Agreement – 360 Reality Capture
This customer agreement (this “Agreement”) contains the terms and conditions that govern your access to and use of the Aiforsite offerings and is an agreement between Aiforsite (Aiforsite Oy, a company incorporated in Finland, registration number 2756625-8) having its registered office at Keilaranta 1, 02150 Espoo, Finland, the “Provider”) and you or the entity you represent (“Customer”). This Agreement takes effect when you click an “I Accept” button or check box presented with these terms or, if earlier, when you use any of the Aiforsite offerings. You represent to us that you are lawfully able to enter into contracts (e.g., you are not a minor). If you are entering into this Agreement for an entity, such as the company you work for, you represent to us that you have legal authority to bind that entity.
Agreement
1. Definitions
1.1 In this Agreement:
“Access Credentials” means the usernames, passwords and other credentials enabling access to the Hosted Services, including both access credentials for the User Interface and access credentials for the Mobile App;
“Agreement” means this agreement including any Schedules, and any amendments to this Agreement from time to time;
“API” means the application programming interface for the Hosted Services defined by the Provider;
“Business Day” means any weekday other than a bank or public holiday in Finland.
“Business Hours” means the hours of 08:00 to 16:00 (UTC +2) on a Business Day;
“Customer Data” means all data, works and materials: uploaded to or stored on the Platform by the Customer; transmitted by the Platform at the instigation of the Customer; supplied by the Customer to the Provider for uploading to, transmission by or storage on the Platform; or generated by the Platform as a result of the use of the Hosted Services by the Customer (but excluding analytics data relating to the use of the Platform and server log files);
“Customer Personal Data” means any Personal Data that is processed by the Provider on behalf of the Customer in relation to this Agreement;
“Data Protection Laws” means the EU GDPR and the UK GDPR, and all other applicable laws relating to the processing of Personal Data;
“Documentation” means the documentation for the Hosted Services produced by the Provider and delivered or made available by the Provider to the Customer;
“Effective Date” means the date of execution of this Agreement;
“EU GDPR” means the General Data Protection Regulation (Regulation (EU) 2016/679) and all other EU laws regulating the processing of Personal Data, as such laws may be updated, amended and superseded from time to time;
“Force Majeure Event” means an event, or a series of related events, that is outside the reasonable control of the party affected (including failures of the internet or any public telecommunications network, hacker attacks, denial of service attacks, virus or other malicious software attacks or infections, power failures, industrial disputes affecting any third party, changes to the law, disasters, epidemics, pandemics, explosions, fires, floods, riots, terrorist attacks and wars);
“Hosted Services” means Aiforsite software made available by the Provider to the Customer as a service via the internet in accordance with this Agreement;
“Hosted Services Defect” means a defect, error or bug in the Platform having a material adverse effect on of the Hosted Services[, but excluding any defect, error or bug caused by or arising as a result of:
(a) any act or omission of the Customer or any person authorised by the Customer to use the Platform or Hosted Services;
(b) any use of the Platform or Hosted Services contrary to the Documentation, whether by the Customer or by any person authorised by the Customer;
(c) a failure of the Customer to perform or observe any of its obligations in this Agreement; and/or
“Intellectual Property Rights” means all intellectual property rights wherever in the world, whether registrable or unregistrable, registered or unregistered, including any application or right of application for such rights (and these “intellectual property rights” include copyright and related rights, database rights, confidential information, trade secrets, know-how, business names, trade names, trade marks, service marks, passing off rights, unfair competition rights, patents, petty patents, utility models, semi-conductor topography rights and rights in designs);
“Mobile App” means the mobile application known as 360 Reality Capture Mobile that is made available by the Provider through the Google Play Store and the Apple App Store;
“Personal Data” means personal data under any of the Data Protection Laws;
“Platform” means the platform managed by the Provider and used by the Provider to provide the Hosted Services;
“Support Services” means support in relation to the use of, and the identification and resolution of errors in, the Hosted Services, but shall not include the provision of training services;
“Supported Web Browser” means the current release from time to time of Microsoft Edge, Mozilla Firefox, Google Chrome or Apple Safari, or any other web browser that the Provider agrees in writing shall be supported;
“Term” means the term of this Agreement, commencing in accordance with Clause 2.1 and ending in accordance with Clause 2.2;
“UK GDPR” means the EU GDPR as transposed into UK law (including by the Data Protection Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019) and all other UK laws regulating the processing of Personal Data, as such laws may be updated, amended and superseded from time to time; and
“User Interface” means the interface for the Hosted Services designed to allow individual human users to access and use the Hosted Services.
2. Term
2.1 This Agreement shall come into force upon the Effective Date.
2.2 This Agreement shall continue in force indefinitely until terminated by the Customer or Provider.
3. Hosted Services
3.1 The Provider shall provide Customer with the Access Credentials once the Customer has ordered and paid the subscription of the Hosted Services.
3.2 The Provider hereby grants to the Customer a worldwide, non-exclusive licence to use the Hosted Services[ by means of the User Interface during the Term.
3.3 The licence granted by the Provider to the Customer under Clause 3.2 is subject to the following limitations:
(a) the User Interface may only be used through a Supported Web Browser or the Mobile App;
(b) the User Interface may only be used by the officers, employees, agents and subcontractors of the Customer;
(c) the User Interface may only be used by the registered users.
3.4 Except to the extent expressly permitted in this Agreement or required by law on a non-excludable basis, the licence granted by the Provider to the Customer under Clause 3.2 is subject to the following prohibitions:
(a) the Customer must not sub-license its right to access and use the Hosted Services;
(b) the Customer must not permit any unauthorised person or application to access or use the Hosted Services;
(f) [the Customer must not conduct or request that any other person conduct any load testing or penetration testing on the Platform or Hosted Services.
3.5 The Customer shall implement and maintain reasonable security measures relating to the Access Credentials to ensure that no unauthorised person or application may gain access to the Hosted Services by means of the Access Credentials.
3.6 The Provider shall use[ reasonable endeavours to maintain the availability of the Hosted Services to the Customer, but does not guarantee 100% availability.
3.7 For the avoidance of doubt, downtime caused directly or indirectly by any of the following shall not be considered a breach of this Agreement:
(a) a Force Majeure Event;
(b) a fault or failure of the internet or any public telecommunications network;
(c) a fault or failure of the Customer’s computer systems or networks;
(d) any breach by the Customer of this Agreement; or
(e) scheduled maintenance carried out in accordance with this Agreement.
3.8 The Customer must comply with Schedule 2 (Acceptable Use Policy)
3.9 The Customer must not use the Hosted Services in any way that causes, or may cause, damage to the Hosted Services or Platform or impairment of the availability or accessibility of the Hosted Services.
3.10 The Customer must not use the Hosted Services in any way that uses excessive Platform resources and as a result is liable to cause a material degradation in the services provided by the Provider to its other customers using the Platform; and the Customer acknowledges that the Provider may use reasonable technical measures to limit the use of Platform resources by the Customer for the purpose of assuring services to its customers generally.
3.11 The Customer must not use the Hosted Services:
(a) in any way that is unlawful, illegal, fraudulent or harmful; or
(b) in connection with any unlawful, illegal, fraudulent or harmful purpose or activity.
3.12 For the avoidance of doubt, the Customer has no right to access the software code (including object code, intermediate code and source code) of the Platform, either during or after the Term.
3.13 The Provider may suspend the provision of the Hosted Services if any amount due to be paid by the Customer to the Provider under this Agreement is overdue, and the Provider has given to the Customer at least 15 days written notice, following the amount becoming overdue, of its intention to suspend the Hosted Services on this basis.
4. Scheduled maintenance
4.1 The Provider may from time to time suspend the Hosted Services for the purposes of scheduled maintenance to the Platform.
5. Support Services
5.1 The Provider shall provide the Support Services to the Customer during the Term.
5.2 The Provider shall make available to the Customer self service web pages and e-mail support.
5.3 The Provider shall respond promptly to requests for Support Services made by the Customer through e-mail.
5.6 The Provider may suspend the provision of the Support Services if any amount due to be paid by the Customer to the Provider under this Agreement is overdue, and the Provider has given to the Customer at least 15 days written notice, following the amount becoming overdue, of its intention to suspend the Support Services on this basis.
6. Customer Data
6.1 The Customer hereby grants to the Provider a non-exclusive licence to copy, reproduce, store, distribute, publish, export, adapt, edit and translate the Customer Data to the extent reasonably required for the performance of the Provider’s obligations and the exercise of the Provider’s rights under this Agreement. The Customer also grants to the Provider the right to sub-license these rights to its hosting, connectivity and telecommunications service providers, subject to any express restrictions elsewhere in this Agreement.
6.2 The Customer warrants to the Provider that the Customer Data will not infringe the Intellectual Property Rights or other legal rights of any person, and will not breach the provisions of any law, statute or regulation,] in any jurisdiction and under any applicable law.
7. Mobile App
7.1 The Customer acknowledges and agrees that the use of the Mobile App provided by the Provider is not for consumer use.
8. No assignment of Intellectual Property Rights
8.1 Nothing in this Agreement shall operate to assign or transfer any Intellectual Property Rights from the Provider to the Customer, or from the Customer to the Provider.
9. Charges
9.1 The Customer shall pay the Charges to the Provider in accordance with this Agreement.
9.2 The Charges are as follows:
(a) 360 Reality Capture Standard: 169 €/month
- The Customer can purchase extra video upload minutes for the price of 25 € per 100 minutes of uploaded video. These extra minutes can be used after the monthly video upload limit has been reached, and they get consumed as video minutes are uploaded.
- The limit for the total video upload minutes of the project is 7200 min. If the Customer expresses the wish to exceed this limit, it has to be communicated with the Provider, who can disable this limit to allow extra video upload minutes with additional charges defined in a separate agreement with the Customer.
9.2 All amounts stated in or in relation to this Agreement are, unless the context requires otherwise, stated exclusive of any applicable value added taxes, which will be added to those amounts and payable by the Customer to the Provider.
9.4 The Provider may elect to add elements or vary any element of the Charges by giving to the Customer not less than 10 days written notice of the variation.
10. Payments
10.1 The Provider shall issue invoices for the Charges to the Customer in advance of the period to which they relate.
10.2 The Customer must pay the Charges to the Provider within the period of 14 days following the issue of an invoice in accordance with this Clause 10.
10.3 The Customer must pay the Charges by supported payment platforms by the Provider, debit card, credit card, or electronic bank transfer.
10.4 If the Customer does not pay any amount properly due to the Provider under this Agreement, the Provider may:
(a) charge the Customer interest on the overdue amount at the rate of 10% per annum; or
(b) terminate this agreement immediately.
11. Provider’s confidentiality obligations
11.1 The Provider must:
(a) keep the Customer Confidential Information strictly confidential;
(b) not disclose the Customer Confidential Information to any person without the Customer’s prior written consent;
(c) use the same degree of care to protect the confidentiality of the Customer Confidential Information as the Provider uses to protect the Provider’s own confidential information of a similar nature, being at least a reasonable degree of care.
11.2 Notwithstanding Clause 11.1, the Provider may disclose the Customer Confidential Information to the Provider’s officers, employees, professional advisers, insurers, agents and subcontractors who have a need to access the Customer Confidential Information for the performance of their work with respect to this Agreement.
11.3 This Clause 11 imposes no obligations upon the Provider with respect to Customer Confidential Information that:
(a) is known to the Provider before disclosure under this Agreement and is not subject to any other obligation of confidentiality;
(b) is or becomes publicly known through no act or default of the Provider; or
(c) is obtained by the Provider from a third party in circumstances where the Provider has no reason to believe that there has been a breach of an obligation of confidentiality.
11.4 The restrictions in this Clause 11 do not apply to the extent that any Customer Confidential Information is required to be disclosed by any law or regulation, by any judicial or governmental order or request, or pursuant to disclosure requirements relating to the listing of the stock of the Provider on any recognised stock exchange.
11.5 The provisions of this Clause 11 shall continue in force for five (5) years following the termination of this Agreement.
12. Data protection
12.1 Each party shall comply with the Data Protection Laws with respect to the processing of the Customer Personal Data.
12.2 The Customer warrants to the Provider that it has the legal right to disclose all Personal Data that it does in fact disclose to the Provider under or in connection with this Agreement.
12.3 The Customer shall only supply to the Provider, and the Provider shall only process, in each case under or in relation to this Agreement:
(a) the Personal Data as outlined in Schedule 2 Data Processing Information
12.4 The Provider shall only process the Customer Personal Data for the purposes specified in Schedule 2 (Data processing information).
12.5 The Provider shall only process the Customer Personal Data during the Term and for not more than 60 days following the end of the Term, subject to the other provisions of this Clause 12.
12.6 The Customer hereby authorises the Provider to make the following transfers of Customer Personal Data:
(a) the Provider may transfer the Customer Personal Data internally to its own employees, offices and facilities;
(b) the Provider may transfer the Customer Personal Data to its third party processors in the jurisdictions identified in Section 5 of Schedule 2 (Data processing information) and may permit its third party processors to make such transfers, providing that such transfers must be protected by any appropriate safeguards identified therein; and
(c) [the Provider may transfer the Customer Personal Data] to a country, a territory or sector to the extent that the competent data protection authorities have decided that the country, territory or sector ensures an adequate level of protection for Personal Data.
12.7 The Provider shall promptly inform the Customer if, in the opinion of the Provider, an instruction of the Customer relating to the processing of the Customer Personal Data infringes the Data Protection Laws.
12.8 Notwithstanding any other provision of this Agreement, the Provider may process the Customer Personal Data if and to the extent that the Provider is required to do so. In such a case, the Provider shall inform the Customer of the legal requirement before processing, unless that law prohibits such information[ on important grounds of public interest.
12.9 The Provider shall ensure that persons authorised to process the Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
12.10 The Provider and the Customer shall each implement appropriate technical and organisational measures to ensure an appropriate level of security for the Customer Personal Data, including those measures specified in Section 4 of Schedule 2 (Data processing information).
12.11 The Provider must not engage any third party to process the Customer Personal Data without the prior specific or general written authorisation of the Customer. In the case of a general written authorisation, the Provider shall inform the Customer in advance of any intended changes concerning the addition or replacement of any third party processor, and if the Customer objects to any such changes before their implementation, then the Customer may terminate this Agreement on written notice to the Provider, providing that such notice must be given within the period of 7 days following the date that the Provider informed the Customer of the intended changes. The Provider shall ensure that each third party processor is subject to equivalent legal obligations as those imposed on the Provider by this Clause 12.
12.12 As at the Effective Date, the Provider is hereby authorised by the Customer to engage, as sub-processors with respect to Customer Personal Data, third parties within the categories identified in Section 5 of Schedule 2 (Data processing information).
12.13 The Provider shall, insofar as possible and taking into account the nature of the processing, take appropriate technical and organisational measures to assist the Customer with the fulfilment of the Customer’s obligation to respond to requests exercising a data subject’s rights under the Data Protection Laws.
12.14 The Provider shall assist the Customer in ensuring compliance with [the obligations relating to the security of processing of personal data, the notification of personal data breaches to the supervisory authority, the communication of personal data breaches to the data subject, data protection impact assessments and prior consultation in relation to high-risk processing under the Data Protection Laws. The Provider may charge the Customer at its standard time-based charging rates for any work performed by the Provider at the request of the Customer pursuant to this Clause 12.14.
12.15 The Provider must notify the Customer of any Personal Data breach affecting the Customer Personal Data without undue delay after the Provider becomes aware of the breach.
12.16 The Provider shall make available to the Customer all information necessary to demonstrate the compliance of the Provider with its obligations under this Clause 12. The Provider may charge the Customer at its standard time-based charging rates for any work performed by the Provider at the request of the Customer pursuant to this Clause 12.16.
12.17 The Provider shall delete all of the Customer Personal Data after the provision of services relating to the processing, and shall delete existing copies.
12.18 The Provider shall allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer in respect of the compliance of the Provider’s processing of Customer Personal Data with the Data Protection Laws and this Clause 12. The Provider may charge the Customer at its standard time-based charging rates for any work performed by the Provider at the request of the Customer pursuant to this Clause 12.18.
12.19 If any changes or prospective changes to the Data Protection Laws result or will result in one or both parties not complying with the Data Protection Laws in relation to processing of Personal Data carried out under this Agreement, then the parties shall use their best endeavours promptly to agree such variations to this Agreement as may be necessary to remedy such non-compliance.
13. Warranties
13.1 The Provider warrants to the Customer that:
(a) the Provider has the legal right and authority to enter into this Agreement and to perform its obligations under this Agreement;
(b) the Platform will incorporate security features reflecting the requirements of good industry practice;
© the Hosted Services, when used by the Customer in accordance with this Agreement, will not infringe the Intellectual Property Rights of any person.
13.2 If the Provider reasonably determines, or any third party alleges, that the use of the Hosted Services by the Customer in accordance with this Agreement infringes any person’s Intellectual Property Rights, the Provider may at its own cost and expense:
(a) modify the Hosted Services in such a way that they no longer infringe the relevant Intellectual Property Rights; or
(b) procure for the Customer the right to use the Hosted Services in accordance with this Agreement.
13.3 The Customer warrants to the Provider that it has the legal right and authority to enter into this Agreement and to perform its obligations under this Agreement.
13.4 All of the parties’ warranties and representations in respect of the subject matter of this Agreement are expressly set out in this Agreement. To the maximum extent permitted by applicable law, no other warranties or representations concerning the subject matter of this Agreement will be implied into this Agreement or any related contract.
14. Acknowledgements and warranty limitations
14.1 The Customer acknowledges that complex software is never wholly free from defects, errors and bugs; and subject to the other provisions of this Agreement, the Provider gives no warranty or representation that the Hosted Services will be wholly free from defects, errors and bugs.
14.2 The Customer acknowledges that complex software is never entirely free from security vulnerabilities; and subject to the other provisions of this Agreement, the Provider gives no warranty or representation that the Hosted Services will be entirely secure.
14.3 The Customer acknowledges that the Provider does not warrant or represent that the Hosted Services will be compatible with any other software or systems.
14.4 The Customer acknowledges that the Provider will not provide any illegal, financial, accountancy or taxation advice under this Agreement or in relation to the Hosted Services; and, except to the extent expressly provided otherwise in this Agreement, the Provider does not warrant or represent that the Hosted Services or the use of the Hosted Services by the Customer will not give rise to any legal liability on the part of the Customer or any other person.
15. Limitations and exclusions of liability
15.1 Nothing in this Agreement will:
(a) limit or exclude any liability for death or personal injury resulting from negligence;
(b) limit or exclude any liability for fraud or fraudulent misrepresentation;
(c) limit any liabilities in any way that is not permitted under applicable law; or
(d) exclude any liabilities that may not be excluded under applicable law.
15.2 The limitations and exclusions of liability set out in this Clause 15 and elsewhere in this Agreement:
(a) are subject to Clause 15.1; and
(b) govern all liabilities arising under this Agreement or relating to the subject matter of this Agreement, including liabilities arising in contract, in tort (including negligence) and for breach of statutory duty, except to the extent expressly provided otherwise in this Agreement.
15.3 The Provider shall not be liable to the Customer in respect of any losses arising out of a Force Majeure Event.
15.4 The Provider shall not be liable to the Customer in respect of any loss of profits or anticipated savings.
15.5 The Provider shall not be liable to the Customerin respect of any loss of revenue or income.
15.6 The Provider shall not be liable to the Customer in respect of any loss of use or production.
15.7 The Provider shall not be liable to the Customer in respect of any loss of business, contracts or opportunities.
15.8 The Provider shall not be liable to the Customer in respect of any loss or corruption of any data, database or software.
15.9 The Provider shall not be liable to the Customer in respect of any special, indirect or consequential loss or damage.
15.10 The liability of the Provider to the Customer under this Agreement in respect of any event or series of related events shall not exceed the the total amount paid and payable by the Customer to the Provider under this Agreement in the 12 month period preceding the commencement of the event.
15.11 The aggregate liability of the Provider to the Customer under this Agreement shall not exceed the greater the total amount paid and payable by the Customer to the Provider under this Agreement.
16. Force Majeure Event
16.1 If a Force Majeure Event gives rise to a failure or delay in either party performing any obligation under this Agreement, that obligation will be suspended for the duration of the Force Majeure Event.
16.2 A party that becomes aware of a Force Majeure Event which gives rise to, or which is likely to give rise to, any failure or delay in that party performing any obligation under this Agreement, must:
(a) promptly notify the other; and
(b) inform the other of the period for which it is estimated that such failure or delay will continue.
16.3 A party whose performance of its obligations under this Agreement is affected by a Force Majeure Event must take reasonable steps to mitigate the effects of the Force Majeure Event.
17. Termination
17.1 Either party may terminate this Agreement by giving to the other party written notice of termination.
17.2 Either party may terminate this Agreement immediately by giving written notice of termination to the other party if the other party commits a material breach of this Agreement.
17.3 Subject to applicable law, either party may terminate this Agreement immediately by giving written notice of termination to the other party if:
(a) the other party:
(i) is dissolved;
(ii) ceases to conduct all (or substantially all) of its business;
(iii) is or becomes unable to pay its debts as they fall due;
(iv) is or becomes insolvent or is declared insolvent; or
(v) convenes a meeting or makes or proposes to make any arrangement or composition with its creditors;
(b) an administrator, administrative receiver, liquidator, receiver, trustee, manager or similar is appointed over any of the assets of the other party;
(c) an order is made for the winding up of the other party, or the other party passes a resolution for its winding up (other than for the purpose of a solvent company reorganisation where the resulting entity will assume all the obligations of the other party under this Agreement).
18. Effects of termination
18.1 Upon the termination of this Agreement, all of the provisions, except the ones that that have been agreed to survive after termination (e.g. Confidentiality), shall cease to have effect.
18.2 Except to the extent expressly provided otherwise in this Agreement, the termination of this Agreement shall not affect the accrued rights of either party.
19. Notices
19.1 The Provider’s contact details for notices under this Clause 19 are as follows: support@aiforsite.com.
20. Subcontracting
20.1 Subject to any express restrictions elsewhere in this Agreement, the Provider may subcontract any of its obligations under this Agreement.
20.2 The Provider shall remain responsible to the Customer for the performance of any subcontracted obligations.
21. General
21.1 No breach of any provision of this Agreement shall be waived except with the express written consent of the party not in breach.
21.2 If any provision of this Agreement is determined by any court or other competent authority to be unlawful and/or unenforceable, the other provisions of this Agreement will continue in effect. If any unlawful and/or unenforceable provision would be lawful or enforceable if part of it were deleted, that part will be deemed to be deleted, and the rest of the provision will continue in effect (unless that would contradict the clear intention of the parties, in which case the entirety of the relevant provision will be deemed to be deleted).
21.3 This Agreement may not be varied except by a written document signed by or on behalf of each of the parties.
21.4 Neither party may without the prior written consent of the other party assign, transfer, charge, license or otherwise deal in or dispose of any contractual rights or obligations under this Agreement.
21.5 This Agreement is made for the benefit of the parties, and is not intended to benefit any third party or be enforceable by any third party. The rights of the parties to terminate, rescind, or agree any amendment, waiver, variation or settlement under or relating to this Agreement are not subject to the consent of any third party.
21.6 Subject to Clause 15.1, this Agreement shall constitute the entire agreement between the parties in relation to the subject matter of this Agreement, and shall supersede all previous agreements, arrangements and understandings between the parties in respect of that subject matter.
21.7 This Agreement shall be governed by and construed in accordance with Finnish law.
21.8 The courts of Finland shall have exclusive jurisdiction to adjudicate any dispute arising under or in connection with this Agreement.
22. Interpretation
22.1 In this Agreement, a reference to a statute or statutory provision includes a reference to:
(a) that statute or statutory provision as modified, consolidated and/or re-enacted from time to time; and
(b) any subordinate legislation made under that statute or statutory provision.
22.2 The Clause headings do not affect the interpretation of this Agreement.
22.3 In this Agreement, general words shall not be given a restrictive interpretation by reason of being preceded or followed by words indicating a particular class of acts, matters or things.
Schedule 1 (Acceptable Use Policy)
1. Introduction
1.1 This acceptable use policy (the “Policy“) sets out the rules governing:
(a) the use of aiforsite.io, any successor website, and the services available on that website or any successor website] (the “Services“); and
(b) the transmission, storage and processing of content by you, or by any person on your behalf, using the Services (“Content“).
1.2 References in this Policy to “you” are to any customer for the Services and any individual user of the Services; and references in this Policy to “us” or “we” are to Aiforsite Oy.
1.3 By using the Services, you agree to the rules set out in this Policy.
1.4 We will ask for your express agreement to the terms of this Policy before you upload or submit any Content or otherwise use the Services.
1.5 You must be at least 18 years of age to use the Services; and by using the Services, you warrant and represent to us that you are [at least 18 years of age.
2. General usage rules
2.1 You must not use the Services in any way that causes, or may cause, damage to the Services or impairment of the availability or accessibility of the Services.
2.2 You must not use the Services:
(a) in any way that is unlawful, illegal, fraudulent, deceptive or harmful; or
(b) in connection with any unlawful, illegal, fraudulent, deceptive or harmful purpose or activity.
2.3 You must ensure that all Content complies with the provisions of this Policy.
3. Unlawful Content
3.1 Content must not be illegal or unlawful, must not infringe any person’s legal rights, and must not be capable of giving rise to legal action against any person (in each case in any jurisdiction and under any applicable law).
3.2 Content and the use of Content by us in any manner licensed or otherwise authorised by you, must not:
(a) be libellous or maliciously false;
(b) be obscene or indecent;
(c) infringe any copyright, moral right, database right, trade mark right, design right, right in passing off, or other intellectual property right;
(d) infringe any right of confidence, right of privacy or right under data protection legislation;
(e) constitute negligent advice or contain any negligent statement;
(f) constitute an incitement to commit a crime, instructions for the commission of a crime or the promotion of criminal activity;
(g) be in contempt of any court, or in breach of any court order;
(h) constitute a breach of racial or religious hatred or discrimination legislation;
(i) constitute a breach of official secrets legislation; or
(k) constitute a breach of any contractual obligation owed to any person.
3.3 You must ensure that Content is not and has never been the subject of any threatened or actual legal proceedings or other similar complaint.
4. Graphic material
4.1 Content must be appropriate for all persons who have access to or are likely to access the Content in question.
4.2 Content must not depict violence in an explicit, graphic or gratuitous manner.
4.3 Content must not be pornographic or sexually explicit.
5. Factual accuracy
5.1 Content must not be untrue, false, inaccurate or misleading.
5.2 Statements of fact contained in Content and relating to persons (legal or natural) must be true[; and statements of opinion contained in Content and relating to persons (legal or natural) must be reasonable, be honestly held and indicate the basis of the opinion].
6. Negligent advice
6.1 Content must not consist of or contain any legal, financial, investment, taxation, accountancy, medical or other professional advice, and you must not use the Services to provide any legal, financial, investment, taxation, accountancy, medical or other professional advisory services.
6.2 Content must not consist of or contain any advice, instructions or other information that may be acted upon and could, if acted upon, cause death, illness or personal injury, damage to property, or any other loss or damage.
7. Etiquette
7.1 Content must be appropriate, civil and tasteful, and accord with generally accepted standards of etiquette and behaviour on the internet.
7.2 Content must not be offensive, deceptive, threatening, abusive, harassing, menacing, hateful, discriminatory or inflammatory.
7.3 Content must not be liable to cause annoyance, inconvenience or needless anxiety.
7.4 You must not use the Services to send any hostile communication or any communication intended to insult, including such communications directed at a particular person or group of people.
7.5 You must not use the Services for the purpose of deliberately upsetting or offending others.
7.6 You must not unnecessarily flood the Services with material relating to a particular subject or subject area, whether alone or in conjunction with others.
7.7 You must ensure that Content does not duplicate other content available through the Services.
7.8 You must ensure that Content is appropriately categorised.
7.9 You should use appropriate and informative titles for all Content.
7.10 You must at all times be courteous and polite to other users of the Services.
8. Marketing and spam
8.1 You must not without our written permission use the Services for any purpose relating to the marketing, advertising, promotion, sale or supply of any product, service or commercial offering.
8.2 Content must not constitute or contain spam, and you must not use the Services to store or transmit spam – which for these purposes shall include all unlawful marketing communications and unsolicited commercial communications.
8.3 You must not send any spam or other marketing communications to any person using any email address or other contact details made available through the Services or that you find using the Services.
8.4 You must not use the Services to promote, host or operate any chain letters, Ponzi schemes, pyramid schemes, matrix programs, multi-level marketing schemes, “get rich quick” schemes or similar letters, schemes or programs.
8.5 You must not use the Services in any way which is liable to result in the blacklisting of any of our IP addresses.
9. Regulated businesses
9.1 You must not use the Services for any purpose relating to gambling, gaming, betting, lotteries, sweepstakes, prize competitions or any gambling-related activity.
9.2 You must not use the Services for any purpose relating to the offering for sale, sale or distribution of drugs or pharmaceuticals.
9.3 You must not use the Services for any purpose relating to the offering for sale, sale or distribution of knives, guns or other weapons.
10. Monitoring
10.1 You acknowledge that we may actively monitor the Content or the use of the Services.
11. Data mining
11.1 You must not conduct any systematic or automated data scraping, data mining, data extraction or data harvesting, or other systematic or automated data collection activity, by means of or in relation to the Services.
12. Hyperlinks
12.1 You must not link to any material using or by means of the Services that would, if it were made available through the Services, breach the provisions of this Policy.
13. Harmful software
13.1 The Content must not contain or consist of, and you must not promote, distribute or execute by means of the Services, any viruses, worms, spyware, adware or other harmful or malicious software, programs, routines, applications or technologies.
13.2 The Content must not contain or consist of, and you must not promote, distribute or execute by means of the Services, any software, programs, routines, applications or technologies that will or may have a material negative effect upon the performance of a computer or introduce material security risks to a computer.
Schedule 2 (Data processing information)
- GENERAL
We at Aiforsite want to create and offer trustworthy, fair and transparent digital solutions for construction sites. We are strongly committed to protecting and promoting fair privacy practices and want you as a Customer to feel that your data is treated with respect and due care with our solution. We are proud to say that data protection has truly been built in in our solution and we are constantly developing and updating our features to meet our Customers’ privacy expectations.
We are committed to protecting personal data in accordance with the principles set out in the EU General Data Protection Regulation (GDPR), as well as other mandatory data protection laws applicable to us and our Customers. The terms used in this guidance follow the terminology used in the GDPR, unless otherwise indicated.
In this guidance we provide our Customers key information on our privacy practices and our rationale behind our choices. We hope that you will find this information useful in fulfilling your own data protection obligations, such as documentation, information, and risk management obligations, as well as in planning and organizing your data protection processes. We also encourage you to transparently communicate with your employees and contractors related to the privacy implications of the Aiforsite solution early on. We are happy to answer your further questions regarding our privacy practices!
- AIFORSITE’S ROLE IN PROCESSING PERSONAL DATA
The GDPR provides for different roles with different obligations to those persons, companies and public authorities involved in the processing of personal data. ‘Controller’ or ‘data controller’ relates to a person or organization, which determines the purposes and means of personal data. ‘Processor’ or ‘data processor’ relates to a person or organization which processes personal data on behalf of the controller.
Aiforsite offers its services for its customers to be used for the customer’s own purposes. Aiforsite does not have control over what the customer intends or decides to do with the data provided by means of Aiforsite’s solution. The Customer decides how it processes its personal data on its construction sites and what technical solutions it decides to deploy. Also, the personal data processed in and by means of the solution offered by Aiforsite relates to the employees and contractors of the Customer which are under the supervision of the Customer. Therefore, the Customer determines the purposes and means of personal data processing, and the Customer is to be considered as the controller. Aiforsite acts as the processor, which processes personal data on behalf of the Customer.
As a controller, the Customer is responsible for using the solution offered by Aiforsite in a manner which complies with the data protection laws and policies applicable to its operations.
Before implementing Aiforsite’s solution at your construction site(s), please consider the following matters:
- What are the purposes for which you intend to deploy the solution and what are the purposes for which you need to process personal data?
- Do you need to identify the data subjects to fulfill your purpose?
- What risks to the rights and freedoms to natural persons can you identify related to your personal data processing practices?
- Is your processing of personal data based on consent to some extent and how should you collect and store the consents?
- If you, for example, intend to use our positioning system for monitoring your human resources in a manner that permits their identification, consent of the monitored persons may be required.
- The Customer as data controller, is responsible for evaluating and determining the correct legal basis for the processing of personal data within their operations, as they also determine the purposes for which the data is processed.
- If you intend to use Aiforsite’s solution for monitoring your employees or contractors on your construction site, please
- consider the need to carry out a data protection impact assessment (GDPR Art. 35). The data provided in this guidance and materials provided by us can be used as a source when carrying out the assessment.
- make sure that the conditions for camera surveillance in the workplace are set out in the Act on the Protection of Privacy in Working Life (§ 16-17) and handle the implementation of the solution in the cooperation procedure (§ 21) and other legal obligations you may have as an employer.
It is advised to also create internal documentation including the above considerations for fulfilling the controller’s accountability obligations (GDPR Art. 24).
- PERSONAL DATA PROCESSED BY AIFORSITE
What is personal data?
According to the GDPR, personal data means any information relating to an identified or identifiable natural person (data subject). In the context of construction site monitoring, data subjects are typically site workers, contractors, overseers, guests and other persons who may move around the site.
The definition of personal data is quite broad, and it covers both direct and indirect identifiers related to data subjects, as well as information related to certain physical, mental, economic, cultural, social or other characteristics of a person that allows their identification. Direct identifiers include information, which reveals the identity of its subject fairly easily, e.g. name, ID numbers, photographs and location data of a specific person. Also identifiers, that may at first glance seem like non-personal data, e.g. license numbers, vehicle registration numbers, phone numbers, device identifiers, account numbers and any other unique identifying number related to a certain individual, are quite easily considered as personal data, if by means of combining such identifiers with other data, the identity of a person can be revealed. Even if the other data enabling the identification is not available to the person or organization holding the unique identifier, the identifier is still considered as personal data as long as the identification of the individual can realistically be achieved. If all identifiers are removed from the data, i.e. the data is irreversibly anonymized, the data is no longer considered as personal data.
Defining data as personal data does not mean that its processing would be wrong or somehow undesired – it simply means that certain principles and provisions laid down in the data protection laws, especially the GDPR, must be taken into consideration when processing it and that the data must be dealt with a certain level of care. We at Aiforsite consider this very important and take pride in our proactive approach to data protection.
Aiforsite’s use cases for processing personal data
Aiforsite processes personal data on behalf of the Customer in the following manner and in connection to the following use cases. At the latest at the end of the contract, Aiforsite will remove all Customer data from the Aiforsite Productivity Platform (and the cloud environments, where they are stored), and return the data to the Customer as agreed with the Customer (e.g. cloud service or storing device).
- 360 images and video
Depending on the use cases by the Customer, 360 images and video footage may contain personal data in a directly identifiable form from the moment of the recording until the optional blurring of the footage. The Customer may select an option (charges apply) to blur faces in the images and footage as a privacy control method.
- Aiforsite Productivity Platform User Data
Aiforsite processes personal data of the users of Aiforsite Productivity Platform to be able to create user accounts and apply certain security measures e.g., passwords and access logging. The personal data content collected from the users or generated by the users’ activities within Aiforsite Productivity Platform are names, usernames, emails, passwords, log information and cookies.
- Development and testing
Aiforsite continuously develops its technological solution, which is necessary for providing the service. As the solution utilizes artificial intelligence (AI), Aiforsite may also need to use the raw data collected on site as training material for the AI e.g., for the purpose of applying privacy controls such as the people blurring feature. If raw data is not needed for the development process, anonymized or pseudonymized data will be used instead.
- INFORMING DATA SUBJECTS
Informing data subjects of the practices applied to the processing of their personal data is the obligation of the Customer who acts as the data controller.
- DATA SUBJECT REQUESTS
Processing data subject requests is a legal duty of the Customer, who acts as the controller.
- SUBPROCESSING AND INTERNATIONAL DATA TRANSFERS
Aiforsite relies on subprocessors, such as public cloud providers, in providing the solution and they are therefore also partly involved in the personal data processing on Aiforsite’s behalf and on Aiforsite’s responsibility..
If personal data is transferred to a location outside of the EU/European Economic Area (EEA), standard contractual clauses (SCC) adopted and published by the European Commission are used as a transfer mechanism.
Also, the Customer should note, that if it allows access to Aiforsite Productivity Platform from locations outside of the EU/EEC, this is considered as international transferring of personal data and the Customer should make sure that they have adequate transfer mechanisms in place to do so.