Privacy Policy
Effective March 10, 2026
How Securvantage Technologies collects, uses, keeps and protects personal information in VantageOpsix, and the choices and rights you have.
Who is responsible
VantageOpsix is a business platform. Our customers (facility owners and operators) decide what sites, cameras, doors and people are managed in it. For that facility data, the customer is the controller (or "business") and Securvantage Technologies is the processor (or "service provider") acting on their instructions under our Data Processing Addendum. For account, security and billing data about the people who sign in, Securvantage Technologies is the controller.
What we collect
| Category | Examples | Source |
|---|---|---|
| Account details | Name, work email, role, assigned facilities | Your organization when it provisions you |
| Credentials | Password and technician PIN (stored only as one-way hashes) | You |
| Session & security data | IP address, browser/device type, sign-in times | Your device when you sign in |
| Audit trail | Who changed what (door unlocks, alarm actions, settings) and when | Generated by your use |
| Facility operations | Alarm events, door/badge activity, device health, work orders | Customer systems and devices |
| Camera stills | Patrol and alarm-verification snapshots (no audio, no facial recognition) | Customer cameras |
| Usage analytics | Aggregated page views and performance metrics (no advertising cookies) | Vercel Analytics |
We do not collect biometric identifiers, we do not record audio, and we do not run facial recognition. We do not knowingly collect information from children under 16; the service is for business use only.
How we use it
- To provide the service: show live status, verify and route alarms, run access control and dispatch technicians.
- To secure the service: authenticate users, rate-limit sign-ins, detect abuse and keep an audit trail.
- To support and improve the service, using aggregated, de-identified metrics where possible.
- To meet legal obligations, such as responding to lawful requests or alarm-response record-keeping.
We do not sell personal information, we do not "share" it for cross-context behavioral advertising, and we do not use it to train AI models.
Legal bases (EEA, UK and similar laws)
Where these laws apply, we rely on performance of a contract (providing the service your organization bought), legitimate interests (security, fraud prevention and service improvement, balanced against your rights), and legal obligation. Customers are responsible for the legal basis for monitoring their premises and staff.
Who we share it with
Only with the subprocessors that host and run the service, with the customer organization you belong to, with monitoring centers and public-safety answering points when an alarm is verified for dispatch, and when required by law. Every subprocessor is bound by confidentiality and data-protection terms.
How long we keep it
| Data | Retention |
|---|---|
| Expired sign-in sessions | Deleted 30 days after expiry |
| Audit log entries | 365 days, then deleted |
| Camera stills held by the platform | 30 days unless preserved for an open incident |
| Operational backups | 30 days |
| System health records | 90 days |
| Revoked store mode tablets | 90 days after revocation |
| Closed accounts | Deleted immediately; residual copies in backups expire within 30 days |
Retention is enforced by an automated daily job. Continuous video stays on the customer's own recorders and follows the customer's retention policy.
Your rights and choices
Depending on where you live (including California under the CCPA/CPRA, other U.S. state privacy laws, and the GDPR/UK GDPR), you may have the right to know, access, correct, delete or port your personal information, to object to or restrict certain processing, and to not be discriminated against for exercising these rights.
- Self-service: signed-in users can download a copy of their data or close their account from Settings → Your account & privacy.
- By request: email privacy@securvantage.io. We verify your identity and respond within 45 days (30 days where GDPR applies). An authorized agent may submit a request with your signed permission.
- If your data is in a facility record (for example a badge swipe at a customer site), we will route your request to that customer, who controls that data.
- We honor Global Privacy Control signals; as we do not sell or share data, no further opt-out is needed.
You may also complain to your local data-protection authority.
Security
Data is encrypted in transit (TLS) and at rest by our hosting providers. Passwords and PINs are stored only as salted hashes, sessions use HTTP-only cookies, sign-in is rate-limited, PIN entry locks after repeated failures, and administrative actions are audit-logged. Report vulnerabilities to security@securvantage.io. If a breach affects your personal information, we notify affected customers without undue delay and as required by law.
International transfers
Data is stored in the United States. Where we transfer personal data from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) incorporated in our DPA.
Changes and contact
We will post updates here and change the effective date; material changes are notified to customer administrators in advance. Contact Securvantage Technologies at privacy@securvantage.io.
