Privacy Policy for PRIMEDIC CRM

Last Updated: September 2025

Dear users, Metrax GmbH (hereinafter referred to as "we") as the data controller for your user data and data processor for your customer data, attaches great importance to the protection of your personal data. When you access and use the PRIMEDIC CRM application (hereinafter referred to as the "App" or "the Service") developed and operated by us, we are committed to protecting your personal data in accordance with this Privacy Policy (hereinafter referred to as the "Policy").

This Policy is designed to help you understand what personal data we collect, why we collect it, and how we protect it. We will collect and process your personal data in accordance with the General Data Protection Regulation ("GDPR"), and other relevant laws and regulations and provide services to you.

Before you use the Service, please be sure to read and understand this Policy carefully and completely, especially the bold and/or underlined parts. If you wish to use the services provided by the App, please provide your explicit consent to this Policy by clicking "Read and Agree". Otherwise, please do not use the App or provide us with your personal data.

If you have any questions, comments or suggestions about this Policy, you can contact our Customer Service Center at service@primedic.com

Related Definitions:

1. Personal Data: Any data relating to an identified or identifiable natural person (data subject).

2. PRIMEDIC CRM: The Service is a cloud-based Customer Relationship Management platform, accessed via a mobile application and web portal, designed to manage customer information and track sales activities.

3. User: The natural person who meets the eligibility requirements of PRIMEDIC CRM users and registers and logs in to the App account through the designated method.

4. User Data: Personal data relating to you as a User of our Service, such as your account login credentials and contact details. For this data, we act as the Data Controller.

5. Customer Data: Data, including personal data, that you and your organization input into the Service about your own customers, contacts, and business activities (e.g., contact names, visit reports). For this data, you and your organization act as the Data Controller, and we act as the Data Processor.

6. Company Group: Metrax GmbH.

7. Distributor: The organization that sells our products to you.

This Policy will help you understand the following:

1. Scope of Application

2. How to Collect and Use Personal Data

3. How to Share and Transfer Personal Data

4. Retention Period of Personal Data

5. How to Protect the Security of Personal Data

6. Protection of Minors' Personal Data

7. Your Privacy Rights

8. How to Contact Us

9. Update of the Privacy Policy

1. Scope of Application

1.1 The App is a mobile client for our cloud-based Service, used to create, manage, and review customer records, and to schedule and report on customer visits. This Policy only applies to you when you use the product or service of this App and its associated web platform.

1.2 This Policy does not apply to services provided to you by third parties. The App may contain links to third-party websites. Any access to and use of such linked websites are not governed by this Policy, but rather by the privacy policy of such third-party websites. We are not responsible for the data practice of such third-party websites.

2. How to Collect and Use Personal Data

Based on your explicit consent, in order to provide you with the product and service, we collect and use the following personal data after taking appropriate security measures. You should provide us with accurate personal data, otherwise you will not be able to use the corresponding products or services accurately.

2.1 We collect and use the following personal data:

2.1.1 Data you provide directly to us

(a) Account Information (User Data)

We will collect your email address and registration password (or phone number and verification code) and may send a verification link to complete the authentication of your account identity, create, activate and manage your account, including verifying your identity and ensuring account security.

(b) Customer and Visit Information (Customer Data)

To use the Service, you will input information related to your business activities, which includes customer details, contact person information, and the contents of your visit reports and customer feedback. As the Data Controller for this information, you are responsible for having a lawful basis for its collection and processing.

2.1.2 Data Collected Automatically

In order to ensure the consistency of this App and provide you with services that better meet your needs, we may collect:

(a) Log Information

We need to keep the necessary logs in order to comply with the applicable GDPR and related laws.

(b) Device and Network Information

We will collect data of the device you use according to the specific permissions you explicitly agree to grant when installing and using the App, to provide corresponding services:

Device Permissions have been Obtained: Camera Permission

Information Collected: Available or not Purpose: Upload photos for the "Photo Check-In" feature or as attachments to visit records.

Device Permissions have been Obtained: Foreground Location (ACCESS_COARSE_LOCATION, ACCESS_FINE_LOCATION)

Information Collected: Location Information

Purpose: Collect location information to verify and record the location of on-site customer visits for reporting and management purposes.

Device Permissions have been Obtained: Storage Permission

Information Collected: Storage Information

Purpose: Read the information of the storage space or store information in the storage space, for uploading and downloading attachments.

Device Permissions have been Obtained: Network Permission

Information Collected: Available or not

Purpose: Check whether the network environment meets the use conditions of products or services required for data synchronization.

2.2 How we use your personal data

We will use your data in accordance with the purposes and methods disclosed in this Policy, and if we need to change the above purposes and types of data, or if we use the data for other purposes not specified in this Policy, or use the data collected for specific purposes for other purposes, we will obtain your explicit consent in advance as required by related personal data protection laws.

3. How to Share and Transfer Personal Data

3.1 We will not share your personal data with other organizations and individuals except in the following circumstances:

(a) Sharing with other Users within Your Organization: The Service is a collaborative platform. Customer Data that you enter is, by design, accessible to other authorized users within your organization (e.g., your manager or colleagues designated as "Joint Colleagues") to facilitate teamwork and provide management oversight.

(b) Sharing by companies within the Company Group: After obtaining your explicit consent where required, we may share your personal data with companies within our Company Group when it is necessary for providing support or operational functions.

(c) Sharing with distributors: If you require product support from your distributor, we will share necessary User Data and relevant technical information to assist in resolving the issue.

(d) Sharing in the Event of a Merger or Division of a Company: In the event of a merger, acquisition or bankruptcy liquidation between us and another legal entity, or other circumstances involving a merger, acquisition or bankruptcy liquidation, if the transfer of personal data is involved, we will require the new organization holding your personal data to continue to be bound by this Policy and obtain your explicit consent again where required.

3.2 Due to global data management, these recipients may be located in countries other than the country in which the personal data was originally collected. These countries may not have the same data protection laws as the country in which you initially provided the data. When we transfer your personal data to recipients in other countries, we will implement appropriate safeguards to ensure an adequate level of data protection under applicable law. This may include selecting partners located in countries that are recognized as providing an adequate level of data protection and, where applicable, implementing safeguards in accordance with standard data protection clauses, such as the European Commission's Standard Contractual Clauses.

3.3 We will sign strict Confidentiality Agreements and Data Protection Agreements with the data receivers, and require them to process your personal data in accordance with laws, this Policy and take any necessary security measures.

4. Retention Period of Personal Data

4.1 User Data: We will retain your User Data for the period necessary to provide you with services. However, if laws and regulations require a different retention period, we may retain it for a longer period to ensure the safety and quality of services, or to achieve the purpose of dispute resolution.

4.2 Customer Data: As the Data Processor for Customer Data, we will retain this data according to your organization's instructions and applicable legal requirements. You, as the Data Controller, are responsible for determining the appropriate retention period for your Customer Data.

4.3 Data Deletion: After the retention period has expired, we will delete or anonymize your personal data in accordance with statutory provisions and, where applicable, your instructions.

5. How to Protect the Security of Personal Data

5.1 We take the security of your personal data very seriously. In order to ensure the security of your personal data, we have taken appropriate data security protection measures to protect your personal data from unauthorized access, use, modification, public disclosure, damage or loss. For example:

(a) Ensure the security of personal information from many aspects such as security management organization and policy.

(b) Implement security measures such as data encryption in transit and at rest, regular data backup strategies, and system status monitoring to effectively protect the integrity and security of personal data.

(c) Implement data authority management for our employees, and establish a role-based access control system to ensure that only authorized personnel can access personal data.

(d) Implement strict confidentiality management for personnel involved in data use and security management, and regularly carry out training related to data security protection.

5.2 In the unfortunate event of a personal data security incident, we will promptly inform you of the basic situation and possible impact of the security incident, the measures we have taken or will take to deal with it, the suggestions you can take to prevent and reduce the risk independently, and the remedial measures for you in accordance with the requirements of laws and regulations. When it is difficult to notify the personal data subject one by one, we will make an announcement in a reasonable and effective manner.

5.3 At the same time, we will report the handling situation of personal data security incidents as soon as possible in accordance with the requirements of the regulatory authorities.

5.4 If our products and services cease to operate, we will take reasonable steps to protect the security of your personal data, including promptly stopping activities that collect data. Notification of cessation of operation will be notified in the form of a notice or announcement on a case-by-case basis, and the stored personal data will be deleted or anonymized.

6. Protection of Minors' Personal Data

We take the protection of minors' information very seriously. Please be aware that our products and services are only intended for adults for business use. Minors under the age of 18 should not use this product. If we become aware that we have collected personal data from a minor without the authorization of a parent or guardian, we will take reasonable steps to delete it as soon as possible.

7. Your Privacy Rights

7.1 We will strive to safeguard your rights in our personal data processing activities, including but not limited to:

(a) Right of Access

Request access to the personal data we hold about you. Your request should include a detailed and accurate description of the personal data you wish to access.

(b) Right to Rectification

Request to correct data that you believe is inaccurate or incomplete.

(c) Right to Restriction of Processing

Ask us to limit or restrict our use of your personal data according to your legal requirements and specific circumstances.

(d) Right to Data Portability

Ask us to provide the personal data you have provided to us in a structured, commonly used, machine-readable and reasonable format and, where technically feasible, to transfer the data to another entity.

(e) Withdrawal of Consent

Withdraw your consent to the use of your personal data that you have previously provided to us. If you do so, this will not affect the lawfulness of the personal data we processed before you withdraw your consent.

(f) Right to Erasure

Request us to delete your personal data. Please note that we may not be able to delete all your personal data due to legal or operational requirements. In this case, we will clearly tell you the reason.

(g) Right to Complaint

If you have any suggestions on our protection of your privacy rights, you can contact us directly to provide feedback, and you also have the right to complain to the supervisory authority.

7.2 If you wish to exercise your rights with respect to your User Data, please contact us as specified in the "How to Contact Us" section below. As the Data Controller for your Customer Data, your organization is responsible for addressing privacy rights requests from your own customers, and we will provide you with the necessary support through the Service. We may ask you to confirm your identity before we process your request.

7.3 Respond to your request We will respond to your request within the timeframes required by applicable law. If you are not satisfied with our response, you can continue to contact us through the contact information described in this Policy.

8. How to Contact Us

8.1 If you have any questions or suggestions about the content of this Policy, or wish to exercise your rights or have other matters, you can contact our Customer Service Center at service@primedic.com by email. You can also write to the following address:

Service Department

Metrax GmbH

Rheinwaldstr. 22, 78628 Rottweil, Germany

9. Update of the Privacy Policy

Our Privacy Policy may be updated periodically to reflect changes in the way we process personal data, and the updated time will be marked at the beginning of the Policy. We will not limit your rights under this Policy without your explicit consent. We will use reasonable efforts to prompt you to read the updated Privacy Policy.