01Spatial Privacy Notice

Version and effective date: 2026-07-21

This Notice explains how 01Spatial processes personal data across its websites, Portal, APIs, SDKs, mapping, localization, billing and support. The registration checkbox acknowledges this Notice; it is not blanket consent for every purpose. Processing relies on contract, legal obligations, legitimate interests where recognized by applicable law, customer instructions, or separate consent where required.

1. Service contact and roles

Service contact and roles. This Notice covers personal-data processing for the 01Spatial services made available through 01spatial.ai. Privacy requests: admin@01spatial.ai. For Customer Personal Data whose purposes and means the customer determines, the customer is normally controller/business and 01Spatial is processor/service provider under the Data Processing Addendum in the User Agreement. If an order or separately signed agreement identifies a responsible party, that document controls for the covered processing.

2. Data processed

We process account and contact data; OAuth and email-verification data; agreement versions, hashes and acceptance evidence; project, map, API, usage, billing and payment status; IP, device, request, error and security logs; and submitted images, video, LiDAR, depth, point clouds, meshes, camera data, poses, locations, maps and spatial content. Localization frames are normally processed transiently, but may be retained when a customer expressly enables archives, Analytics, diagnostics or support.

3. Purposes and legal bases

We process data to perform contracts and pre-contract steps; follow documented customer instructions; protect accounts and infrastructure, prevent fraud, evidence acceptance, enforce limits, diagnose faults and improve reliability through non-identifying aggregated/de-identified signals; comply with legal duties and establish legal claims; and, with consent, provide optional marketing, non-essential cookies or optional features.

4. Spatial, facial and sensitive data

Facial identification is not a mapping purpose and ordinary facial appearance is not used to build a recognition database. Nevertheless, identifiable faces, plates, traces and interiors may be personal or sensitive data, and technical processing for unique identification may be biometric processing. Customers are responsible for capture notices, legal bases, permissions, impact assessments, data-subject requests and minimization. We assist under the DPA. Without written opt-in, identifiable Customer Content is not used for public 3D maps, advertising profiles, unrelated customers, or general-purpose/third-party model training.

5. Recipients

Necessary providers may support hosting, storage, delivery, email, identity, payments, logging, monitoring, security and support under appropriate obligations. Google, Apple, WeChat, payment providers, device platforms and customer-selected integrations apply their own policies. We may disclose data when lawfully required, to protect rights and safety, or in a corporate transaction. The material subprocessor schedule is stated in the Data Processing Addendum incorporated into the User Agreement and is updated by publishing a new legal-document version.

6. Regions and transfers

Primary service data is processed in the EU/international or China environment selected for the account, subject to the deployment, order and DPA. Support, backup, identity, email, payment or other providers may involve other locations. Where EEA or Chinese data is transferred, applicable SCCs, certification, assessment, separate notice/consent or other lawful mechanisms will be used. This Notice does not obtain cross-border consent from data subjects on a customer’s behalf.

7. Retention and deletion schedule

8. Security

We use risk-appropriate access control, transport encryption, credential protection, least privilege, logging, monitoring, backup and incident response. No system is absolutely secure. We provide legally required incident notices according to our role.

9. Rights

Depending on law, you may request access, copies, correction, deletion, restriction, objection, consent withdrawal and portability, or complain to a regulator. Contact us with appropriate identity verification. For customer-controlled mapping data, contact the customer first and we will assist under the DPA. Legal retention, security, third-party rights and litigation holds may limit deletion.

10. Children, automated decisions and changes

The Service is not for minors, and customers must not upload children’s data without valid guardian consent and safeguards. We do not use account personal data for solely automated decisions with legal or similarly significant effects; localization outputs are technical results whose use the customer determines. Material changes receive a new version and renewed express acceptance where required.