Trust · Privacy & Compliance

How we protect privacy

Video is processed on the device

SpaceVision is anonymous audience measurement, closer to a digital tally that counts people than to CCTV. This page explains what our devices see, what leaves them, and how that maps to the GDPR, the EU AI Act, and Korea's PIPA.

male(0.99)
30-39(0.84)
female(0.97)
18-29(0.71)
male(0.96)
18-29(0.73)
male(0.98)
18-29(0.77)
male(1.00)
30-39(0.80)
male(0.97)
30-39(0.79)
female(0.92)
40-49(0.58)
WHAT LEAVES THE DEVICE
Records transmitted from this scene
7 records · 0 images · 0 faces
Drag the boundary to compare the camera frame with the transmitted records

Video never leaves the device

The AI Box analyzes each frame in memory and discards it within milliseconds. Frames are not written to disk or transmitted. The device sends measurement records instead.

Raw video & framesFaces & biometric templatesNames, accounts, IP addressesPeople countsDwell & attentionAge band & gender estimate

The device sends measurement records and does not transmit the camera frame.

On-site · SpaceVision AI Box
stays in the box
videoframebiometric templateidentity
zone · A2event · glanceage · 30–39dwell · 128scount · +1
Cloud · EU region available

Only the numbers move forward

The on-site AI Box keeps visual data inside the device. It sends non-biometric event records to the cloud for aggregation and dashboard reporting.

Built without video storage or identity tracking

The system does not create or transmit stored video, biometric templates, or identifiers for cross-visit tracking. The compliance pack below documents the engineering controls.

Video storage and identity tracking are excluded from the architecture

01
No video survives

Frames are discarded from device memory in milliseconds. No video exists on disk, in transit, or in the cloud.

02
No identities are created

No facial recognition, no biometric templates. The system has no material to identify anyone with.

03
No one can be tracked

Anonymous tracks live within a single visit and then reset. There is structurally no way to connect yesterday's visitor to today's.

04
Decisions touch aggregates only

Only zone-level statistics leave the store, and no decision is ever made about an individual person.

The system knows someone is still here, never who came back

An anonymous visit is linked only long enough to measure movement and dwell. The system stores no video or identity and retains only the de-identified behavior data needed for analysis.

Anonymous linkage data is deleted automatically after a short period. Only aggregated results are used for reporting.

No identity recognition or long-term tracking
  • Not facial recognition, gait recognition, or body-shape identification
  • No persistent biometric templates, no matching databases
  • No matching across sessions, days, sites, or customers

The system is not designed to identify a visitor across sessions, days, sites, customers, or tenants.

The system records presence, location, dwell, and attention for the current visit without creating an identity record.

Answering what the law asks

Three regulators ask different questions. One architectural fact answers all three: what leaves the store is anonymous, aggregated measurement, not personal information.

One architectural fact

The reporting layer receives anonymous, aggregated measurements

GDPR
EU AI Act
Korea's PIPA
01GDPR
What this law asks

Who is the controller, and what is the legal basis?

The architecture's answer
Built for data minimization, from Article 25 up
Clear roles

You remain the Data Controller; SpaceVision acts as your Data Processor under an Art. 28 DPA. Under the EU AI Act, SpaceVision is the Provider and you are the Deployer, and we supply the documentation both roles need.

Anonymous by design at the reporting layer

Dashboards and KPIs are aggregated statistics designed to be anonymous (Recital 26). Underlying event records are non-biometric and session-scoped, and we conservatively handle them under GDPR-grade controls until aggregation.

Legal basis, documented

Deployments typically rest on legitimate interests (Art. 6(1)(f)), supported by a documented balancing test. No special-category data (Art. 9) is processed under the intended use, and no automated individual decisions (Art. 22) are made.

Data residency & transfers

EU hosting is available (AWS Frankfurt, eu-central-1). Where transfers apply, EU Standard Contractual Clauses are in place, and Korea holds an EU adequacy decision (in force since 2021). No video or biometric data exists to transfer at all.

What we keep, and for how long
Raw video
never stored · RAM only, milliseconds
Transient features
RAM only, single session
Session token
resets within 1–24 hours
Event records (edge buffer)
up to 1 month
Event records (cloud)
up to 12 months, adjustable by contract
Aggregated KPIs
anonymous statistics · no personal data

If a security incident is ever confirmed, we notify you within 24 hours, supporting your own 72-hour notification duty as controller.

02EU AI Act
What this law asks

What risk tier is this, and does it use any prohibited techniques?

The architecture's answer
A limited-risk AI system, and transparent about it

SpaceVision is an AI system in scope of Regulation (EU) 2024/1689, assessed as Limited Risk for its documented intended use. It practices none of the prohibited techniques of Article 5, and falls in no high-risk category: it is not a safety component and never uniquely identifies a person.

SpaceVision AI is intended exclusively for anonymous audience measurement and content effectiveness analytics in retail stores, exhibitions, events, and out-of-home digital signage environments.
Intended Purpose statement
No facial recognition

No face databases, no scraping, no matching. By design, the system cannot answer the question of who a person is.

No emotion recognition

Attention is head-pose-based gaze estimation: is someone looking at the screen, and for how long. It does not infer feelings or intent.

No biometric categorisation by sensitive traits

Only coarse gender and age-band estimates for audience statistics. Race, ethnicity, beliefs, or health are never inferred or emitted.

No remote biometric identification

No unique identification of any person, in real time or retrospectively.

What does apply is Article 50 transparency: visitors should know an AI system is measuring the space. We ship multilingual in-store notice templates and operator training materials (Art. 4 AI literacy) with every deployment.

03Korea's PIPA
What this law asks

Is what leaves the country personal information?

The architecture's answer
Compliance reviewed under Korea's PIPA

The architecture was reviewed against Korea's Personal Information Protection Act (PIPA), with compliance confirmed by legal opinion. The basis is the structure this page keeps repeating: what leaves the store is aggregated, anonymized measurement data, not personal information.

What you see, what you get

The dashboard reports aggregate statistics

Storefront AI dashboard showing funnel KPIs, daily trends and audience mix as aggregated statistics
Storefront AI dashboard · live export, restyled
What your dashboard shows
  • ·pass, glance, and attention counts per zone and hour
  • ·walk-in conversion and average dwell time
  • ·audience mix as coarse estimates: an age band like “30–39”, never a birthdate
  • ·trends across days, campaigns, and locations

Reports are grouped by zone, hour, audience, campaign, and location. The product does not provide person-level records.

And the data never contains
  • names or contact details
  • account or loyalty identifiers
  • visitor IP addresses
  • images or image hashes
  • facial or biometric templates

Documents provided for privacy and legal review

DPIA support

A DPIA template for the EU (with a UK GDPR addendum) plus DPO-led support sessions to help your privacy team complete the assessment.

Data Processing Agreement

A standard DPA meeting Art. 28(3) GDPR, with EU Standard Contractual Clauses where transfers apply.

In-store transparency notice

A multilingual notice template (EN · DE · FR · NL · IT · ES) for store entrances, supporting your EU AI Act Art. 50 and GDPR Art. 13 duties.

Technical documentation

High-level architecture, security architecture, and model documentation available on request under NDA, plus a disclosed sub-processor list.

· TLS 1.2+ in transit· AES-256 at rest· outbound-only edge networking· per-tenant isolation· signed OTA updates
Questions from your DPO or legal team?

Our Data Protection Officer answers directly, and detailed documentation is available under NDA.

Talk to our DPO →