Legal

Privacy policy

Effective and last updated: August 17, 2026

Your hosted files are end-to-end encrypted by default.

OÜ Asius does not have the keys needed to read their contents unless you deliberately enable Share with Asius on your device. We still process limited metadata needed to store and deliver those encrypted files.

This policy explains how OÜ Asius (“Asius”, “we”, “us”) processes personal data through the Asius device, mobile and web apps, website, hosted services, shop, and support channels (together, the “Services”). OÜ Asius is the data controller for the processing described here. Our registry code is 16157235 and our registered address is Turu tn 34b, 51004 Tartu, Estonia.

1. Data we process

App and device identity

Each app installation and device uses its own public-key identity. We process public keys, device identifiers, pairing and access-control information, signed request metadata, software and hardware versions, connectivity state, and security events. Private signing and decryption keys remain on your app or device and are not intentionally sent to Asius.

Encrypted hosted data

Your device may upload driving files, logs, video, and related records as encrypted blobs. When Share with Asius is off, we can store and transmit these blobs but cannot read their contents. We can still see operational metadata such as the public device identifier, object name or identifier, size, cryptographic hash, upload time, retention status, and network information needed to operate and secure the service.

Vehicle and driving data

The device may generate vehicle-bus data, routes and approximate or precise location, speed, acceleration, braking, system state, diagnostics, exterior road video, driver-monitoring information, and other sensor or derived data. This content remains inaccessible to Asius while it is end-to-end encrypted, unless you enable Share with Asius or separately send it to support.

Information you submit

We process information you provide through purchases, waitlists, surveys, support, returns, and other communications. This may include your name, email, shipping and billing details, order number, device identifier, vehicle details, message contents, and attachments. Payment processors handle full payment card details; Asius generally receives transaction and payment-status information instead of the complete card number.

Website and service telemetry

We and our infrastructure providers process IP address, request timestamps, browser or app type, crash and diagnostic information, and security logs. Bluetooth and local-network permissions are used to discover, pair with, and communicate with your Asius device. We do not use those permissions to build an advertising profile.

2. Share with Asius

Share with Asius is optional and off unless you enable it. While enabled, your device may give Asius access to selected driving content and may upload additional readable data. You authorize Asius to collect, decrypt, copy, label, combine, analyze, modify, and otherwise use data shared through this setting for safety analysis, support, research, analytics, product improvement, and the development, training, testing, evaluation, and commercialization of machine-learning models and other products and services, as well as other lawful purposes consistent with these activities.

We may use service providers, contractors, and research or commercial collaborators for those purposes. Where practical, we remove or reduce direct identifiers before broader use. Driving data can nevertheless be identifying because it may contain faces, voices, license plates, locations, routes, or distinctive behavior. You are responsible for informing other drivers and occupants where required by law.

Turning the setting off stops new sharing governed by that setting. It does not automatically retrieve copies already used in completed research, aggregated results, published datasets, derived statistics, or trained model parameters. You may still exercise applicable deletion or objection rights; those rights may be limited where data can no longer reasonably be linked to you or retention is legally permitted.

3. Why we use data

PurposeTypical legal basis
Provide pairing, connectivity, encrypted storage, updates, purchases, returns, and supportPerforming our contract with you
Protect users, devices, infrastructure, and the integrity of signed requestsLegitimate interests and legal obligations
Comply with tax, accounting, consumer-protection, and lawful government requirementsLegal obligations
Use readable driving content enabled through Share with AsiusYour consent and, where applicable, our legitimate interests described above
Send optional product newsYour consent; you may unsubscribe at any time

4. When we disclose data

We may disclose personal data:

We do not sell personal data for cross-context behavioral advertising.

5. Retention

We retain data only as long as reasonably necessary for the purposes above. Encrypted hosted files remain until you or an authorized user deletes them, the applicable service ends, or our retention controls remove them. Support records are generally kept for up to three years after resolution; order, tax, and accounting records are kept for the periods required by law; security logs are generally shorter-lived unless needed to investigate abuse. Shared research data may be retained longer where necessary for reproducibility, safety, or model development, subject to applicable law.

6. International processing

Our providers may process data outside Estonia or the European Economic Area. Where required, we use adequacy decisions, standard contractual clauses, or other lawful transfer safeguards. End-to-end encryption limits provider access to hosted file contents when Share with Asius is off.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive your personal data; object to certain processing; and withdraw consent. Withdrawing consent does not make earlier processing unlawful. You can disable Share with Asius on the device and can delete hosted data from an authorized app. See our data-deletion instructions or contact us for help.

To exercise a right, email [email protected]. We may need to verify control of the relevant app or device key before acting. You may complain to the Estonian Data Protection Inspectorate or your local supervisory authority.

8. Security and children

We use cryptographic authentication, access controls, encryption, and other safeguards appropriate to the Services. No system is completely secure, and you are responsible for protecting your device, app installation, recovery material, and authorized keys. The Services are not directed to children under 16, and the driving features are intended only for licensed drivers who can lawfully operate the vehicle.

9. Changes and contact

We may update this policy as the Services or law change. We will change the date above and provide additional notice when required. Questions and privacy requests can be sent to [email protected] or OÜ Asius, Turu tn 34b, 51004 Tartu, Estonia.