Privacy Policy
Your trust is the whole product. This policy sets out, in plain terms, what information Visbi handles, how, and the choices you have.
Working draft — not yet legal-reviewed. This document is grounded in Visbi's actual data-handling practices, but every bracketed item still needs to be completed and the whole policy reviewed by qualified legal counsel before publishing. It is not legal advice.
01Who we are & what this covers
This Privacy Policy explains how Visbi ("Visbi", "we", "us"), a product built by the team at Innovatics, handles information when you visit www.visbi.ai, contact us, or when your organization uses the Visbi platform.
Visbi is operated by Innovatics, based in Knoxville, Tennessee, USA. This policy is governed by the laws of the State of Tennessee, United States.
02Information we process
When you visit our website or contact us
- Details you give us: name, work email, company, number of locations, and your message when you request a Readiness Audit or reach out.
- Standard technical and usage data (e.g. IP-derived region, device/browser, pages viewed) via Google Analytics.
When your organization deploys Visbi
Visbi reads video from your existing cameras on-site to produce anonymized operational insight and anonymized proof. By design: no facial recognition, no demographic or emotion inference, and no cloud archive of identifiable people. Raw video is never continuously uploaded off-site.
For this deployment data, your organization is the data controller and Visbi acts as processor, on your documented instructions under a Data Processing Agreement [ link to DPA ].
03How we use information
- To provide, operate, and support the Visbi platform and website.
- To respond to your enquiries and deliver your Readiness Audit read.
- To secure, maintain, and improve the service.
- To meet legal, regulatory, and contractual obligations.
We do not sell your personal data, and we do not use it for advertising.
04Legal bases
Visbi operates from the United States. Where laws that require a "legal basis" apply, such as the EU/UK GDPR or India's DPDPA for international visitors, we rely on performance of a contract (providing the service), our legitimate interests (operating and securing the service, responding to enquiries), consent where required, and legal obligation. Deployment data is processed on the customer's (controller's) legal basis and instructions.
05On-site processing & anonymization
Footage is processed on-site on an edge device per location. What leaves the premises is anonymized insight and anonymized proof (scores, flags, and anonymized moments), never a live feed of your floor or a searchable archive of individuals. Full detail is on our Security page.
06Sharing & sub-processors
We never sell your data or share it with third parties for their own purposes. We share data only with service providers (sub-processors) who help us run the platform, under contract and appropriate safeguards. Current sub-processors: [ list: hosting, email, analytics, etc. ]. We may also disclose information where required by law.
07How we protect information
Security is operated under an ISO/IEC 27001-certified information security management system maintained by Innovatics. Measures include on-site processing, access controls, encryption in transit, and least-privilege access. No method of transmission or storage is 100% secure, but we work to protect your information at a level appropriate to its sensitivity.
08Retention & deletion
Deployment footage and derived data are retained for 15 days, and nothing is kept beyond the policy we agree together; deletion is available on request, confirmed in writing. Website enquiry data is retained for 1 year unless a longer period is required by law.
09Your rights
Depending on where you live, you may have rights over your personal data, including to access, correct, delete, or receive a copy of it, and to opt out of its "sale" (we do not sell personal data). U.S. state privacy laws (such as California's CCPA/CPRA) and, for international visitors, laws like the GDPR or DPDPA may apply. To exercise any right, email privacy@visbi.ai and we will respond as required by applicable law. You may also have the right to complain to a relevant data-protection regulator. For deployment data captured on a customer's premises, please contact that customer (the controller).
10International transfers
Visbi is operated from the United States, and information may be processed and stored in the U.S. Where personal data is transferred to the U.S. from other regions, we use appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms.
11Cookies & analytics
We use a small number of cookies and similar technologies to run the site and understand usage. You can control non-essential cookies via cookie settings. See our Cookie Policy for detail.
12Children's privacy
Visbi is a business product and is not directed to children. We do not knowingly collect personal data from anyone under 18.
13Changes to this policy
We may update this policy from time to time. Material changes will be posted here with a new "last updated" date, and where appropriate we will notify you.
14Contact us
Questions about privacy? Email us at privacy@visbi.ai.