VisionCTRL
Privacy Policy
Draft: for review by the product owner before publication.
This page has not been reviewed by a lawyer and is not in force. Nothing on it should be relied on as a binding commitment until the product owner replaces this notice. It also does not decide whether a separate Data Processing Agreement is executed with a customer. That is a decision the product owner records before a second customer is onboarded.
What this service does
VisionCTRL is an AI-assisted safety monitoring service. Cameras at a customer's site feed video into a detection pipeline that identifies hazards and activity (people, vehicles, fire, smoke and similar), groups related sightings into occurrences, grades them for severity, and, where warranted, notifies people the customer has designated, by email and, where enabled, SMS. This page explains what data that process touches, how long it is kept, and who it is shared with.
What data we process
- Camera frames from the customer's own video streams, read for the purpose of detection. Raw frames are not retained as video beyond what the detection pipeline needs.
- Detections and occurrences: structured records of what the detector identified, when, and where (which camera, which zone).
- Evidence clips and image crops captured around a detection, used to confirm and review it.
- Notification records: who was notified, when, by what channel, and what action they took (acknowledge, assign, escalate, false-alarm, notes).
- Account and configuration data: recipient names and contact details, zones, alert rules, and role assignments entered by the customer.
We do not knowingly collect information beyond what a customer's own camera feeds and configured recipients provide.
How long we keep it
Retention is not uniform across the categories above, and this section states plainly which parts are enforced today and which are not, rather than implying a single policy covers everything.
- Detections are kept indefinitely today; occurrences (grouped sightings) expire after 90 days. A customer's configured retention setting (90 days for the Canning pilot) is a stated policy for detections, not yet a mechanism that deletes them. Enforcing it on that category is a deliberate future decision, not a default.
- Evidence clips and crops move to cheaper, slower storage after 90 days but are not automatically deleted.
- Notification records are kept indefinitely as the duty-of-care record of who was alerted and what was done in response.
- Account and configuration data is kept for as long as the customer's account is active.
The mechanism behind each of these (what triggers a move to cheaper storage, and what is not yet automatically enforced) is tracked internally. A customer should not assume any category above is deleted on a schedule unless VisionCTRL confirms it in writing.
Who it is shared with
Detection and notification content is shared only with the recipients the customer's organisation has configured. Nobody outside that list is notified. Delivering an email requires passing it to our email delivery provider, which processes the message on our behalf; delivering an SMS, once enabled for a site, requires the equivalent for text messages through our cloud provider's messaging service. Camera frames, detections, and notification records are stored on infrastructure operated by our cloud provider in the Sydney (Australia) region. We do not sell this data, and we do not share it with third parties for their own purposes.
Your responsibilities
- Only configure the service to monitor sites and areas you have the authority to monitor.
- Keep your notification recipients' contact details accurate, and remove someone as a recipient once they no longer need to receive alerts.
- Keep account credentials confidential and report suspected unauthorised access.
Contact
Questions about this policy, or a request about data we hold on your behalf: alerts@visionctrl.ai.