OtsoVision
How it works Features Pricing FAQ
Log in Get started →
How Features Pricing FAQ

Privacy & cookies

Last updated: 2026-09-18. Effective from 2026-09-18. Issued under Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Finnish Data Protection Act (Tietosuojalaki 1050/2018), the UK GDPR and the Data Protection Act 2018, the Swedish Dataskyddslag (2018:218), the German Bundesdatenschutzgesetz (BDSG), the French Loi Informatique et Libertés as amended, and the ePrivacy Directive (2002/58/EC) as transposed in each Member State.

Our commitment

We do not sell your personal data. We do not rent or trade it, we do not hand it to third parties for their own purposes, and we do not use it for advertising or profiling. The only organisations that receive it are listed in section 5: our hosting provider, which acts solely on our instructions, and a small number of independent recipients such as our payment provider, each named there with what it receives and why.

If we ever wanted to share your personal data for a purpose not described in this policy, we would ask you first. That request would be separate and specific, refusing it would not affect your use of OtsoVision, and you could withdraw your agreement at any time without giving a reason.

Two things follow from how the service is built. Your photos are analysed on our own servers in the EU and are never sent to an external AI provider. Corrections you make to species tags improve the suggestions for your own cameras only; OtsoVision does not train a shared model on your images for other customers.

We do build an anonymised wildlife research dataset from images of game species and license it to research organisations. Section 4a says exactly what goes into it and what is removed first: no people, no vehicles, no camera or account identity, no exact location. Because the dataset contains no personal data, it is not a sale or a sharing of your personal data.

1. Who we are

The controller for personal data processed through otsovision.com, app.otsovision.com and api.otsovision.com is:

Otsovision Oy
Kurkimoisio 9 A
00960 Helsinki
Email: hello@otsovision.com

We have not appointed a Data Protection Officer; appointment is not mandatory under GDPR Article 37 for our scale and the nature of our processing. You can reach the person responsible for data-protection questions at the email address above.

2. Roles: when we are a controller, when we are a processor

We act as a controller for account, billing and security data we collect about you in order to operate the service. We act as a processor for the camera images and metadata you upload through the service: it is the camera operator (you, the customer) who decides which images to capture and what to do with them, and accordingly you are the controller for any personal data of bystanders, vehicle drivers, neighbours or third parties that incidentally appear in those images. The processor relationship is governed by our Data Processing Agreement, which forms part of the terms you accept when you sign up.

For one activity we are neither. When we select images of game animals for the anonymised research dataset described in section 4a and strip them of everything that could identify a person, a place or a customer, we decide the purpose and the means ourselves and are an independent controller for that selection and anonymisation step. Once anonymised, the images are no longer personal data.

3. Categories of personal data we process

CategoryExamplesSource
Account dataEmail, name, password hash, language preference, timezoneYou, on signup
Billing dataPaddle customer ID, plan, billing period, country (for VAT), invoice records; payment-card data is collected and stored by Paddle (our Merchant of Record) and never reaches our serversYou and Paddle, when paid plans are enabled
Authentication dataPassword reset tokens, MFA codes (hashed), refresh-token family identifiersSystem
Service usage dataSign-in timestamps, IP addresses (the full address only in short-lived server logs that rotate by size; the network part alone, last octet removed, in the 12-month audit log and on trusted-device records), user-agent strings, request-rate metadataSystem
Camera contentUploaded images and their EXIF metadata (capture time, camera model, GPS if present), AI-derived classifications, your own tags and album choices The AI records every species it recognises in every image, including ones you have chosen not to display.You and your cameras
Email-ingestion recordsEmail envelope and headers from cameras you have authenticatedYour cameras
Cookies and local storageSee section 9Your browser

4. Purposes and legal bases

PurposeLegal basis (GDPR)
Provide the service to you (account, image storage, classification, sharing)Article 6(1)(b), performance of a contract
Process payments and issue invoicesArticle 6(1)(b) and Article 6(1)(c) (statutory accounting duties)
Account security, fraud and abuse prevention, rate-limiting, audit loggingArticle 6(1)(f), legitimate interest in keeping the service secure for all users
Send transactional emails (verification, password reset, billing receipts)Article 6(1)(b)
Comply with legal obligations (e.g. respond to lawful requests, retain accounting records)Article 6(1)(c)
Improve the service in aggregate (counts and error rates only, no profiling)Article 6(1)(f)
Wildlife research and product development: selecting images in which a game species was identified, removing anything identifying, and licensing the resulting anonymised dataset to research organisations and using it ourselves to test and improve the species recognition (section 4a)Article 6(1)(f), legitimate interest in wildlife research, with the safeguards of Article 89(1); you may object at any time (section 8)

We do not rely on consent (Article 6(1)(a)) for any of the above and we do not engage in direct marketing.

4a. Research and development dataset

What we use it for. Two things, both on the same anonymised set: we license it to research organisations, and we use it ourselves to test and improve our species recognition. Measuring how well the recognition works, and whether a change makes it better, can only be done against real trail-camera frames.

Which images qualify. An image qualifies only if our AI identified a game species in it, that identification still stands after any correction, and everything else tagged in it, by the AI or by a person, is also a game species. Tags you have chosen not to display still count. Images showing people, vehicles, pets, protected species or unidentified subjects never qualify. The game species are: White-tailed deer, Roe deer, Moose, Reindeer, Brown bear, Gray wolf, Lynx, Wolverine, Red fox, Raccoon dog, Pine marten, European badger, Otter, European hare, Mountain hare, Red squirrel, Beaver, Wild boar, Capercaillie, Black grouse, Hazel grouse, Pheasant, Mallard, Bean goose, Pigeon.

What we remove. Before an image enters the dataset we strip all embedded metadata (EXIF), including any GPS position and camera serial number; drop the camera's name, our internal identifiers and every reference to your account; round the camera's position to a 0.1-degree grid (about 10 km), or omit it where you have set none; and keep the capture time and the weather at capture but not the place name and not sunrise, sunset or moon times, because those could be inverted into a precise position.

What stays. The image at the resolution we hold, the species labels (the AI's identification and any human correction, with the scientific name), the grid cell, the capture time and the weather.

Who receives it.

  • No research organisation has received a dataset yet. This list is updated before any dataset is delivered.

How to keep a camera out. You may object at any time (Article 21) by writing to hello@otsovision.com or through Help → Contact support in the app, naming the camera. We then exclude the camera: its images stop qualifying, any that qualified are marked ineligible and follow your plan's normal storage limit. Because the dataset contains no personal data, images already delivered to a research organisation cannot be recalled.

Retention of qualifying images is described in section 7.

5. Recipients and sub-processors

We share personal data only with the following sub-processors, each engaged under a written agreement that meets Article 28 GDPR:

  • Hetzner Online GmbH: Hosting of the application, database, image storage and backups. All customer content is processed on servers this provider operates. Location: Germany and Finland (EU/EEA). Privacy notice: https://www.hetzner.com/legal/privacy-policy/.

These organisations also receive personal data, but not as our processors — each decides its own purposes, or receives it because your own browser contacts it:

  • Paddle.com Market Limited — Independent controller. Merchant of Record for paid plans: Paddle is the seller, and determines the purposes and means of processing payment, invoicing and tax data itself. It receives no camera images or other content you store with us. Location: United Kingdom (European Commission adequacy decision). https://www.paddle.com/legal/privacy
  • MapTiler AG — Separate controller for the request your browser makes. Map tiles and place lookup. Your browser contacts MapTiler directly when you open the map, so it sees your IP address and the area you are viewing. It never receives your account or your stored content. Location: Switzerland (European Commission adequacy decision). https://www.maptiler.com/privacy-policy/
  • Open-Meteo — Not a recipient of personal data. Weather and place-name lookup for a camera's coordinates. Our server sends a coordinate and an hour, with no account identifier and not your IP address, so nothing identifying reaches them. Listed here for completeness. Location: Germany (EU/EEA). https://open-meteo.com/en/terms
  • Browser push services (Google, Mozilla or Apple) — Your browser's own infrastructure. Delivery of web push notifications, only if you switch them on. The address is issued to you by your own browser vendor, and the notification is encrypted to your device under RFC 8291 so the relay cannot read it. We do not choose the vendor; your choice of browser does. Location: Depends on your browser vendor. https://datatracker.ietf.org/doc/html/rfc8030

We do not sell, rent or otherwise make personal data available to third parties for marketing or profiling.

Research organisations listed in section 4a receive only the anonymised dataset described there, which contains no personal data; they receive nothing else from us.

6. Transfers outside the EU/EEA

All processing we carry out ourselves, including storage and backups, takes place in the EU/EEA on Hetzner infrastructure; no sub-processor is established outside the EU/EEA (see section 6 of the Data Processing Agreement).

Three independent recipients listed in section 5 are outside the EU/EEA: Paddle.com Market Limited (United Kingdom, covered by the European Commission's adequacy decision), MapTiler AG (Switzerland, covered by an adequacy decision) and, only if you switch push notifications on, the push service of your own browser vendor, whose location depends on the browser you chose and which receives an encrypted payload it cannot read.

We do not rely on the Standard Contractual Clauses for any current transfer. Should we ever need a provider in a country without an adequacy decision, we will put the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and a transfer impact assessment in place first and update this section.

7. Retention

  • Account data: kept while your account is active. Deleting your account erases it immediately and irreversibly — there is no recovery window, so export anything you want to keep first. Copies remain only in our database backups, which are deleted on a 14-day rotation.
  • Camera images and tags: kept while your account is active. You may delete individual images, albums or your whole account at any time. Deletions are propagated to backups within 30 days. Your plan's limit on visible images applies to every camera: beyond it the entry and thumbnail stay for your statistics and the picture files are deleted. Images eligible for research and development (section 4a) will be saved for later use; deleting the image, its camera or your account deletes them as well.
  • Photos on an account without an active subscription or trial: kept for six months after the trial or subscription ended, then deleted, with reminders at the lapse, after three months and one month before deletion. Photos already included in the anonymised research dataset (section 4a) are kept as described there. The account itself is kept until you delete it.
  • Photos on a camera you replaced: when you replace a camera, the old one is disabled and its photos are kept for six months, then the picture files are deleted while the entries, tags and thumbnails stay for your statistics. We email you before that happens. Images already selected for the anonymised research dataset (section 4a) keep their files and are simply no longer shown to you. Re-enabling the camera before the date keeps everything.
  • Billing records: 6 years from the end of the financial year in which the invoice was issued, as required by Finnish bookkeeping law (Kirjanpitolaki 1336/1997).
  • Security and audit logs: 12 months, after which they are aggregated or deleted.
  • Email-ingestion records: kept only as long as needed to ingest each message; once the resulting image has been written to your camera, the surrounding email envelope and headers are no longer retained beyond short-lived processing logs.

8. Your rights

Under the GDPR (and equivalent national laws including the UK GDPR) you have the right to:

  • access the personal data we hold about you (Article 15);
  • have inaccurate data corrected (Article 16);
  • have your data erased (Article 17), subject to retention obligations stated above;
  • restrict processing (Article 18);
  • obtain your data in a portable, machine-readable format (Article 20);
  • object to processing based on legitimate interests (Article 21), including the selection of your images for the research dataset (section 4a);
  • withdraw consent at any time, where processing relies on consent (Article 7(3)), note that we do not currently rely on consent;
  • not be subject to a decision based solely on automated processing that produces legal effects (Article 22). Our species-classification model does not produce legal effects.

You can exercise any of these rights by emailing hello@otsovision.com. We will respond within one month.

You also have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Finnish Tietosuojavaltuutetun toimisto. Residents of other countries may also complain to:

  • Sweden: Integritetsskyddsmyndigheten (IMY)
  • Germany: Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) / your competent state DPA (Landesdatenschutzbehörde)
  • France: Commission nationale de l'informatique et des libertés (CNIL)
  • United Kingdom: Information Commissioner's Office (ICO)

9. Cookies and similar technologies

The service uses only strictly necessary cookies and equivalent local-storage entries. None of them are used for advertising or for tracking your behaviour across third-party sites.

IdentifierPurposeStorageDuration
access_token / refresh_tokenKeep you signed in to the appLocal storageUntil logout or 30 days
trusted_device_tokenRemember a browser you chose to trust, so the two-factor code is not asked again on itLocal storage30 days, or until you revoke the device
app_localeRemember your language preferenceLocal storageUntil changed
app_themeRemember your light / dark / system theme preferenceLocal storageUntil changed
push_prompt_dismissed_v1 / push_banner_dismissed_v1Remember that you dismissed the push-notification promptLocal storageUntil you clear the browser's site data
ts_cookies_ack_v1Remember that you dismissed the storage notice on the websiteFirst-party cookie on otsovision.com (local storage as fallback)1 year

Because every entry is strictly necessary or a functional preference set at your own request, we do not ask for consent. The website shows a one-time notice about this storage and remembers that you dismissed it; the app shows none. This is consistent with EDPB Guidelines 2/2023 on Article 5(3) of the ePrivacy Directive and with CNIL guidance on cookies and similar trackers (Délibération n° 2020-091).

10. Security

We use TLS 1.2 or newer for every connection to the app, the website and our outbound mail. The two ports trail cameras sign in on require encryption but still accept the older TLS 1.0 and 1.1, because camera firmware in the field offers nothing newer; the public mail port that cameras without a password deliver to encrypts where the camera supports it, so a camera that cannot negotiate TLS is accepted rather than losing its photos. We hash passwords with bcrypt at a work factor calibrated to current hardware; store one-time codes and trusted-device tokens only as one-way hashes; scope authentication tokens to short-lived families with reuse detection; and, before each release, run an automated test suite that pins our authentication, authorisation, tenant-isolation and outbound-request guards together with an audit of our dependencies for known vulnerabilities. Data at rest on the production server is not disk-encrypted; the server is a single virtual machine in Hetzner's EU data centres, whose physical and environmental controls are set out in Hetzner's technical and organisational measures. Despite these measures, no system can guarantee absolute security; in case of a personal-data breach we will notify the competent supervisory authority within 72 hours and affected users without undue delay where the breach is likely to result in a high risk to your rights and freedoms (Articles 33–34 GDPR).

11. Children

The service is not directed to children. Users must be at least 13 years old; in countries where the age of consent for online services is higher (e.g. 16 in Germany, 15 in France) that higher age applies. We do not knowingly collect personal data from children below the applicable age.

12. Country-specific notes

United Kingdom

We do not currently maintain a UK Article-27 representative. UK residents may direct any questions to hello@otsovision.com or lodge a complaint with the ICO (https://ico.org.uk/).

Germany

Notwithstanding our Finnish establishment, the German BDSG applies to the extent required by GDPR Article 3(2) where we process personal data of users in Germany. The competent supervisory authority is the Land authority of the data subject's residence; the BfDI page above lists each of them.

France

Under the French Loi Informatique et Libertés, you also have the right to issue advance directives concerning the storage, deletion and disclosure of your personal data after death (Article 85 of the law).

Sweden

Disputes concerning Swedish residents may also be reported to IMY (link above).

13. Changes to this policy

We may update this policy from time to time. The "last updated" date at the top reflects the most recent change. Material changes will be communicated by email to active users at least 30 days before they take effect.

OtsoVision

AI-organised trail-camera monitoring, maintained in the EU.

Product

Features Pricing Log in

Legal

Terms of service Refunds Privacy & cookies Data processing agreement Legal notice
© 2026 OtsoVision. All rights reserved. Otsovision Oy · Business ID 3648032-5 · 00960 Helsinki, Finland hello@otsovision.com

We use strictly necessary browser storage (auth session, language preference) to run the service. No tracking or advertising cookies. More in our Privacy & cookies.