← JoynVision

Privacy Policy

Version 0.1 (draft) · Last updated 11 August 2026 · Not yet effective

⚠️ Draft — not yet reviewed by a lawyer

This policy is a working draft. It describes accurately what the software does today, but it has not yet been reviewed against Indonesia's Personal Data Protection Law by a lawyer, and it is not yet in force. The highlighted gaps are details still to be confirmed.

In plain language

A summary, so you can understand this in half a minute. The detail follows below.

  • Your video stays in your shop. The counting happens on a PC on your premises. No video recording and no video stream is sent to JoynVision. We could not hand over your footage if we were asked for it, because we do not have it.
  • What we do receive is mostly numbers. One person crossed the entrance line inward at 14:32. No image, no name, no face, nothing that points at a person.
  • The one exception, stated plainly. Once a minute, per camera, the software uploads a single still photo so the dashboard can show you a current view of the doorway to draw your counting line on. That photo can contain people, in the same way a CCTV monitor does. It is automatically deleted after 30 days, and nothing in the product analyses it or matches it against anything.
  • We do not do faces. No face recognition, no face templates, no age or gender estimation, no identification of anyone. Not an off switch — it is not built, and we have decided not to build it.
  • Live viewing goes direct. When you watch a camera from the dashboard, the video travels from your shop to your browser. Our server helps the two find each other and then steps out of the way. We do not record it.
  • You can get it out, or have it deleted. Ask us and we will export your data or delete it.

1. Who this policy covers

1.1 This policy explains how [TO CONFIRM: full legal entity name, form, NPWP and registered address] (JoynVision, we) handles information in the JoynVision service.

1.2 It covers two different groups of people, and the difference matters:

  • Our customers — the shop, café, arcade or factory that subscribes, and the named users inside that business. We hold account data about them.
  • People recorded by our customers' cameras — shoppers, visitors, staff. We do not hold video of these people. What we hold is anonymous counts, and the periodic still frames described in section 2.4.

1.3 The camera owner — our customer — is the one who decides to operate CCTV on their premises, who is responsible for notice and signage, and who holds the recordings. If you were recorded in a shop and want to ask about that footage, ask the shop, not us: we do not have it and cannot retrieve it.

2. What we collect

2.1 Account and organisation data

  • Name, email address and hashed password of each user.
  • Business name, and roles and permissions within the organisation.
  • Billing contact, invoices, payment references you record, and — where you are an Indonesian taxable entity — NPWP and NITKU.
  • Support correspondence you send us.

2.2 Site and camera configuration

  • Site name, address or label, timezone, opening and closing times.
  • Camera name, make and model where detected, local network address, and the counting lines and zones you draw.
  • Camera credentials. The username and password for your own camera are needed to read the stream. They are encrypted at rest with a key held in the application environment and never in the database, so a stolen database backup does not contain them. They are never shown back to a browser.

2.3 Count events — the main thing we hold

A count event is: a timestamp, which camera, which line or zone, a direction (in or out), and a number. That is all it is. There is no image, no identifier, no track that follows a person between visits, and nothing that distinguishes one visitor from another. Occupancy figures, dwell times, queue lengths and heat-map grids are all derived from the same kind of anonymous numbers.

Heat maps are a grid of numbers describing which parts of the camera's view were busy. They are not images and they contain no picture of anyone.

2.4 Setup frames — the honest exception

Roughly once every 60 seconds, per camera, the site software uploads one still JPEG frame to our server. Its only purpose is so that when you open the camera setup screen you see a current view of your doorway to draw a line on, rather than a view from whenever the camera was first connected.

  • A setup frame can contain images of people, because it is a photograph of your entrance.
  • It is not analysed, not matched against anything, and not used to identify anyone. The counting does not use it — counting happens on your own PC.
  • It is automatically deleted 30 days after capture, file and database record together.
  • It is visible only to signed-in users of your own organisation.

[TO CONFIRM: whether to offer a per-site switch to stop setup-frame uploads entirely — it would cost the calibration screen its live view]

2.5 Operational data

  • Health signals from your site software and cameras (online or offline, last seen, error text), so we can tell you a camera has stopped.
  • Server logs, including IP address and request metadata, for security and debugging.
  • Audit records of significant account actions such as invites, role changes and billing events.

2.6 What we do NOT collect

We want to be specific, because “we take your privacy seriously” is worth nothing:

  • No video recordings. Ever. Not for a minute, not as a buffer.
  • No live video passing through our servers in normal operation — see section 5.
  • No faces, face templates, face embeddings or any other biometric data.
  • No age, gender, ethnicity or emotion estimation. Not implemented, and deliberately not on the roadmap — it would drag the product into the biometric and sensitive-data category under UU PDP for a feature our customers rarely use.
  • No identification or re-identification of individuals, and no linking of a visit to a person, a phone, a MAC address, a loyalty card or a payment.
  • No audio. We do not read or record microphone input.
  • No tracking cookies, no advertising networks and no analytics trackers in the dashboard. [TO CONFIRM: verify no third-party analytics script has been added before this sentence is published]

3. Where processing happens

3.1 Counting runs on your premises, on a PC you own, against cameras on your own local network. This is a deliberate architecture decision, not a configuration option.

3.2 The hosted dashboard, the database and the reporting run on servers we operate at [TO CONFIRM: hosting provider and region, and whether data leaves Indonesia — UU PDP has cross-border transfer requirements]

4. Why we process it, and on what basis

WhatWhy
Account and organisation dataTo provide the service, authenticate you and support you — performance of our contract with you
Billing and tax dataTo invoice you and to meet Indonesian tax and accounting obligations — legal obligation
Site and camera configurationTo operate the service you asked for — performance of contract
Count events, occupancy, heat mapsTo produce the analytics you subscribed to — performance of contract
Setup framesTo let you configure counting lines against a current view — performance of contract
Health and log dataTo keep the service secure and working — our legitimate interest, and yours

[TO CONFIRM: UU PDP's lawful bases are not identical to the GDPR's — each row must be mapped to the correct Article 20 basis]

5. Live video

5.1 When you open a live camera view in the dashboard, the video is sent directly from your site to your browser. Our server only passes the two short connection-negotiation messages that let them find each other. The video does not pass through our servers and is not recorded by us.

5.2 On restrictive networks a relay server may be needed to carry the connection. This is switched off by default. If it is ever enabled for you, the video passes through the relay encrypted and is not stored. We will tell you before enabling it.

5.3 Remote live viewing across separate networks is a newer feature and has not yet been proven across two independent real-world networks. It may simply not connect. It never sends video to us either way.

6. Sharing and sub-processors

We do not sell data. We do not share it for advertising. We share it only with suppliers who help us run the service:

SupplierWhat they handleWhere
[TO CONFIRM: hosting provider]Hosting of the application, database and setup frames[TO CONFIRM: region]
[TO CONFIRM: email provider]Sending account emails and scheduled reports, which contain count figures and your site names[TO CONFIRM: region]
Browser push services (Google, Apple or Mozilla, depending on your browser)Delivering push notifications you have opted into. They see a routing token and the notification content.Operated by the browser vendor
  • We do not send anything to WhatsApp, and we do not store phone numbers for notifications. That feature was removed from the product in August 2026. Alerts and reports are delivered by email to the owners and admins of your account, and by browser push if you have enabled it.
  • We may also disclose information where we are legally required to, or to establish or defend legal claims. If we receive a legal demand for your data we will tell you unless we are prohibited from doing so. For video, there is nothing to give.
  • If our business is sold or merged, data may transfer to the buyer, subject to this policy.

7. How long we keep things

DataRetention
Setup frames and heat-map frames30 days, then automatically deleted
Count events and derived analyticsFor the life of the account — they are your business history and contain no imagery or personal identifier
Resolved alerts180 days
Camera-discovery records, which briefly hold a camera password, encrypted15 minutes
Account, organisation and configuration dataFor the life of the account
Invoices and tax recordsAs required by Indonesian tax law after the account closes — [TO CONFIRM: period]
Server logs[TO CONFIRM: period, and make log rotation match it]

After you close your account we keep your data for [TO CONFIRM: 30] days so you can export it, then delete it other than what tax law requires us to keep.

8. Security

  • Camera passwords are encrypted at rest with a key held outside the database.
  • Each site connects to our message broker with its own credentials, restricted to its own topics. [TO CONFIRM: a shared legacy credential is still enabled during migration — do not publish this line until the cutover is complete]
  • Traffic between your site, your browser and our servers is encrypted in transit.
  • Access to your organisation's data is limited to users you have invited, with the role you gave them.
  • Our own access to customer data is limited to what is needed for support and operations.
  • No system is perfectly secure. If a breach affects your personal data we will notify you and the authority as required by UU PDP. [TO CONFIRM: notification deadline and recipient]

9. Your rights and choices

You can ask us to:

  • Give you a copy of your data, including a machine-readable export of your count events;
  • Correct anything inaccurate;
  • Delete your data, subject to what we must keep for tax and legal reasons;
  • Stop a specific processing activity, or close your account entirely.

Write to [TO CONFIRM: privacy contact email]. We will respond within [TO CONFIRM: the period UU PDP requires]. We may need to verify who you are first.

If you were recorded by a camera in a shop that uses JoynVision and you want to exercise rights over that footage, contact the shop. They hold it; we do not. We will help them respond if they ask us to.

You can complain to us first, and to [TO CONFIRM: the supervisory authority designated under UU PDP].

10. Children

The service is sold to businesses and is not intended for children's use. Some customer premises — an arcade, a family restaurant — will have children walking past a camera. Those children are counted as anonymous numbers like anyone else, they are not identified, and any setup frame containing them is deleted after 30 days. Our customers are responsible for the lawfulness of operating cameras where children are present.

11. Changes to this policy

We may update this policy. The updated version will be posted here with a new date. For a material change we will notify your account email at least 30 days in advance.

12. Contact

[TO CONFIRM: entity, address, privacy contact email, and whether a Data Protection Officer must be appointed under UU PDP at this scale]

Terms of Service