Privacy Policy

Last updated: November 2025

This Privacy Policy explains how Caterra AG (“we”, “our”, “us”) processes personal data when you use MyCaterra, our field and fleet management platform for autonomous laser-weeding robots.

1. Who we are

Company details

Caterra AG

Wright-Strasse 31

8152 Glattpark (Opfikon)

Zürich, Switzerland

Commercial Register No. CHE-229.703.046

Email: info@caterra.org

Responsible for data processing: Caterra AG

If you have any questions about how we handle your data, please contact us at the above address.

2. What data we collect

We process the following categories of personal data:

Account information

  • Name, email address, password / password hash, organisation name, role and access status.
  • We also store verification tokens and password reset tokens to confirm account ownership and let you regain access.

Purpose: to create, secure, and manage user accounts.

Profile & preference data

  • Phone number, preferred language, timezone, notification/report preferences (e.g. daily email reports), whether you are configured as customer support admin, and other access-related flags.

Purpose: to localise the interface, communicate with you, send operational updates, and determine what parts of the system you are allowed to access.

Security credentials

  • Authentication and session data such as session tokens, expiry timestamps, login timestamps, IP address, and public-key credentials.
  • This includes authenticator metadata such as credential public keys, device type, backup status, and security counters.

Purpose: to authenticate you securely, prevent unauthorised access, keep you signed in, and detect misuse.

Notification data

  • We keep a record of notifications and alerts addressed to you (for example rover status updates).
  • This includes notification content (title/body), delivery channel (push, email, in-app), whether you have viewed/read it, and push subscription data (browser endpoint and keys) so we can deliver web push messages.

Purpose: to deliver operational and safety-critical alerts and to support incident traceability.

Work scheduling data

This section applies only to internal administrative users who participate in operational duty scheduling (for example, rover check-in rotations).

  • Data may include stated time preferences (morning/evening), weekday/weekend availability, assigned duty times, unavailability periods (for example, vacation or leave), and optional notes or “avoid slots.”

We do not request or require any sensitive information such as health details. If you voluntarily include such details (for example “medical leave”), they are used solely for scheduling and coverage planning and are handled confidentially.

Purpose: to coordinate internal duty schedules, ensure coverage for required system monitoring and field activities, and maintain safe and reliable operation of autonomous equipment.

Operational and location data

  • Field and crop-row information associated with your organisation, such as field names, geofences, row geometry, reference rows, boundaries, assigned areas, and similar geospatial data.
  • Rover status and telemetry such as assigned area, field heading, last known position, battery state, and work progress.
  • Weeding job data such as job name, weed pressure, crop density, progress per row, timestamps of activity, battery change requests, autonomy state, and similar task status.

Purpose: to plan and monitor weeding jobs, ensure correct robot deployment, provide traceability, generate operational reports, and improve performance and safety in the field.

Performance and weeding analysis data

  • We collect image data captured before and after each lasering cycle to analyse weeding performance and adjust laser parameters.
  • The images contain only plant and soil content and do not include any information that can identify individuals or customers.
  • Associated metadata (such as device identifier, timestamp, and field or job reference) is used solely to link the images to specific jobs or robot configurations.

Purpose: to evaluate and improve weeding accuracy, calibrate laser parameters, and enhance the performance and safety of autonomous equipment.

Audit and activity data

  • We keep records that link specific operational actions in the system to specific user accounts.
  • Examples include who added, approved, or rejected downtime; who activated, paused, or deactivated a rover; who was assigned to a check-in; or who claimed control of a device.

Purpose: to ensure traceability and accountability in the operation of autonomous machinery; to enable investigation of incidents, malfunctions, or user-reported issues; to demonstrate proper execution of tasks and service activities to customer organisations; and to comply with internal safety, warranty, and quality-management requirements.

Technical data

  • Browser type, device characteristics, crash/error logs, and similar diagnostic information.

Purpose: to maintain and improve platform stability.

Cookies and session data

  • We use only strictly necessary cookies/session tokens. These keep you logged in, maintain CSRF/session integrity, and associate your browser with your authenticated session.

Purpose: to provide secure access to MyCaterra.

We do not use analytics, advertising, or tracking cookies.

3. Why and how we process your data

We process personal data only as necessary to:

  • Provide, maintain, and improve the MyCaterra service for your organisation.
  • Authenticate users, protect accounts from unauthorised access, and enforce permissions.
  • Plan, run, and monitor weeding sessions and robot deployments in the field.
  • Coordinate support assignments, availability, and coverage for on-site and remote support.
  • Deliver operational and safety-related notifications, including push and email alerts.
  • Maintain audit trails of actions taken in the system for safety, accountability, and customer reporting.
  • Generate operational and performance reports for your organisation (for example weeding progress, downtime records, deployment history).
  • Comply with legal, contractual, and safety obligations relating to the operation of autonomous agricultural machinery (for example traceability of who changed a geofence and when).

Legal bases for processing

Performance of a contract (Art. 6(1)(b) GDPR): to provide access to MyCaterra, run weeding sessions, generate reports, schedule coverage, and otherwise deliver the service to your organisation.

Legitimate interest (Art. 6(1)(f) GDPR): to secure accounts; prevent misuse or unsafe operation; maintain audit trails; coordinate staffing and coverage; and prove service quality and traceability to customers.

Legal/contractual obligations and safety requirements: in some cases we must keep certain operational records (for example deployment logs and downtime approvals) for safety, warranty, or compliance reasons.

Where required under the Swiss Federal Act on Data Protection (nFADP), we rely on the same legal bases.

4. Who we share your data with

We only share personal data with:

Authorised users within your organisation

Managers or admins in your organisation can view operational data, assignments, and status related to your organisation’s fields and devices.

Authorised employees of Caterra AG

Selected support, operations, and engineering staff may access data when necessary to troubleshoot issues, provide assistance or ensure safe operation of hardware.

Data labeling partners

To improve our crop and weed recognition algorithms, we share image data collected by our robots with trusted labeling partners. The images contain only plant and soil content and do not include any information that can identify individuals or customers. No field names, coordinates, or customer information are included.

Our labeling partners process data solely for model training and quality improvement under our documented instructions. Because this data is effectively non-personal, it is not subject to data-protection regulations, but we nevertheless apply appropriate confidentiality and security safeguards.

Infrastructure and application services

Infrastructure and application services are operated primarily by Caterra AG on self-hosted systems under our direct control. For email delivery and communication, we use a secure mail server provided by hosttech GmbH (Switzerland). Apart from this mail infrastructure, all data storage, processing, and application hosting are performed in environments managed directly by Caterra AG. We do not use any external analytics, tracking, or advertising providers.

All third parties that process personal data on our behalf are bound by written agreements that comply with GDPR and Swiss data-protection law.

5. International data transfers

If personal data is transferred outside Switzerland or the EU/EEA (for example, to our labeling partners), we ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, and/or
  • Other appropriate safeguards recognised under the GDPR and the Swiss Federal Act on Data Protection.

6. How long we keep your data

We retain personal data only as long as necessary for the purposes described in this Policy.

  • Account/profile data: kept while your account is active.
  • Session / authentication data: kept for the duration of the active session plus a short security period.
  • Scheduling, assignment, and notification data: kept while needed to coordinate coverage and to document completion of assigned duties.
  • Operational data (for example weeding jobs, rover progress, downtime logs, deployment/rollback history, audit trails): may be retained after a specific user account is deactivated, if needed for safety investigations, warranty, service traceability, contractual reporting to the customer, or legal/regulatory obligations.
  • Backups: automatically rotated and deleted after defined retention cycles.

When data is no longer required, we delete it or irreversibly anonymise it.

7. Applicability of EU GDPR

Caterra AG is established in Switzerland, which has been recognised by the European Commission as providing an adequate level of data protection.

MyCaterra does not offer services directly to private individuals in the European Union, nor does it monitor user behaviour for marketing, analytics, or profiling purposes.

Our processing of EU-related personal data is limited, occasional, and poses no significant risk to the rights and freedoms of individuals. In addition, MyCaterra is offered exclusively to business customers (B2B) rather than private consumers.

For these reasons, the appointment of an EU representative under Article 27 GDPR is not required.

Nevertheless, Caterra AG processes all personal data in accordance with the principles and safeguards of both the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP).

8. Your rights

You have the following rights under applicable data-protection law:

  • Access – request a copy of your personal data.
  • Rectification – correct inaccurate or incomplete data.
  • Erasure (“right to be forgotten”) – request deletion of your data, subject to our need to retain certain operational/safety records and audit trails.
  • Restriction – request that we limit processing of your data under certain conditions.
  • Objection – object to processing based on our legitimate interests, where applicable.
  • Data portability – request to receive certain data in a structured, machine-readable format.

You also have the right to lodge a complaint with a data-protection supervisory authority, in particular in the country where you live, work, or where the alleged infringement occurred.

In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC).

To exercise your rights, contact info@caterra.org.

9. Data security

We use technical and organisational measures to protect personal data, including:

  • Encrypted HTTPS transport
  • Secure password hashing and strong authentication options (including public-key credentials)
  • Role-based access controls and internal access restriction
  • Session management, audit trails, and activity logging for safety-relevant actions
  • Regular security reviews and monitoring

10. Automated decision-making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects for you.

11. Data ownership and usage

Operational, image, and sensor data collected by Caterra robots or uploaded within MyCaterra may include two categories:

  • Organisation-uploaded data, such as field information and user information (eg. names and email addresses); and
  • System-generated data, such as telemetry, diagnostics, and performance statistics produced automatically by Caterra robots or backend systems.

The organisation remains the owner of the data it uploads within its account.

Caterra AG retains ownership of all system-generated and aggregated data produced by its hardware and software.

By using MyCaterra, the organisation grants Caterra AG an irrevocable, worldwide, royalty-free, and perpetual licence to store, process, copy, modify, and use the organisation-uploaded data for operating, maintaining, and improving MyCaterra and associated robotics systems.

Caterra AG may also create and retain anonymised or aggregated datasets derived from any data for analytics, research, and product-development purposes, provided that no individual organisation or user is identifiable.

Where any operational data contains or can be linked to personal information, Caterra AG processes it strictly in accordance with this Privacy Policy and applicable data-protection laws.

12. Children’s data

MyCaterra is not intended for individuals under the age of 16, and we do not knowingly collect personal data from them.

13. Updates to this policy

We may update this Privacy Policy to reflect technical, operational, or legal changes.

The latest version will always be available within the app or at https://my.caterra.org/policy.

If our contact details change, the updated information will be published at the same address.