Privacy Policy & GDPR Compliance
Last updated: January 2026 · myaisentry.com
1. Data Controller & Processor
AI-Sentry acts as Data Processor on behalf of security agencies and their clients, who act as Data Controllers for their sites, feeds and personnel. Contact: dpo@myaisentry.com. Primary hosting runs in EU data centres or customer-selected jurisdictions.
2. Data We Process
- •Video streams: processed locally at the edge; not uploaded unless cloud archiving is enabled.
- •Alarm evidence: snapshots, short clips and generated PDF reports stored per tenant.
- •Guard account data: name, work e-mail, role, country, timezone, pay rate.
- •Location pings: only while a shift is active (see §4).
- •Billing data: subscriptions and invoices; crypto payments stored as transaction hash + wallet address only.
3. Legal Bases (Art. 6 GDPR)
- •Contract: accounts, scheduling, payroll and alarm handling.
- •Legitimate interests: platform security — signed requests and audit logs.
- •Consent: optional notifications and client tipping features.
- •Legal obligation: invoicing records kept per statutory periods.
4. Strict No-GPS-Tracking Off Shift
Guard location is captured exclusively between check-in and check-out. The app requests positioning only during active shifts and stops at OS level after check-out. No background collection, no off-duty history, no sale of location data. Pings are deleted automatically by retention policies.
5. Cookies & Local Storage
- •Essential session tokens for authentication only — no advertising or third-party trackers.
- •Offline queue stored locally on the guard’s device and erased after sync.
- •UI preferences stay on the device and are never transmitted.
6. Security Measures
- •Cryptographically signed machine authentication with anti-replay timestamps.
- •Hierarchical role-based access control with strict tenant isolation.
- •Encryption in transit, traversal-guarded storage and automated retention windows.
7. Your Rights
Access, rectification, erasure, restriction, portability and objection (Art. 15–21 GDPR) — free of charge via your administrator or dpo@myaisentry.com, answered within 30 days. You may also contact your national supervisory authority.
8. Retention & Transfers
Evidence and pings are pruned by automated retention workers; billing records persist as required by tax law. Sub-processors (e-mail delivery, payment gateways, blockchain networks) are bound by DPAs; non-EEA transfers rely on adequacy decisions or Standard Contractual Clauses.