Privacy Policy
Last updated: May 2026
What we collect
When you use RMADOR, we collect information you provide directly — such as your name, email address, phone number, and company details when you request a demo or create an account. We also collect usage data such as which features are accessed, alert counts, and platform performance metrics, to improve the service.
What we never collect
Video footage from your cameras never leaves your site. RMADOR processes camera feeds on your local hardware (Air-Gap plan) or on our dedicated servers (Cloud plan), but raw video is never stored, transmitted, or retained by RMADOR. We do not collect biometric data, facial recognition data, or licence plate information off-site.
Cookies and tracking
Our marketing website (rmador.com) uses strictly necessary cookies to maintain your session and remember your preferences. We do not use advertising or cross-site tracking cookies. We use privacy-preserving analytics to understand aggregate page traffic — no individual visitors are identified or profiled. You can disable non-essential cookies in your browser settings without affecting core site functionality.
How we use your data
We use the information we collect to operate and improve the platform, respond to support and sales requests, send product updates you have opted into, and meet our legal obligations. We do not sell, rent, or trade your personal data to third parties for marketing purposes.
Data sharing
We share data with service providers who help us operate RMADOR, including cloud infrastructure providers, payment processors, and customer support tools. These providers are contractually bound to use data only for the services they provide to us and are prohibited from using it for their own purposes. We may disclose information where required by law, in which case we will notify you where permitted to do so.
International data transfers
RMADOR is headquartered in Canada. If you are located in the European Economic Area, the United Kingdom, or other jurisdictions with data transfer restrictions, your personal data may be transferred to Canada, which the European Commission has determined provides adequate protection under GDPR. Where we transfer data to processors in other countries, we use Standard Contractual Clauses or equivalent safeguards approved by the relevant data protection authority.
Data retention
Alert metadata and audit logs are retained for 7 years by default to support compliance and legal review requirements. Account and contact data is retained for the life of your subscription plus 90 days after cancellation, after which it is permanently deleted. You may request earlier deletion by contacting [email protected].
Your rights
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. To exercise any of these rights, email [email protected]. We will respond within 30 days. If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.
Automated decisions
RMADOR's platform makes automated decisions that may have physical consequences — including raising vehicle barriers and dispatching emergency services. These decisions are based on AI threat scoring derived from sensor data. You can configure the thresholds at which automated actions trigger, and all automated decisions are logged with full sensor context so they can be reviewed and contested. No automated action is taken solely on the basis of personal data such as facial recognition or identity — all decisions are based on behavioural and sensor patterns.
AI model improvement
With your explicit consent, anonymised performance data from your deployment may contribute to improving RMADOR's detection models. This data contains no video, no identifying information, and no location data — only aggregate performance metrics. Consent can be withdrawn at any time from your account settings. Revoking consent does not affect the operation of your system.
Security
We protect personal data using industry-standard security measures including TLS 1.3 encryption in transit, AES-256 encryption at rest, and access controls that follow the principle of least privilege. For more information, see our Security page.
Data breach notification
If we become aware of a security incident that affects your personal data, we will notify you without undue delay and within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Notification will include the nature of the breach, the categories of data affected, likely consequences, and the measures we have taken or propose to take. We will also notify the relevant supervisory authority where required by law.
Contact
For privacy questions or to exercise your rights, email [email protected]. For general enquiries, visit our Contact page. This policy was last updated in May 2026.