Antare

Legal

Antare Privacy Policy

Antare collects, uses, and protects personal data both in operating our own business and in providing our body-worn camera systems and associated software (the “Service”) to customers. This policy explains how we do so and the rights available to the individuals whose data we handle.

Version 1.0 · Effective date: 01 June 2026 · Last updated: 01 June 2026

Antare’s contracting entities

EntityAddressRole
Antare Technology Limited7 Bell Yard, London, England, WC2A 2JRContracts with customers outside the Americas
Antare Technology Inc.1177 Avenue of the Americas, New York, NY 10036, USAContracts with customers in the Americas

Antare acts in two distinct roles depending on the data being processed:

  • As a data processor for footage and related data generated by Antare Devices in customer deployments (“Customer Footage”). The customer is the controller and determines purposes, retention, and use. Part 1 describes this processing.
  • As a data controller for personal data we collect in our own operations — including data about customer administrators, website visitors, marketing leads, and individuals who contact us directly. Part 2 describes this processing.

Part 3 sets out provisions that apply regardless of role, including international transfers, security, data subject rights, and complaints.

Related documents

  • Cookie Policy — information about cookies and similar technologies used on Antare’s website and admin console.
  • Master Services Agreement (MSA) — the contract governing customer use of the Service.
  • Data Processing Agreement (DPA) — terms governing Antare’s processing of personal data on behalf of customers, referenced from the MSA.

Data Protection Officer: dpo@antare.ai

EU Representative under Article 27 GDPR: [to be confirmed]

Part 1 — Where Antare Acts as a Processor

1.1 Our Role

When customers deploy Antare body-worn cameras, fixed security cameras, docking systems, and associated software (“Antare Devices”), the resulting footage and related data (“Customer Footage”) includes the personal data of members of the public, employees, and other individuals captured during normal or continuous operation.

For Customer Footage, the customer is the data controller. Antare is the data processor. The customer determines the purposes and means of processing, including lawful basis, retention period, sharing, and use. Antare processes Customer Footage only on documented instructions from the customer, as set out in the Master Services Agreement and the associated Data Processing Agreement.

If you are a member of the public, a customer employee, or any other individual whose personal data appears in Customer Footage, your data protection rights are owed by the controller — the organization deploying Antare Devices. Section 1.5 explains how to exercise them.

1.2 Categories of Data Processed as Processor

CategoryExamples
Audio, video, and image footageContinuous and event-triggered recordings made by Antare Devices
Biometric data (incidental)Facial features and voice characteristics captured within footage
Location dataGPS coordinates and network-derived location at the resolution configured by the customer
Telemetry and device metadataDevice identifier, battery state, network status, recording timestamps
User and device assignment dataThe customer’s authenticated user assigned to or associated with the device at the time of recording, where applicable
AI-derived dataTranscriptions, classifications, summaries, and other outputs generated from footage on customer instruction

1.3 How We Process Customer Footage

Antare processes Customer Footage strictly on the documented instructions of the controller. Activities include secure upload, storage, retrieval, encryption, access control, audit logging, application of AI-driven analytics (transcription, event classification, search), service maintenance and diagnostics, security operations, and disclosure to legal authorities only where required by applicable law.

Antare does not access, view, or share Customer Footage for purposes outside the customer’s instructions, other than where required by law or necessary for the security and integrity of the Service.

1.4 AI and Machine Learning Training

Under the Master Services Agreement, customers grant Antare rights to use Customer Footage and associated data — including video, audio, biometric data, and AI-derived outputs — to train, improve, and develop Antare’s AI models and analytics. Customers may opt out of this use in writing.

Where such authorization is in place, Antare is the data controller and processing is carried out under Antare’s instructions and applicable data protection law. The lawful basis for such processing is determined by the controller. Footage subjects may exercise data protection rights against the controller. See Section 1.5 for how to exercise them.

Antare’s AI sub-processors (currently including OpenAI, AssemblyAI, and Google for image and video analysis services) are contractually prohibited from using Customer Footage to train their own models.

1.5 Rights of Footage Subjects

If you are an individual whose personal data appears in Customer Footage, your rights — including access, rectification, erasure, restriction, objection, and portability — are owed by the controller (the organization deploying the Antare Device). To exercise these rights, contact the controller directly.

If you do not know which organization is the controller, or are unable to reach them, you may contact Antare’s Data Protection Officer at dpo@antare.ai. Antare will identify the relevant controller where possible, route the request to them, and assist with fulfillment on their instruction. Antare cannot fulfill footage subject requests without controller authorization.

Where Antare Devices are deployed in workplaces or other employment contexts, employees and other individuals subject to monitoring should also refer to the controller’s workplace privacy notice and consultation arrangements alongside exercising their data protection rights.

You also have the right to lodge a complaint with a supervisory authority — see Section 3.6.

1.6 Retention of Customer Footage

Retention periods for Customer Footage are determined by the controller. Antare applies the retention configuration set by the customer.

Antare’s default configuration, applied unless the customer specifies otherwise:

Data typeDefault retention
Routine footage30 days
Footage flagged as evidence or incident90 days
Telemetry and metadata12 months
System and access logs24 months

For continuous-capture deployments — including fixed security cameras — routine footage retention is typically configured by the customer at shorter intervals to reflect the higher volume and continuous nature of the data. The customer’s configured retention takes precedence over the defaults above.

After the retention period, data is deleted or anonymized by an automated lifecycle process. The full Data Retention Policy is referenced in the Data Processing Agreement.

1.7 Data Protection Impact Assessment

Antare has conducted a Data Protection Impact Assessment for high-risk processing activities, including biometric data processing and AI-driven analytics under customer instruction. The DPIA summary is available to controllers under NDA.

General security controls applicable to all processing — including encryption, access management, breach notification, and certification status — are described in Section 3.5.

Part 2 — Where Antare Acts as a Controller

2.1 Categories of Data Collected as Controller

Antare acts as a data controller for personal data we collect in our own operations — including data about customer administrators, website visitors, marketing leads, applicants, and individuals who contact us directly.

CategoryExamplesSource
Account and administrator dataName, business email, telephone, job title, organization, role permissionsCustomer onboarding, account self-service
Billing and contractual dataBilling contact, signatory details, payment-related information processed by payment providerCustomer, order forms
Website and product usage dataIP address, browser type, device identifiers, pages viewed, session activityAutomatic collection on website and admin console
Marketing dataName, business email, organization, marketing preferences, consent recordsForms, events, demo requests
Support and communication dataCommunications with Antare support, sales, or other staffEmails, tickets, calls
Event and conference dataName, organization, contact details, session attendanceEvent registrations
Job application and recruitment dataName, contact details, CVInbound CVs on website and recruitment portals
Inbound contact dataName, business email, telephone, communications with Antare staffForms, emails

2.2 Lawful Bases for Processing

PurposeLawful basis (UK / EU GDPR)
Providing the Service, account management, customer supportContract performance — Art 6(1)(b)
Service security, fraud prevention, system administrationLegitimate interests — Art 6(1)(f)
Product improvement and analytics (controller-scope only — not Customer Footage)Legitimate interests — Art 6(1)(f)
Marketing communicationsConsent — Art 6(1)(a), or legitimate interests for existing customers’ related services
Compliance with tax, regulatory, and law-enforcement obligationsLegal obligation — Art 6(1)(c)
Establishing, exercising, or defending legal claimsLegitimate interests — Art 6(1)(f)

2.3 Special Category Data

Antare does not collect or process special category personal data (Article 9 GDPR) of customers, website visitors, or other controller-scope data subjects in the ordinary course of its business.

Where customers instruct Antare to process special category data on their behalf — including biometric and audio data within Customer Footage — Antare acts as a processor. The relevant terms are set out in Part 1 and the Data Processing Agreement.

2.4 How We Use Controller-Scope Data

We use this data to deliver, support, and bill for the Service; authenticate and manage user accounts; communicate with customers about service operation, security, and contractual matters; maintain and improve our website, marketing surfaces, and operational systems; send marketing communications to individuals who have opted in, with an unsubscribe option in every communication; conduct product analytics at controller-scope (excluding any Customer Footage); comply with legal, tax, and regulatory obligations; and establish, exercise, or defend legal claims.

Antare does not sell controller-scope personal data and does not share it with third parties for their own marketing purposes.

2.5 Automated Decision-Making

Antare does not make automated decisions producing legal effects, or similarly significant effects, on customers in its capacity as controller.

AI-generated outputs delivered to customers — such as transcriptions, classifications, and summaries — are informational. The customer is responsible for any consequential decision made on the basis of those outputs.

2.6 Retention of Controller-Scope Data

Data typeRetention period
Active customer account dataDuration of contractual relationship + 6 months
Billing and tax records7 years from invoice date (UK / EU statutory requirement)
Contractual records (Order Forms, signed MSAs)7 years from termination
Marketing data36 months from last engagement, or earlier on consent withdrawal
Marketing consent withdrawal records6 years (evidence of compliance)
Support and communications24 months from closure
Website analytics14 months
System and access logs12–24 months depending on log type

Aggregated and anonymized data may be retained indefinitely.

2.7 Processors

Antare engages third-party processors for the operation of day-to-day business activities including cloud hosting, AI infrastructure, customer relationship management, analytics, payment processing, and communications platforms.

A current list of sub-processors and their processing regions is available to enterprise customers on request under non-disclosure agreement. We notify affected customers of material sub-processor changes in advance.

Part 3 — Provisions Applying Regardless of Role

3.1 International Transfers

Antare operates from two entities — Antare Technology Limited (UK) and Antare Technology Inc. (United States). Personal data processed under this policy may be transferred between these entities and to sub-processors located in the United Kingdom, European Economic Area, United States, or other jurisdictions where our hosting and infrastructure providers operate.

Where customers elect a specific hosting region (UK, EU, or US) for Customer Footage and associated data, Antare applies that election and data remains within the elected region for the duration of the customer’s instructions.

Where personal data of UK or EEA data subjects is transferred to a jurisdiction without an adequacy decision, Antare relies on appropriate safeguards under Chapter V of the UK and EU GDPR, including the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, and the EU-US, UK Extension, and Swiss-US Data Privacy Frameworks where Antare or its sub-processors are certified.

Transfer Impact Assessments are conducted in line with Schrems II and equivalent UK ICO guidance, and are available to controllers under NDA.

3.2 Children’s Data

Antare does not knowingly collect personal data from children under the age of 18 in its capacity as data controller.

Where Antare Devices incidentally capture minors as footage subjects, the controller is responsible for the lawful basis for that processing and for any additional protections required under applicable law, including parental consent where applicable.

3.3 Data Subject Rights

You have the following rights in relation to your personal data:

  • Access your personal data and obtain a copy
  • Rectification of inaccurate or incomplete personal data
  • Erasure in certain circumstances (“right to be forgotten”)
  • Restriction of processing in certain circumstances
  • Objection to processing where Antare relies on legitimate interests
  • Data portability for data you provided under contract or consent
  • Withdrawal of consent at any time where consent is the lawful basis, as easily as it was given
  • The right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects on you

To exercise any of these rights as a controller-scope data subject, contact Antare’s Data Protection Officer at dpo@antare.ai. For footage subject requests, see Section 1.5.

Antare will verify the identity of the requestor before fulfilling a request. We will respond within one month of receipt, extended by a further two months for complex or numerous requests with prior notice.

You also have the right to lodge a complaint with a supervisory authority — see Section 3.6.

3.4 California and Other US State Privacy Rights

If you are a resident of California or another US state that grants comparable privacy rights — including Virginia, Colorado, Connecticut, Utah, and other states with similar laws — you have the following rights with respect to controller-scope personal information:

  • The right to know what personal information we collect, use, and disclose
  • Access to a copy of your personal information
  • Deletion of your personal information
  • Correction of inaccurate personal information
  • Opt-out of the sale or sharing of personal information for cross-context behavioural advertising
  • Limit the use of sensitive personal information

Antare does not sell or share personal information for cross-context behavioural advertising. We do not discriminate against individuals for exercising these rights.

To exercise these rights, contact dpo@antare.ai. You may use an authorized agent — please provide written authorization when submitting through an agent. For information specific to Customer Footage, contact the controller.

3.5 Security

Antare maintains technical and organizational security measures appropriate to the risk of the processing, including:

  • Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
  • Role-based access controls and multi-factor authentication
  • Audit logging and integrity verification
  • Regional data isolation in accordance with customer election
  • Secure deletion and automated lifecycle management
  • Sub-processor risk management and contractual security obligations
  • Personnel security training and access reviews

Antare is in the final stages of independent security certification. ISO 27001 Stage 1 audit is complete, as is SOC 2 Type I. ISO 27001 Stage 2 audit and SOC 2 Type II report are targeted for Q3 2026, ahead of general availability.

Where a personal data breach occurs in Antare’s systems, Antare will notify affected controllers without undue delay, and in any event within 72 hours of becoming aware of the breach, in accordance with the Data Processing Agreement. Where Antare is the controller and notification is required by law, Antare will notify supervisory authorities within 72 hours and data subjects directly without undue delay where required.

3.6 Complaints

If you have a concern about how Antare processes your personal data, contact the Data Protection Officer at dpo@antare.ai in the first instance.

You also have the right to lodge a complaint with a supervisory authority:

  • United Kingdom — Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Helpline: 0303 123 1113. ico.org.uk
  • European Economic Area — the data protection authority of the EEA member state where you live, work, or where the alleged infringement occurred. A list is maintained at edpb.europa.eu
  • Switzerland — Federal Data Protection and Information Commissioner (FDPIC) — edoeb.admin.ch
  • United States — your State Attorney General, or where applicable the California Privacy Protection Agency

3.7 Cookies

Antare uses cookies and similar technologies on our website and admin console. For full information, including the categories of cookies we use and how to manage your preferences, see our Cookie Policy at [antare.ai/cookies — to be confirmed].

3.8 Changes to This Policy

Antare may update this Privacy Policy from time to time. The current version and effective date are shown at the top of the policy.

Material changes will be notified to customers in advance through their account or by direct communication. Previous versions are available on request.

3.9 Contact

  • Data Protection Officer — dpo@antare.ai
  • EU Representative under Article 27 — Please contact dpo@antare.ai for more information
  • Antare Technology Limited (UK) — 7 Bell Yard, London, England, WC2A 2JR
  • Antare Technology Inc. (US) — 1177 Avenue of the Americas, New York, NY 10036, USA