// Privacy
Privacy policy.
Last updated: 2026-04-25
PIMgate is built and operated in Switzerland for the European and Swiss markets. We take data protection seriously and design the platform to comply with the EU General Data Protection Regulation (GDPR) and the revised Swiss Federal Act on Data Protection (revFADP), in force since 1 September 2023.
This policy explains what data we collect about you when you use this website or the PIMgate service, why we collect it, how we keep it safe, and what choices you have. We aim to be plain about it. If anything is unclear, write to us — contact details are at the bottom.
1. Who we are
2. What data we collect
Visitors to pimgate.ai
When you visit this website, our server logs your IP address (truncated for privacy), the page you requested, the timestamp, and your browser user-agent. These logs are kept for security and abuse-prevention purposes and are deleted after 30 days unless required for incident response.
We do not run analytics, behavioral tracking, advertising cookies, or third-party trackers on this website. There is no cookie banner because we do not set cookies that require consent.
Contact form submissions
When you fill out the "Talk to us" form, we collect the data you provide:
- Full name
- Work email address
- Company name
- Role (optional)
- Existing PIM (optional)
- Your message (optional)
- Submission timestamp, masked IP, and browser user-agent (audit)
We use this data only to respond to your inquiry and, where you become a customer, to maintain the business relationship. We do not sell, rent, or trade this data with anyone.
Customer accounts (PIMgate service)
If your organisation is a PIMgate customer, we process the personal data you and your colleagues enter into the platform: names, work email addresses, role and group assignments, login activity, and audit-log entries. The legal basis is contract performance under our agreement with your organisation.
Your organisation is the data controller for the product and asset information you upload. PIMgate (Netgen Switzerland AG) acts as data processor on your behalf, governed by a Data Processing Agreement (DPA) signed at onboarding.
3. Why we process this data — legal bases
Under GDPR Art. 6 and revFADP Art. 31, we rely on:
- Contract performance — to provide the PIMgate service to your organisation.
- Legitimate interest — to keep the website secure, prevent abuse, and respond to inquiries.
- Consent — where you actively submit a form or sign up for updates.
- Legal obligation — to comply with Swiss tax, accounting, and data-protection law.
4. Where we store your data
Production data is hosted in the European Union, on dedicated servers operated by Hetzner Online GmbH in Falkenstein, Germany. We do not transfer personal data to the United States or other third countries without an appropriate transfer mechanism (Standard Contractual Clauses and supplementary measures) and a documented necessity.
Backups are encrypted and stored within the EU. Database access is restricted to a small number of named operators at Netgen Switzerland AG and is fully logged.
5. Sub-processors
We use a small set of carefully selected service providers to operate the platform. Each is bound by a contract that requires the same level of protection we provide. The current sub-processor list is available on request and through your DPA.
- Hetzner Online GmbH (Germany) — server hosting
- Resend, Inc. — transactional email delivery (with EU SCCs)
- Cloudinary Ltd. — optional asset CDN (per-tenant opt-in)
We notify you of material changes to this list at least 30 days in advance.
6. How long we keep your data
- Server logs: 30 days, then deleted.
- Contact-form submissions: up to 24 months, or until you ask us to delete them.
- Customer account data: for the duration of the contract, plus retention periods required by Swiss law (typically 10 years for accounting records).
- Audit-log entries: tied to the contract; preserved as long as the underlying account is active.
7. Your rights
Under GDPR and revFADP, you have the right to:
- Access — ask what data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your data, subject to legal retention.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive a copy of your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — at any time, where consent is the basis.
- Lodge a complaint — with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your EU national supervisory authority.
To exercise any of these rights, email support@avidia.ai. We respond within one month, or sooner where required by law.
8. Security
We protect personal data with technical and organisational measures appropriate to the risk: TLS encryption in transit, encryption at rest for backups, role-based access control, audit logging, regular security updates, and isolated tenant environments. We test our defences and train our team. No system is perfectly secure — if a breach occurs that is likely to result in risk to your rights, we notify the competent supervisory authority and affected individuals as required by law.
9. Children
PIMgate is a B2B service. It is not directed at children, and we do not knowingly process personal data of persons under 16.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. Material changes will be communicated to active customers in advance.
Questions about your data? Email us at support@avidia.ai. We read every message.