Privacy Policy & GDPR Compliance

Last updated: January 2026 · myaisentry.com

1. Data Controller & Processor

AI-Sentry acts as Data Processor on behalf of security agencies and their clients, who act as Data Controllers for their sites, feeds and personnel. Contact: dpo@myaisentry.com. Primary hosting runs in EU data centres or customer-selected jurisdictions.

2. Data We Process

  • Video streams: processed locally at the edge; not uploaded unless cloud archiving is enabled.
  • Alarm evidence: snapshots, short clips and generated PDF reports stored per tenant.
  • Guard account data: name, work e-mail, role, country, timezone, pay rate.
  • Location pings: only while a shift is active (see §4).
  • Billing data: subscriptions and invoices; crypto payments stored as transaction hash + wallet address only.

3. Legal Bases (Art. 6 GDPR)

  • Contract: accounts, scheduling, payroll and alarm handling.
  • Legitimate interests: platform security — signed requests and audit logs.
  • Consent: optional notifications and client tipping features.
  • Legal obligation: invoicing records kept per statutory periods.

4. Strict No-GPS-Tracking Off Shift

Guard location is captured exclusively between check-in and check-out. The app requests positioning only during active shifts and stops at OS level after check-out. No background collection, no off-duty history, no sale of location data. Pings are deleted automatically by retention policies.

5. Cookies & Local Storage

  • Essential session tokens for authentication only — no advertising or third-party trackers.
  • Offline queue stored locally on the guard’s device and erased after sync.
  • UI preferences stay on the device and are never transmitted.

6. Security Measures

  • Cryptographically signed machine authentication with anti-replay timestamps.
  • Hierarchical role-based access control with strict tenant isolation.
  • Encryption in transit, traversal-guarded storage and automated retention windows.

7. Your Rights

Access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR) — free of charge via your administrator or dpo@myaisentry.com, answered within 30 days. You may also contact your national supervisory authority.

8. Retention & Transfers

Evidence and pings are pruned by automated retention workers; billing records persist as required by tax law. Sub-processors (e-mail delivery, payment gateways, blockchain networks) are bound by DPAs; non-EEA transfers rely on adequacy decisions or Standard Contractual Clauses.