A. Privacy by design
Privacy, controlled access and documented procedures are considered from the start of every engagement — during onboarding and service configuration, not as an afterthought. Camera selections, monitoring schedules and notification rules are agreed with the customer before monitoring begins, and the resulting configuration is documented.
B. Human verification
Automated detection is a starting point, not a conclusion. Trained analysts review relevant alerts, confirm what is visibly happening and follow the rules each customer has approved.
C. Controlled access
Access to customer video and account information is designed to be limited to the people who need it for the contracted service. Controls include:
- role-based access aligned to job function;
- least-privilege permissions, so accounts carry only the access they require;
- confidentiality obligations for personnel;
- documented access approvals;
- periodic access reviews;
- credential controls for accounts and connected platforms; and
- event logging, where configured and subject to the capabilities of the connected system.
D. Cross-border processing
Where the contracted service requires it, authorized service resources may access information from outside Canada. When this applies:
- cross-border processing is disclosed during contracting and onboarding;
- access is limited to approved functions;
- confidentiality and security controls apply; and
- contractual and operational documentation governs the arrangement.
Whether cross-border access applies depends on the specific service configuration — it is not universal across customers.
E. Customer-defined operating rules
Each customer approves the rules their service runs on, including:
- which cameras and zones are monitored;
- monitoring schedules;
- the observation scenarios that matter to their site;
- notification criteria;
- authorized contacts;
- escalation pathways; and
- actions that are explicitly prohibited.
F. Operating boundary
Our role is clear and deliberately limited: we provide information. Analysts observe, verify and notify — they do not direct activity on site and do not take operational control of any customer system. Offshore analysts do not independently dispatch anyone. Where the contracted service includes formal security response or emergency escalation, it follows approved Canadian pathways.
G. Data retention and deletion
Retention depends on the applicable service, the connected video system, contractual requirements and approved policies. Because these vary by customer and configuration, we do not publish universal retention periods. Retention and deletion expectations are documented during contracting and onboarding.
H. Camera and system health
Supported configurations may include oversight of camera connectivity, recording status and other aspects of system health, helping customers find out about problems such as offline cameras or blocked views sooner. Capabilities depend on the connected cameras, video platform and contracted service configuration.
I. Incident response
Visualitic maintains procedures for identifying, documenting, containing, investigating and escalating suspected information-security incidents. No provider can guarantee that incidents will never occur; our commitment is to respond in a structured, documented and timely way when they do.
J. Questions and related policies
For the formal terms that govern personal information collected through this website, see our Privacy Policy. For the terms governing use of this website, see the Website Terms of Use. To speak with us directly, use our contact page.
Have specific privacy or security requirements?
We are happy to walk through how these practices apply to your site and connected systems.
Discuss Your Privacy and Security Requirements