As you made your way to this privacy statement, it appears that you care about privacy – and so do we. We therefore pursue a privacy-by-design approach you can read about here.
As we apply the same high standards to our privacy policy as we do to the quality of our products, we do not wish to leave any questions unanswered. We therefore set-up the following data privacy statement for the use of our iw.hub robot. We aim to make it as comprehensive yet straightforward to understand as possible.
In the following, we provide you with the answers to:
If you nevertheless find your individual concern unanswered, please do not hesitate to contact us directly: [email protected]. We want anyone who encounters our robot to feel safe and rest assured that their privacy is respected at any time.
1. Who is collecting your personal data?
IDEALworks GmbH, Riesstraße 22, 80992 Munich, domicile and court of registry: Munich HRB 260546 (hereinafter “idealworks” or simply “we”) is the data controller in the meaning of the General Data Protection Regulation (hereinafter "GDPR”). We are responsible for the data processing as well as the measures to ensure data protection as described in the following.
2. What personal data is collected?
The iw.hub robot is equipped with a camera that collects images during operations. As the robot is employed in various environments, it might capture natural persons while doing so. These images are considered personal data according to GDPR.
Capture of Images during Operations
As we follow a strict data-minimization approach, no further personal data is collected on the iw.hub. Instead, we rely on the processing of “non-human-readable” and therefore non-personal data like depth images or LiDAR data wherever we can.
3. Why is the personal data collected?
The iw.hub robot autonomously navigates within a variety of sites like logistic centers or warehouses. As each use case differs, the robot needs to perceive and understand differing environments to appropriately interact with its surroundings. Many functionalities (for example distance estimations or detection of specific objects) can be based on non-personal data like LiDAR or depth images.
To provide our customers with an even more reliable driving behavior, we developed features that enable the robot to constantly recognize as well as remember different obstacles in its environment. These functionalities are based on pre-trained artificial neural network models. As common scenarios which the robot encounters can strongly differ, these models need to be fine-tuned during operations for optimal performance. Here, non-personal data no longer suffice.
The fine-tuning is done by feeding the models images the robot collects while executing its daily tasks. These images are referred to as training data. By continuously refining our models through up-to-date training data, we can ensure that our robot’s interactions with its surroundings are tailor-made for each customer’s use case and achieve most appropriate and dependable autonomous behavior.
4. How is the collected data processed?
The images are initially stored on the robot’s local file system that can only be viewed by the customer operators who are granted access rights on the robot. After a dedicated amount of time and when operations allow for it, the images are securely uploaded to a bucket on a cloud server using the customer’s wifi network.
Upload through your private network
After the upload, the images on the robot are deleted. In case the upload should not be feasible for an extended period of time, the images will nevertheless be auto-deleted on the robot after 30 days.
On the server, an anonymization service then fetches the images. This service detects and subsequently removes all natural persons pictured in the images. The fully anonymized images are then moved to a separate bucket and used to train and enhance the models. If the images are not fetched for anonymization within 30 days, they are auto-deleted from the bucket.
Anonymization of Images on the Server
As the resulting data can no longer be related to a natural person, the anonymized images are not considered personal data and any further processing does not fall under the scope of GDPR. The processing of your personal data is therefore limited to the collection, storage, upload, and anonymization of collected images.
5. How do we protect your privacy?
We execute every processing step in an appropriate and secure way to protect your privacy. For this purpose, we exclusively rely on state-of-the-art methods and technologies. In the following, you can find out how we assure data privacy step-by-step along the processing chain.
Safe storage on the robot
The images are saved on the robot’s local file system in encrypted form. The folder containing the collected images is password-protected and we encourage the customer to only share this password with trained employees on a need-to-know-basis. This folder is not accessible by idealworks.
Encrypted Storage on the Robot
Safe uploading procedure
The upload of the images to the cloud server is done through the customer’s private wifi network and fully encrypted using the TLS standard.
Safe cloud storage
On the cloud server, the images are again stored in encrypted form. The cloud-bucket cannot be accessed by any employee’s account, but the root user. Only the algorithm that fetches the image data for anonymization can load the raw images data.
Reliable Anonymization
The images are anonymized using state-of-the-art AI-based algorithms. The employed models are pre-trained and use-case refined by idealworks. The algorithm is trained to detect any (partially) pictured person within an image. The detected pixels are then blackened in a subsequent processing step.
To assure full anonymization, the images are then once more passed to the AI-models trained for detecting humans. This way, we can double-check if all relevant pixels were successfully blackened. If the models detect any remaining pixel-sets they classify as belonging to a person, the picture is deleted and not kept as potential training data.
AI-based Detection and Blackening of captured Persons
As we do not intend to ever identify any natural person within the collected images, we additionally clear the anonymized images of any meta-data that might facilitate identifying a natural person. This includes the exact time of when and location of where the picture was taken.
For further information on the code the anonymization is based on, please refer to the GitHub repository: BMW-InnovationLab/BMW-Anonymization-API.
6. How long is the data kept for?
Due to the applied auto-deletion regimes, the images remain on the robot for a maximum of 30 days and a maximum of 30 days in the bucket they were initially uploaded to. In total, any personal data is therefore kept for no longer than 60 days.
7. Who do we share your personal data with?
For storing our data, we rely on the infrastructure of our cloud computing provider that fully commits to GDPR-compliance and applies state-of-the-art security measures. We assure that all our acquired processing services are based on EU servers.
8. What is the legal basis for processing the data?
The legal basis for the collection and processing of the images as described above is the legitimate interest of idealworks pursuant to Art. 6 (1) lit. f GDPR.
Our legitimate interest in the processing of image data results from our interest in further developing and enhancing our robot’s navigation features. Also, after the initial release of a feature, the processing of image data remains relevant to develop and validate updates for the released software.
Additionally, we have a keen interest in continually improving our robot’s situational awareness to reduce bottlenecks and enable smooth operations. Developing and refining methods to assure safe cooperations of humans and robots at the same site could serve the interest of the general public.
9. What are your rights and who can you reach out to for further questions?
As the party affected by the processing of your data, you may claim certain rights under the GDPR and other relevant data protection regulations. If you wish to execute any of your rights listed below or have any other questions regarding our privacy policy, please contact us with your concern by sending an email to [email protected].
In certain situations, we may be unable to respond to your request as a data subject due to legal requirements or information available to us. For instance, we may not be able to retrieve images of pictured persons without additional information. Since the persons captured by the robot cannot be identified without additional information, and since such identification is neither necessary nor ever intended for the purposes pursued by idealworks, we are prevented by law from carrying out additional data processing for the purpose of identification. In such cases, your rights under Art. 15 to 20 GDPR may not be applicable.
Your data subject's rights may only apply if you provide us with additional information which enables us to clearly identify you. Even with this additional information, we may not be able to verify your entitlement to access or delete the data, since we do not identify any persons in the images and would therefore not know who the data subjects on the images are, and your data subject rights are restricted due to rights of others or the need to keep the data for reasons of law.
Under the GDPR, you are entitled to claim the following specific rights vis-à-vis idealworks as the data subject:
Right to access by the data subject (Art. 15 GDPR)
You have the right to request information on the data we hold about you from us at any time. This information includes, but is not limited to, the categories of data we process, the purposes for which it is processed, the source of the data if not collected directly from you, and, if applicable, the recipients with whom we have shared your data. You can obtain a copy of your data from us free of charge.
Right to rectification (Art. 16 GDPR)
You have the right to request that we rectify inaccurate data relating to you. Images are by nature "correct" because they represent a photographed person in reality. We will not edit images prior to their anonymization in any way so that the (briefly) stored data is accurate and up-to-date at any time.
Right to erasure (Art. 17 GDPR)
You have the right to request that we erase your data, as long as the legal requirements for this are satisfied. This may be the case under Art. 17 GDPR if
the data is no longer required for the purposes for which it was collected or otherwise processed;
you withdraw the consent on which data processing is based, and there is no other legal basis for processing;
you lodge an objection to the processing of your data and there are no legitimate reasons for processing, or you object to data processing for direct marketing purposes;
the data was processed unlawfully, and provided that processing is not required
for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject;
for scientific research purposes and provided that the deletion of the data is not likely to prevent or seriously affect the achievement of that objective;
to establish, exercise or defend legal claims.
Right to restriction of processing (Art. 18 GDPR)
You have the right to request that we restrict processing of your data if
you dispute the accuracy of the data – in which case processing may be restricted during the time it takes to verify the accuracy of the data;
processing is unlawful, and you reject the deletion of your data, requesting that its usage be restricted instead;
we no longer need your data, but you need it to establish, exercise or defend your rights;
you have lodged an objection to its processing, as long as it is not certain that our legitimate reasons outweigh yours.
Right to data portability (Art. 20 GDPR)
You have the right to request that we transfer your data – if technically possible – to another responsible party. However, you may only enforce this right if data processing is based on your consent or is necessary for the performance of a contract. Rather than receiving a copy of your data, you may also ask us to submit the data directly to another responsible party specified by you.
Right to object (Art. 21 GDPR)
You have the right to object to the processing of your data at any time for reasons that arise from your particular situation, as long as data processing is based on your consent, on our legitimate interests or those of a third party. In this case, we will cease to process your data. This does not apply if we can show that there are compelling legitimate grounds for processing that outweigh your interests, or if we need your data for the establishment, exercise or defence of legal claims.
We make every effort to reply to all requests within 14 days. However, this period may be extended for reasons relating to the specific right or complexity of your request. No matter the complexity of your request, we will try to get back to you as soon as possible to update you on your request’s status.
Complaint to supervisory authority
idealworks takes your concerns and rights very seriously. In every processing step we decide on, we consider your privacy as top priority. Yet if you believe that we have not responded in an appropriate manner to your complaints or concerns, you have the right to lodge a complaint with your local data protection authority.






