Privacy
Privacy Policy
Last updated: June 30, 2026
Overview
This Privacy Policy explains how Kotelab. ("Kotelab," "Kote," "we," "us") collects, uses, and protects information across (1) the kotelab.com website and (2) the Kote product, which processes video from customer-owned cameras to deliver real-time operations and security intelligence.
If you are a visitor to our website, Section 1 applies to you. If your organization is a Kote customer, or if you are an employee, contractor, or visitor at a site monitored by Kote on behalf of one of our customers, Section 2 applies to you as well.
Section 1: Website Privacy
Information we collect
- Contact details submitted through the demo form: name, work email, company, phone number, message.
- Basic analytics about website visits: page views, approximate location, device type, browser, referral source.
- Technical information needed to operate, secure, and troubleshoot the website.
How we use this information
- To respond to demo requests and commercial inquiries.
- To understand website performance and improve page content.
- To protect the website from abuse, spam, and security threats.
Service providers
We use trusted service providers for website analytics, email delivery, hosting, security, and related business operations. These providers may process limited technical or contact data only as needed to provide services to Kotelab and are subject to confidentiality and data protection obligations.
Retention
Demo request information is retained for as long as needed to respond to inquiries, manage prospective customer relationships, comply with legal obligations, and maintain business records.
Section 2: Product Privacy (Video & Site Data)
The Kote product connects to camera feeds (RTSP, IP cameras, DVRs/NVRs) operated by our customers and applies AI analysis to surface operational and security events. Because Kote processes video of real people, this section explains what we process, why, and how it's protected.
Who controls this data
Our customers, the businesses deploying Kote at their sites, are the data controllers for video and event data captured by their cameras. Kote acts as a data processor / service provider, processing this data only on the customer's instructions and for the purposes set out in our customer agreement and Data Processing Addendum (DPA).
If you are an employee, shopper, driver, or visitor at a site using Kote, your camera footage is governed by your relationship with that site operator, not directly with Kotelab. Requests to access, correct, or delete footage involving you should generally go to the site operator first; we will support them in fulfilling valid requests.
Customer notice obligations
Customers are responsible for ensuring that their use of CCTV and Kote complies with applicable laws in the places where they operate. This may include providing clear notices, signage, employee policies, visitor notices, or other disclosures informing individuals that camera monitoring, video analytics, and related security or operations processing may occur on the premises.
These requirements are not limited to one country. CCTV and workplace monitoring notice rules vary by jurisdiction, including Kenya, the EU/UK, the United States, and other regions. Customers should assess their own legal obligations before enabling monitoring or analytics features at a site.
What we process
- Video feeds from customer-connected cameras, processed to detect events (e.g., queue length, restricted-zone entry, suspicious behavior patterns, vehicle presence).
- Derived event data: timestamps, zone/camera identifiers, short event clips, alert metadata, and natural-language search queries run against footage.
- Account and configuration data: admin and operator accounts, site/camera configuration, alert rules, access logs.
- Re-identification signals used to track a person or vehicle across multiple cameras within a customer's site, where this feature is enabled by the customer.
Kote does not require new cameras or hardware; it connects to feeds the customer already operates.
Biometric and sensitive data
Some Kote capabilities (e.g., cross-camera person tracking, facial or appearance-based search) may involve processing that is treated as biometric or sensitive personal data under certain laws (such as Illinois' BIPA, Texas' CUBI, the EU/UK GDPR, and similar state and national laws). Where this applies:
- Customers are responsible for providing any legally required notice or consent to individuals at their sites (e.g., signage, employee notices) before enabling these features.
- We provide customers with disclosure tooling and documentation to support these obligations.
- We do not use biometric identifiers from customer footage to build cross-customer profiles, and we do not sell biometric data.
How we use product data
- To deliver the core product: real-time alerts, footage search, event detection, and analytics dashboards.
- To maintain and improve detection model accuracy, using de-identified or aggregated data where feasible.
- To provide customer support and troubleshoot reported issues.
- To meet security, audit, and legal obligations.
We do not use customer video to train models for the benefit of other customers, and we do not sell, rent, or use customer video for advertising purposes.
Retention and deletion
- Video and derived event data are retained according to the retention period set in the customer's plan/configuration (typically a rolling window measured in days).
- Customers can configure shorter retention or request earlier deletion of specific clips.
- Upon contract termination, customer video and event data are deleted within the timeframe specified in the customer agreement, except where retention is required by law or active legal process.
Sub-processors
We use a limited set of sub-processors to operate the product, including infrastructure, storage, security, support, and AI processing services. A current sub-processor list is available to customers under our customer agreement or Data Processing Addendum. We require sub-processors to maintain confidentiality, security, and data protection obligations consistent with this policy.
International transfers
Depending on the customer's deployment region, video and data may be processed and stored in data centers located outside the customer's or data subject's country. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of personal information. Site visitors and employees should direct these requests to the operator of the site where footage was captured. Kotelab will assist our customers in responding to valid, verifiable requests as required under our DPA and applicable law.
Security
See our Security page for details on encryption, access controls, and compliance posture.
Contact
Questions about this policy, website privacy, or product privacy can be sent to privacy@kotelab.com.
Changes to this policy
We may update this policy as our product, legal obligations, or practices evolve. Material changes will be reflected by updating the "Last updated" date above.