Depending on where you are based or where you purchased the product, your relevant BDR Thermea Group company is, and this Privacy Policy is issued and adhered to by: Baxi SpA (Italy), BDR Thermea France S.A.S (France), Baxi Climatización SLU (Spain), Baxi – Sistemas de Aquecimento Unipessoal LDA (Portugal) or Baxi Heating UK Limited (United Kingdom) further referenced as ‘the BDR Thermea Group company’.
The BDR Thermea Group company and subsidiaries (collectively, “we”,“us”, “our”) are committed to protecting your privacy. This Privacy Policy(“Policy”) describes our practices in connection with information privacy andthe Personal Data we process through your individual use of the followingservices, products, and related mobile applications (collectively, the“Products”): My Baxi AC Mobile Application and DeDietrich Smart AC MobileApplication.
Before you use our Products, please carefully read through thisPolicy and understand our purposes and practices of collection and processingof your Personal Data, including how we use, store, share and transfer PersonalData. In the Policy you will also find ways to execute your rights of access,update, delete or protect your Personal Data.
When you accept this Policy, when you register with your PersonalData, or if you start to use our Products and do not expressly object to thecontents of this Policy, we will consider that you fully understand and agreewith this Policy.
Definition
In this Policy, Personal Data means information generated,collected, recorded and/or stored, electronically or otherwise, that can beused to identify an individual or reflect the activity of an individual, eitherfrom that information alone, or from that information and other information wehave access to about that individual.
Personal Sensitive Data includes personal biometric information,communication records and contents, health information, transactioninformation, and precise location information.  We do not ask you to share Personal SensitiveData. If we would collect Personal Sensitive Data from you, it shall be onlybecause you provided us with this information and we will generate an explicitnotification for your consent.
Smart Devices refers to those computing devices produced ormanufactured by hardware manufacturers, with human-machine interface and theability to transmit data that connect wirelessly to a network, including: smarthome appliances, smart wearable devices, smart air cleaning devices, etc.
Apps refers to those mobile applications developed by the BDRThermea Group company that provides end users remote control to Smart Devices.
WhatPersonal Data do we collect
In order to provide our services to you, we will ask you to providenecessary Personal Data that is required to provide those services. If you donot provide your Personal Data, we may not be able to provide you with ourproducts or services.
1.Informationyou provide us
· Registered Account Data: When you register anaccount with us, we may collect your name and contact details, such as youremail address, phone number, username, and login credentials. During yourinteraction with our Products, we may further collect your nickname, profilepicture, country code, language preference or time zone information into youraccount.
· Feedback: (only applicable whenthe feedback function in the App is enabled): When using feedback andsuggestion features in our Products, we will collect your email address, mobilephone number and your feedback content to address your problems and solvedevice failures on a timely basis.
Informationbased on additional functions:
In order to offer you with more convenient and higher-qualityServices with optimized user experiences, we may collect and use certaininformation if you consent to use additional functions in the App. Please note,if you do not provide such information, you may continue to use basic Servicesof the App and connected Smart Devices, but certain features based on theseadditional functions may not be available. These additional functions mayinclude:
1)Additional functionsbased on location information (only if applicable):
When you enable the location-based functions through permissionsettings on your mobile device, we will collect and process your locationinformation to enable these functions, such as pairing with your Smart Devices.Also, we may collect information about your: a) real-time and precise location,for instance when you choose to use the automation scenarios for controllingyour Smart Devices, or b) non-precise geo-location when you use certain SmartDevices or the Services, such as robot cleaner and weather service.
Based on your consent, when you enable the geo-fence feature, yourlocation information will be generated and shared with Google Maps services.Please note that Google has corresponding data protection measures, which youmay refer to Google’s Data Processing and Security Terms for more details.
You maydisable the collection and use of your location information by changing yourmobile device settings ("Me - Settings - Privacy Settings - Switch on/offLocation Information"), upon which we will cease to collect and use yourlocation information.
2)Additional services based on camera (only if applicable):
You may use the camera to scan the code by turning on the camerapermission to pair with a Smart Device, take video, etc. Please be aware thateven if you have agreed to enable the camera permission, we will only obtaininformation when you actively use the camera for scanning codes, videorecording, etc.
You may opt-out the using of camera permission: "Me - Settings- Privacy Settings - Switch on/off Camera".
3)Additional servicesfor accessing and uploading pictures/videos based on photo albums (picturelibrary/video library) (only if applicable):
You can use this function to upload your photos/pictures/videosafter turning on the photo album permission, so as to realize functions such aschanging the avatar, reporting device usage problems by providing photo proofs,etc.. When you use the photos and other functions, we will not recognize thisinformation; but when you report a device usage problem, we may use thephotos/pictures you upload to locate your problem.
You may opt-out the using of photo album permission: " Me -Settings - Privacy Settings - Switch on/off Photo Album".
4)Additional servicesrelated to microphone-based service (only if applicable):
You can use the microphone to send voice information after turningon the microphone permission, such as shooting videos, waking up the voiceassistant, etc. For these functions, we will collect your voice information torecognize your command. Please be aware that even if you have agreed to enablethe microphone permission, we will only obtain voice information through themicrophone when you voluntarily activate the microphone in the App.
You may opt-out the using of microphone permission: "Me -Settings - Privacy Settings - Switch on/off Microphone".
5)Additional servicesbased on storage permission (Android) (only if applicable):
The purpose is to ensure the stable operation of the App byutilizing the storage permission. After you give or indicate the permission toread/write your mobile device’s storage, we will access pictures, files, crashlog information and other necessary information from your mobile device’sstorage to provide you with functions, such as information publications, orrecord the crash log information locally.
You may opt-out the using of storage permission: "Me -Settings - Privacy Settings – Access storage permissions".
6)Additional servicesbased on Notification permission (only if applicable):
The reason why we ask you for the permission is to send younotifications about using the Smart Devices or Services, especially if you havepurchased security services and you require an alert or message so that you cancapture the real-time status.
You may opt-out the using of App notifications: "Me – Settings– App Notification Settings".
7) Additional servicesbased on Alert Window permission (only if applicable):
You may choose to bind a camera in the App and require the App todisplay the real-time image of the camera in a separate window.
You may opt-out the using of alert window information: "Me –Settings – App Notification Settings ".
8) Additional servicesbased on Bluetooth permission (only if applicable):
You can enable Bluetooth functions after turning on the permission,including controlling the Smart Devices, acquiring status of, discovering andconfiguring Smart Devices. In these functions, we will communicate with SmartDevices via Bluetooth. Please be aware that even if you have agreed to enablethe Bluetooth permission, we will only use Bluetooth for communication in thesescenarios: display device status on the home page and Smart Device panel;perform device control on the home page and Smart Device panel; discoveringSmart Devices on the home page and the add device page, Smart Devicedistribution network.
You may opt-out the using of Bluetooth via "Me - Settings -Privacy Settings – Access to nearby devices permissions".
9)Additionalservices based on HomeKit permission (iOS) (only if applicable):
You can enable related functions after enabling HomeKitpermissions, including discovering Smart Devices, enabling Smart Device networkconfiguration, controlling Smart Devices, and checking device status. Amongthese functions, we will process data with the "Home“ App that comes withthe iOS system through HomeKit. Please be aware that even if you have agreed toenable the HomeKit permission, we will only use it in these scenarios: on thehome page, to discover HomeKit devices, HomeKit device network configuration;in "Settings - HomeKit" for discovering HomeKit devices, HomeKitdevice network configuration.
You may opt-out the using of HomeKit permission via "Me -Settings - Privacy Settings-Turn off/on HomeKit permission".
Please note that if you turn on any permission, you authorize us tocollect and use relevant personal information to provide you with correspondingServices. Once you turn off any permission, we will take it as canceling theauthorization, and we will no longer continue to collect Personal Data based onthe corresponding permissions, and the related functions may be terminated.However, your decision to turn off the permission will not affect the previouscollection and use of information based on your authorization.
2.InformationWe Collect Automatically
· MobileDevice Information: When you interact with our Services, in orderto provide and maintain the normal operation of our Services, to improve andoptimize our Services, and to protect your account security as well, weautomatically collect mobile device information, such as mobile device modelnumber, IP address, wireless connection information, the type and version ofthe operating system, application version number, push notificationidentifier, log files, and mobile network information. Meanwhile, we willcollect your software version number. In order to ensure the security of theoperating environment or to provide services, we will collect information aboutthe installed mobile applications and other software you use.
· Usage Data: Duringyour interaction with our websites and Services, we automatically collect usagedata relating to visits, clicks, downloads, messages sent/received, and otherusage of our websites and Services.
· LogInformation: When you use the App, in order to improve your user experience,the system and exception log may be uploaded, including your IP address,language preference setting, operating system version, date or time of access,so that we can facilitate and accurately identify problems and help you solvethem in timely manner.
Pleasenote that we cannot identify a specific individual by using deviceinformation or log information alone. However, if these types of non-personalinformation, combined with other information, may be used to identify aspecific individual, such information will be treated as Personal Data. Unlesswe have obtained your consent or unless otherwise provided by data protectionlaws and regulations, we will aggregate or desensitize such information.
3.SmartDevices Related Information:
· BasicInformation of Smart Devices: When you connect your Smart Devices with theServices, we may collect basic information about your Smart Devices such asdevice name, device ID, online status, activation time, firmware version, andupgrade information.
· Informationcollected during the process of connecting to a Smart Device: Based onthe type of Smart Device you need to connect, the basic information collectedincludes: Wi-Fi information, device MAC address, etc.
· InformationReported by Smart Devices: Depending on the different Smart Devices youelect to connect with our Products or Services, we may collect differentinformation reported by your Smart Devices.
Purposesand legal basis for processing Personal Data
The purpose and legal basis for which we may process informationabout you are as follows:
· Provide Youwith Our Services: We process your account data, mobile deviceinformation, usage data, location information, and Smart Device relatedinformation to provide you with the Services that you have requested.
· Explicit Consent: we may collect anduse certain information if you consent to use additional functions in the App.
· Improve OurServices: We process your mobile device information,usage data, location information and Smart Device related information to ensurethe functions and safety of the Services, to develop and improve the Services,to analyze the efficiency of our operations and to prevent and trace fraudulentor inappropriate usage. Non-marketingCommunication: We process your Personal Data to send you importantinformation regarding the Services, changes to our terms, conditions, andpolicies and/or other administrative information. At the same time, we willalso send you notifications related to the services you have purchased, such asalert services. You can check the “App Notification” in the App ("Me &rt;Message Center &rt; Setting &rt; Notification Setting”) to manage thesecommunications. When you decide not to enable the Notifications function, wewill no longer process your information for such purpose.
· DataAnalysis: In order to analyze the usage of the products we provide andimprove your user experience, we will analyze the data you provide us, a) weneed to check your problems when you encounter any malfunctions during theusage of the product, under such circumstance, you may not able to opt-outbecause it is highly relate to your functionalities and quality of using ourproduct and service, and b) analyze data about how you interface with theproduct or under particular scenarios so that you can better enjoy the conveniencebrought by our Services, under such circumstance, if you do not agree to dataanalysis of your data, you can enter the privacy settings of App (“Me &rt;Settings &rt; Privacy Settings &rt; Service & Maintenance & ImprovementActivity”) to opt-out your selection. The legal basis for such processing isbased on your consent.
· MarketingCommunication and Personalization: We may process youraccount data, usage data, device information to personalize product design andto provide you with services tailored for you, such as recommending anddisplaying information and advertisements regarding products suited to you, andto invite you to participate in surveys relating to your use of the Services.If you do not allow us to process your Personal Data for personalization, youmay opt out when you enter the App, or by changing your preferences in “PrivacySettings” (“Me &rt; Settings &rt; Privacy Settings &rt; PersonalizedRecommendations”) in the App. The legal basis for this processing is yourconsent.
· LegalCompliance. We disclose information if we are legally required to do so, orif we have a good faith belief that such use is reasonably necessary to:
· comply with a legal obligation, process orrequest;
· enforce our User Agreement and otheragreements, policies, and standards, including investigation of any potentialviolation thereof;
· protect the rights, property or safety of us,our users, a third party or the public as required or permitted by law; or
· detect, prevent or otherwise address security,fraud or technical issues.
If there is any change in the purposes for processing your personaldata, we will inform such change to you via email and/or a prominent notice onour website of such changes of purposes, and choices you may have regardingyour Personal Data.
Whodo we Share Personal Data with?
At the BDR Thermea Group company, we only share Personal Data inways that we tell you about. We may share your Personal Data with the followingrecipients:
· To our third-party service providers whoperform certain business-related functions for us, such as website hosting,data analysis, payment and credit card processing, infrastructure provision, ITservices, customer support service, e-mail delivery services, and other similarservices to enable them to provide services to us.
· To our customers and other business partnerswho provide you, directly or indirectly, with your Smart Devices, and/ornetworks and systems through which you access and use our websites andServices.
· To subsidiaries or affiliates within ourcorporate family for purpose of regular business activities based on ourinstructions and in compliance with applicable law, this Policy and otherappropriate confidentiality and security measures.
· To an affiliate or other third party in theevent of any reorganization, merger, sale, joint venture, assignment, transferor other disposition of all or any portion of our business, assets or stock(including without limitation in connection with any bankruptcy or similarproceedings). In such an event, you will be notified via email and/or aprominent notice on our website of any change in ownership, and choices you mayhave regarding your Personal Data.
· As we believe in good faith that access to, oruse, preservation, or disclosure of the information is reasonably necessary orappropriate to:
(a)Complywith applicable law, regulation, legal process, or lawful governmental request;
(b)Enforceour User Agreement and other agreements, policies, and standards, includinginvestigation of any potential violation thereof;
(c) Protectour operation and business systems;
(d)Protectthe rights, property or safety of us, our users, a third party or the public asrequired or permitted by law; or
(e)Performrisk management, screening and checks for unlawful, fraudulent, deceptive ormalicious activities.
Except for the third parties mentioned above, we only disclose yourPersonal Data to other third parties with your consent.
InternationalTransfer of Information Collected
The BDR Thermea Group company will complywith applicable data localization requirements in corresponding jurisdictionswith respect to storage of data. To facilitate our operation, we may transfer,store and process your Personal Data in jurisdictions other than where youlive. Laws in these countries may differ from the laws applicable to yourcountry of residence. When we do so, we will ensure that an adequate level ofprotection is provided for the information by using one or more of thefollowing approaches:
· Agreement on the basis of approved EU standardcontractual clauses per GDPR Art. 46. For more information,see https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.
If you would like further detail on the safeguards we have inplace, you can contact us directly as described in this Privacy Policy.
YourRights Relating to Your Personal Data
We respect your rights and control over your Personal Data. You mayexercise any of the following rights:
You do not have to pay a fee and we will aim to respond you within30 days. If you decide to email us, in your request, please make clear whatinformation you would like to have changed, whether you would like to have yourPersonal Data deleted from our database or otherwise let us know whatlimitations you would like to put on our use of your Personal Data. Please notethat we may ask you to verify your identity before taking further action onyour request, for security purposes.
You may:
· Request that we correct inaccurate orincomplete Personal Data about you: 1) Modify your account number (emailaddress or phone number): "Me-Settings-Account and Security” "; 2)Modify the nickname and/or time zone: "Me-Settings-PersonalInformation";
· Request deletion of Personal Data about you:"My-Setting-Account and Security-Delete Account", when you confirmthe deletion of your account, your Personal Data will be deleted accordingly.
· Request restrictions, temporarily orpermanently, on our processing of some or all Personal Data about you: Pleasesend over the email request to the BDR Thermea Group company on the emailaddress provided in the Contact Us paragraph at the end of this document.;
· Request transfer of Personal Data to you or athird party where we process the data based on your consent or a contract withyou, and where our processing is automated: Please send over email request to theBDR Thermea Group company on the email address provided in the Contact Usparagraph at the end of this document.
· Opt-out or object to our use of Personal Dataabout you where our use is based on your consent or our legitimate interests.
Withdrawal of consent: We will exercise your privacy right towithdraw consent through the following approaches:
1)For privacy permissions acquired through device system settings,your consent can be withdrawn by changing device permissions, including:location, camera, photo album (picture library/video library), microphone,Bluetooth settings, notification settings and other related functions;
2)You may opt-out the non-marketing communication through “Me &rt;Settings &rt; Privacy Settings &rt; Service Maintenance & ImprovementActivity” to manage your selection;
3)You may opt-out the data analysis features through “Me &rt;Settings &rt; Privacy Settings &rt; Service Maintenance & ImprovementActivity”;
4)You may opt-out the Personalization feature through “Me &rt;Settings &rt; Privacy Settings &rt; Personalized Recommendations”;
5)Unbind the Smart Device through the App, and the informationrelated to the Smart Device will not be collected;
6)By using product with the "Try Now" mode, and notenable certain location setting for particular smart scene, we willnot collect any Personal Data about you;
7)If you previously agreed to associate App account with athird-party service, such as a health platform, please unbind it on thethird-party platform.
When you withdraw your consent or authorization, we may not be ableto continue to provide you with certain products or services correspondingly.However, your withdrawal of your consent or authorization will not affect theprocessing of personal information based on your consent before the withdrawal.
About Deletion of theAccount: You can find the Delete function through “Me &rt; Settings &rt;Account and Security &rt; Delete Account” (Deactivate Account
SecurityMeasures
We use commercially reasonable physical, administrative, andtechnical safeguards to preserve the integrity and security of your PersonalData. The BDR Thermea Group company provides various security strategiesto effectively ensure data security of user and device. As for device access, the BDR Thermea Group company proprietaryalgorithms are employed to ensure data isolation, access authentication,applying for authorization. As for data communication, communication usingsecurity algorithms and transmission encryption protocols and commerciallevel information encryption transmission based on dynamic keys aresupported. As for data processing, strict data filtering and validation andcomplete data audit are applied. As for data storage, all confidentialinformation of users will be safely encrypted for storage. If you have reasonto believe that your interaction with us is no longer secure (for example, ifyou feel that the security of any account you might have with us has beencompromised), you could immediately notify us of the problem by emailing theBDR Thermea Group company on the email address provided in the Contact Us paragraphat the end of this document.
DataRetention
We store your personal data in our systemsfor as long as this is necessary for the purposes described in this privacystatement. If we no longer need your personal data, we will take measures todelete it.
If you ask us to delete your account, or ifyou have not used our services for more than three years, we will delete thedata for which we no longer have a need to keep it.
In all cases, personal data may be kept for a) a longer periodwhere there is a legal or regulatory reason to do so (in which case it will bedeleted if it is no longer required for the legal or regulatory purpose) or b)a shorter period if the processing of personal data is objected to and there isno longer a legitimate interest or legal obligation in keeping it.
· For as long as you require us to fulfill theproducts and services you request from us;
· Personal Data will no longer be retained whenyou request to remove your Personal Data, we will accordingly complete thetask.
Children’sPrivacy
Protecting the privacy of young children is especially important tous. The Services are not directed to individuals under the age of sixteen (16)(or such other age provided by applicable law in your country/region ofresidence), and we request that these individuals do not provide any PersonalData to us. We do not knowingly collect Personal Data from any child unless wefirst obtain permission from that child’s parent or legal guardian. If webecome aware that we have collected Personal Data from any child withoutpermission from that child’s parent or legal guardian, we will take steps toremove that information.
Changesto this Privacy Policy
This privacy statement may be changed from time to time. To let youknow when we make changes to this statement, we will amend the revision date.The new modified or amended privacy statement will apply from that revisiondate.
ContactUs
If you have any queries, concerns, or complaints regarding theprocessing of your personal data, please contact the BDR Thermea Group company at: