Privacy policy
Draft. This text is a working draft and has not been reviewed by a lawyer. Bracketed placeholders must be filled before publication.
This policy describes what [COMPANY NAME] (“we”) processes when you use openIVR Cloud, the remote-access relay for openIVR, and why. It is written to comply with the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP / nLPD).
Controller
[COMPANY NAME], [ADDRESS]. Data-protection contact: [DPO EMAIL].
The short version
- We store your account email, the identifiers of the sites you pair, and connection metadata.
- We count how many bytes the TURN relay carries per site, for fair use and billing. We do not look inside them.
- We never store video, snapshots or audio. Media packets transit encrypted end to end and are forgotten immediately.
- Payments are handled by Stripe; we never see your full card number.
Data we process and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account email and password hash | Creating and securing your account, sending service notices | Contract (art. 6(1)(b) GDPR) | Life of the account, then 30 days |
| Site identifiers, site names, pairing state | Routing your requests to your NVR and nowhere else | Contract | Until you unpair or delete the site |
| Connection metadata: timestamps, IP address, user agent, requested paths, HTTP status | Operating the relay, rate limiting, abuse prevention, the audit log offered to Pro and Enterprise plans | Contract; legitimate interest in security (art. 6(1)(f)) | [RETENTION, e.g. 90 days] |
| TURN byte counters per site | Fair use and billing | Contract | [RETENTION, e.g. 13 months] as aggregated monthly totals |
| Billing status and Stripe customer identifier | Knowing whether a subscription is active | Contract; legal obligation for invoices | Statutory accounting periods |
| Push-notification tokens (when you enable notifications) | Delivering alerts you asked for | Consent, withdrawable at any time | Until you disable notifications |
Video: transit, never storage
When you watch a camera through openIVR Cloud, the media is negotiated between your NVR and your browser with WebRTC and encrypted end to end (DTLS-SRTP). Whenever a direct path between the two is possible, the video does not touch our servers at all. When it is not, typically behind CGNAT, the encrypted packets transit through our TURN relay. The relay forwards them in memory, does not decrypt them, does not inspect them, and does not write them to disk. The same applies to the HTTP tunnel that carries the interface: requests are relayed in memory. Downloads of recordings and backup exports are refused by the relay.
Because the images your cameras capture may include people, the video you relay is personal data under the GDPR and the nFADP. For that data, you are the controller and we act as a processor that handles it only in transit. You are responsible for the lawfulness of your cameras (signage, field of view, consent where required).
Processors
- Stripe for subscription payments. Your card details go directly to Stripe; we receive a customer identifier and the subscription status. See Stripe's privacy policy.
- [HOSTING PROVIDER] hosts the relay and the TURN server in [HOSTING LOCATION, e.g. Switzerland / EU].
- [EMAIL PROVIDER] for transactional emails (account confirmation, invoices, service notices).
We do not sell data and we do not use advertising trackers. This website sets no cookies; it uses your browser's local storage only to remember your language and the pricing toggle.
Where data is stored
Account, site and billing data are stored in [HOSTING LOCATION]. Transfers outside Switzerland and the EEA, if any (for instance to Stripe), rely on the European Commission's standard contractual clauses or an adequacy decision.
Your rights
You can ask for access to your data, rectification, erasure, restriction, portability, and object to processing based on legitimate interest. You can withdraw consent to notifications at any time. Write to [DPO EMAIL]; we answer within 30 days. You may also lodge a complaint with your supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), in the EU the authority of your country of residence.
Deleting your account removes your email, sites and pairing state. Invoices are kept for the statutory period.
Security
Traffic to the relay is TLS-only. TURN credentials are ephemeral and scoped to one site. The relay requires its own session and an active subscription before a request reaches your NVR, and your NVR's own authentication applies after that. Sensitive operations are recorded in a tamper-evident audit chain that never contains a request body.
Changes
We will announce material changes to this policy by email and on this page at least 14 days before they take effect.