Legal
Antare Privacy Policy
Antare collects, uses, and protects personal data both in operating our own business and in providing our body-worn camera systems and associated software (the “Service”) to customers. This policy explains how we do so and the rights available to the individuals whose data we handle.
Version 1.0 · Effective date: 01 June 2026 · Last updated: 01 June 2026
Antare’s contracting entities
| Entity | Address | Role |
|---|---|---|
| Antare Technology Limited | 7 Bell Yard, London, England, WC2A 2JR | Contracts with customers outside the Americas |
| Antare Technology Inc. | 1177 Avenue of the Americas, New York, NY 10036, USA | Contracts with customers in the Americas |
Antare acts in two distinct roles depending on the data being processed:
- As a data processor for footage and related data generated by Antare Devices in customer deployments (“Customer Footage”). The customer is the controller and determines purposes, retention, and use. Part 1 describes this processing.
- As a data controller for personal data we collect in our own operations — including data about customer administrators, website visitors, marketing leads, and individuals who contact us directly. Part 2 describes this processing.
Part 3 sets out provisions that apply regardless of role, including international transfers, security, data subject rights, and complaints.
Related documents
- Cookie Policy — information about cookies and similar technologies used on Antare’s website and admin console.
- Master Services Agreement (MSA) — the contract governing customer use of the Service.
- Data Processing Agreement (DPA) — terms governing Antare’s processing of personal data on behalf of customers, referenced from the MSA.
Data Protection Officer: dpo@antare.ai
EU Representative under Article 27 GDPR: [to be confirmed]
Part 1 — Where Antare Acts as a Processor
1.1 Our Role
When customers deploy Antare body-worn cameras, fixed security cameras, docking systems, and associated software (“Antare Devices”), the resulting footage and related data (“Customer Footage”) includes the personal data of members of the public, employees, and other individuals captured during normal or continuous operation.
For Customer Footage, the customer is the data controller. Antare is the data processor. The customer determines the purposes and means of processing, including lawful basis, retention period, sharing, and use. Antare processes Customer Footage only on documented instructions from the customer, as set out in the Master Services Agreement and the associated Data Processing Agreement.
If you are a member of the public, a customer employee, or any other individual whose personal data appears in Customer Footage, your data protection rights are owed by the controller — the organization deploying Antare Devices. Section 1.5 explains how to exercise them.
1.2 Categories of Data Processed as Processor
| Category | Examples |
|---|---|
| Audio, video, and image footage | Continuous and event-triggered recordings made by Antare Devices |
| Biometric data (incidental) | Facial features and voice characteristics captured within footage |
| Location data | GPS coordinates and network-derived location at the resolution configured by the customer |
| Telemetry and device metadata | Device identifier, battery state, network status, recording timestamps |
| User and device assignment data | The customer’s authenticated user assigned to or associated with the device at the time of recording, where applicable |
| AI-derived data | Transcriptions, classifications, summaries, and other outputs generated from footage on customer instruction |
1.3 How We Process Customer Footage
Antare processes Customer Footage strictly on the documented instructions of the controller. Activities include secure upload, storage, retrieval, encryption, access control, audit logging, application of AI-driven analytics (transcription, event classification, search), service maintenance and diagnostics, security operations, and disclosure to legal authorities only where required by applicable law.
Antare does not access, view, or share Customer Footage for purposes outside the customer’s instructions, other than where required by law or necessary for the security and integrity of the Service.
1.4 AI and Machine Learning Training
Under the Master Services Agreement, customers grant Antare rights to use Customer Footage and associated data — including video, audio, biometric data, and AI-derived outputs — to train, improve, and develop Antare’s AI models and analytics. Customers may opt out of this use in writing.
Where such authorization is in place, Antare is the data controller and processing is carried out under Antare’s instructions and applicable data protection law. The lawful basis for such processing is determined by the controller. Footage subjects may exercise data protection rights against the controller. See Section 1.5 for how to exercise them.
Antare’s AI sub-processors (currently including OpenAI, AssemblyAI, and Google for image and video analysis services) are contractually prohibited from using Customer Footage to train their own models.
1.5 Rights of Footage Subjects
If you are an individual whose personal data appears in Customer Footage, your rights — including access, rectification, erasure, restriction, objection, and portability — are owed by the controller (the organization deploying the Antare Device). To exercise these rights, contact the controller directly.
If you do not know which organization is the controller, or are unable to reach them, you may contact Antare’s Data Protection Officer at dpo@antare.ai. Antare will identify the relevant controller where possible, route the request to them, and assist with fulfillment on their instruction. Antare cannot fulfill footage subject requests without controller authorization.
Where Antare Devices are deployed in workplaces or other employment contexts, employees and other individuals subject to monitoring should also refer to the controller’s workplace privacy notice and consultation arrangements alongside exercising their data protection rights.
You also have the right to lodge a complaint with a supervisory authority — see Section 3.6.
1.6 Retention of Customer Footage
Retention periods for Customer Footage are determined by the controller. Antare applies the retention configuration set by the customer.
Antare’s default configuration, applied unless the customer specifies otherwise:
| Data type | Default retention |
|---|---|
| Routine footage | 30 days |
| Footage flagged as evidence or incident | 90 days |
| Telemetry and metadata | 12 months |
| System and access logs | 24 months |
For continuous-capture deployments — including fixed security cameras — routine footage retention is typically configured by the customer at shorter intervals to reflect the higher volume and continuous nature of the data. The customer’s configured retention takes precedence over the defaults above.
After the retention period, data is deleted or anonymized by an automated lifecycle process. The full Data Retention Policy is referenced in the Data Processing Agreement.
1.7 Data Protection Impact Assessment
Antare has conducted a Data Protection Impact Assessment for high-risk processing activities, including biometric data processing and AI-driven analytics under customer instruction. The DPIA summary is available to controllers under NDA.
General security controls applicable to all processing — including encryption, access management, breach notification, and certification status — are described in Section 3.5.
Part 2 — Where Antare Acts as a Controller
2.1 Categories of Data Collected as Controller
Antare acts as a data controller for personal data we collect in our own operations — including data about customer administrators, website visitors, marketing leads, applicants, and individuals who contact us directly.
| Category | Examples | Source |
|---|---|---|
| Account and administrator data | Name, business email, telephone, job title, organization, role permissions | Customer onboarding, account self-service |
| Billing and contractual data | Billing contact, signatory details, payment-related information processed by payment provider | Customer, order forms |
| Website and product usage data | IP address, browser type, device identifiers, pages viewed, session activity | Automatic collection on website and admin console |
| Marketing data | Name, business email, organization, marketing preferences, consent records | Forms, events, demo requests |
| Support and communication data | Communications with Antare support, sales, or other staff | Emails, tickets, calls |
| Event and conference data | Name, organization, contact details, session attendance | Event registrations |
| Job application and recruitment data | Name, contact details, CV | Inbound CVs on website and recruitment portals |
| Inbound contact data | Name, business email, telephone, communications with Antare staff | Forms, emails |
2.2 Lawful Bases for Processing
| Purpose | Lawful basis (UK / EU GDPR) |
|---|---|
| Providing the Service, account management, customer support | Contract performance — Art 6(1)(b) |
| Service security, fraud prevention, system administration | Legitimate interests — Art 6(1)(f) |
| Product improvement and analytics (controller-scope only — not Customer Footage) | Legitimate interests — Art 6(1)(f) |
| Marketing communications | Consent — Art 6(1)(a), or legitimate interests for existing customers’ related services |
| Compliance with tax, regulatory, and law-enforcement obligations | Legal obligation — Art 6(1)(c) |
| Establishing, exercising, or defending legal claims | Legitimate interests — Art 6(1)(f) |
2.3 Special Category Data
Antare does not collect or process special category personal data (Article 9 GDPR) of customers, website visitors, or other controller-scope data subjects in the ordinary course of its business.
Where customers instruct Antare to process special category data on their behalf — including biometric and audio data within Customer Footage — Antare acts as a processor. The relevant terms are set out in Part 1 and the Data Processing Agreement.
2.4 How We Use Controller-Scope Data
We use this data to deliver, support, and bill for the Service; authenticate and manage user accounts; communicate with customers about service operation, security, and contractual matters; maintain and improve our website, marketing surfaces, and operational systems; send marketing communications to individuals who have opted in, with an unsubscribe option in every communication; conduct product analytics at controller-scope (excluding any Customer Footage); comply with legal, tax, and regulatory obligations; and establish, exercise, or defend legal claims.
Antare does not sell controller-scope personal data and does not share it with third parties for their own marketing purposes.
2.5 Automated Decision-Making
Antare does not make automated decisions producing legal effects, or similarly significant effects, on customers in its capacity as controller.
AI-generated outputs delivered to customers — such as transcriptions, classifications, and summaries — are informational. The customer is responsible for any consequential decision made on the basis of those outputs.
2.6 Retention of Controller-Scope Data
| Data type | Retention period |
|---|---|
| Active customer account data | Duration of contractual relationship + 6 months |
| Billing and tax records | 7 years from invoice date (UK / EU statutory requirement) |
| Contractual records (Order Forms, signed MSAs) | 7 years from termination |
| Marketing data | 36 months from last engagement, or earlier on consent withdrawal |
| Marketing consent withdrawal records | 6 years (evidence of compliance) |
| Support and communications | 24 months from closure |
| Website analytics | 14 months |
| System and access logs | 12–24 months depending on log type |
Aggregated and anonymized data may be retained indefinitely.
2.7 Processors
Antare engages third-party processors for the operation of day-to-day business activities including cloud hosting, AI infrastructure, customer relationship management, analytics, payment processing, and communications platforms.
A current list of sub-processors and their processing regions is available to enterprise customers on request under non-disclosure agreement. We notify affected customers of material sub-processor changes in advance.
Part 3 — Provisions Applying Regardless of Role
3.1 International Transfers
Antare operates from two entities — Antare Technology Limited (UK) and Antare Technology Inc. (United States). Personal data processed under this policy may be transferred between these entities and to sub-processors located in the United Kingdom, European Economic Area, United States, or other jurisdictions where our hosting and infrastructure providers operate.
Where customers elect a specific hosting region (UK, EU, or US) for Customer Footage and associated data, Antare applies that election and data remains within the elected region for the duration of the customer’s instructions.
Where personal data of UK or EEA data subjects is transferred to a jurisdiction without an adequacy decision, Antare relies on appropriate safeguards under Chapter V of the UK and EU GDPR, including the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, and the EU-US, UK Extension, and Swiss-US Data Privacy Frameworks where Antare or its sub-processors are certified.
Transfer Impact Assessments are conducted in line with Schrems II and equivalent UK ICO guidance, and are available to controllers under NDA.
3.2 Children’s Data
Antare does not knowingly collect personal data from children under the age of 18 in its capacity as data controller.
Where Antare Devices incidentally capture minors as footage subjects, the controller is responsible for the lawful basis for that processing and for any additional protections required under applicable law, including parental consent where applicable.
3.3 Data Subject Rights
You have the following rights in relation to your personal data:
- Access your personal data and obtain a copy
- Rectification of inaccurate or incomplete personal data
- Erasure in certain circumstances (“right to be forgotten”)
- Restriction of processing in certain circumstances
- Objection to processing where Antare relies on legitimate interests
- Data portability for data you provided under contract or consent
- Withdrawal of consent at any time where consent is the lawful basis, as easily as it was given
- The right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects on you
To exercise any of these rights as a controller-scope data subject, contact Antare’s Data Protection Officer at dpo@antare.ai. For footage subject requests, see Section 1.5.
Antare will verify the identity of the requestor before fulfilling a request. We will respond within one month of receipt, extended by a further two months for complex or numerous requests with prior notice.
You also have the right to lodge a complaint with a supervisory authority — see Section 3.6.
3.4 California and Other US State Privacy Rights
If you are a resident of California or another US state that grants comparable privacy rights — including Virginia, Colorado, Connecticut, Utah, and other states with similar laws — you have the following rights with respect to controller-scope personal information:
- The right to know what personal information we collect, use, and disclose
- Access to a copy of your personal information
- Deletion of your personal information
- Correction of inaccurate personal information
- Opt-out of the sale or sharing of personal information for cross-context behavioural advertising
- Limit the use of sensitive personal information
Antare does not sell or share personal information for cross-context behavioural advertising. We do not discriminate against individuals for exercising these rights.
To exercise these rights, contact dpo@antare.ai. You may use an authorized agent — please provide written authorization when submitting through an agent. For information specific to Customer Footage, contact the controller.
3.5 Security
Antare maintains technical and organizational security measures appropriate to the risk of the processing, including:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
- Role-based access controls and multi-factor authentication
- Audit logging and integrity verification
- Regional data isolation in accordance with customer election
- Secure deletion and automated lifecycle management
- Sub-processor risk management and contractual security obligations
- Personnel security training and access reviews
Antare is in the final stages of independent security certification. ISO 27001 Stage 1 audit is complete, as is SOC 2 Type I. ISO 27001 Stage 2 audit and SOC 2 Type II report are targeted for Q3 2026, ahead of general availability.
Where a personal data breach occurs in Antare’s systems, Antare will notify affected controllers without undue delay, and in any event within 72 hours of becoming aware of the breach, in accordance with the Data Processing Agreement. Where Antare is the controller and notification is required by law, Antare will notify supervisory authorities within 72 hours and data subjects directly without undue delay where required.
3.6 Complaints
If you have a concern about how Antare processes your personal data, contact the Data Protection Officer at dpo@antare.ai in the first instance.
You also have the right to lodge a complaint with a supervisory authority:
- United Kingdom — Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline: 0303 123 1113. ico.org.uk
- European Economic Area — the data protection authority of the EEA member state where you live, work, or where the alleged infringement occurred. A list is maintained at edpb.europa.eu
- Switzerland — Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
- United States — your State Attorney General, or where applicable the California Privacy Protection Agency
3.7 Cookies
Antare uses cookies and similar technologies on our website and admin console. For full information, including the categories of cookies we use and how to manage your preferences, see our Cookie Policy at [antare.ai/cookies — to be confirmed].
3.8 Changes to This Policy
Antare may update this Privacy Policy from time to time. The current version and effective date are shown at the top of the policy.
Material changes will be notified to customers in advance through their account or by direct communication. Previous versions are available on request.
3.9 Contact
- Data Protection Officer — dpo@antare.ai
- EU Representative under Article 27 — Please contact dpo@antare.ai for more information
- Antare Technology Limited (UK) — 7 Bell Yard, London, England, WC2A 2JR
- Antare Technology Inc. (US) — 1177 Avenue of the Americas, New York, NY 10036, USA