top of page

FULL PRIVACY POLICY
BONSAI TECHNOLOGY COMPANY

Last updated: Dec 18, 2024

Bonsai Technology Company ("we," "us," "our") is committed to protecting your privacy and complying with the EU General Data Protection Regulation (“GDPR”) and other applicable data protection laws. This Privacy Policy explains how we collect, use, store, share, and protect personal data when you use our website athttps://www.techbybonsai.com/ (the “Website”) and our forklift safety software and hardware services and products (the “Services”). It also outlines your rights and how you can exercise them.

If you have any requests or questions concerning your personal data or this Policy, please contact us at braum@safewithbonsai.com.

If you do not agree with this Privacy Policy, you should immediately discontinue use of the Website and Services.

Definitions

  • “Services” refer to our forklift safety software and hardware solutions, including camera systems that capture images and videos of workplace incidents.

  • “Bonsai Technology Company” (“we,” “us,” “our”) refers to the Delaware corporation providing these Services.

  • “Website” refers tohttps://www.techbybonsai.com/ and any associated online presence.

  • “User,” “you” means any individual accessing our Website or using our Services.

  • “Personal data” means any information relating to an identified or identifiable natural person.


In certain circumstances, we may act as a joint controller with our customers (e.g., employers using our Services to improve workplace safety). This means we share responsibility for determining certain aspects of how personal data is processed.
 


Legal Basis for Processing Personal Data


We process personal data primarily under the legal basis of legitimate interests (Article 6(1)(f) GDPR). Our legitimate interests include:

  • Improving and refining our computer vision models to enhance workplace safety.

  • Providing ongoing safety analytics and incident review capabilities to our customers.

  • Maintaining historical records for long-term safety analysis and facilitating data continuity if a customer’s subscription ends and later resumes.

 

When required, we may also rely on other legal bases, such as contractual necessity (e.g., processing payment details) or compliance with legal obligations.
 


Personal Data We Collect

  1. Customer and Contact Data:
    When you register for or purchase our Services, we collect and maintain business relationship data including names, email addresses, job titles, billing details, contract information, and other business contact information.

  2. Worker Images and Videos (Captured by Our Camera Systems):
    Our camera systems may capture images and videos of workers involved in warehouse incidents (e.g., near misses, collisions). While we attempt to anonymize this data by blurring faces and removing personally identifiable information, we cannot guarantee perfect anonymization. As a result, we treat this data as personal data. This data may include:

    • Images and videos showing individuals and forklifts at the time of incidents.

    • Metadata such as time, location, and incident details.

  3. Payment Information:
    We may process payment information via our third-party payment processors to facilitate transactions. We do not store full payment details ourselves.

  4. Employee Data:
    For our employees and contractors, we collect and process personal data necessary for employment purposes, including contact information, employment agreements, and payroll information as required by law.

  5. Marketing Website Data:
    Form submissions and contact information from website visitors, retained for business development purposes.

  6. Analytics Data:
    We use Google Analytics with IP anonymization enabled and EU-based data storage to collect anonymous usage statistics about our website. Since this data is fully anonymized, it is not considered personal data under GDPR.

  7. Cookies:
    Our website uses cookies for essential functionality and, with your consent, for non-essential purposes:

    • Essential Cookies: Required for basic website functionality

    • Non-Essential Cookies: Used to enhance website experience and functionality

    • You can control cookie settings through your browser preferences

 


How We Use Your Personal Data

  • Model Improvement (Retained Up to 5 Years from Collection):
    We keep certain images and videos for up to five years from the date of collection to improve our computer vision models. Over this period, we refine detection accuracy, address biases, and adapt to evolving workplace conditions.

  • Historical Records for Safety Analytics (During Subscription + 5 Years Post-Termination):
    We retain incident data during the customer’s active subscription to provide immediate analytics and incident review capabilities. After the subscription ends, we retain this data for up to 5 additional years, allowing continuity if the customer re-subscribes and ensuring valuable long-term safety trend analysis.

  • Providing Services and Customer Support:
    We process personal data to deliver our Services, respond to inquiries, handle support requests, and maintain service quality.

  • Compliance and Legal Requirements:
    We may use personal data to comply with legal obligations, respond to lawful requests, or protect our rights and interests.

 


Data Subject Rights


You have rights regarding your personal data, including:

  • Right to Access: Obtain a copy of your personal data.

  • Right to Rectification: Request correction of inaccurate or incomplete data.

  • Right to Erasure: Request deletion of data when no longer needed or if you withdraw consent and no other legal basis applies.

  • Right to Restrict Processing: Under certain circumstances.

  • Right to Data Portability: Receive personal data in a structured, commonly used format.

  • Right to Object: Object to processing based on legitimate interests, including profiling.

  • Right to Withdraw Consent: Where we rely on consent, you can withdraw it at any time.


To exercise your rights, please contact us at braum@safewithbonsai.com. We will respond within a reasonable timeframe. Note that some data is essential for providing the Services, and deleting it may prevent continued use.

If you have any concerns about our handling of your personal data, you may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence or where an alleged infringement occurred. In the Netherlands, this is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
 


Data Subject Requests Regarding Worker Images


Workers captured in incident footage are generally employees of our customers. As joint controllers in some respects, we rely on our customers (the employers) to inform workers that data may be captured. If a worker believes personal data about them is processed, they can exercise their rights by contacting us or their employer. We require our customers to ensure workers are informed and direct them to our privacy notice.
Identification Limitations:

  • We do not use facial recognition or maintain direct personal identifiers (e.g., names) linking images/videos to individuals.

  • To locate specific footage, we require sufficient contextual details, such as:

    • Approximate date and time of the incident (within a narrow window)

    • Location (warehouse or area)

    • If known, relevant forklift/equipment ID

    • Identifying characteristics (e.g., what you were wearing)

  • Without this information, we may be unable to identify your personal data among large volumes of footage.

 

Once identified, we will handle the request per GDPR, which may include providing access to the data or erasing it if no lawful basis for continued retention exists.

 

Please note: If you cannot supply these necessary details, we may lawfully decline the request in accordance with GDPR’s principle of proportionality.
 


Data Sharing and Transfers


We do not sell personal data. We may share data with:

  • Authorized personnel within our company who need access for model improvement or customer support.

  • Third-party service providers (e.g., hosting on AWS) under Data Processing Agreements that ensure GDPR compliance.

  • Payment processors for handling transactions securely.

  • Safety managers at customer sites, for reviewing incidents and safety analytics.

Data may be transferred outside the EEA. In such cases, we rely on Standard Contractual Clauses (SCCs) or other approved safeguards.
 


Data Security


We implement technical and organizational measures to protect personal data, such as encryption, role-based access controls, and regular security audits. Although we strive to ensure data security, no transmission over the Internet is 100% secure.
 


Data Retention

  • Model Training Data: 

    • Retained for up to 5 years from the date of collection. After 5 years, we securely delete or fully anonymize it.

  • Historical Records Data (Customer-Specific): 

    • Retained during the active subscription and for up to 5 years following subscription termination. After the applicable period, we securely delete or fully anonymize the data.

  • Customer and Business Contact Data:

    • Active customers: Duration of relationship + 7 years

    • Inactive contacts: 3 years from last meaningful interaction

  • Marketing Website Data: 

    • Form submissions and inquiries retained for 3 years

  • Website Analytics Data: 

    • Not subject to GDPR retention (fully anonymized)

  • Employee Data: 

    • Retained as long as required by employment laws and regulations

We review retention periods periodically to ensure they remain necessary and proportionate.
We review retention periods periodically to ensure they remain necessary and proportionate.
 


Children’s Data


Our Services are not intended for children under 13. We do not knowingly process children’s personal data. If discovered, we will delete it.
 


International Transfers


As a US-based service, personal data may be processed and stored in the United States. When transferring data internationally, we implement safeguards to ensure an adequate level of protection.
 


Your Choices


You may choose not to provide certain personal data (e.g., contact details in inquiry forms), but doing so may limit our ability to respond to your requests or deliver certain features effectively. You can always opt out of marketing emails by using the unsubscribe link in those emails. We do not engage in automated decision-making or profiling that would significantly affect individuals; if you have concerns, please contact us at braum@safewithbonsai.com.
 


Changes to This Privacy Policy


We may modify this Privacy Policy from time to time. Changes will be effective 30 days after posting and emailing notice to registered Users. Continued use of the Website or Services after changes means you accept the updated policy.
 


Contact Information

 

If you have questions, requests, or concerns about this Privacy Policy or your personal data, please contact us at:

Bonsai Technology Company
11710 Old Georgetown Road, #413
Rockville, Maryland 20852
Email: braum@safewithbonsai.com 

 

By using our Website and Services, you acknowledge that you have read and understood this Privacy Policy and agree to be bound by it. If you do not agree, please discontinue use of our Website and Services.


If you have questions, requests, or concerns about this Privacy Policy or your personal data, please contact us at:
Bonsai Technology Company
11710 Old Georgetown Road, #413
Rockville, Maryland 20852
Email: braum@safewithbonsai.com 
 
By using our Website and Services, you acknowledge that you have read and understood this Privacy Policy and agree to be bound by it. If you do not agree, please discontinue use of our Website and Services.

bottom of page