Privacy Policy
Effective date: August 19, 2026
This Privacy Policy explains what personal data Cordatus B.V. ("Cordatus", "we", "us") collects, how and why we use it, with whom we share it, and the rights you have. It applies to the Cordatus web dashboard (cordatus.ai, app.cordatus.ai), the Cordatus desktop/edge client, our APIs, and related services (the "Services"). The short version at the start of each section is a plain-language summary of the full text.
Data controller: Cordatus B.V., High Tech Campus 9, 5656 AE Eindhoven, The Netherlands · KvK No. 42058021 · support@cordatus.ai. For personal data we process on behalf of business customers (see Section 2), the customer is the controller and Cordatus is the processor.
Summary
| Section | What it covers |
|---|---|
| 1. Data We Collect | Account, usage, and device telemetry |
| 2. Camera & Video Data | Who controls video of people |
| 3. How We Use Data | Purposes |
| 4. Legal Bases | GDPR grounds |
| 5. How We Share Data | Sub-processors; we don't sell data |
| 6. International Transfers | SCCs / adequacy |
| 7. Retention | How long we keep data |
| 8. Security | How we protect data |
| 9. Your Rights | Access, deletion, KVKK |
| 10. Marketing | Opt out anytime |
| 11. Children | Not for children |
| 12. Contact | How to reach us |
| 13. Changes | Updates |
1. Data We Collect
Short version: Account details you give us, usage/log data, and technical telemetry from the edge devices you connect. CPU/GPU usage is measured on the fly and not stored.
Data you provide: name, email, password (stored hashed), organization, role; optional profile details; billing details for paid plans (payment data is handled by our payment provider — we don't store full card numbers); the content of your communications with us; and device names you assign.
Data collected automatically: log/usage data (IP address, client/browser type, device identifiers, OS, language, timestamps, actions in the Services); edge-device telemetry (device ID, manufacturer/model/version such as Jetson/JetPack, CPU/GPU brand/model/architecture/ cores, OS, storage info) used to deliver platform-appropriate content and assess workload capacity; Remote Access Tunnel (RAT) records (tunnel URL, creation/deletion times, creating IP and user ID, data transferred); and cookies (see our Cookie Policy). CPU/GPU utilization is measured on the fly for scheduling and is not stored as history.
Data from other sources: if you sign in through or connect a third-party service, we may receive basic profile information as you authorize.
2. Camera, Video, and Inference Data (Important)
Short version: If you connect cameras, we process video and detection data that may include people. For that data, you are the controller and we are your processor.
If you use recording or analytics features, the Services process video streams, recorded segments, images, object-detection metadata (e.g. bounding boxes), and inference logs, which may contain personal data of individuals captured by your cameras. For this data:
- You are the controller and Cordatus is a processor, processing only on your instructions under a Data Processing Agreement.
- You are responsible for a lawful basis, notices/consents, signage, and compliance with surveillance and workplace-monitoring laws.
- Storage may be on your edge device, in storage you control, or in cloud object storage (e.g. MinIO/S3). In on-premise/air-gapped deployments, video may never leave your environment.
- Live streams and remote access use WebRTC; media is transmitted peer-to-peer and is not routinely proxied or stored by our servers.
- Retention follows the settings you configure.
3. How and Why We Use Data
Short version: To provide, secure, and improve the Services, communicate with you, and meet legal obligations.
We use personal data to provide the Services (accounts, licences, device management, workloads, payments); secure and maintain them (authentication, fraud/abuse and incident prevention, debugging); improve them; communicate with you (service, security, and account notices, support, and — where permitted — marketing you can opt out of); and comply with legal obligations and enforce our Terms.
4. Legal Bases (GDPR)
Short version: Contract, legitimate interests, consent, and legal obligation.
We rely on: performance of a contract (to provide the Services and administer your account/licences); legitimate interests (to secure, maintain, and improve the Services and prevent abuse, balanced against your rights); consent (for non-essential cookies and certain marketing — you can withdraw anytime); and legal obligation.
5. How We Share Data
Short version: We don't sell your data. We share it with vetted service providers and when legally required.
We do not sell personal data. We share it with: service providers / sub-processors under contract (cloud hosting and object storage, message-queue infrastructure, email delivery, payment processing, and bot/abuse protection such as Google reCAPTCHA on sign-in/registration); third-party model registries (e.g. NVIDIA NGC, Hugging Face) as one-way model retrievals (no personal data sent to them); legal and safety recipients in response to valid legal requests or to protect rights and safety; business transfers (with this Policy continuing to apply); and others with your consent.
6. International Transfers
Short version: We're EU-based; transfers outside the EEA use adequacy decisions or SCCs. We do not rely on the invalidated Privacy Shield.
Where we transfer personal data outside the EEA, we rely on European Commission adequacy decisions or Standard Contractual Clauses (SCCs) with supplementary measures as needed.
7. Data Retention
Short version: We keep data only as long as needed or legally required.
Examples: server/access logs ~30 days; RAT records up to 365 days after deletion, with backups retained for a limited additional period; account data for the life of your account (with limited retention afterward for legal/business needs); video recordings per your configured settings.
8. Security
Short version: We use encryption in transit, access controls, and monitoring — but no system is 100% secure.
We apply reasonable technical and organizational measures, including encryption in transit (TLS/SSL), access controls, and role-based permissions, and we continuously monitor and improve our safeguards.
9. Your Rights
Short version: You can access, correct, delete, restrict, object, and port your data, and complain to a supervisory authority.
Depending on your location, you may have the rights to access, correct, delete, restrict, or object to processing; data portability; and to withdraw consent. In the Netherlands you may complain to the Autoriteit Persoonsgegevens. Use your account settings or contact us (Section 12); we may verify your identity first. If you are captured by a customer's cameras, direct requests to that customer (controller); we assist as processor.
Turkey (KVKK): if your data is subject to Turkish Law No. 6698 (KVKK), Cordatus B.V. acts as data controller ("veri sorumlusu"). You have the rights set out in Article 11 of the KVKK (including to learn whether your data is processed, request information, correction, or erasure, and object to results of solely automated analysis). Submit KVKK requests to support@cordatus.ai; you may also complain to the Turkish Data Protection Authority (KVKK).
10. Marketing Choices
Short version: Opt out of marketing anytime; we don't run an ad network.
You can opt out of marketing at any time via the unsubscribe link or by contacting us. We will still send essential service and account messages. We do not operate an advertising network and do not use your data to serve third-party ads.
11. Children
Short version: Not for children.
The Services are intended for business/professional use and are not directed to children. We do not knowingly collect data from children.
12. Contact Us
Cordatus B.V. · High Tech Campus 9, 5656 AE Eindhoven, The Netherlands · KvK No. 42058021 Email: support@cordatus.ai (response within 24 hours)
13. Changes to This Policy
We may update this Policy from time to time. Material changes will be indicated by a new effective date and, where appropriate, by email or an in-dashboard notice.