Legal
Privacy Policy
This policy explains what [LEGAL ENTITY NAME] collects through the visaroxy.com website, why it is collected, and how camera and video data is handled when a customer runs the VisaRoxy platform. It applies from [EFFECTIVE DATE].
The short version
The website collects the details you type into the demo request form and standard server logs. In a customer deployment, video is processed inside the environment the customer nominates, and VisaRoxy stores event records and short clips around those events rather than continuous recordings. VisaRoxy does not sell personal data, and this site runs no advertising cookies and no third-party tracking scripts.
Who this policy is from, and what it covers
This policy is published by [LEGAL ENTITY NAME], the company that operates visaroxy.com. Its registered address is [REGISTERED ADDRESS]. For the personal data described in the first half of this policy — the data we collect through this website — [LEGAL ENTITY NAME] is the controller. This version takes effect on [EFFECTIVE DATE].
The policy covers two things. The first is the visaroxy.com website: the pages you are reading, the demo request form, and the small amount of technical data a web server records when a browser asks for a page. The second is the VisaRoxy platform: the software that connects to a customer's cameras, converts live video into named operational events, and sends those events to systems the customer already runs. Those two things are related, but they are not the same, and they are handled differently. The website sections describe data we control. The platform sections describe data a customer controls.
Where this policy refers to "we" and "us", it means [LEGAL ENTITY NAME]. Where it refers to "you", it means the person reading this page, whether you are visiting the site or working for an organisation that runs the platform.
What the website collects
The demo request form
This site has one form. It asks for your name, your work email address, your company, your role, the type of site you operate, and a description of the workflow you want to discuss. We ask for those fields because a useful first conversation needs them: who you are, how to reply to you, which organisation you represent, and what problem you want to solve. We do not ask for a phone number, a postal address or a payment detail, and we do not buy those details from anyone else.
Please do not put confidential information, personal data about other people, or anything commercially sensitive into the description field. If you would rather not use the form at all, email [CONTACT EMAIL] and we will pick the conversation up from there.
Server logs
The web server that hosts this site records standard request information: the page that was requested, the date and time, the address the request came from, the browser and operating system the request identified itself with, and the result the server returned. This is ordinary infrastructure logging, and it exists for security and reliability. It is how a hosting provider spots automated abuse, diagnoses a broken page, and sees which pages are being asked for.
Server logs are not used to build a profile of you, are not matched against advertising data, and are not sold. They are the record a server keeps in order to serve pages at all.
Why we use it, in plain terms
We use the form details to reply to you and to prepare for the walkthrough you asked for. We use server logs to keep the site available, secure and free of abuse. Where we ask you for something optional, we ask first, and you can change your mind at any time by emailing [CONTACT EMAIL]. In the language of data protection law, the form details are used because you asked us to take those steps, the logs are used because we have a legitimate interest in a working and secure website, and anything optional rests on your agreement.
Video and camera data in a customer deployment
This is the part of the policy that matters most to the teams who run VisaRoxy, because a vision platform sees people — staff, contractors, visitors and members of the public.
In a customer deployment, video is processed inside the environment the customer nominates. That may be an on-premises appliance inside the site network, a private cloud tenancy the customer controls, or a managed tenancy operated by VisaRoxy. The platform pulls streams from cameras the customer already owns over RTSP or ONVIF, and inference runs in the deployment that was chosen. Video does not have to leave the customer's network for the platform to work.
VisaRoxy stores event records and the short clip around each event, rather than continuous recordings of every stream. A clip exists because a named event happened at a known time in a known zone; it is the evidence attached to that event, not an archive of the day. The customer's existing video management system keeps recording exactly as it did before.
Retention windows are configured per site and per camera group, so a customer can keep events from a loading dock for a different period than events from a car park, and can shorten or extend those windows as its own policy requires.
Privacy zones exclude chosen areas from analysis. An excluded area is not masked after the fact and it is not blurred in a stored file — those pixels are not passed to the model in the first place, which is why an excluded area can never appear in an event or a clip the platform produces.
Events leave the platform through outbound webhooks and a REST API, which means they land in systems the customer nominates: alerting tools, ticketing queues, dashboards or a video management system. What those systems then do with an event is governed by the customer's own agreements with those providers.
For platform data, the customer is the controller and we act on the customer's instructions under the agreement that covers the deployment. If you work for a site that runs VisaRoxy and you want to know what it holds about you, that request belongs with your employer, and we will help them answer it. There is more detail on how video and data are handled on the Security & data page.
What we do not do
We do not sell, rent or trade personal data. We do not share it with advertising networks or data brokers. We do not use the video a customer's cameras produce for our own purposes.
This website runs no third-party analytics, no tracking scripts, no advertising pixels and no session recording. You can confirm that yourself: each page loads a font stylesheet, two interface libraries, one stylesheet and one script that belongs to us. That script handles the navigation menu, the accordion and the form's own checks. It sends nothing anywhere, and it holds no identifiers.
The single script in the page head adds a class to the page element to record that JavaScript is available, so that content which depends on it can be styled correctly. That value is not stored, not transmitted, and disappears when you close the tab.
Cookies and similar technologies
Visaroxy.com sets no cookies of its own for tracking, advertising or analytics. Nothing on this site reads a cookie to decide what to show you, and there is no consent banner because there is nothing on this site that would require one.
A hosting provider can set its own cookies, for example to keep a session alive or to protect the site from automated abuse. The specific names, purposes and lifetimes of any such cookies have not been supplied for this version of the document, and we have not guessed at them. Before this policy is published, [LEGAL ENTITY NAME] must either list the exact cookies the hosting provider sets or confirm in writing that none are set. Until that confirmation exists, ask us at [CONTACT EMAIL] and we will answer in writing.
Who we share data with
We share personal data only with categories of provider that are needed to run the website and answer your enquiry:
- The hosting provider that serves this website and keeps its server logs.
- The email and customer relationship provider we use to receive, store and answer demo requests.
- For the platform, the systems the customer itself nominates to receive events.
- Professional advisers, and public authorities where the law requires us to respond.
Those are categories, not names. We have not listed specific vendors here because none was supplied for this version of the document, and inventing names would be worse than leaving the gap visible. The current list of subprocessors is available on request from [CONTACT EMAIL], and it is shared with customers as part of a deployment. Where a provider processes data on our behalf, it does so under a written contract that limits it to our instructions.
International transfers
Some providers in those categories may store or process data in a country other than the one you are in. That is a normal consequence of using hosted email, hosting and cloud infrastructure, and it is a consideration rather than a detail: a transfer of personal data across a border needs a lawful basis and appropriate safeguards, and what those look like depends on where you are, where the provider operates, and where the data is actually held.
This version of the policy does not assert a particular transfer mechanism, because the facts have not been supplied. Before publishing, [LEGAL ENTITY NAME] must state the mechanism it relies on and the safeguards that apply to each category of recipient. If you need the current position for a specific provider, email [CONTACT EMAIL] and we will set it out for you.
How long we keep data
Retention depends on what the data is. Demo request records are kept while the enquiry is live and for as long as needed to answer it and keep a record of the conversation. Server logs are kept for a short operational window and then rotated out of the system. Platform data — event records, clips, and the history of configuration changes — is kept for the window agreed with the customer for each site and each camera group.
We are not stating a specific period for any of those categories here, because the periods are agreed per deployment rather than fixed by this policy, and a number printed on a marketing page would be a guess. When a window ends, the data is deleted or overwritten in the ordinary course of operation.
How we protect data
Encryption is used in transit for the website and for connections into a deployment. Access is role-based: people see the sites, cameras and events their role requires, and administrative actions are tied to named accounts rather than shared logins. Configuration changes and exports are written to an audit log, so a change to a rule, a zone or a retention window can be attributed to the person who made it.
Deployments are separated from one another, so one customer's cameras, events and clips are not visible from another customer's tenancy.
VisaRoxy does not hold or claim SOC 2, ISO 27001, HIPAA, GDPR or any other certification or compliance attestation. Compliance posture for a deployment is agreed with the customer's security team.
Your rights
Subject to the law that applies to you, you can ask for a copy of the personal data we hold about you, ask us to correct anything that is wrong, ask us to delete it, object to a particular use of it, and ask for it in a portable form. You can also withdraw an agreement you gave us earlier.
To make a request about data we control, email [CONTACT EMAIL] and describe what you want. We may ask you to confirm your identity before we act, so that we do not hand data to the wrong person, and we will tell you what we have done.
For data inside a customer deployment, the request goes to the customer who controls that deployment. They decide what their platform holds and why, so they are the right party to action a request about it. If you contact us about data inside a customer's deployment, we will pass the request to that customer and tell you we have done so. If you are not satisfied with how a request is handled, you can raise it with the authority that covers [GOVERNING JURISDICTION].
Children's data
This site and the platform are business tools. They are not directed at children and are not intended for anyone under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has submitted data through this site, email [CONTACT EMAIL] and we will delete it.
Changes to this policy
When something material changes, we publish a new version on this page. The effective date at the top of the document is the date that version takes effect; it is not the date the policy was first written. If a change affects how we handle data we already hold, the new version will say so, and we will not apply a new purpose to old data without a basis for doing so. If you need an earlier version, email [CONTACT EMAIL].
How to contact us
The controller of the website data described in this policy is [LEGAL ENTITY NAME], whose registered address is [REGISTERED ADDRESS]. Privacy questions, requests and complaints go to [CONTACT EMAIL]. We would rather answer a question early than have you guess at an answer, so write to us even if the point seems small.
This policy describes how data is handled. It is not legal advice to you, and it does not create rights beyond those the law already gives you.