Privacy Policy

This Privacy Policy explains how Camlocus, UAB, V. Nagevičiaus g. 3, LT-08237 Vilnius, Lithuania (“Camlocus”, “we”, “us” or “our”), collects, uses, stores, shares and protects personal data.

This Privacy Policy applies to:

  • The Camlocus website;
  • Camlocus accounts and online platform;
  • Camlocus Cloud Services;
  • Applications, portals, APIs and integrations;
  • Customer support and business communications;
  • Sales, billing and subscription management;
  • Other services that link to this Privacy Policy.

This Privacy Policy should be read together with the applicable:

  • Terms of Use;
  • Software License Agreement;
  • Business Terms and Conditions;
  • Data Processing Agreement;
  • Order, quotation, invoice or separately signed agreement.

1. Who Is Responsible for Your Personal Data?

The entity responsible for personal data processed under this Privacy Policy is:

Camlocus, UAB
V. Nagevičiaus g. 3
LT-08237 Vilnius
Lithuania

General and support enquiries: support@camlocus.com
Privacy and legal enquiries: legal@camlocus.com

The role performed by Camlocus depends on the type of personal data and the circumstances in which it is processed.

When Camlocus Acts as a Data Controller

Camlocus normally acts as an independent data controller when processing personal data concerning:

  • Website visitors;
  • Camlocus customers and prospective customers;
  • Account administrators and business contacts;
  • Billing and payment administration;
  • Customer support communications;
  • Website security and technical logs;
  • Sales, marketing and business communications;
  • Camlocus employees, contractors and suppliers.

In these situations, Camlocus determines why and how the relevant personal data is processed.

When Camlocus Acts as a Data Processor

When a customer uses Camlocus Cloud Services to transmit, store, organize or access camera footage, images, alerts, detection metadata and related customer data, the customer or white-label service provider will normally determine the purposes and means of that surveillance.

In those circumstances:

  • The customer or white-label provider normally acts as the data controller;
  • Camlocus normally acts as the data processor;
  • Camlocus processes the data according to the customer’s instructions and the applicable agreement;
  • The customer remains responsible for the legality of its surveillance activities.

The parties may enter into a separate Data Processing Agreement where required by applicable law.

Self-Hosted Installations

For Self-Hosted installations, personal data is normally stored and processed on infrastructure controlled by the customer.

Camlocus does not normally access personal data stored in a Self-Hosted installation unless:

  • The customer requests technical support;
  • Camlocus provides managed hosting or server administration;
  • The customer intentionally provides logs, recordings or access for troubleshooting;
  • Access is otherwise required under a separately agreed service.

The Self-Hosted customer remains responsible for its own hosting environment, user access, backups, security, data retention and legal compliance.

2. Personal Data We Collect

The personal data we collect depends on how you interact with Camlocus and which Services you use.

Account and Contact Information

We may collect:

  • First and last name;
  • Business email address;
  • Telephone number;
  • Company or organization name;
  • Job title or professional role;
  • Country and business address;
  • Account username and identifiers;
  • Language and communication preferences;
  • Information supplied when registering or updating an account.

Account Administration Information

Where you administer a Camlocus account, we may process:

  • Organizations and End Customers created within the account;
  • User roles and permissions;
  • User invitations;
  • Account activity;
  • Camera, location and site assignments;
  • Subscription and service settings;
  • Branding and domain settings;
  • Administrative actions and audit records.

Billing and Transaction Information

We may process:

  • Customer and company billing details;
  • Billing address;
  • VAT or tax information;
  • Subscription plan;
  • Invoice and payment status;
  • Transaction amount and currency;
  • Purchase history;
  • Payment references;
  • Information required to prevent fraud or resolve payment disputes.

Payment card information is normally processed directly by an authorized third-party payment provider. Camlocus does not need to store complete payment card details where payment is handled by that provider.

Customer Content and Video-Surveillance Data

Depending on the selected deployment and customer configuration, Camlocus may process:

  • Live video streams;
  • Recorded video clips;
  • Alert videos;
  • Images and snapshots;
  • Audio, where lawfully enabled by the customer;
  • Camera names and identifiers;
  • Camera location or site information;
  • Date and time information;
  • Motion events;
  • Object-detection results;
  • Person, vehicle or other object classifications;
  • Number-plate data;
  • Detection confidence or event labels;
  • Zones, line-crossing events and other analytical metadata;
  • Storage and retention settings;
  • Data produced by connected cameras, local video software or third-party AI systems.

Camlocus may receive completed streams, alert clips and recognition metadata generated by a customer’s cameras, local video-management software, edge device or third-party analytical system.

The exact Customer Content processed depends on the customer’s configuration and connected systems.

Technical and Device Information

We may automatically collect:

  • IP address;
  • Browser type and version;
  • Operating system;
  • Device type;
  • Device and session identifiers;
  • Login date and time;
  • Access logs;
  • Authentication activity;
  • Requested pages and functions;
  • Referring website;
  • Error and diagnostic information;
  • API requests;
  • Stream and connection status;
  • General geographic area derived from an IP address;
  • Security events and suspected unauthorized activity.

Support and Communications Data

When you contact Camlocus, we may process:

  • Email messages;
  • Support tickets;
  • Chat or contact-form messages;
  • Screenshots and screen recordings;
  • Error logs;
  • Configuration details;
  • Recordings or examples intentionally supplied for troubleshooting;
  • Feedback and feature requests;
  • Records of discussions and resolutions.

Please avoid sending personal data or video footage that is not necessary for investigating the relevant support request.

Website, Cookie and Analytics Data

Subject to your cookie choices and applicable law, we may collect:

  • Website visits;
  • Pages viewed;
  • Clicks and navigation activity;
  • Referring and exit pages;
  • Cookie identifiers;
  • General campaign or referral information;
  • Website performance and error data;
  • Consent and cookie-preference records.

Sales and Marketing Information

We may process:

  • Business contact details;
  • Product enquiries;
  • Demo requests;
  • Partner applications;
  • Sales correspondence;
  • Communication preferences;
  • Information about Services in which a person or business has expressed interest.

3. How We Receive Personal Data

We may receive personal data:

  • Directly from you;
  • From your employer or organization;
  • From a Camlocus customer or white-label service provider that creates your account;
  • From an account administrator;
  • From connected cameras, devices and local video systems;
  • From APIs, integrations and third-party software configured by the customer;
  • Automatically when you use the website or Services;
  • From payment, hosting, email, support and security service providers;
  • From a person or business that refers you to Camlocus;
  • From public business sources where lawful and appropriate.

If you provide personal data concerning another person, you must have the right to provide that information and must ensure that the person receives any legally required privacy information.

4. Why We Process Personal Data

We process personal data only where there is a valid purpose and legal basis.

Providing the Services

We process account, contact, technical and Customer Content data to:

  • Create and administer accounts;
  • Provide access to the Camlocus platform;
  • Transmit and display video streams;
  • Store and organize alert videos and recordings;
  • Display event and detection metadata;
  • Manage cameras, users, customers and locations;
  • Provide white-label and multi-customer functionality;
  • Operate APIs and integrations;
  • Deliver purchased hosting, support and other Services.

The legal basis is normally performance of a contract or taking steps at your request before entering into a contract.

Where Camlocus acts as a processor, Customer Content is processed according to the customer’s documented instructions.

Billing and Commercial Administration

We process personal data to:

  • Process orders and payments;
  • Issue invoices;
  • Administer subscriptions;
  • Maintain transaction records;
  • Resolve billing disputes;
  • Manage renewals and cancellations;
  • Comply with tax and accounting obligations.

The legal bases are performance of a contract, compliance with legal obligations and our legitimate interest in administering our business.

Customer Support and Technical Maintenance

We process personal data to:

  • Respond to enquiries;
  • Diagnose technical problems;
  • Investigate failed streams, alerts or uploads;
  • Perform maintenance;
  • Restore Services;
  • Communicate about incidents;
  • Improve documentation and support processes.

The legal bases are performance of a contract and our legitimate interest in maintaining and improving the Services.

Security, Fraud Prevention and Abuse Detection

We process technical, account and usage data to:

  • Authenticate users;
  • Detect unauthorized access;
  • Prevent fraud and abuse;
  • Investigate security incidents;
  • Protect customer accounts;
  • Maintain logs and audit records;
  • Enforce applicable agreements;
  • Protect Camlocus infrastructure and intellectual property.

The legal bases are our legitimate interests in protecting the Services, customers and business, and compliance with legal obligations where applicable.

Service Improvement

We may use aggregated, statistical or appropriately minimized data to:

  • Understand how the Services are used;
  • Identify recurring errors;
  • Improve performance;
  • Develop product functionality;
  • Improve user experience;
  • Plan infrastructure capacity.

Where reasonably possible, data used for statistical or development purposes will be aggregated or de-identified.

The legal basis is our legitimate interest in improving and developing the Services.

Camlocus does not use customer video footage to train public or third-party AI models unless the relevant customer has expressly agreed to such use in writing.

Service Communications

We may send communications concerning:

  • Account activity;
  • Security events;
  • Service availability;
  • Subscription or payment issues;
  • Important product changes;
  • Updated legal terms;
  • Support requests;
  • Required administrative information.

These messages are necessary for providing the Services and are not treated as optional marketing communications.

The legal bases are performance of a contract, compliance with legal obligations and our legitimate interests in administering the Services.

Marketing Communications

Where permitted by law, we may send information about Camlocus products, updates, services or events.

The legal basis may be:

  • Your consent;
  • Our legitimate interest in communicating with existing business customers;
  • Another basis permitted under applicable electronic-marketing law.

You may unsubscribe at any time using the unsubscribe function in the message or by contacting us.

Withdrawing from marketing does not prevent us from sending necessary account, billing, security or service communications.

Legal Compliance and Claims

We may process personal data to:

  • Comply with applicable laws;
  • Respond to valid requests from public authorities;
  • Establish, exercise or defend legal claims;
  • Investigate suspected contractual violations;
  • Protect our legal rights;
  • Meet regulatory, tax, accounting or reporting obligations.

The legal bases are compliance with legal obligations and our legitimate interests in protecting our rights.

Consent-Based Processing

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal does not affect the lawfulness of processing performed before consent was withdrawn.

5. Customer Responsibilities for Video Surveillance

Customers decide:

  • Where cameras are installed;
  • What areas are recorded;
  • Whether audio is enabled;
  • Which local motion or AI functions are used;
  • Which recordings and metadata are transmitted to Camlocus;
  • How long Customer Content is retained;
  • Who is permitted to access the data;
  • How the data is used;
  • Whether information is shared with third parties.

The customer is responsible for:

  • Establishing a lawful basis for surveillance;
  • Providing required signs and privacy notices;
  • Informing employees, visitors, customers and other affected persons;
  • Restricting monitoring in private or sensitive areas;
  • Obtaining necessary permissions;
  • Responding to data-subject requests;
  • Configuring appropriate retention periods;
  • Limiting access to authorized users;
  • Complying with applicable surveillance, privacy, employment and data-protection laws.

Camlocus does not determine whether a specific camera location or surveillance purpose is lawful.

6. White-Label Providers and End Customers

A Camlocus customer may use the platform under its own brand and provide Services to its own End Customers.

Where an account is provided through a white-label provider, reseller or system integrator:

  • That provider will normally be the primary data controller;
  • The provider may create and administer accounts;
  • The provider may manage cameras, users, permissions and retention;
  • The provider may access Customer Content;
  • The provider is responsible for its own privacy notice and customer agreements;
  • Camlocus may act as a processor or sub-processor supporting that provider.

An End Customer should normally direct privacy requests concerning camera footage, account access, surveillance purposes or retention settings to the white-label provider that operates the account.

Camlocus will assist its customer in responding to such requests where required by the applicable Data Processing Agreement and data-protection law.

7. AI and Automated Detection Data

Camlocus may receive or display analytical results generated by:

  • Connected cameras;
  • Local video-management software;
  • Edge devices;
  • Customer-controlled AI systems;
  • Third-party integrations.

These results may include classifications such as person, car, truck, number plate or other event information.

Automated detection results may be inaccurate, incomplete, delayed or associated with the wrong event.

Camlocus does not use account or billing personal data to make decisions that produce legal or similarly significant effects concerning individuals solely through automated processing.

Customers must independently determine whether their use of facial recognition, biometric identification, number-plate recognition or other advanced analytics is lawful.

Where special-category or biometric personal data is processed, the customer must establish any additional legal basis and safeguards required by applicable law.

8. Cookies and Similar Technologies

Camlocus uses cookies and similar technologies to operate and improve its website and online Services.

Cookies may be categorized as:

Strictly Necessary Cookies

These cookies are required for:

  • Website and account functionality;
  • Authentication;
  • Security;
  • Session management;
  • Remembering privacy choices;
  • Delivering a service requested by the user.

These cookies cannot normally be disabled through the Camlocus cookie settings because the website or requested function may not operate correctly without them.

Preference Cookies

These cookies may remember:

  • Language;
  • Display settings;
  • Interface preferences;
  • Other optional user selections.

Analytics and Statistics Cookies

Subject to consent where required, these cookies help us understand:

  • How visitors use the website;
  • Which pages are viewed;
  • Whether errors occur;
  • How website performance can be improved.

Marketing Cookies

Subject to consent where required, these cookies may be used to:

  • Measure advertising performance;
  • Understand campaign referrals;
  • Limit repeated advertisements;
  • Support relevant marketing communications.

You can manage non-essential cookie choices through the cookie settings displayed on the website.

You may also control cookies through your browser. Disabling certain cookies may affect website functionality.

Your cookie choices can be changed or withdrawn at any time through the available cookie-preference controls.

9. When We Share Personal Data

We do not sell or rent personal data.

We may share personal data with the following categories of recipients where necessary:

Hosting and Infrastructure Providers

Providers that supply:

  • Cloud hosting;
  • Server infrastructure;
  • Video storage;
  • Database services;
  • Content delivery;
  • Backup and disaster recovery;
  • Network and security services.

Payment and Billing Providers

Providers that process payments, manage billing or help prevent payment fraud.

Payment providers process payment information under their own privacy terms and legal obligations.

Communication and Support Providers

Providers used for:

  • Email delivery;
  • Support ticketing;
  • Transactional notifications;
  • Customer communications;
  • Error monitoring.

Analytics and Website Providers

Providers used for website operation, consent management, analytics and performance measurement, subject to your cookie choices and applicable law.

Professional Advisers

Lawyers, accountants, auditors, insurers and other professional advisers where access is necessary for legitimate business or legal purposes.

Corporate Transactions

Potential buyers, investors, advisers or successor entities in connection with a merger, financing, reorganization, acquisition or sale of all or part of the business.

Appropriate confidentiality and data-protection safeguards will be applied.

Public Authorities

Courts, regulators, law-enforcement agencies and other public authorities where disclosure is:

  • Required by applicable law;
  • Necessary to comply with a valid legal process;
  • Required to protect legal rights;
  • Necessary to respond to an urgent and legitimate safety or security issue.

Camlocus reviews requests for data and will disclose only information that it reasonably believes it is legally required or permitted to disclose.

10. Service Providers and Sub-Processors

Camlocus may engage service providers and sub-processors to help deliver the Services.

They may process personal data only for specified purposes and under applicable contractual, confidentiality and data-protection obligations.

Where Camlocus acts as a processor, the use of sub-processors is governed by the applicable Data Processing Agreement.

Information about material sub-processors may be requested by contacting legal@camlocus.com.

Camlocus remains responsible for selecting service providers appropriate to the nature of the Services, subject to the allocation of responsibilities in the applicable agreements.

11. International Data Transfers

Depending on the selected hosting region, customer location and service providers used, personal data may be processed outside Lithuania or the European Economic Area.

Where personal data is transferred outside the European Economic Area, Camlocus will use an appropriate lawful transfer mechanism where required, such as:

  • A European Commission adequacy decision;
  • Standard Contractual Clauses;
  • Binding contractual and organizational safeguards;
  • Another transfer mechanism permitted by applicable law.

Where appropriate, Camlocus may also apply supplementary technical and organizational measures based on the nature of the data and transfer risk.

Customers using Self-Hosted Software are responsible for determining where their own infrastructure and backups are located.

12. How Long We Retain Personal Data

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.

Retention periods depend on:

  • The type of data;
  • The selected plan;
  • Customer configuration;
  • Contractual requirements;
  • Security needs;
  • Applicable legal obligations;
  • Limitation periods for legal claims;
  • Whether an account or Service remains active.

Customer Content

Video footage, alert clips, images and metadata stored through Camlocus Cloud Services are retained according to:

  • The selected subscription plan;
  • Storage availability;
  • The customer’s retention settings;
  • The applicable Order;
  • Customer deletion instructions;
  • Applicable legal requirements.

Customer Content may be deleted automatically when the applicable retention period expires.

Customers are responsible for exporting recordings that must be retained longer than the purchased retention period.

Account Information

Account and contact information may be retained while the account remains active and for a reasonable period after closure where needed for:

  • Contract administration;
  • Security;
  • Fraud prevention;
  • Legal claims;
  • Compliance obligations.

Billing Information

Invoices, transaction records and related billing information are retained for the period required by applicable tax, accounting and commercial law.

Technical and Security Logs

Technical, authentication and security logs are retained for a limited period appropriate to:

  • Detecting security incidents;
  • Troubleshooting;
  • Preventing fraud;
  • Maintaining service integrity;
  • Meeting legal obligations.

Support Communications

Support records may be retained for as long as reasonably necessary to:

  • Resolve the request;
  • Document the resolution;
  • Identify recurring issues;
  • Protect legal rights;
  • Meet contractual obligations.

Marketing Information

Marketing contact information is retained until:

  • You unsubscribe;
  • You withdraw consent;
  • The information is no longer accurate or relevant;
  • Continued retention is no longer legally justified.

A limited suppression record may be retained to ensure that an unsubscribe request continues to be respected.

Backups

Deleted data may remain temporarily in encrypted or access-restricted backups until the relevant backup is overwritten according to the normal backup cycle.

Backup data is not restored for ordinary use unless required for disaster recovery, security or legal purposes.

13. Data Security

Camlocus applies technical and organizational measures designed to protect personal data against:

  • Unauthorized access;
  • Accidental or unlawful destruction;
  • Loss;
  • Alteration;
  • Unauthorized disclosure;
  • Misuse.

Depending on the Service and risk, these measures may include:

  • Role-based access controls;
  • Authentication controls;
  • Access logging;
  • Network and infrastructure security;
  • Data encryption in transit and, where appropriate, at rest;
  • Backup and recovery procedures;
  • Restricted staff and contractor access;
  • Security monitoring;
  • Software maintenance;
  • Incident-response procedures;
  • Confidentiality obligations.

No internet, cloud or software service can guarantee absolute security.

Customers are also responsible for:

  • Protecting their credentials;
  • Configuring user permissions correctly;
  • Securing cameras and local systems;
  • Maintaining operating-system and third-party updates;
  • Protecting Self-Hosted infrastructure;
  • Maintaining appropriate backups;
  • Promptly notifying Camlocus about suspected unauthorized access.

14. Personal Data Breaches

Camlocus maintains procedures for responding to suspected personal-data breaches.

Where Camlocus acts as a data controller, we will notify the relevant supervisory authority and affected individuals where required by applicable law.

Where Camlocus acts as a data processor, we will notify the relevant customer without undue delay after becoming aware of a personal-data breach affecting data processed on that customer’s behalf, in accordance with the applicable agreement and law.

Customers must promptly provide any information and cooperation reasonably required to investigate and respond to an incident.

15. Your Data-Protection Rights

Depending on applicable law and the circumstances, you may have the right to:

  • Obtain confirmation whether your personal data is being processed;
  • Access your personal data;
  • Correct inaccurate or incomplete personal data;
  • Request deletion of personal data;
  • Request restriction of processing;
  • Object to processing based on legitimate interests;
  • Object to direct marketing;
  • Receive certain personal data in a structured, commonly used and machine-readable format;
  • Request transfer of eligible data to another controller where technically feasible;
  • Withdraw consent at any time where processing is based on consent;
  • Obtain information about applicable international-transfer safeguards;
  • Lodge a complaint with a competent data-protection supervisory authority.

These rights are not absolute. A request may be refused or limited where permitted by law, including where data must be retained for legal obligations, security, fraud prevention or legal claims.

How to Exercise Your Rights

You may submit a request to:

legal@camlocus.com

Please clearly explain:

  • Who you are;
  • Which account or organization is involved;
  • What right you wish to exercise;
  • Which personal data or processing activity your request concerns.

We may request additional information where reasonably necessary to verify your identity and protect personal data from unauthorized disclosure.

We normally respond within one month, subject to any extension permitted by applicable law for complex or multiple requests.

Requests Concerning White-Label Accounts

If your account was provided by a white-label provider, reseller, employer or another Camlocus customer, that organization may be the relevant data controller.

Requests concerning camera footage, surveillance purposes, data retention or user access should normally be submitted directly to that organization.

Camlocus will assist the relevant customer where required.

Complaints

You have the right to lodge a complaint with the data-protection supervisory authority in the country where you live, work or believe a violation occurred.

In Lithuania, the relevant supervisory authority is the State Data Protection Inspectorate (VDAI).

We encourage you to contact Camlocus first so that we have an opportunity to investigate and address your concern.

16. Children’s Personal Data

Camlocus Services are intended primarily for businesses and professional users.

Camlocus does not knowingly allow children to create independent commercial Camlocus accounts.

Camera footage may incidentally include children where cameras are operated by a customer. The customer operating those cameras is responsible for ensuring that such surveillance is lawful and appropriately protected.

If you believe that Camlocus is processing a child’s personal data unlawfully, contact legal@camlocus.com.

17. Third-Party Websites and Services

The Camlocus website and Services may contain links to or integrations with third-party websites, software and services.

Third parties process personal data according to their own privacy policies and terms.

Camlocus does not control and is not responsible for the privacy practices of independent third parties.

You should review the privacy information of any third-party service before providing personal data or enabling an integration.

18. Changes to This Privacy Policy

Camlocus may update this Privacy Policy to reflect changes in:

  • Applicable law;
  • Camlocus Services;
  • Processing activities;
  • Technology;
  • Security practices;
  • Business operations.

The updated Privacy Policy will be published with a revised effective date.

Where a change materially affects how personal data is processed, Camlocus will provide additional notice where reasonably necessary or legally required.

Previous versions may be retained where appropriate for accountability and contract administration.

19. Contact Us

Questions, requests or concerns about this Privacy Policy or the processing of personal data may be sent to:

Camlocus, UAB
V. Nagevičiaus g. 3
LT-08237 Vilnius
Lithuania

General and support enquiries: support@camlocus.com
Privacy and legal enquiries: support@camlocus.com

When contacting us about an account provided by a white-label provider, please include the provider’s name and the email address associated with the account.