Data Processing Addendum

How Kardo processes personal data on your behalf. Forms part of the Terms of Service.

1. Roles

For customer content — video, pictures, audio, access records, business documents, and the people in them — the customer is the controller and Kardo is the processor. For the customer’s own account and user records, Kardo acts as an independent controller as described in the Privacy Policy. [Counsel: terminology for non-GDPR jurisdictions (business / service provider) and any joint-controller analysis for Kardo AI Cloud features.]

2. Subject matter, duration, nature and purpose

3. Instructions

Kardo processes customer content only on the customer’s documented instructions: these terms, the settings the customer makes in the Service (privacy modes per camera, retention, the Kardo AI Cloud, cross-site search, semantic index and screenshot switches, roles and site limits, support grants), and any written instruction the customer sends to [contact]. Kardo will tell the customer if it believes an instruction breaks the law, unless the law forbids it.

4. Confidentiality and staff

Kardo staff reach a customer’s content only through a support session the customer’s owner or manager opened — read-only, for one, four or twenty-four hours, ended by the customer at any moment, limited to devices unless the customer also allows video or figures — and each session and what it opened is written into the customer’s own audit log. Staff on the platform console use a separate credential with two-step sign-in and see only what their role allows. Staff are bound by [confidentiality obligations in their contracts].

5. Security measures

Kardo maintains the measures below. They describe what exists; more detail is on the Security page.

6. Sub-processors

The customer authorises the sub-processors listed at /sub-processors, each bound by written terms that protect the data at least as well as this addendum. Two of them (the cloud AI provider and the embeddings provider) receive data only while the customer keeps the corresponding switch on. Kardo will update that page and email account owners at least [30] days before adding or replacing a sub-processor; the customer may object in writing within that period, and if the objection cannot be resolved may end the affected part of the Service without penalty. Kardo remains responsible for its sub-processors.

7. International transfers

Processing takes place in the United States (us-east-1). Where the customer’s data is subject to a law that restricts transfer outside its territory, [the transfer mechanism (e.g. EU standard contractual clauses, UK addendum) to be attached as an annex by counsel] applies.

8. Breach notification

Kardo will notify the customer without undue delay, and in any case within [72 hours], after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to customer content, with what is known at the time and updates as more is known, by email to the account’s owners.

9. Deletion and return at the end of the term

During the term the customer deletes content itself (alerts, clips, people, devices) and sets retention; the nightly schedule deletes what is past it. At the end of the term, or on written request, Kardo deletes the customer’s content and account data within [30 days], except what the law requires it to keep and what remains in backups until they expire ([backup lifetime]). Before deletion the customer may request an export; today that is CSV of alerts, insights and Intelligence figures, and clips with their manifests, through the Service, and anything else by request to support. Video on the customer’s own KardoHub and cameras is the customer’s to keep or wipe.

10. Assistance

Kardo will help the customer, as far as the Service allows, to answer requests from data subjects, to carry out impact assessments for camera deployments, and to consult authorities. The Cloud & Privacy page, the audit log and the Sub-processors page are the first sources for those.

11. Audit

On written request, no more than [once a year] unless a breach or an authority requires it, Kardo will provide the information reasonably needed to show compliance with this addendum: this page, the Security page, the audit log of the customer’s account, and answers to a reasonable questionnaire. [Counsel: whether on-site audits are offered, at whose cost, with what notice; note that Kardo holds no third-party certification or audit report today.]

12. Order of precedence

If this addendum conflicts with the Terms of Service on the processing of personal data, this addendum wins.

Annex — the customer’s configuration

The customer’s current instructions are the settings in the Service: each camera’s privacy mode, the retention periods, and the account and site switches on Cloud & Privacy, each change of which is recorded in the audit log with before and after.

Last updated 29 September 2026. KardoVision is a product of Kardo.