Privacy Policy & Data Governance
Entity: Tech Driven Basic Private Limited ("CamSec AI", "We", "Us") | Last Revised: September 2026
🛡️ Privacy by Architecture: 100% On-Premise Edge Computing
Unlike traditional cloud-hosted camera solutions that continuously stream live video footage to public cloud servers, CamSec AI Pro Mini executes all neural network inference, facial feature extraction, and video analytics locally on physical hardware inside your premises. Raw CCTV video feeds never leave your local physical network.
1. Statutory Governance Roles (DPDPA 2023 Compliance)
Under the Digital Personal Data Protection Act, 2023 (India), the legal responsibilities are structured as follows:
- • Client as "Data Fiduciary": You (the retail store owner, corporate entity, or commercial enterprise deploying CamSec AI) act as the statutory Data Fiduciary. You determine the lawful purpose for biometric attendance tracking, customer footfall counting, and employee monitoring. You are solely responsible for obtaining requisite notices and consent from your personnel, visitors, or customers.
- • CamSec AI as "Data Processor / Technology Provider": Tech Driven Basic Private Limited provides the hardware gateway, operating system, and neural algorithms. We process data strictly upon your local instructions and provide zero cloud access to your video streams.
2. Scope of Data Collected & Where It Resides
A. On-Premise Device Data
- Biometric Vector Embeddings: Mathematical representations (128/512-dimension vector arrays) extracted from employee faces for attendance verification.
- Attendance Telemetry: Timestamp logs of check-ins, exits, breaks, and shift hours.
- Video Stream Buffers: Short-term RTSP memory frames ingested from your existing NVR/IP cameras. These are evaluated in RAM and never saved to cloud repositories.
B. Commercial & Web Store Data
- Billing & Order Details: Business name, GSTIN, shipping address, contact phone, and official email collected at
store.camsecai.comfor delivery fulfillment and tax invoicing. - Payment Information: Processed securely via RBI-authorized payment gateways (UPI, Credit Cards, Net Banking). CamSec does not record or store sensitive card numbers or CVVs.
3. Purpose of Data Processing
We utilize information strictly for the following operational objectives:
- Automated Work Force Telemetry: Generating automated shift attendance, in-out stamps, and payroll export sheets.
- Security Alerts & Event Pushes: Dispatching real-time event alerts (such as unauthorized door breaches or people count limits) to your registered Telegram bots or admin dashboards.
- Hardware Dispatch & Licensing: Binding firmware licenses to individual hardware gateway MAC addresses and serial numbers.
- Technical Diagnostic Support: Performing remote diagnostics (via AnyDesk/TeamViewer) strictly upon client invitation to resolve local IP camera connection issues.
4. Zero Third-Party Monetization & Data Disclosures
We do not sell, rent, lease, or monetize your business or biometric telemetry data to third parties, data brokers, or advertisers under any circumstances.
Information may only be disclosed if required by statutory Indian law, judicial court orders, or governmental law enforcement agencies possessing lawful warrants under the Bharatiya Nagarik Suraksha Sanhita (BNSS) or Information Technology Act, 2000.
5. Security Measures & Data Retention
- Encrypted Local Templates: Facial vectors on CamSec AI Pro Mini gateways are stored in secured partitions and are mathematically irreversible (they cannot be reverse-constructed back into original human photos).
- Client Controlled Retention: You retain complete autonomy to wipe, delete, or reset employee biometric templates, attendance logs, and camera configs at any time via your local admin panel.
- Commercial Logs: Order receipts, tax invoices, and accounting records are preserved in accordance with standard statutory Indian taxation and GST filing retention requirements.
Grievance Redressal & Data Protection Officer (DPO)
In accordance with the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, the designated Grievance Officer for data inquiries and compliance matters is: