OtsoVision
How it works Features Pricing FAQ
Log in Get started →
How Features Pricing FAQ

Data processing agreement

Last updated: 2026-09-18. Effective from 2026-09-18. This Data Processing Agreement ("DPA") is concluded under Article 28(3) of Regulation (EU) 2016/679 (GDPR). It forms part of the agreement between you (the customer, "Controller") and Otsovision Oy ("Processor", "we") for the use of OtsoVision, and prevails over any conflicting provision of those terms regarding personal-data processing carried out on your behalf.

1. Subject-matter and purpose

The Controller uses OtsoVision to ingest, store, classify and present images captured by trail cameras the Controller owns or operates. The Processor processes any personal data contained in those images (e.g. images of bystanders, vehicle plates, neighbours) only to the extent strictly necessary to provide the service and only on documented instructions from the Controller, namely these terms, the Data Processing Agreement and the configuration the Controller selects in the application.

This DPA does not cover the selection and anonymisation of game-species images for the research dataset described in section 4a of the Privacy Notice: for that step the Processor acts as an independent controller on its own legal basis and not on the Controller's instructions, and the resulting dataset contains no personal data.

2. Duration

This DPA applies for as long as the Processor processes personal data on behalf of the Controller, that is, for the duration of the Controller's OtsoVision subscription and any post-termination retention period set out in section 7 of our Privacy & Cookies Policy.

3. Nature and scope of processing

  • Operations performed: receipt of camera-uploaded images via SMTP/REST, secure storage, image-classification inference, thumbnail generation, on-demand retrieval, sharing with users authorised by the Controller, deletion on request, classification of every species the model recognises.
  • Categories of data subject: persons whose likeness, vehicle, voice or other identifying information may be captured by the Controller's cameras (typically incidental bystanders).
  • Categories of personal data: images, image timestamps, GPS coordinates if the camera records them, and AI-derived classifications.
  • Special categories: images may incidentally include features that could be classed as biometric (Article 9 GDPR) if used for identification. The Processor does not attempt to identify individuals; the species classifier is a generic object-recognition model and does not maintain templates of individual humans.

4. Obligations of the Processor

The Processor:

  1. processes personal data only on documented instructions from the Controller, including with regard to transfers to a third country, unless required to do so by EU or Member-State law (in which case it informs the Controller before processing, unless the law prohibits such information on important grounds of public interest) (the research-dataset step described in section 1 is outside these instructions);
  2. ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  3. takes all measures required pursuant to Article 32 GDPR (see Annex II below);
  4. respects the conditions of section 5 below for engaging another processor;
  5. taking into account the nature of the processing, assists the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling its obligation to respond to data-subject requests under Chapter III of the GDPR;
  6. assists the Controller in ensuring compliance with Articles 32 to 36 GDPR taking into account the nature of processing and the information available to the Processor;
  7. at the choice of the Controller, deletes or returns all the personal data to the Controller after the end of the provision of services and deletes existing copies, unless EU or Member-State law requires storage of the personal data;
  8. makes available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller (see section 7 below);
  9. immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member-State data-protection provisions.

5. Sub-processors

The Controller authorises the engagement of the sub-processors listed in Annex I. The Processor will inform the Controller of any intended addition or replacement at least 30 days in advance, giving the Controller the opportunity to object on reasonable data-protection grounds; if such an objection cannot be resolved, the Controller may terminate the affected service for cause. Each sub-processor is bound by a written contract that imposes data-protection obligations no less protective than those set out in this DPA.

6. International transfers

All processing carried out by the Processor under this DPA, including all storage and all backups, takes place on infrastructure located in the EU/EEA. No sub-processor listed in Annex I operates outside the EU/EEA, so no transfer mechanism under Chapter V GDPR is required. Should the Processor ever need to engage a sub-processor outside the EU/EEA, it will notify the Controller in advance under section 5 and will not begin such processing without an adequacy decision or the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 in place.

7. Audit rights

The Controller may, no more than once every twelve months and upon at least 30 days' notice, request information reasonably necessary to verify the Processor's compliance with this DPA. Where additional inspection is justified, the Controller (or an independent auditor it mandates and which is not a competitor of the Processor) may conduct an on-site or remote audit at the Controller's expense, during business hours, with reasonable disruption to operations and subject to confidentiality undertakings. The Processor will provide reasonable cooperation; recent third-party security reports, where they cover the Controller's questions, may be relied upon in lieu of duplicating such audits.

8. Personal-data breach

The Processor will notify the Controller without undue delay (and in any event within 48 hours) of becoming aware of a personal-data breach affecting the Controller's data, providing the information required by Article 33(3) GDPR insofar as it is then known and supplementing the notification as further information becomes available. The Processor will assist the Controller, taking into account the nature of processing and the information available to the Processor, in meeting the Controller's own obligations under Articles 33 and 34 GDPR.

9. Return and deletion

On termination of the service, the Processor will, at the Controller's documented choice, either return all personal data or irreversibly delete it within 30 days, except to the extent that EU or Member-State law requires further storage (e.g. accounting records under Finnish law, see Privacy & Cookies Policy section 7). The Processor will provide written confirmation of deletion on request.

Deletion does not extend to anonymised research datasets already delivered under section 4a of the Privacy Notice, which contain no personal data.

10. Liability

Each party is liable for breaches of its own obligations under the GDPR and this DPA. Compensation between the parties for damages arising from a breach is governed by the limits set out in the underlying service agreement, except where the GDPR or applicable mandatory law provides otherwise.

Annex I: List of sub-processors

  • Hetzner Online GmbH: Hosting of the application, database, image storage and backups. All customer content is processed on servers this provider operates. Location: Germany and Finland (EU/EEA). Privacy notice: https://www.hetzner.com/legal/privacy-policy/.

Annex II: Technical and organisational measures (Article 32 GDPR)

  • Confidentiality: per-user account isolation, role-based authorisation in the API, principle of least privilege for operator access, hashed passwords (bcrypt), refresh-token families with reuse detection.
  • Integrity: TLS 1.2+ on the web and app endpoints; encryption required on the camera login ports (465 and 587), which still permit TLS 1.0/1.1 for field firmware; TLS when the camera offers it on the mail ports without a login (25 and 2525), which also accept unencrypted mail from send-by-email cameras and from cameras the Controller has set to "Without SSL"; signed JSON Web Tokens, server-side input validation, rate-limiting and audit logs of authentication events.
  • Availability and resilience: nightly database backups kept for 14 days, database health checks and post-deploy verification probes.
  • Restoration: documented restore procedure.
  • Process for regular testing: automated linting and a gating test suite on every release, including tests that pin the security invariants (authentication, authorisation, tenant isolation, outbound-request guards); an audit of dependencies for known vulnerabilities on every release.
  • Pseudonymisation and encryption: data in transit is encrypted at TLS 1.2+ on the web and app endpoints and at TLS 1.0 or better on the camera login ports (465 and 587), because camera firmware in the field offers nothing newer; the mail ports without a login (25 and 2525) use TLS when the camera offers it and also accept unencrypted mail, which send-by-email cameras and cameras the Controller has set to "Without SSL" use; passwords, one-time codes and trusted-device tokens are stored only as one-way hashes; data at rest on the production server is not disk-encrypted (a single virtual server in Hetzner's EU data centres, whose physical and environmental controls are listed in Hetzner's technical and organisational measures).
  • Personnel: only the operator (sole developer) has administrative access to production; access is logged.
OtsoVision

AI-organised trail-camera monitoring, maintained in the EU.

Product

Features Pricing Log in

Legal

Terms of service Refunds Privacy & cookies Data processing agreement Legal notice
© 2026 OtsoVision. All rights reserved. Otsovision Oy · Business ID 3648032-5 · 00960 Helsinki, Finland hello@otsovision.com

We use strictly necessary browser storage (auth session, language preference) to run the service. No tracking or advertising cookies. More in our Privacy & cookies.