Privacy Policy
Effective Date: April 23, 2026
Last Updated: April 23, 2026
Operated by: Platinum Health Equipment Pty Ltd (ACN: 678 244 963)
Contact: [email protected]
Service: AegisGates Vision AI – AI-powered video monitoring and analytics platform
This Privacy Policy describes how Platinum Health Equipment Pty Ltd ("Company", "we", "us", "our") collects, uses, discloses, and protects information when you use AegisGates Vision AI (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, company name, billing address, phone number, and password when you create an account.
- Payment Information: Payment card details processed securely through Stripe. We do not store complete card numbers.
- Camera Configuration: Camera names, locations, RTSP URLs, API keys, and alert keywords you configure.
- Communications: Messages, feedback, and support inquiries you send to us.
1.2 Information Automatically Collected
- Video Data: Video footage captured by cameras connected to the Service, including timestamps, motion detection events, and AI-generated descriptions/narratives.
- Usage Data: IP addresses, browser type, device information, access times, pages viewed, and referring URLs.
- Cookies and Tracking: Session cookies for authentication, analytics cookies (if consented), and performance monitoring data.
- Log Data: Server logs including API requests, errors, and system events.
1.3 Biometric and Personal Data in Video
IMPORTANT: Video footage may contain biometric identifiers (facial images, gait patterns) and personal information (license plates, conversations). You are responsible for obtaining all necessary consents before deploying cameras in accordance with applicable laws (see Section 11).
2. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery: Process video feeds, generate AI narratives, deliver alerts, and provide dashboard access.
- Account Management: Create and maintain accounts, process payments, provide customer support.
- Security & Fraud Prevention: Monitor for unauthorized access, abuse, and fraudulent activity.
- Communications: Send transactional emails (account verification, password resets, alert notifications, billing statements).
- Improvement & Analytics: Analyze usage patterns, improve AI models, develop new features, and optimize performance.
- AI Model Training: AI-generated narratives and video footage may be used for AI model training and performance improvement prior to their scheduled deletion. Video footage is used only within the processing window (typically 2–30 seconds); narratives may be used at any point during their 90-day retention period. Data used for training is anonymized where practicable.
- Legal Compliance: Comply with legal obligations, respond to lawful requests, enforce our Terms of Service.
3. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), UK, or Switzerland, we process your personal data under the following legal bases:
- Contractual Necessity: Processing required to provide the Service you requested.
- Legitimate Interests: Fraud prevention, security monitoring, service improvement (balanced against your rights).
- Legal Obligation: Compliance with laws, court orders, or regulatory requirements.
- Consent: Optional analytics cookies and marketing communications (where consent is required).
4. Data Sharing and Disclosure
4.1 Service Providers
We share data with trusted third-party providers who assist in operating the Service:
- Hosting: Google Cloud Platform (GCP) – server infrastructure, database storage
- AI Processing: Google Gemini API – video analysis and natural language generation
- Payment Processing: Stripe – secure payment transactions
- Email Delivery: Resend – transactional emails and alert notifications
- SMS Alerts: Twilio – text message notifications
- CDN & Security: Cloudflare – content delivery and DDoS protection
All third parties are contractually obligated to protect your data and use it only for specified purposes.
4.2 Legal Requirements
We may disclose information if required by law, court order, subpoena, or government request, or to protect our rights, property, or safety.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the successor entity. We will notify you via email and/or prominent notice before your data is transferred.
4.4 No Sale of Personal Data
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5. Data Retention
5.1 Video Footage
We do not store video footage. Video clips are processed in real-time and deleted immediately after AI analysis (0 seconds retention). No video recordings are ever written to disk or retained on our servers.
5.2 AI-Generated Narratives and Alert Records
- All Subscribers: 90 days from capture date
- Alert Records: 90 days (same as regular narratives)
- User Request: You may request earlier deletion via support
5.2 Account Data
- Active Accounts: Retained for the duration of your subscription plus 90 days
- Deleted Accounts: Permanently deleted within 30 days (backup copies within 90 days)
- Billing Records: Retained for 7 years for tax and accounting compliance
5.3 Log Data
- Access Logs: 90 days
- Security Logs: 12 months
- Aggregated Analytics: Indefinitely (anonymized)
6. Data Security
We implement industry-standard security measures to protect your information:
- Encryption: HTTPS/TLS for data in transit; AES-256 for data at rest
- Access Controls: Role-based access controls with authenticated session management
- Network Security: Firewalls, intrusion detection, DDoS protection via Cloudflare
- Database Security: Localhost-only PostgreSQL, encrypted backups
- Monitoring: 24/7 security monitoring and incident response procedures
- Audits: Regular security assessments and penetration testing
No system is 100% secure. If you suspect a security breach, contact [email protected] immediately.
7. Your Rights and Choices
7.1 GDPR Rights (EEA/UK/Swiss Residents)
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent for optional processing (e.g., marketing)
- Right to Lodge a Complaint: File a complaint with your local data protection authority
7.2 CCPA Rights (California Residents)
- Right to Know: Request disclosure of data collected, used, and shared
- Right to Delete: Request deletion of personal information
- Right to Opt-Out: Opt-out of sale (we do not sell personal data)
- Right to Non-Discrimination: Equal service regardless of privacy choices
7.3 How to Exercise Your Rights
Email [email protected] with your request. We will respond within:
- GDPR: 30 days (extendable to 60 days for complex requests)
- CCPA: 45 days (extendable to 90 days)
7.4 Account Management
- Update Profile: Edit your profile in account settings
- Delete Account: Contact support or use self-service deletion (if available)
- Download Data: Request data export via support
8. Cookies and Tracking Technologies
8.1 Types of Cookies We Use
- Essential Cookies: Session authentication (required for Service functionality)
- Analytics Cookies: Google Analytics, usage tracking (optional, requires consent)
- Security Cookies: Cloudflare security and performance monitoring
8.2 Cookie Consent
For EU/UK visitors, we display a cookie consent banner. You may withdraw consent at any time by clearing browser cookies or contacting us.
8.3 Do Not Track
Our Service does not currently respond to Do Not Track (DNT) browser signals.
9. International Data Transfers
Our servers are located in the United States and Australia. If you access the Service from outside these regions, your data will be transferred internationally. We ensure adequate safeguards through:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Compliance with GDPR Article 46 transfer mechanisms
- Data Processing Agreements (DPAs) with third-party processors
10. Children's Privacy
The Service is not intended for children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us immediately for deletion.
11. Video Surveillance Compliance
11.1 Your Responsibilities
As a Service user deploying video cameras, YOU are responsible for:
- Complying with all applicable video surveillance laws in your jurisdiction
- Obtaining necessary consents from individuals being recorded
- Posting visible signage notifying individuals of video monitoring
- Limiting camera placement to lawful areas (no bathrooms, private spaces)
- Implementing appropriate security measures for recorded footage
- Responding to data subject requests regarding recorded footage
11.2 Jurisdiction-Specific Requirements
- Australia: Comply with Privacy Act 1988, APP 3 (collection notice), APP 11 (security)
- United States: Comply with state biometric privacy laws (BIPA in Illinois, CCTPA in Texas, etc.)
- European Union: Comply with GDPR Article 6 (lawful basis), Article 35 (DPIA for high-risk processing)
- United Kingdom: ICO guidance on video surveillance and CCTV
11.3 Signage Template
We recommend displaying the following notice where cameras are deployed:
NOTICE: VIDEO MONITORING IN PROGRESS
This area is monitored by AI-powered video surveillance for [safety/security/operational purposes].
Operator: [Your Company Name]
Questions: [Your Contact Email]
Privacy Policy: https://www.aegisgates.com/privacy
12. Data Processing Agreement (DPA)
For customers subject to GDPR, we offer a Data Processing Agreement (DPA) upon request. Contact [email protected] to execute a DPA.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Material changes will be communicated via:
- Email notification to your registered email address
- Prominent banner on the Service homepage
- 30-day notice period for significant changes
Continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact Information
Privacy Inquiries: [email protected]
Security Issues: [email protected]
Legal/DPA Requests: [email protected]
General Support: [email protected]
Mailing Address:
Platinum Health Equipment Pty Ltd
7 Eden Park Drive, Unit 5 Suite #1061
Macquarie Park, NSW 2113
Australia
15. EU Representative
If required by GDPR Article 27, we will appoint an EU representative. Contact details will be listed here.
16. California Shine the Light
California residents may request information about our disclosure of personal information to third parties for marketing purposes. We do not share personal information for third-party marketing.