01 · Technology · Privacy by design

Privacy is in the architecture, not the policy.

Policies can change. Architectures don't. We never built the pipeline that would let us see a face - there's no toggle to flip, no premium tier to unlock. The privacy answer is structural.

The architecture is the promise.

Drag the handle. Surveillance-era CCTV on the left. Occivar™ on the right.

02 · Data flow

What leaves the room - and what doesn't.

Never leaves the device
  • Raw video frames
  • Bounding boxes around individuals
  • Face embeddings
  • Biometric identifiers of any kind
  • Re-identification across cameras
  • Demographic inference (age, gender)
What leaves the device
  • Anonymous count totals per zone
  • Density grids (no per-person tracks)
  • Threshold events (entered, exited, crossed)
  • Health-check telemetry of the sensor itself
03 · Compliance

What this means in regulatory language.

AUS

Australian Privacy Act

We don't collect personal information as defined under APP 3 - there's nothing to govern under APPs 6, 8, 11, 12, 13. The architecture removes the question.

EU

GDPR

No personal data under Article 4. No special category data under Article 9. No DPIA triggered by deployment. We can sign a clean DPA on request.

UK

UK GDPR + ICO guidance

Aligned with ICO's "data protection by design" guidance and the Surveillance Camera Code of Practice - by being neither.

04 · What we never collect

A table you can take to your privacy officer.

Category Status Mechanism
Facial features ❌ Never No face model in the build pipeline
Gait / biometric track ❌ Never Track IDs are scoped to a single frame
Re-identification ❌ Never No cross-camera identity continuity
Video storage (device) ❌ Never Frame buffer freed on inference exit
Video storage (cloud) ❌ Never No video ingress path exists
Audio recording ❌ Never Sensor has no microphone
Demographic inference ❌ Never No demographic model deployed
Anonymous zone counts ✓ Yes On-device inference, JSON to platform
Density grid (8×8) ✓ Yes On-device aggregation, no per-person
Threshold events ✓ Yes Rule engine, routed to subscribers
· Frequently asked

Privacy questions, answered plainly.

Does Occivar store video footage?

No. Raw video frames never leave the sensor. The inference runs on-device and only anonymous counts and density values are transmitted.

Does Occivar recognise faces?

No. There is no face-detection model in the build pipeline. The system cannot identify individuals.

Is Occivar GDPR compliant?

The platform does not collect personal data as defined under GDPR Article 4. No DPIA is triggered by deployment. A clean DPA is available on request.

How does Occivar comply with the Australian Privacy Act?

Occivar does not collect personal information as defined under APP 3, so APPs 6, 8, 11, 12 and 13 do not apply to the system's output. The architecture removes the question.

Can a customer audit what leaves the sensor?

Yes. Every deployment ships with a customer-side proxy. All telemetry passes through it before reaching Occivar, and customers can mirror it to their own warehouse.

Does the system perform re-identification across cameras?

No. Tracking IDs are scoped to a single frame. There is no cross-camera identity continuity.

05 · Take it to your privacy officer

We'll send a clean DPA on request.