Privacy
Know what is happening. Collect only what you need.
Privacy in Ambianceintel is a constraint applied at the sensing layer. The system is built so there is less to govern, not so that more can be governed carefully.
Data boundary
What Ambianceintel knows — and what it does not need to know
What Ambianceintel knows
- A room is occupied or vacant
- Activity has been detected in a zone
- Activity has stopped for longer than usual
- A transition between zones has occurred
- Duration in a zone is unusual against the learned baseline
- Environmental state such as temperature or door position, where those sensors are deployed
What Ambianceintel does not need to know
- A person's face or identity
- What someone is wearing
- What someone is watching or reading
- Documents, screens or whiteboards in a space
- Conversation or any continuous audio
- A continuous recording of anything at all
Understand spaces without watching people.
Commitments
Eight design commitments
No facial recognition by default
Identification is not part of the core model and is not enabled as standard.
No continuous audio recording
Ambianceintel does not record conversation.
No requirement for video
Cameras are optional, customer-chosen and limited to places where visual verification is the explicit requirement.
Local and edge processing
Where practical, signal is reduced to events on site rather than transmitted.
Minimal event data
The output surface is a small set of states, by design.
Configurable retention
Customers set how long event data is kept, within their own policy.
Role-based access control
Who can see what is defined by role, and enforced.
Encryption and audit logs
Data encrypted in transit and at rest; access recorded.
For review
Built to be examined
Privacy officers, works councils, residents' committees and procurement reviewers should be able to understand exactly what a deployment collects. We provide documented sensing modalities, data-flow descriptions, retention configuration and access models as part of every pilot.