PREAMBLE
This AI & Data Policy (hereinafter the “AI Policy”) aims to describe, in full transparency, the conditions under which Nereva SA designs, trains, deploys, supervises and evolves the artificial intelligence models underlying its Services, as well as the conditions under which the data collected via the platform is used for these purposes.
Statutory corporate purpose of Nereva SA. In accordance with Article 3 of its articles of association entered in the commercial register of the canton of Vaud, the purpose of Nereva SA is the design, development, publishing, marketing, integration and operation, in Switzerland and abroad, of software and digital solutions for orchestrating and synchronising logistics flows operated by vehicles, in particular flows of materials, waste, machinery, equipment and skips linked to construction, civil engineering, recycling, construction-site transport and related sectors.
The company may in particular provide, in the form of software on demand (Software as a Service) or licences, platforms for planning, executing, documenting, tracing and archiving logistics operations, as well as associated configuration, integration, support, training and consulting services.
The company may acquire, hold, exploit, license and defend any intellectual property right, in particular patents, trademarks, designs, models, copyrights and know-how, directly or indirectly related to its main purpose.
The company may carry out, both in Switzerland and abroad, on its own behalf or on behalf of third parties, all administrative, technical, commercial, financial, movable and immovable transactions directly or indirectly related to its main purpose. It may establish branches and subsidiaries in Switzerland and abroad, acquire holdings in companies pursuing a similar or complementary purpose, and grant loans or guarantees to its subsidiaries and group companies.
The company does not carry out any transport activity and does not act as a commercial intermediary between principals and transport companies. It does not capture the commercial contractual relationship between its users.
Contractual relationship. This AI Policy constitutes an annex to the Terms and Conditions of Use (“T&Cs”) of Nereva SA and is articulated with the Privacy Policy, the Data Processing Agreement (“DPA”) and the Copyright and Intellectual Property document. In the event of a contradiction, the T&Cs and the DPA prevail.
Express acceptance. By subscribing to the Services, signing the order form or accessing the platform, the Client (i) expressly acknowledges having taken full and complete knowledge of this AI Policy; (ii) declares having had the time and means necessary to analyse it, where applicable with its advisers; (iii) accepts without reservation all the processing, terms and limitations described below, in particular the use of derived and anonymised data for the purpose of training artificial intelligence models; (iv) expressly waives any claim of ignorance or lack of knowledge of this Policy; (v) acknowledges that continued use of the Services constitutes a continuous reiteration of this acceptance.
The Client acknowledges in particular that the provisions of this AI Policy apply regardless of the Client's subscription terms or the capacity of its Users, and that acceptance of this AI Policy constitutes an essential condition of access to the Services. This AI Policy is governed by the indemnification terms provided for in Article 25 bis of the T&Cs.
TABLE OF CONTENTS
Article 1 — Purpose and scope
Article 2 — Definitions
Article 3 — Scope of Nereva's AI models
Article 4 — Legal frame of reference
Article 5 — Qualification of the Parties
Article 6 — Data lake architecture and separation of zones
Article 7 — Categories of data used for training
Article 8 — Data transformation regimes before training
Article 9 — Special case of geolocation data
Article 10 — Exclusive purposes of training
Article 11 — Legal bases of the processing
Article 12 — Client warranties and obligations
Article 13 — Rights of data subjects
Article 14 — Specific technical and organisational measures
Article 15 — Compliance with Regulation (EU) 2024/1689 (AI Act)
Article 16 — Internal governance
Article 17 — Sub-processors for training
Article 18 — International transfers
Article 19 — Retention period of training data and Models
Article 20 — Fate of data and Models upon termination
Article 21 — Documentation of training runs
Article 22 — Limits and exclusively indicative nature of outputs
Article 23 — Indemnification
Article 24 — Amendment of the AI Policy
Article 25 — Applicable law and jurisdiction
Article 26 — Reference language
Article 27 — Contact
Article 1 — Purpose and scope
This AI Policy applies to any design, training, retraining, validation, deployment, supervision and evolution of the artificial intelligence models used in the context of the Nereva Services, as well as to any use of the Client's or Users' data for the purposes of these operations.
It is applicable from the effective date of the main contract and survives its termination for the obligations which by their nature are intended to continue.
Article 2 — Definitions
The terms defined in the T&Cs and the DPA retain their meaning. The terms specific to this AI Policy are as follows.
Artificial intelligence or AI : a set of techniques and computer systems enabling machines to produce predictions, classifications, recommendations, optimisations or decisions from data, in particular through machine learning.
Model : a software object produced by a training process, capable of producing outputs from inputs.
Training : all the computing operations carried out to produce or improve a Model from Training Data.
Data lake : infrastructure for the storage and governance of data collected and generated via the Services.
Zone A (pseudonymised operational) : zone of the data lake containing pseudonymised data used for the provision of the Services and operational management by the Client. No data from this zone enters the AI training pipeline.
Zone B (anonymised and aggregated) : zone of the data lake containing data that has undergone irreversible anonymisation and, where applicable, aggregation, used exclusively for AI training and the improvement of the Services.
Irreversible anonymisation : transformation of data resulting in it no longer being possible, by means reasonably likely to be used, to identify a natural person directly or indirectly.
AI Act : Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024.
Article 3 — Scope of Nereva's AI models
Nereva SA develops and operates a set of analytics and operational intelligence functionalities grouped under the name EVA (Engine for Virtual Anticipation), including in particular multi-constraint planning and routing optimisation functions, functions assisting the allocation and arbitration of resources, functions for anticipating and estimating durations and waiting times, operational image recognition functions, and sector statistical analysis functions.
Article 4 — Legal frame of reference
This AI Policy is designed to comply in particular with the GDPR and the FADP, Regulation (EU) 2024/1689 (AI Act), Swiss employment law and in particular Article 26 of Ordinance 3 to the Employment Act (ArGV 3), and the recommendations of the FDPIC, the CNIL and the EDPB.
Article 5 — Qualification of the Parties
For processing linked to the provision of the Services to the Client, Nereva SA acts as processor and the Client as controller, in accordance with the DPA.
For the training, validation and improvement of the Models from irreversibly anonymised data, Nereva SA acts as controller, in accordance with Article 10 of the T&Cs.
This duality is expressly accepted by the Client. No use for training purposes concerns non-anonymised data.
Article 6 — Data lake architecture and separation of zones
The data lake architecture is based on two strictly separated zones.
Zone A — Pseudonymised operational. This zone receives the data entered, transmitted or generated by the Client. It is used exclusively for the provision of the Services to the Client. No data from Zone A enters the AI training pipeline.
Zone B — Anonymised and aggregated. This zone receives exclusively data that has undergone an irreversible anonymisation transformation and, where applicable, aggregation. It is used for AI training, sector statistical analysis and the improvement of the Services under the conditions of Article 10 of the T&Cs.
The separation between Zone A and Zone B is documented and auditable. The transformation of data from Zone A to Zone B is unidirectional and traced.
Article 7 — Categories of data used for training
The Models are trained from the following categories of data, after anonymisation transformation within the meaning of Article 8: (i) operational request data (flow types, quantities, time windows); (ii) planning and execution data (sequences, durations, steps, statuses); (iii) positioning data from the Drivers mobile application, after irreversible anonymisation under the conditions of Article 9; (iv) documentation data (types of notes, certificates); (v) technical data on the use of the platform; (vi) sector context data produced by Nereva or from public sources.
No sensitive data within the meaning of Article 9 of the GDPR or Article 5 of the FADP is used for training.
Article 8 — Data transformation regimes before training
Before training, the data undergoes an irreversible anonymisation transformation which combines (i) the removal of direct identifiers; (ii) the removal or substitution of indirect identifiers with a high re-identification potential; (iii) temporal or spatial aggregation; (iv) the controlled addition of statistical noise where applicable; (v) uniqueness checking before integration into Zone B.
The process is documented, versioned and subject to an internal review at least annually.
Article 9 — Special case of geolocation data
Data from the Drivers mobile application presents a structural risk of re-identification. Consequently, Nereva applies to geolocation data, before any use for training, the following enhanced measures: (i) removal of the technical identifiers of driver and vehicle; (ii) aggregation of journeys into anonymised segments, without possible reconstruction of continuous individual routes; (iii) controlled degradation of temporal and spatial resolution; (iv) re-identification test carried out periodically.
Raw or pseudonymised geolocation data is under no circumstances used for training the Models.
Article 10 — Exclusive purposes of training
The training of the Models pursues the following exclusive purposes: (i) improving the quality, accuracy and relevance of the functionalities; (ii) developing new functionalities; (iii) producing sector statistical analyses; (iv) contributing to the intellectual property of Nereva SA under the conditions of Article 9 of the T&Cs.
The Models are under no circumstances used to evaluate, sanction, monitor or compare the behaviour of identified individual Drivers, or to make automated individual decisions within the meaning of Article 22 of the GDPR.
Article 11 — Legal bases of the processing
The processing of data for training purposes rests on two distinct legal bases. On the one hand, the legitimate interest of Nereva SA in developing and improving its Services, pursuant to Article 6(1)(f) of the GDPR and Articles 31 et seq. of the FADP, after a documented balancing test. On the other hand, contractual performance for operations that directly benefit the Client, pursuant to Article 10 of the T&Cs and Article 6(1)(b) of the GDPR.
The use of irreversibly anonymised data takes this data outside the scope of the GDPR and the FADP, in accordance with recital 26 of the GDPR and the doctrine of the FDPIC.
Article 12 — Client warranties and obligations
The Client warrants (i) having informed the data subjects, in particular its Drivers, of the processing carried out via the Services and of the terms of this AI Policy; (ii) having complied, where applicable, with the obligations to consult staff representatives; (iii) having identified the legal bases applicable to the processing implemented via the Services; (iv) having carried out or had carried out any data protection impact assessment that may be required.
The Client expressly accepts the use of derived data and anonymised data for the AI training purposes provided for in Article 10 and acknowledges that this use constitutes an essential condition of the economic balance of the Services.
Article 13 — Rights of data subjects
Data subjects have all the rights provided for by the GDPR and the FADP. Any request is handled by the Client as controller for operations falling under the DPA, and by Nereva SA for operations falling under this AI Policy. Nereva SA provides the Client with the necessary technical functionalities.
Article 14 — Specific technical and organisational measures
Nereva SA implements the following specific technical and organisational measures: (i) logical and technical separation between Zone A and Zone B; (ii) logging of anonymisation transformation operations and of access to Zone B; (iii) periodic internal review of the anonymisation process; (iv) enhanced access control according to the principle of least privilege; (v) versioned documentation of training datasets; (vi) documented re-identification tests; (vii) continuous supervision of the quality, bias and drift of the Models.
Article 15 — Compliance with Regulation (EU) 2024/1689 (AI Act)
As at the effective date of this AI Policy, the Models developed by Nereva SA are classified as limited or minimal risk AI systems within the meaning of the AI Act, in that they are not designed for automated individual decision-making producing legal or significant effects.
Nereva SA provides the Client, upon request, with the documentation useful for demonstrating compliance with the AI Act.
Article 16 — Internal governance
Nereva SA's internal governance in matters of AI includes an AI officer serving as point of contact for Clients (privacy@nereva.com), a documented procedure for validation prior to the deployment of any new Model, and a documented procedure for managing AI incidents.
Article 17 — Sub-processors for training
The conditions of Article 10 of the DPA apply. The list of sub-processors is made available to the Client upon request sent to privacy@nereva.com.
Article 18 — International transfers
AI training operations are conducted exclusively on infrastructure located in Switzerland or in the European Economic Area, except by express derogation in compliance with the safeguards provided for by the GDPR and the FADP.
Article 19 — Retention period of training data and Models
The anonymised data used for training is kept for a maximum of thirty-six (36) months, unless there is a documented need for extended retention. The Models constitute intellectual property assets of Nereva SA and are kept for the duration of their operation.
Article 20 — Fate of data and Models upon termination
Termination entails the deletion or irreversible anonymisation of the Client Data kept in Zone A. Data already transferred to Zone B through irreversible anonymisation, as well as Models already trained, are not affected. The Client acknowledges and expressly accepts this.
Article 21 — Documentation of training runs
Nereva SA maintains internal, versioned and auditable documentation of training operations, including the version of the Model, the description of the dataset, the anonymisation process, the evaluation results and the internal persons responsible.
Article 22 — Limits and exclusively indicative nature of outputs
The outputs produced by the Models are of an exclusively indicative nature. They do not relieve the Client of the exercise of its own judgement and do not constitute automated decisions within the meaning of Article 22 of the GDPR. The Client remains solely responsible for the use it makes of the outputs in the context of its physical operations.
Article 23 — Indemnification
The use of the Services and the application of this AI Policy are governed by the indemnification terms provided for in Article 25 bis of the T&Cs. The Client indemnifies Nereva SA under the conditions provided for in that Article in the event of a claim against Nereva resulting directly or indirectly from a breach by the Client of its own obligations, in particular to inform the data subjects.
Article 24 — Amendment of the AI Policy
Nereva SA reserves the right to amend this AI Policy. Any substantial amendment is notified to the Client with reasonable notice, which may not be less than thirty (30) days.
Article 25 — Applicable law and jurisdiction
This AI Policy is governed exclusively by Swiss law. Any dispute falls within the exclusive jurisdiction of the ordinary courts of the canton of Vaud, subject to a mandatory appeal to the Swiss Federal Supreme Court.
Article 26 — Reference language
The French version alone is legally authoritative.
Article 27 — Contact
Nereva SA, Rue de Rive 22D, CH-1260 Nyon, Switzerland.
Contact : privacy@nereva.com.
