Privacy Policy
How VIASERVA handles personal data while keeping the focus on products, not people.
Effective date: [PUBLICATION DATE]
Last updated: [PUBLICATION DATE]
01Who we are
Who we are
VIASERVA provides privacy-first retail loss-prevention technology that uses machine learning together with movement, timing, and physics-based analysis to follow product journeys across selected CCTV feeds.
The service is operated by:
[VIASERVA LEGAL ENTITY NAME]
[REGISTERED OFFICE]
Company number: [COMPANY NUMBER]
Ireland
For the purposes of the General Data Protection Regulation (EU) 2016/679 (GDPR), the Irish Data Protection Act 2018, and other applicable data-protection law, the roles described below apply according to the relevant processing activity. For privacy questions about personal data controlled directly by VIASERVA, contact privacy@viaserva.com.
02Scope and roles
What this policy covers
This policy covers the VIASERVA website, business enquiries, customer administration, and the VIASERVA retail monitoring service.
- VIASERVA as controller. VIASERVA is the data controller for personal data it collects for its own business purposes, including website enquiries, customer contacts, billing and administration, support correspondence, website security logs, and similar business records.
- The retailer as controller. The retailer operating the CCTV system is generally the data controller for CCTV footage and review clips generated from its premises. The retailer determines why its CCTV is used, its lawful basis, its notices and signage, who can access retained clips, and what actions are taken after review.
- VIASERVA as processor. When VIASERVA processes customer CCTV on the retailer's behalf, VIASERVA acts as data processor and processes that data only on the retailer's documented lawful instructions and under the applicable Data Processing Agreement.
For requests relating to CCTV or review clips from a particular store, individuals should normally contact the retailer operating that CCTV system first. VIASERVA will assist the retailer where required by applicable data-protection law and the Data Processing Agreement.
03Privacy by design
Track the product, not the person
VIASERVA is designed around the principle that privacy is a fundamental right. Our business model is not based on identifying, profiling, or exploiting people.
- We analyse product movement rather than persistent human identity.
- We do not build person profiles or repeat-visitor records.
- We do not use customer CCTV footage as a cloud video archive.
- We do not make automated decisions that a person has committed theft or wrongdoing.
- We seek to retain only the minimum information needed to operate, secure, and improve the Service.
04Data we collect directly
Website and business information
Demo and beta-interest enquiries
When you submit an enquiry, we may collect your work email address, company name, approximate camera count, and any information you choose to include in the enquiry. Submitting an enquiry does not subscribe you to a newsletter or marketing list.
If the conversation progresses, we may also collect business contact names, telephone numbers, store locations, deployment details, CCTV setup information, commercial notes, and other information reasonably needed to assess, quote, onboard, and support the deployment. We will collect that information transparently as the relationship develops.
Customer administration
For active customers we may process authorised management contact details, billing information, deployment locations, enabled camera information, node identifiers and configuration, support history, contract and order-form information, and records needed to administer the commercial relationship.
Website and security logs
Our hosting and security systems may process ordinary technical information such as IP address, browser or user-agent information, request time, requested page, and similar server-log data needed to operate and secure the website.
05Service data
Customer CCTV and VIASERVA processing
VIASERVA works alongside a retailer's existing CCTV system. Selected camera feeds are copied or forwarded from the retailer's existing CCTV environment into an on-site VIASERVA node. VIASERVA does not operate or replace the retailer's cameras.
The Service may process:
- Selected CCTV feed data needed to analyse product movement.
- Temporary product-tracking state used to maintain a product journey while that journey remains active. The temporary product token belongs to the product journey, not to a person, and is destroyed when the journey is resolved or no longer needs to remain active.
- Potential loss-event information needed to create a short review clip for authorised store management.
- Node health telemetry such as software version, connectivity, uptime, resource use, update state, and technical errors.
- Limited technical diagnostics where an issue requires investigation or remediation.
The Service does not require point-of-sale, payment-card, or loyalty-card data to determine whether a product journey has reached the retailer-selected checkout zone. VIASERVA does not determine whether payment actually occurred.
06People in camera frames
What VIASERVA does not do
People may naturally appear in retail CCTV frames. They are not VIASERVA's intended analytical subject. The platform is designed so that customers cannot repurpose it into a person-surveillance system.
- No facial recognition or biometric identification.
- No facial embeddings or other biometric identifiers.
- No persistent person IDs or cross-camera person tracking.
- No demographic profiling such as age, gender, race, or ethnicity classification.
- No person watchlists, repeat-visitor records, human risk scores, or suspicious-person profiles.
- No customer-configurable person-surveillance rules.
Product continuity can use product characteristics and context such as shelf origin, movement, timing, path, approximate colour, size, location, and other weak product signals. Those signals belong to the product journey, not to a persistent identity assigned to a person.
07Processing flow
How video moves through the Service
- Selected CCTV feed data is received by the on-site VIASERVA node.
- The required video data is protected during transmission to VIASERVA's EU-based cloud processing infrastructure.
- The cloud environment processes the video transiently to follow product journeys and identify potential loss events.
- Where a potential loss event is surfaced, the relevant short review clip is protected in transit and returned to the local VIASERVA node for authorised management review.
- VIASERVA does not retain the source CCTV footage or review clip in its cloud environment after the relevant processing and delivery are complete.
The VIASERVA cloud is not a customer CCTV archive. A customer may separately retain footage within its own existing CCTV system, which is outside VIASERVA's control and subject to the retailer's own retention rules.
Keep or Discard
After management reviews a VIASERVA review clip, the retailer can choose to Keep or Discard it. A kept clip remains on the local VIASERVA node under the retailer's control. A discarded VIASERVA review clip is permanently removed from the node and VIASERVA does not keep a recoverable cloud copy. This does not delete footage that the retailer's separate CCTV system may independently retain.
08Performance data
Service improvement and training
VIASERVA does not use customer CCTV footage or retained review clips to train general-purpose models.
We may retain limited abstract performance information needed to evaluate and improve VIASERVA's own product-tracking systems. Examples can include broad product category, event type, confidence values, success or false-flag outcome, software or model version, and similar technical measurements.
Before information is retained for longer-term improvement or training, store-identifying and human-identifying information is removed. VIASERVA does not retain source footage with that dataset and does not design the dataset to reconstruct a person or a store's CCTV history. We only describe information as anonymised where it has been processed so that individuals are no longer identifiable using reasonably available means.
09Lawful basis and customer duties
Who is responsible for what
For personal data that VIASERVA controls directly, we process information where needed to respond to enquiries, take steps toward or perform a contract, administer and secure the Service, protect our legitimate business interests, and comply with legal obligations.
For customer CCTV, the retailer remains responsible as controller for determining and documenting its lawful basis and for its own controller obligations. This includes, where applicable, privacy notices, CCTV signage, staff procedures, access controls, retention decisions, and any required Data Protection Impact Assessment.
VIASERVA does not choose or validate the retailer's lawful basis on the retailer's behalf. VIASERVA processes customer CCTV only on documented instructions and under the applicable Data Processing Agreement, while remaining responsible for the processor obligations that apply directly to VIASERVA.
10Cookies and tracking
No behavioural analytics
The VIASERVA website is designed to operate without advertising analytics, behavioural profiling, social-media tracking, fingerprinting, or similar marketing surveillance. We do not use Google Analytics, Meta Pixel, Microsoft Clarity, Hotjar, or equivalent behavioural analytics tools on the website.
We may use strictly necessary security or anti-abuse technology to protect forms and the website. If that technology changes how personal data is handled, we will update this policy and any required notices before or when the change is introduced.
11Sharing and sub-processors
Who receives personal data
VIASERVA does not sell personal data and does not share it with advertisers or data brokers.
We may share personal data only where reasonably necessary with:
- Service providers and sub-processors that help us provide hosting, networking, email, security, support, billing, and other operational services.
- Professional advisers such as legal, accounting, insurance, or audit providers where reasonably necessary.
- Regulators, courts, law enforcement, or other authorities where disclosure is required or permitted by law.
- A successor organisation in connection with a merger, acquisition, restructuring, or sale of the business, subject to appropriate protections.
Where a provider processes customer CCTV on VIASERVA's behalf, VIASERVA will put the required processor arrangements in place. Current sub-processor information is available from VIASERVA on request.
12EU processing
Where processing happens
Core customer CCTV processing is designed to use cloud infrastructure located within the European Union. VIASERVA does not intentionally route customer CCTV footage or VIASERVA review clips outside the EU for core video processing.
Other business services used by VIASERVA may involve providers operating in other countries. Where personal data is transferred outside the European Economic Area and the data remains subject to GDPR, VIASERVA will use an available lawful transfer mechanism and appropriate safeguards.
13Retention and deletion
How long information is kept
VIASERVA keeps personal data only for as long as needed for the purpose for which it was collected, including legitimate operational, contractual, security, tax, accounting, dispute, and legal requirements.
| Category | Typical retention approach |
|---|---|
| Unsuccessful demo or sales enquiries | Up to 6 months after the last meaningful contact, unless another lawful reason requires longer retention. |
| Routine website and security logs | Up to 30 days, unless relevant records are required longer for a specific security incident. |
| Customer administration and operational records | For the customer relationship and then only as long as needed for offboarding, legal, contractual, security, accounting, tax, or dispute purposes. |
| Accounting and tax-supporting records | Kept for the period required by applicable Irish law, which may require relevant business records to be retained for up to 6 years. |
| Customer CCTV and cloud review clips | Processed transiently. VIASERVA does not retain a cloud video archive after processing and delivery are complete. |
| Kept review clips on the local node | Controlled by the retailer. On normal offboarding the retailer is given reasonable notice to export clips it wishes to preserve before the node is decommissioned. |
| Discarded VIASERVA review clips | Permanently deleted from the VIASERVA node. VIASERVA does not keep a recoverable cloud copy. |
| Live node-health telemetry | Generally transient and used for current operational monitoring. |
| Issue-specific technical logs | Up to 3 months where needed to investigate, remediate, and verify a technical issue. These logs do not contain customer CCTV footage or retained review clips. |
| Anonymised performance and training data | May be retained for service improvement and model training after identifying customer and human information has been removed so the retained dataset is no longer personal data. |
During customer offboarding, operational customer data that VIASERVA no longer needs is deleted or stripped promptly. Information that must be retained for legal, accounting, tax, security, or dispute reasons is kept only for the applicable period.
14Your rights
Data-protection rights
Where EU data-protection law applies, individuals may have rights including access, rectification, erasure, restriction, data portability, objection, and the right to withdraw consent where consent is the lawful basis.
Ask whether VIASERVA controls personal data about you and request a copy where applicable.
Ask us to correct inaccurate or incomplete personal data that VIASERVA controls.
Ask for deletion where the legal conditions for erasure are met.
Ask for processing to be restricted in circumstances provided by law.
Request eligible data in a portable format where the legal conditions apply.
Object to eligible processing based on legitimate interests.
Store CCTV and review clips. If your request concerns CCTV or a review clip from a particular retailer, contact that retailer first. The retailer is generally the controller and is best placed to identify the relevant footage. VIASERVA will assist the retailer where required.
Data controlled by VIASERVA. For website, enquiry, account, billing, or support information controlled directly by VIASERVA, contact privacy@viaserva.com.
You also have the right to lodge a complaint with the Data Protection Commission in Ireland or another competent supervisory authority where applicable.
15Security
How we protect the Service
VIASERVA applies technical and organisational safeguards designed to protect personal data and the operation of the Service. These safeguards include secure transmission, controlled access, system monitoring, maintenance processes, and measures intended to prevent unauthorised access, loss, misuse, or disclosure.
VIASERVA may remotely access an on-site node for pre-agreed or reasonably necessary software updates, maintenance, diagnostics, security, and support. Remote technical administration is limited to those purposes and is not used by VIASERVA personnel to view, retrieve, or use customer CCTV footage or retained review clips.
Deployed nodes maintain operational telemetry so VIASERVA can identify faults, check software and update state, and resolve many issues remotely. Where planned work is expected to cause material downtime, VIASERVA aims to coordinate an appropriate maintenance window with authorised management. Urgent work may be carried out sooner where reasonably necessary to protect security or stability, with notice where practicable.
If you believe you have found a security issue, contact security@viaserva.com.
16Human review
VIASERVA does not decide that theft occurred
VIASERVA does not make automated decisions that an individual has committed theft or wrongdoing. The Service surfaces potential loss events for review by authorised store management.
Customers cannot configure VIASERVA to replace that human review with automated accusations, enforcement decisions, person scoring, person tracking, or person-surveillance rules. The retailer decides what action, if any, is appropriate after reviewing the information.
17Changes to this policy
Keeping this policy current
We may update this Privacy Policy as VIASERVA develops or as legal and operational requirements change. We will update the "Last updated" date above. Where a change materially affects an active customer's processing or rights, we will communicate it to authorised management where appropriate.
18Contact
Privacy contact
Privacy requests and questions about this policy can be sent to privacy@viaserva.com or by post to [REGISTERED OFFICE], Ireland.