// Privacy
Privacy policy.
Last updated: 2026-08-18
PIMgate is built and operated in Switzerland for the European and Swiss markets. We design the platform around the EU General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (revFADP), in force since 1 September 2023.
This policy explains what data we collect when you use this website or the PIMgate service, why we collect it, how we keep it safe, and what choices you have. If anything is unclear, write to us — contact details are at the bottom.
1. Who we are
2. What data we collect
Visitors to pimgate.ai
When you visit this website, our web server records your IP address, the page requested, the timestamp, and your browser user-agent. These records exist for security and abuse prevention.
Server and application logs are deleted automatically: API request logs after 90 days, security and audit records after 365 days, share-link access records after 90 days.
We do not run web analytics, behavioural tracking, advertising cookies, or third-party marketing trackers on this website. Usage statistics shown in the admin console are computed from our own database and are not shared with third parties.
Cookies and local storage
We use a small number of strictly necessary cookies. Under Art. 5(3) of the ePrivacy Directive (as implemented in §25(2) TTDSG in Germany) and Art. 45c FMG in Switzerland, these do not require consent because they are required to deliver a service you actively requested.
Strictly necessary
- NEXT_LOCALE — remembers your chosen interface language. 1 year.
- pimgate-theme — remembers your light/dark preference. 1 year.
- next-auth.session-token (and its __Secure- variant over HTTPS) — keeps you signed in to the application. 30 days, HttpOnly.
- next-auth.csrf-token and next-auth.callback-url — protect the sign-in flow against cross-site request forgery. Deleted when you close the browser.
Consent management
We use Cookie Script (Aptigo B.V.) to record cookie preferences. The tool sets its own cookie to store your choice and is loaded from a third-party server, which means your IP address is transmitted to that provider when the banner loads. You can change or withdraw your choice at any time through the banner.
We currently set no advertising, profiling, or cross-site tracking cookies. Should that change, we will obtain your consent beforehand.
The signed-in application stores your theme preference in your browser's local storage. It never leaves your device.
Contact form submissions
When you use the "Talk to us" form, we collect the data you provide:
- Full name
- Work email address
- Company name
- Role (optional)
- Existing PIM (optional)
- Your message (optional)
- Submission timestamp, shortened IP address, and browser user-agent
For this form specifically, your IP address is shortened before it reaches us — the last block of an IPv4 address is set to zero. We use the data only to answer your enquiry and, if you become a customer, to maintain the business relationship. We do not sell, rent, or trade it.
Customer accounts (PIMgate service)
If your organisation is a PIMgate customer, we process the personal data you and your colleagues enter into the platform: names, work email addresses, role and group assignments, sign-in activity, and audit-log entries. Security-relevant actions are recorded together with the acting user and the originating IP address. The legal basis is performance of the contract with your organisation.
Your organisation is the controller for the product and asset information it uploads. Netgen Switzerland AG acts as processor on your behalf, governed by a Data Processing Agreement (DPA) concluded at onboarding.
3. Why we process this data — legal bases
Under Art. 6 GDPR and Art. 31 revFADP, we rely on:
- Contract performance — to provide the PIMgate service to your organisation.
- Legitimate interest — to keep the website and service secure, prevent abuse, and answer enquiries. Where we log IP addresses for security purposes, this is the basis, and you may object (see section 7).
- Consent — where you actively submit a form or accept optional cookies.
- Legal obligation — to comply with Swiss and EU accounting, tax, and data-protection law.
4. Where we store your data
Production data is hosted in the European Union on dedicated servers operated by Hetzner Online GmbH in Falkenstein, Germany. Backups are encrypted and stored within the EU. Database access is restricted to a small number of named operators at Netgen Switzerland AG and is logged.
Some providers listed below are established outside the EU/EEA and Switzerland. Where personal data reaches them, the transfer is based on the EU Standard Contractual Clauses together with supplementary measures, and — for Switzerland — the FDPIC-recognised variant of those clauses.
5. Processors and recipients
We use a small set of service providers to operate the platform. Each is bound by a contract requiring an equivalent level of protection. The current list:
- Hetzner Online GmbH (Germany) — server hosting and object storage for uploaded files.
- Resend, Inc. (USA) — delivery of transactional email such as invitations, password resets, and notifications. Transfer safeguarded by Standard Contractual Clauses.
- Anthropic PBC (USA) — AI-assisted translation, task assistance, and SEO term generation. Content you submit to these specific features is transmitted for processing. Transfer safeguarded by Standard Contractual Clauses.
- Cookie Script (Aptigo B.V., Netherlands) — cookie consent management on this website.
- Cloudinary Ltd. — legacy asset delivery network. Used only where a tenant has explicitly opted in, and for historical asset links that have not yet been migrated.
We inform customers of material changes to this list at least 30 days in advance.
Where your organisation configures its own integrations (for example a connection to a DXP, or custom code embedded in a portal), data may reach further recipients chosen by your organisation. Your organisation is responsible for those choices.
6. How long we keep your data
- API request logs (including IP address and user-agent): 90 days.
- Security and audit records (including IP address): 365 days.
- Share-link access records: 90 days. Asset download records: 365 days.
- Contact-form submissions: up to 24 months, or until you ask us to delete them.
- Customer account data: for the duration of the contract, plus statutory retention periods (typically 10 years for accounting records under Swiss and German law).
7. Your rights
Under the GDPR and the revFADP you have the right to:
- Access — ask what data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data, subject to statutory retention.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive a copy of your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — at any time, with effect for the future.
- Lodge a complaint — with a supervisory authority (see below).
To exercise any of these rights, email support@avidia.ai. We respond within one month, as required by Art. 12(3) GDPR.
Supervisory authorities
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern.
- Germany: the data protection authority of your federal state, or the Federal Commissioner for Data Protection and Freedom of Information (BfDI), Graurheindorfer Str. 153, 53117 Bonn.
- Other EU/EEA states: your national supervisory authority.
8. Security
We protect personal data with technical and organisational measures appropriate to the risk: TLS encryption in transit, encrypted backups, role-based access control, database-level tenant isolation, audit logging, and regular security updates. No system is perfectly secure — if a breach occurs that is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours and inform affected individuals where the law requires it.
9. Automated decision-making
We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR. AI features in the product assist with translation and content drafting; they do not make decisions about individuals.
10. Children
PIMgate is a B2B service. It is not directed at children, and we do not knowingly process personal data of persons under 16.
11. Changes to this policy
We may update this policy from time to time. The date at the top reflects the most recent change. Material changes are communicated to active customers in advance.
Questions about your data? Email us at support@avidia.ai. We read every message.