Legal
Privacy Policy
Last updated: September 28, 2026
In short: On our website we collect only the minimum data needed to reply to you. Our customers’ camera footage is their data. With on-prem deployment, footage never leaves your site; our role is that of a service provider acting on your instructions and within the limits of our contract.
This Privacy Policy explains how VigiLens (“VigiLens”, “we”, “us”) approaches personal data and privacy on the vigilens.online website (the “Site”) and in connection with the VigiLens software and services (the “Services”). The legally required information about personal data processed through the Site is set out in our Privacy Notice (KVKK); this policy complements it.
1. Our principles
In line with Article 4 of the Turkish Personal Data Protection Law No. 6698 (KVKK), we process personal data:
- lawfully and fairly,
- accurately and, where necessary, kept up to date,
- for specified, explicit and legitimate purposes,
- in a manner relevant, limited and proportionate to those purposes,
- and only for as long as necessary.
We do not sell personal data or share it with third parties for advertising.
2. Website visitors
- Demo request form: full name, work email and number of cameras. We use this only to respond to your request and run the demo process.
- Email communication: the messages and attachments you send to info@vigilens.online.
- Technical logs: for the Site’s security, our hosting infrastructure briefly records IP address, date and time, browser and request information.
- No cookies or tracking: the Site uses no cookies, advertising pixels, analytics or behavioral tracking tools. See our Cookie Policy for details.
Which data is processed on which legal ground, who it is transferred to, how long it is kept and how to exercise your rights are explained in detail in our Privacy Notice (KVKK).
3. Our customers’ camera footage and event data
VigiLens analyzes footage from our customers’ own security cameras according to rules set by the customer and generates event alerts. In this context:
- Roles: for camera footage and the event records derived from it, the customer is the data controller. VigiLens acts as a data processor within the meaning of Article 3 of the KVKK, solely on the customer’s instructions and in accordance with our contract.
- Contract: before the Services begin, we sign a data processing agreement with each customer covering the categories of data processed, security measures, sub-processors, retention periods, and the return or deletion of data at the end of the contract.
- On-prem deployment: when video analysis runs on the customer’s own server, camera streams do not leave the customer’s premises. VigiLens does not access this footage except for support activities separately authorized by the customer in writing.
- Cloud and hybrid options: for these options, where and by which sub-processors data will be processed, whether any international transfer takes place, and the safeguards that will apply are agreed with the customer in writing before deployment.
- Purpose limitation: we do not use customer footage to improve our own product, train models or for any other purpose without the customer’s separate written approval.
- Customer obligations: as the data controller, the customer is responsible for informing people in areas under camera surveillance (e.g. warning signs and a privacy notice) and for determining the legal basis for monitoring. We provide technical guidance on this to customers who request it.
- Requests from people in the footage: requests under the KVKK from individuals who appear in the footage should be addressed to the relevant customer as the data controller. We forward any such requests we receive to that customer without delay and support them in responding.
4. Security
Under Article 12 of the KVKK, we take appropriate technical and organizational measures to prevent unlawful processing of and access to personal data and to safeguard it. These include:
- all communication with the Site taking place over an encrypted connection (HTTPS/TLS),
- limiting access to data to authorized people who need it for their work,
- rate limiting and bot filtering against automated and malicious requests,
- selecting service providers with their security and data protection commitments in mind,
- regularly deleting data that is no longer needed.
Security measures specific to the Services (e.g. role-based access, audit logs and optional face masking) are set out separately in the contract with each customer.
No system can guarantee absolute security. If we learn that personal data has been obtained by others through unlawful means, we will notify the individuals concerned and the Personal Data Protection Board as soon as possible, in accordance with Article 12(5) of the KVKK. In an incident affecting customer data, we will inform the customer, as the data controller, without delay.
5. Commercial electronic messages
We only send you replies and information related to your request. If we ever need to send promotional or campaign messages, we will do so in accordance with Turkish Law No. 6563 on the Regulation of Electronic Commerce and related regulations, and every message will include an easy way to opt out.
6. Children’s privacy
The Site and Services are intended for business users. We do not knowingly collect personal data from anyone under the age of 18.
7. Third-party links
The Site may contain links to other websites. We are not responsible for their privacy practices and recommend reviewing the policies of the sites you visit.
8. Changes
We may update this policy when necessary. The current version is always published on this page, and the date at the top shows when it took effect. We will also notify customers we are in contact with of any significant changes.
9. Language
This policy is an English translation provided for convenience. In the event of any inconsistency, the Turkish version (Gizlilik Politikası) prevails.
10. Contact
For any privacy questions or requests: info@vigilens.online