Nextech AR Solutions
Effective date November 23, 2021
We care about your privacy.
Our “products and services” include any and all services related to the various augmented reality (AR) services provided through https://www.nextechar.com/, including but not limited to the ARitize App, Map Dynamics, HoloX, ARWAY, LiveX, and the 3D modelling and serving provided through https://www.threedy.ai/ and our other related websites, services, applications, products and content and excluding any third party software, websites, or services that may interact with our products and services. “Personal data” means information about an identifiable individual.
This Policy references the General Terms and Conditions available at [link] (the “Terms”) and forms an integral part of the Terms. All capitalized terms not defined in this Policy have the meaning provided in the Terms.
We will give you additional privacy information that is specific to a product or service in supplements to this Policy and other notices you may see while using our products or services (“Supplements”). If there is a difference between such Supplements and this Policy, the terms of the Supplements prevail as necessary to resolve the difference.
Software on your device may access your information. Our products or services may contain links to, or may be embedded within, other companies’ websites and services that have privacy policies of their own. We have no responsibility or liability for, or control over, any such third party products or services or such third parties’ collection, use and disclosure of your personal data. We encourage you to read the privacy policies of those other products and services to learn how they collect and use your personal data.
Where our products or services are embedded to products and services of our customers, we require our customers to provide necessary transparency to you. This might include linking to this Policy and the relevant Supplements, or providing the transparency in integrated and embedded notices which identify us as the service provider or controller.
If you do not agree with this Policy, do not use our products and services or provide us with your personal data.
What information do we collect?
We collect your personal data and other information when you make a purchase, use or register into our services, take part in campaigns or research or otherwise interact with us. This includes following categories:
Product and service activations
Our products and services may require electronic activation, where your device and application type, as well as unique device, application, network and subscription identifiers are sent to Nextech.
Use of products and services
Our applications may contact our servers periodically, for example to check for updates or to send us information relating to service usage.
Additionally, we may invite you to join voluntary beta testing and other product and service improvement or research programs where detailed information is collected.
Information you provide us with.
When you create an account, make a purchase, request services, participate in research or campaigns or otherwise interact with us, we may ask for information such as your name, email address, phone number, street address, user names and passwords, feedback, information relating to your devices, age, gender, and language, bank account number, credit card details and other such financial information.
We also maintain records of your consents, preferences and settings relating to, for example, location data, marketing and sharing of personal data.
When you use certain products and services, such as HoloX, you necessarily provide us with images and videos. You therefore provide us with any personal data that may be contained within the the images and videos you provide to us. For example, if you send us a selfie for us to turn into a hologram via HoloX.
Your transactions with us.
We maintain records of your purchases, downloads, the content you have provided us with, your requests, agreements between you and Nextech, the products and services provided to you, payment and delivery details, your contacts and communications and other interactions with us. We may, in accordance with applicable law, record your communication with our customer care or with other such contact points.
Positioning and Location data.
Location-based services establish location through the use of satellite, mobile, Wi-Fi, Bluetooth Low Energy (“BLE”) or other network based positioning methods. These technologies may involve exchanging your location data and unique device and mobile, Wi-Fi, Bluetooth, or other network related identifiers with Nextech. Our products may operate on multiple device platforms, applications and services which may also collect your location data. We do not use this information to identify you personally without your consent.
When you use our location based services and features, for example location based search, navigation and routing, or request for map data, your location data is sent to Nextech to serve you with the right content, which may also include location based advertising.
Information provided by partners.
We obtain information from industry partners and a variety of other sources, including publicly available sources such as business registries. We require these sources to comply with applicable laws with regard to collecting and transferring this data to us, including ensuring that there is a legal basis for the transfer or anonymizing the data in accordance with applicable laws prior to disclosure of the data to us.
Why do we process Personal Data?
Nextech may process your personal data for the following purposes. One or more purposes may apply simultaneously.
Providing products and services
We may use your personal data to provide you with our products and services, to process your requests or as otherwise may be necessary to perform the contract between you and Nextech, to ensure the functionality and security of our products and services, to identify you as well as to prevent and investigate fraud and other misuses.
Some services may require an account to help you manage your content and preferences. Depending on the service, an account creation may be either required or voluntary. Account creation requires you to provide us with basic contact details about yourself, such as name, email address, country of residence and date of birth. You may also be able to voluntarily provide more information about yourself while creating a profile, such as a photo or avatar of your choice.
Developing and managing products and services
We may use your personal data to develop and manage our products, services, customer care, sales and marketing. We may combine personal data collected in connection with your use of a particular Nextech product and/or service with other personal data we may have about you, unless such personal data was collected for a purpose, where the original purpose is incompatible with this purpose.
Communicating with you
We may use your personal data to communicate with you, for example, to inform you that our services have changed or to send you critical alerts and other such notices relating to our products and/or services and to contact you for customer care related purposes.
Marketing, advertising and making recommendations
We may contact you to inform you of new products, services, or promotions we may offer and to conduct market research when we have your consent or it is otherwise allowed. We may use your personal data to personalize our offering and to provide you with more relevant services, for example, to make recommendations and to display customized content and advertising in our services. This may include displaying Nextech and third party content.
What is our legal basis for processing your Personal Data?
Our legal basis for processing your personal data is dependent on the purpose of processing and may vary as described in the Supplement applicable to the product or service you are using. In general, we process your personal data under the following legal bases:
We will process your personal data only with your knowledge and consent, except where exempted, required or permitted by applicable laws. The form of consent may vary depending on the circumstances and the type of data being requested. Your consent may be express with clear options to say “yes” or “no”, such as by being asked to check a box to indicate your consent, or implied, such as when you provide us with your address through a form or email seeking information and we use those means to respond to your request. Your consent can also be provided by your authorized representative. Taking into account the sensitivity of your personal information, purposes of collection, and your reasonable expectations, we will obtain the form of consent that is appropriate to the personal information being processed. By using our products and services, or otherwise by choosing to provide us with your personal information, you acknowledge and consent to the processing of your personal data in accordance with this Policy and as may be further identified when the personal data is collected or through applicable Supplements. When we process your personal data for a new purpose, we will document that new purpose and ask for your consent again.
If you do not consent to the processing of your personal data in accordance with this Policy, please do not access or continue to use any of our products or services, or otherwise provide any personal information to us.
You may refuse to provide consent or may notify us at any time that you wish to withdraw or change your consent to the processing of your personal data without penalty, subject to legal or contractual restrictions and reasonable notice by (i) changing your privacy preferences through the product or service, as applicable, (ii) deleting your account with us and stopping use of our products and services, or (iii) opting out of the use of your personal data by contacting our Privacy Officer (see below). However, if you withdraw or change your consent, we may not be able to provide you our products and services.
Other Legal Bases
Aside from consent, we may also process your personal information under other legal bases, as permitted by applicable laws.
Residents of the European Economic Area (EEA)
If you are resident in the European Economic Area (EEA) the following legal bases apply to our processing of your personal data by us.
Performance of a contract with you
We process your personal data to perform our obligations under the terms and conditions applicable to the product or service you are using, provided by us or our customers, including without limitation our Terms.
We process your personal data if you have consented to the processing activity. You may revoke your consent at any time. Doing so will bar us from further processing of your personal data based on your consent, but will not impact the lawfulness of processing based on your consent before it was withdrawn. Some of the features of our products and services might be only available based on consent.
We process your personal data as needed to comply with laws and regulations.
We process your personal data to further our legitimate interests, such as in connection with managing, developing, testing, securing, and in limited circumstances marketing, advertising, and making recommendations regarding our products and services. Any such processing is conducted subject to appropriate measures to protect your fundamental rights and freedoms related to your personal data, and in any event, will be subject to the restrictions provided in this Policy. Further information or specification of our legitimate interests may be provided in relevant Supplements applicable to the product or service.
How long do we retain Personal Data?
We endeavor to only collect personal data that are necessary for the purposes for which they are collected and to retain such data for no longer than is necessary for such purposes. The length of time personal data is retained, and criteria for determining that time, are dependent on the nature of the personal data and the purpose for which it was provided. For example, your personal data related to managing your account (such as name, email address, and account content and preferences) are maintained for as long as they are retained by you within your account. Other data, such as records of your activity within the application, are typically maintained only for a short period before being anonymized or pseudonymized. Additional information may be provided in the Supplement applicable to the product or service you are using. You may contact the Nextech Privacy Office at privacy@NextechAR.com to obtain additional information about the retention of your personal data.
Do we share Personal Data?
We do not sell, lease, rent, or otherwise disclose your personal data to third parties unless otherwise stated below.
Your consent and social sharing services
We may share your personal data if we have your consent to do so. Some services may allow you to share your personal data with other users of the service or with other services and their users. Please consider carefully before disclosing any personal data or other information that might be accessible to other users.
NexTech companies and authorized third parties
We may share your personal data with other Nextech companies or authorized third parties who process personal data for Nextech for the purposes described in this Policy. This may include for example billing through your network service provider or otherwise, delivery of your purchases, providing services including customer service, managing and analyzing consumer data, credit checks, conducting research, and managing marketing and other such campaigns. When you purchase a Nextech product from us with a network service provider plan, we may need to exchange information with your network service provider to provide you with such service.
We may conduct joint marketing and other communications with our partners, for example, your mobile operator. To avoid duplicate or unnecessary communications and to tailor the message to you we may need to match information that NexTech has collected with information that the partner has collected where this is permitted by law.
These authorized third parties are not permitted to use your personal data for any other purposes. We bind them contractually, require them to act consistently with this Policy and to use appropriate security measures to protect your personal data.
International transfers of personal data
Our products and services may be provided using resources and servers located in various countries around the world. Therefore your personal data may be transferred across international borders outside the country where you use our services, including to countries outside of Canada or the European Economic Area (EEA) that do not have laws providing specific protection for personal data or that have different legal rules on data protection, for example, certain jurisdictions within the United States of America. In such cases we ensure that there is a legal basis for such a transfer and that adequate protection for your personal data is provided as required by applicable law, for example, by using standard contractual clauses approved by the European Commission or relevant authorities (where necessary) and by requiring the use of other appropriate technical and organizational information security measures. You may contact the Nextech Privacy Office at privacy@NextechAR.com to obtain additional information about the safeguards we take in connection with these transfers. A copy of the unchangeable Standard Contractual Clauses can be accessed at https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-o….
We may be obligated by mandatory law to disclose your personal data to certain authorities or other third parties, for example, to law enforcement agencies in the countries where we or third parties acting on our behalf operate. We may also disclose and otherwise process your personal data in accordance with applicable law to defend Nextech’s legitimate interests, for example, in legal proceedings or in connection with governmental requests and filings.
Mergers and Acquisitions
If we decide to sell, buy, merge or otherwise reorganize our businesses in certain countries, this may involve us disclosing personal data to prospective or actual purchasers and their advisers, or receiving personal data from sellers and their advisers.
How do we address the privacy of children?
NexTech products and services are typically intended for general audiences. NexTech does not knowingly collect information about children without the consent of their parents or guardians.
How do we address Data Quality?
We take reasonable steps to keep the personal data we possess accurate and to delete incorrect or unnecessary personal data.
We encourage you to access your personal data through your account from time to time to ensure that it is up to date.
What steps are taken to safeguard Personal Data?
Privacy and security are key considerations in the creation and delivery of our products and services. We have assigned specific responsibilities to address privacy and security related matters. We enforce our internal policies and guidelines through an appropriate selection of activities, including proactive and reactive risk management, security and privacy engineering, training and assessments. We take appropriate steps to address online security, physical security, risk of data loss, and other such risks taking into consideration the risk represented by the processing and the nature of the data being protected. Also, we limit access to our databases containing personal data to authorized persons having a justified need to access such information.
Use of Apple’s Truedepth API
Nextech’s ARitize iOS app may use your device’s TrueDepth camera system to track facial features. This allows for unique interactive AR Experiences — try on virtual glasses, earrings, headwear. In order for this functionality to be possible, the app requires access to your device’s camera. Camera access is strictly user-controlled and can be enabled or disabled at any time in your device’s settings.
The camera images and resulting depth data are only used for interactive AR Experience purposes. The live video feed is never used, and its data is never stored locally or remotely. Camera access is required to get depth data from Apple’s API’s.
This data is retained on the device only for the duration of your current session. Every time the home screen is presented or the app is closed, the data is deleted.
Face data is never stored remotely or given to third parties. The face data only remains on your device, and never leaves your device at any time.
What are your rights?
You have a right to know what personal data we hold about you, and to access it. You have a right to have incomplete, incorrect, unnecessary, or outdated personal data updated. You have the right to request that your personal data be erased, and to obtain a copy of your data in a machine-readable format. You have the right to object to or restrict processing in certain circumstances, such as where you believe the data is inaccurate or the processing activity is unlawful. You have a right to unsubscribe from direct marketing messages and to request that we stop processing your personal data for direct marketing purposes or on other compelling legal grounds. However, if you opt-out from marketing and other communications from Nextech, critical alerts may still be sent to you. If you are located in Canada, a European Union member state or within the European Economic Area, you have the right to lodge a complaint about our data collection and processing activities with the supervisory authority concerned.
You may exercise your rights by contacting us or by managing your account and choices through available profile management tools on your device and our services. In some cases, especially if you wish us to delete or stop processing your personal data, this may also mean that we may not be able to continue to provide the services to you. Applicable data protection law may provide certain restrictions on the extent to which these rights may be exercised. If a restriction applies, we will respond to your request with an explanation of what action will be taken, to the extent required under applicable data protection law.
Who is the controller of your Personal Data?
Nextech AR Solutions, Suite 501, 121 Richmond ST W, Toronto, ON M5H 2K1, Canada is the controller of your personal data.
In addition, the Nextech affiliate providing the product or service may be a controller of your personal data. You may find the identity of the controller and its contact details by reviewing the terms and conditions of such a product or service or by using contact information provided in the applicable Nextech websites.
In matters pertaining to Nextech’s privacy practices you may contact our Data Protection Officer, Scott Jenkins, at:
Nextech AR Solutions
121 Richmond ST W, Toronto,
Ontario, Canada M5H 2K1
Nextech may from time to time change this Policy or change, modify or withdraw access to this site at any time with or without notice. However, if this Policy is changed in a material, adverse way, Nextech will post a notice advising of such change at the beginning of this Policy and on this site’s home page for 30 days. We recommend that you re-visit this Policy from time to time to learn of any such changes to this Policy.