site, and
  • measure usage or support marketing where you have consented or where otherwise permitted.

Essential cookies are required for the website to operate and cannot be disabled through our consent tools.

Restricting cookies in your browser may affect site functionality. You can change or withdraw optional cookie consent at any time via our cookie banner controls where available.

9. Security Safeguards

We implement appropriate technical and organisational measures to protect personal data against loss, damage, unauthorised access, and unlawful processing. These include:

  • Encryption of data in transit (for example HTTPS/TLS)
  • Role-based access controls and multi-factor authentication where appropriate
  • Regular security reviews, backups, updates, and testing
  • Hosting and deployment options designed for data residency and auditability

No method of transmission or storage is completely secure. We will notify the relevant supervisory authority and affected individuals of personal data breaches as required by the GDPR and Swiss FADP.

10. Automated Processing

Where we use personal data for analytics or profiling in connection with our website or marketing, we do so as permitted by applicable law (typically consent or legitimate interests).

We do not make decisions with legal or similarly significant effects based solely on automated processing of personal data without appropriate human involvement. Where our products assist customers with automated analysis (for example video analytics), those customers remain responsible for ensuring human oversight, transparency, and lawful use in their deployments, including compliance with the EU AI Act where applicable.

11. Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law (including Swiss tax and company records obligations). Thereafter, data is destroyed, deleted, or anonymised in a manner that prevents reconstruction in ordinary course.

Where data is needed for more than one purpose, access is restricted to the purpose still requiring retention until all applicable periods expire.

12. Your Data Subject Rights

Under the GDPR and Swiss FADP, you have the following rights in relation to your personal data, subject to applicable conditions and legal exceptions:

Right of access

You may request confirmation of whether we process personal data about you, and obtain a copy of that data together with information about the processing.

Right to rectification

You may request that we correct inaccurate personal data or complete incomplete personal data.

Right to erasure

You may request deletion of personal data where there is no compelling reason for continued processing, subject to legal exceptions (for example records we must retain).

Right to restriction

You may request that we restrict processing of your personal data in certain circumstances, for example while accuracy is being verified or where you have objected to processing.

Right to data portability

Where processing is based on consent or contract and carried out by automated means, you may request to receive your personal data in a structured, commonly used, machine-readable format, or have it transmitted to another controller where technically feasible.

Right to object

You may object to processing based on legitimate interests, including profiling. You may also object at any time to processing for direct marketing purposes.

Withdraw consent

Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

Exercising your rights

To exercise these rights, contact us at privacy@ava-x.ai. We may request reasonable proof of identity before actioning a request, to prevent unauthorised disclosure. We will respond within the timeframes required by applicable law (generally one month under the GDPR).

13. Legal Bases for Processing

We process personal data only where we have a valid legal basis. The table below summarises the bases we rely on most frequently:

PurposeLegal basis
Contract performanceArt. 6(1)(b) GDPR
Legal complianceArt. 6(1)(c) GDPR
Security and fraud preventionArt. 6(1)(f) GDPR
Marketing (where required)Art. 6(1)(a) GDPR
Biometric processing (where applicable)Art. 9 GDPR (as applicable)

Where we rely on legitimate interests, we balance those interests against your rights and freedoms. You may request further information about the balancing test by contacting privacy@ava-x.ai.

14. Complaints

If you believe that your personal data has been processed unlawfully, please contact us first so we can attempt to resolve the matter. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement, or with the Swiss Federal Data Protection and Information Commissioner (FDPIC):

Federal Data Protection and Information Commissioner (FDPIC)

Feldeggweg 1, 3003 Bern, Switzerland

Website: edoeb.admin.ch

For processing subject to the GDPR, you may also contact your local EU/EEA data protection authority. A list of authorities is published by the European Data Protection Board.

15. Changes to this Policy

We may update this Privacy Policy from time to time to reflect legal, operational, or product changes. The current version is always published on this page with the "Last updated" date. Material changes will be communicated in an appropriate manner (for example by notice on our website or by email where we hold a current address for that purpose).

16. Questions and Contact

For questions, suggestions, or requests regarding privacy at AVA-X AG, please contact:

Privacy contact

AVA-X AG

Email: privacy@ava-x.ai

Postal correspondence:

attn. Privacy
Rychenbergstrasse 67, 8400 Winterthur, Switzerland

Related: Privacy, GDPR & AI Ethics

Closing note

This Privacy Policy explains how we handle personal data and reflects our commitment to responsible processing under European and Swiss data protection law.

Unless otherwise stated, the GDPR and Swiss FADP govern the processing described here, to the extent they apply to AVA-X AG.

© 2026 AVA-X AG: All rights reserved.