Privacy Policy
What KardoVision collects, why, where it is kept, for how long, and who else touches it.
Draft — not yet reviewed by counsel. This text describes KardoVision as it works today. Anything in [brackets] is a placeholder to be settled before this page is final.
1. Two kinds of personal data
KardoVision handles personal data in two roles. Account data — the people who sign in, their devices and how they use the Service — is data Kardo is responsible for as a controller. Customer content — video, pictures, audio, access records, sales and the people in them — is your business’s data: you decide what is captured and why, and Kardo processes it only on your instructions, under the Data Processing Addendum. If you were recorded by a customer’s cameras, your questions go to that business; we will help it answer.
2. What is collected
Account and people
- Company name, business type, time zone; your name, email address, role, the sites, cameras, doors and screens you may reach, and when that access ends.
- Your password, stored only as a salted hash; two-factor secrets, sealed; recovery codes, hashed like a password.
- Sign-in times, the address a request came from (kept with audit entries), and the language you chose.
- Notification choices, and a push token for each phone the app is signed in on (used only to send you notifications).
- Support access grants: who granted them, for how long, what support may see, and every session opened under one.
Devices
- For every KardoHub, camera, terminal, reader, screen, phone and speaker: kind, name, serial, hardware address, model, software version, certificate, health and the reasons for it, the settings the account wants and what the device reports it has, its last report, and its local network address as the device reports it.
- For Kardo-made devices: the factory record (serial, model, batch) and a hash of the secret written into the hardware — never the secret.
Events, alerts and figures
- Events: a card swiped, a refund rung up, a person detected, a door opened, a call — each with its site, area, time and type.
- Alerts (Moments): the event assembled with its findings, who handled it, notes, and the video or picture it points at.
- Kardo Intelligence figures: people in and out, occupancy, queues, dwell — as counts by the hour and by the day, never as video. Heat maps stay on the KardoHub.
- Business documents your Kardopal account publishes to KardoVision (sales, refunds, invoices, purchases, inventory, expenses, attendance), by document id, in your currency. KardoVision never reads Kardopal’s database.
- Access: people, cards, PIN hashes and QR passes you create for doors; entries and refusals with their reason. Faces enrolled at a door terminal are sealed on that terminal and never leave it.
Pictures and video — set per camera
Each camera has a privacy mode, chosen by you, that decides what may leave the building:
- Local only — no picture of any kind leaves the KardoHub. The cloud strips any thumbnail or clip pointer that arrives, so the timeline stays complete without imagery.
- Events to the cloud, video stays local (the default) — events and figures go up; pictures and video stay on site.
- Events and snapshots to the cloud — a small picture may accompany an event.
- Alert clips to the cloud too — short clips of alerts are stored in the cloud as well.
Continuous recording always lives on the KardoHub’s own disk at your site, or on a Kardo camera’s own storage. Live view and playback from the web or the app are relayed through the cloud and are not stored there. A clip you export is uploaded to cloud storage with a manifest (camera, seconds, who, when, why, and a hash of the bytes). Search across sites keeps result pictures in memory for 30 minutes and never in the database; a photo you search with is not kept; search history is not kept. Screens can be asked for a screenshot only while the account and the site allow it.
Audio — only when you enable it
- Talking to speakers, door intercom calls and phone calls run through the KardoHub. Call recordings, voicemail and announcements, where you switch them on, are stored on the KardoHub.
- A message you record or upload for the speakers passes through the cloud to the KardoHub, which plays it and keeps it if you save it as an announcement.
- “Talk to the screen” from the app sends the recording to the cloud; it is transcribed by the cloud AI provider when one is configured, and the recording and the words heard are kept on the KardoHub (the last fifty).
Usage
- Counts of sites, devices, cameras, people and events against your plan, shown to you on the Usage page and to Kardo on its console.
- Server logs with request, correlation and account ids; device commands and their results; email and notification counts against the caps that stop a sender running away.
- An audit log of who did what in your account: role, site, device-limit, grant, privacy and retention changes with before and after; sign-ins; exports; support sessions. Zones and settings changed on a KardoHub’s own screen are sent up and marked as such.
KardoVision uses no advertising or analytics trackers, and does not sell or share data for advertising.
3. Why
- To provide the Service: show you your sites, ring your phone for a door call, keep the right people in and out, raise an alert when two systems disagree.
- To secure it: verify sign-ins, rate-limit guesses, check every device’s certificate, and keep a record of who changed what.
- To bill and meter the plan you chose.
- To support you when you ask, within a session you granted.
- To keep the platform healthy: aggregate figures across accounts (counts, versions, health), never pictures.
- To meet legal obligations and answer lawful requests, which we will tell you about unless the law forbids it.
[Counsel: legal bases per purpose (contract, legitimate interest, consent, legal obligation) for the jurisdictions in scope.]
4. Where
The KardoVision Cloud runs in one cloud region: us-east-1 (Northern Virginia, United States). Video stays on your KardoHub and cameras at your site unless a camera’s privacy mode sends pictures or clips up. The sub-processors below process data where they operate; see /sub-processors. If your business is outside the United States, this is an international transfer: [transfer mechanism (e.g. standard contractual clauses) to be settled by counsel].
5. How long
These are the retention rules as the software enforces them, every night at 03:15 (UTC), in batches:
| Data | Kept | Notes |
|---|---|---|
| Events | Your plan’s period, or fewer days if the owner chooses (1 to 3,650). A plan may be unlimited. | An account with no subscription keeps 3 days. |
| Alerts (Moments) | Four times the events period, once resolved or dismissed. | Open alerts stay. An alert marked as evidence is never deleted automatically. |
| Audit log | 730 days, or the owner’s choice between 365 and 3,650. | Append-only: only this schedule removes entries. |
| Kardo Intelligence figures | 400 days by the hour; 5 years by the day. | Counts, not video. |
| Semantic index of alerts | While the switch is on. | Switching it off deletes the whole index at once. |
| Video and audio on the KardoHub | Until the disk is nearly full (the oldest minute makes room), or a “keep N days” you set. | Minutes marked as preserved are never removed. |
| Clips in the cloud, exports | Until you delete them or close the account. | [Confirm a lifecycle rule for exported clips.] |
| Search results across sites; search photos | 30 minutes in memory; not kept. | |
| Sign-up codes; password reset links | A sign-up code 15 minutes; a reset link 1 hour. | Expired reset tokens are deleted nightly. |
| Push tokens | While the phone is signed in. | Removed when you sign out, when the push service reports the phone gone, or when the person is deleted. |
| Support grants and sessions | With the audit log. | A grant lasts 1, 4 or 24 hours; a session at most an hour. |
| Account data | While the account is open. | Deleted on closure, by request; see section 7. |
6. Who else
Kardo staff see your account only through the platform console, each according to their role, and reach inside it only during a support session you granted. The companies that process data for us, what they do and where, are listed at /sub-processors: cloud hosting and storage, email, push notifications, and two optional AI providers that only receive anything while the owner keeps Kardo AI Cloud and the semantic index switched on. We will update that page before adding a sub-processor. We do not sell personal data.
7. Your rights
Depending on where you are, you may have the right to access, correct, export, delete or object to the processing of your personal data, and to complain to a supervisory authority. Today these are handled by request to support at [privacy contact email]: self-serve export and deletion of a whole account are not yet available. Within the Service an owner can already remove people, delete alerts and clips, change retention, switch off cloud AI and the semantic index, and set every camera to Local only. CSV export of alerts, insights and Intelligence figures, and clip export, are available to people with those permissions. We answer within [30 days]. If you were recorded by a customer’s cameras, please contact that business; we will help it find and act on what concerns you.
8. Cookies and browser storage
The web console sets only what it needs to work; there are no advertising or analytics cookies.
| Name | What for | How long |
|---|---|---|
kv_session | Keeps you signed in. Sent only over HTTPS in production; not readable by scripts. | 7 days |
kv_admin_session | The same for Kardo staff on the platform console (a separate credential). | 12 hours |
kv-lang | The language you chose, so pages render in it. | 1 year |
The browser’s local storage holds your light/dark choice, whether the Devices menus were left open, and — only if you tick “Remember me” — your email address for the sign-in form. None of these leave your browser. The phone app keeps its session on the phone and registers a push token so notifications can reach it.
9. Children
The Service is for businesses and is not directed at children. Cameras may nonetheless record minors in a customer’s premises; the customer is responsible for that lawfulness.
10. Changes to this policy
We will post changes here and, for material ones, email account owners at least [30] days before they take effect.
11. Contact
[Kardo legal entity, postal address, privacy contact email, and (where required) data protection officer or EU/UK representative].
Last updated 29 September 2026. KardoVision is a product of Kardo.