Guardian AI is an edge-AI surveillance and incident-intelligence platform operated by Navicore Technologies Private Limited ("Navicore Technologies"). AI detection runs on the Guardian AI edge system installed at the customer's own site, and camera feeds together with AI-generated alerts and incident metadata are delivered to authorized monitoring teams through a secure web dashboard and native mobile and desktop applications.
This Privacy Policy explains what information we collect, how we use it, how long we keep it, how we secure and share it, the choices and rights available to you, and how you can delete your account and associated data. We have written it in plain language so that customers, their authorized users, and individuals whose data may be processed in authorized monitoring environments can understand our practices.
Guardian AI is designed for authorized monitoring environments only. Access to the dashboard and applications is restricted to authorized customers and their authorized users. AI outputs are designed to assist and support authorized teams, may require human verification, and can produce both false positives and false negatives. Guardian AI is not an emergency service and does not replace emergency services, on-site security personnel, or professional monitoring providers.
Important note about this document
1. Introduction and scope
This Privacy Policy applies to the Guardian AI platform, including the edge-AI detection software that runs on the Guardian AI edge system at customer sites, the secure web dashboard, the native mobile and desktop applications, and the public marketing website at https://www.navicoretechnologies.com (together, the "Services"). It also describes how we handle information you provide when you contact us about the Services.
Guardian AI is supplied to authorized enterprise, industrial, critical-infrastructure, and smart-city customers, for example electrical substations, facilities, campuses, and public infrastructure. The platform is designed for authorized monitoring environments only. Where Guardian AI is deployed by an organization, that organization typically determines the purposes and means of processing the information captured within its environment and acts as the data controller for that information; Navicore Technologies generally acts as a service provider or processor on the organization's behalf. The relationship between the organization and Navicore Technologies, including roles and responsibilities, is governed by the applicable customer agreement.
References to "Navicore Technologies", "we", "us", and "our" mean Navicore Technologies Private Limited, the provider of Guardian AI, with its registered office at R. No. 94, Kamgar Nagar, Shell Colony Road, Mumbai, Maharashtra 400071, India. The Services support English plus several Indian languages.
2. Who is responsible for your data
For information that Navicore Technologies processes about you in connection with our own operation of the Services, the data controller is Navicore Technologies Private Limited, registered at R. No. 94, Kamgar Nagar, Shell Colony Road, Mumbai, Maharashtra 400071, India. You can reach our privacy contact at privacy@navicoretechnologies.com or by telephone at +91 7738551596.
Where Guardian AI is deployed by a customer organization, that organization typically acts as the data controller for the information captured and processed within its authorized monitoring environment, including camera video, any audio, and the alerts and incident metadata derived from them. In those deployments Navicore Technologies generally acts as a processor and handles such information in accordance with the customer agreement and the organization's instructions. If you are an authorized user provisioned by an organization, requests about information processed within that organization's environment may be directed to your organization, and we will assist as required.
3. Information we collect
The information we collect depends on how you interact with the Services and on the configuration chosen by the customer organization that deploys Guardian AI. We group the categories of information below.
Account and contact information. When an authorized user is provisioned, or when you contact us, we may collect identifiers and contact details such as name, work email address, organization name, role or job title, telephone number where provided, and the credentials used to authenticate to the dashboard and applications. Customer organizations typically supply and manage this information for their authorized users.
Device and technical information. To operate and secure the Services, we may collect technical information such as IP address, browser type and version, operating system, application version, device and hardware identifiers for the edge appliances and client devices used to access the Services, configuration and diagnostic data, connection and session metadata, log files, and error reports. This information helps us deliver, maintain, and troubleshoot the Services.
Camera, video, and audio captured in authorized environments. Where a customer enables relevant capabilities, the platform processes camera video and, where configured, audio captured by cameras and microphones installed within the customer's authorized monitoring environment. AI detection runs on the Guardian AI edge system at the customer site, and feeds together with derived outputs may be made available to the customer's authorized monitoring team through the dashboard and applications. The presence, placement, and operation of cameras and microphones, and the capture of any audio, are determined and controlled by the customer organization in accordance with the laws applicable to it.
Alert and incident metadata. The platform generates AI-derived outputs such as detection events, alerts, classifications, captions, timestamps, camera or zone identifiers, and related incident metadata. These outputs are designed to assist and support authorized teams. They may require human verification and can produce false positives and false negatives; they are not determinations of fact and should not be treated as such.
Application and usage information. We may collect information about how authorized users interact with the dashboard and applications, such as features used, actions taken within the interface, preferences and settings, language selection, and aggregated performance and reliability metrics. This helps us understand how the Services are used and how to improve them.
Cookies and local storage on the website. The public marketing website and the dashboard may use cookies, local storage, and similar technologies to keep you signed in, remember preferences, maintain session security, and understand website usage. You can manage cookies through your browser settings; disabling certain cookies may affect how parts of the Services function.
4. How we use information
We use the information described above for the following purposes, in each case consistent with the applicable customer agreement and the instructions of the customer organization where we act as a processor:
- To provide, operate, and maintain the Services, including delivering camera feeds and AI-generated alerts and incident metadata to authorized monitoring teams.
- To authenticate users, enforce access controls, and help keep the Services and accounts secure.
- To generate detection outputs designed to assist and support authorized teams, recognizing that such outputs may require human verification and can produce false positives and false negatives.
- To deliver notifications and alerts to authorized users who have enabled them.
- To troubleshoot, diagnose, and resolve technical issues and to monitor the reliability and performance of the Services.
- To develop, test, and improve the Services, including detection quality, usability, and language support, using appropriate safeguards.
- To respond to support requests and communicate with customers and authorized users about the Services.
- To comply with legal obligations and to establish, exercise, or defend legal claims.
- To help protect the rights, property, and safety of Navicore Technologies, our customers, authorized users, and others, consistent with applicable law.
We do not use camera, video, audio, or incident data captured in customer environments to build advertising profiles, and we do not sell personal information. Any use of such data to improve the Services is governed by the applicable customer agreement and is subject to appropriate safeguards.
5. Camera, microphone, and notification permissions
The Guardian AI applications may request device permissions so that authorized users can use certain features. These permissions are optional, are requested in context, and can be controlled or revoked through your device or operating system settings at any time. Declining a permission may limit the related feature but does not prevent you from using other parts of the Services.
- Camera permission: requested only if you choose to use features that rely on your device camera, such as scanning or capturing within the app. It is not used to access cameras in monitored environments, which are configured by the customer organization.
- Microphone permission: requested only if you choose to use features that rely on your device microphone, such as two-way audio or talk functionality. It is used solely for the feature you initiate and can be turned off at any time.
- Notification permission: requested so the app can deliver alerts and operational notifications you have chosen to receive. You can manage or disable notifications in your device settings or within the app.
The capture of camera video and any audio within a monitored environment is governed by the customer organization's configuration and applicable law, and is separate from the device-level permissions described in this section.
6. Legal bases for processing
Where data protection laws that require a legal basis for processing apply, we rely on one or more of the following, depending on the context and on the role of the customer organization as data controller:
- Performance of a contract: to provide the Services to a customer and its authorized users under the applicable agreement.
- Legitimate interests: to secure, operate, troubleshoot, and improve the Services, in a manner balanced against the rights and interests of affected individuals.
- Compliance with legal obligations: where processing is necessary to meet obligations to which we are subject.
- Consent: where required for specific activities, such as certain device permissions or cookies, which you may withdraw at any time.
- Protection of vital interests or other lawful bases: where applicable and permitted by law.
Where Navicore Technologies acts as a processor on behalf of a customer, the customer is responsible for establishing the appropriate legal basis for the processing it directs, including any capture of camera, video, or audio in its monitored environment.
8. Data retention
We retain information for as long as needed to provide the Services, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Retention periods vary by category of information and by the configuration chosen by the customer organization.
For camera, video, audio, alert, and incident data captured in a customer environment, retention is typically determined and controlled by the customer organization under the applicable customer agreement and applicable law. When information is no longer required, we take reasonable steps to delete it or to anonymize it so it can no longer be associated with an individual.
Verified deletion requests are handled as described in the sections on your rights and choices and on account and data deletion. Our target response timeline for data-deletion requests is within 30 days.
9. Data security
We use technical and organizational measures designed to help protect information against unauthorized access, disclosure, alteration, and destruction. These measures are intended to reduce risk; no method of transmission or storage is completely secure, and no system can be made perfectly secure.
- Encryption in transit and at rest: we use encryption designed to help protect data while it is transmitted across networks and while it is stored.
- Mutually authenticated edge connectivity: edge appliances and the platform establish mutually authenticated connections so that only recognized, authorized devices participate in communications.
- Role-based access control: access to data and functionality is restricted based on role and need, so users see only what their role permits.
- Authentication and access controls: account authentication, session management, and administrative controls help restrict access to authorized users.
- Monitoring and logging: we maintain logging and monitoring designed to help detect and respond to operational and security events.
- Operational safeguards: we apply internal policies, access governance, and least-privilege principles to limit who can access information and under what conditions.
Access to the dashboard and applications is restricted to authorized customers and their authorized users. Customer organizations are responsible for managing their own users, credentials, and access policies, and for promptly removing access that is no longer authorized.
10. Your rights and choices
Depending on your jurisdiction and your relationship to a customer organization, you may have rights regarding the personal information we process about you. Subject to applicable law and verification, these may include:
- The right to access the personal information we hold about you.
- The right to request correction of inaccurate or incomplete information.
- The right to request deletion of personal information, subject to legal and contractual limits.
- The right to object to or restrict certain processing.
- The right to data portability where applicable.
- The right to withdraw consent where processing is based on consent.
- The right to lodge a complaint with a competent data protection authority.
Where Navicore Technologies acts as a processor on behalf of a customer organization, we will direct requests to the relevant customer or assist that customer in responding, as required by the applicable agreement and law. To make a request, contact us at privacy@navicoretechnologies.com. We will take reasonable steps to verify your identity before acting on a request, and we may decline or limit a request where permitted by law. To delete your account and associated data specifically, see the next section.
11. Account and data deletion
You can request deletion of your Guardian AI account and the personal data associated with it. Guardian AI accounts are created and managed by your organization's authorized administrator; there is no public sign-up, and only pre-registered users can sign in. There is no in-app "delete account" control — instead, you request deletion either by contacting your administrator or by emailing our privacy team. Both routes are described below.
Through your administrator: because your Guardian AI account is provisioned and managed by your organization's authorized administrator, you can ask your administrator to remove your account and the personal data associated with it. Administrators can deactivate and delete the users they manage.
By email: send a deletion request from the email address associated with your account to privacy@navicoretechnologies.com with the subject "Data deletion request", or contact us using the details in the Contact us section. You may also reach us by telephone at +91 7738551596 to ask questions about the process.
What is deleted. A completed deletion removes your account profile and authentication credentials, your contact and account information, your app preferences and settings, and personal information we hold that is associated with your account, including usage and activity records linked to you, unless we are required or permitted to retain specific items as described below. We will also instruct our service providers and subprocessors to delete the relevant information they hold on our behalf.
Response timeline. We aim to acknowledge deletion requests promptly and to complete verified deletion within 30 days. If we need additional time because of the volume or complexity of a request, we will let you know within that period and explain the reason. We may take reasonable steps to verify your identity before acting on a request, and we may decline or limit a request where permitted by law.
Enterprise and administrator deployments. Where you are an authorized user provisioned by a customer organization, that organization typically acts as the data controller for information processed within its environment, including camera, video, audio, alert, and incident data captured in its authorized monitoring environment. In those cases, we will direct your deletion request to your organization or assist that organization in responding, and your organization's administrators may be responsible for deleting or retaining account and environment data under their own policies and the applicable customer agreement. Deletion of camera, video, audio, alert, and incident data captured within an organization's environment is governed by that organization's configuration, retention settings, and applicable law.
Data we may retain. We may retain limited information after a deletion request where retention is required or permitted by law, for example to comply with legal, tax, accounting, or regulatory obligations, to resolve disputes, to detect and prevent fraud or abuse, to enforce our agreements, or to establish, exercise, or defend legal claims. We may also retain information in de-identified or aggregated form that can no longer reasonably be associated with you. Any retained information remains protected by the safeguards described in this policy and is deleted or anonymized when it is no longer required.
Permanence. Completed deletion is permanent and cannot be undone. After your account and associated data are deleted, you will lose access to the account and its history, and we will not be able to recover the deleted information. If you wish to use the Services again afterward, a new account would need to be created and provisioned.
12. Enterprise and administrator provisioning
Guardian AI is provided to organizations that control access for their authorized users. When your organization provisions Guardian AI, its administrators are responsible for creating and managing user accounts, assigning roles, configuring features such as cameras, microphones, alerts, and retention, and enforcing the organization's own policies.
In these deployments, the customer organization typically acts as the data controller for the information processed within its environment and determines the purposes for which that information is used. If you are an authorized user provisioned by an organization, your use of the Services may also be subject to that organization's policies, and requests concerning your information, including access and deletion requests, may be directed to your organization. We process information in these contexts in accordance with the applicable customer agreement and the organization's instructions.
13. Children's privacy
The Services are intended for use by authorized organizations and their authorized users in professional monitoring environments. They are not directed to children, and we do not knowingly collect personal information directly from children through the Services. If you believe a child's personal information has been provided to us in error, please contact us at privacy@navicoretechnologies.com so we can take appropriate action consistent with applicable law.
14. International data transfers
We may process and store information in countries other than the one in which it was collected, including for hosting, support, and operational purposes. Data protection laws in those countries may differ from those in your jurisdiction.
Where information is transferred across borders, we take steps designed to help ensure it remains protected, which may include using recognized transfer mechanisms, contractual safeguards, and appropriate technical and organizational measures. Where Navicore Technologies acts as a processor, such transfers are carried out consistent with the applicable customer agreement and applicable law.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will update the effective date and, where appropriate, provide additional notice through the Services or by other reasonable means.
We encourage you to review this policy periodically. Your continued use of the Services after an update becomes effective indicates that you have reviewed the current version, subject to any consent requirements under applicable law.
16. Contact us
If you have questions about this Privacy Policy or our handling of information, or if you wish to exercise a privacy right or submit a data-deletion request, please contact us using the details below. To request deletion of your account or personal data, contact your organization's authorized administrator or email privacy@navicoretechnologies.com. Returning users can sign in to the dashboard at https://www.navicoretechnologies.com/dashboard/.
Legal entity: Navicore Technologies Private Limited
Registered business address: R. No. 94, Kamgar Nagar, Shell Colony Road, Mumbai, Maharashtra 400071, India
Phone: +91 7738551596
Privacy and data deletion: privacy@navicoretechnologies.com
Support: support@navicoretechnologies.com
General, sales, and partnerships: support@navicoretechnologies.com
Website: https://www.navicoretechnologies.com
Dashboard login: https://www.navicoretechnologies.com/dashboard/