Privacy Policy
EgoVista — egovista.app
Effective 11 September 2026 · Version 2.5
See also: Contributor Terms
This Privacy Policy explains how EgoVista processes personal data when you visit egovista.app, register as a contributor, contact us as a prospective buyer, or appear incidentally in a video uploaded by a contributor. It is written to be read by humans, not only lawyers; defined terms are kept to a minimum and references to the law are provided so that any data protection authority or counsel can verify the analysis underlying each section.
EgoVista is committed to the principles of the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), the French Loi Informatique et Libertés as amended, and to the transparency and AI-literacy expectations of Regulation (EU) 2024/1689 (the “AI Act”). This Policy is consistent with the recommendations published by the French data protection authority (“CNIL”) on the development of AI systems and with the work of the European Data Protection Board (“EDPB”) on pseudonymisation and on facial recognition.
1. Identity of the controller
EgoVista is a French simplified joint-stock company (société par actions simplifiée), registered with the Paris Trade and Companies Register under SIREN 106 489 735. The data controller within the meaning of Article 4(7) GDPR is:
EgoVista SAS, registered with the Paris Trade and Companies Register under SIREN 106 489 735, represented by Mr Léonard Docquier, founder.
Registered office: 47 rue Vivienne, 75002 Paris, France.
Email: privacy@egovista.app (data protection enquiries) / contact@egovista.app (general enquiries).
EgoVista’s intra-Community VAT identification number is available on request at the contact addresses above. The substance of the obligations described below remains unchanged irrespective of any subsequent update to these identification details.
EgoVista has not appointed a Data Protection Officer. The applicability of Article 37(1) GDPR has been assessed and none of its three conditions is met: EgoVista is not a public authority; its core activity does not consist of regular and systematic monitoring of data subjects on a large scale, contributors submitting discrete sequences under missions they are free to join or not; and it does not process data within Article 9 or Article 10 on a large scale. That analysis, together with the events that would reopen it, is set out in EgoVista’s combined data protection and AI Act assessment, available on request. This Policy will be updated if a Data Protection Officer is designated.
2. Who this Policy concerns
This Policy is addressed to four categories of data subjects:
- Contributors — natural persons aged 18 or above who voluntarily upload egocentric (first-person) video footage to the Platform.
- Prospective buyers — natural persons acting in a business capacity who contact EgoVista through the website to discuss the supply of annotated datasets.
- Visitors — natural persons who browse the Platform without registering.
- Third parties incidentally captured in videos uploaded by contributors (passers-by, household members, colleagues).
3. Categories of personal data processed
3.1 Data provided directly
Contributors provide their first name, last name, email address, the country in which the footage was recorded, a free-text description of the filming environment, and the video file itself.
Prospective buyers provide their name, professional email address, organisation, project type, estimated volume, target environments, indicative timeline, and any message they choose to include.
Payment data. EgoVista pays contributors by one of three methods, determined by the country of residence and by the payment routes available at the time. The method applicable to a given contributor is displayed to them before they ask to be paid. What EgoVista holds differs by method:
- Transfer from EgoVista’s own account, used where the account is reachable in euros within the Single Euro Payments Area. The contributor supplies their banking details to EgoVista, which retains them, encrypted, with the key held outside the database. They are decrypted only when a payment is prepared, and each decryption is recorded. The legal basis is the performance of the contributor agreement (Article 6(1)(b) GDPR). They are retained for the duration of the active contractual relationship, then erased, subject to the retention required by accounting and tax obligations.
- Transfer executed by a payment provider. EgoVista instructs the provider to pay the contributor; the provider invites the contributor to supply their banking details directly to it. EgoVista neither receives nor retains those details.
- Payment to an account identified by an electronic address. EgoVista retains that address and no banking identifier.
The providers used for the second and third methods, and the region in which each processes data, are named in the list at egovista.app/legal/sub-processors.
Fingerprint of the banking identifier. Where EgoVista retains banking details under the first method, it also retains a cryptographic fingerprint of the normalised identifier. That fingerprint serves one purpose and no other: detecting that two contributor accounts designate the same bank account, which the Contributor Terms prohibit. It does not allow the identifier to be reconstituted. It rests on EgoVista’s legitimate interest in the integrity of its contributor base (Article 6(1)(f) GDPR), and a contributor may object to it under section 7.4.
This fingerprint is computed only for contributors paid by the first method. Contributors paid by either of the other two are not covered by it, and EgoVista therefore has no equivalent signal for those countries. That limitation is recorded in EgoVista’s combined data protection and AI Act assessment as a residual risk accepted knowingly.
Verification documents. EgoVista may request a document to verify a contributor’s identity, age or residence. The document is used for that verification and for nothing else. It is deleted as soon as the verification is carried out, and in any event no later than thirty days after it is received, whether or not the verification has been completed. EgoVista retains a record stating the date of the verification, the type of document produced, the outcome and the person who carried it out — neither a copy of the document nor its number.
3.2 Data collected automatically
When you interact with the Platform, EgoVista collects technical data necessary for operation and security: IP address, user-agent string, connection and upload timestamps, HTTP error codes, and rate-limiting counters. These data are processed on the basis of EgoVista’s legitimate interest in operating a secure service (Article 6(1)(f) GDPR).
Identifiers used for rate limiting (IP address or email address depending on the endpoint) are transmitted to the rate-limiting provider in the form of a cryptographic fingerprint rather than in clear text. This fingerprint is a pseudonymisation measure and not an anonymisation: it is computed without a secret salt, and the corresponding data therefore remains personal data within the meaning of Article 4(1) GDPR.
EgoVista does not currently deploy any audience-measurement or advertising analytics tool. If one is deployed in the future, it will be selected to operate without cross-site tracking or advertising purpose, and this Policy will be updated to disclose the tool and its retention period.
3.3 Data derived from AI processing of videos
Videos uploaded by contributors are processed through an automated pipeline. Storage and the main processing run in the European Union; the exceptions are described in section 5. The pipeline produces, in this order:
- Frames extracted at a fixed sampling rate by local processing on EgoVista-controlled infrastructure.
- Visual occultation (pseudonymisation) of faces detected in each frame, performed by a face-detection step. Every subsequent stage of the pipeline declares a dependency on this step, so that the frames reaching any later stage are occulted by construction rather than by instruction. It is a security and data-minimisation measure; the processed video remains personal data within the meaning of Article 4(1) GDPR (see section 3.5).
- Two-dimensional and three-dimensional skeletal keypoints of the body and of each hand, produced by a pose-estimation step. These keypoints are used to characterise the action being performed; they are not used, and the pipeline is not configured, to identify any individual contributor or third party.
- Depth estimation produced by a depth-estimation step on EgoVista-controlled infrastructure.
- Hand-object segmentation masks produced by a GPU compute step. Only frames to which visual occultation has been applied are transmitted to this step.
- Contact-timing labels derived by post-processing the segmentation masks.
- Textual descriptions of the actions visible in the footage, produced by an action-labelling step. That step runs on a single processing path, hosted by a cloud provider in a European region, with a region check that halts processing if the region is not European. Only frames to which visual occultation has been applied are transmitted to it, by construction of the pipeline dependency graph rather than by configuration. The provider and the place of processing are stated in the sub-processor list referred to below.
- Camera intrinsics derived from EXIF metadata, and dataset-level enrichment.
The specific tools and sub-processors used at each step, together with the region of processing and the applicable transfer safeguard, are maintained in an up-to-date, dated list at egovista.app/legal/sub-processors. That list is described by functional category in this Policy so that a change of tool or sub-processor does not, by itself, require a formal amendment of this Policy.
Technical metadata of the file. EgoVista may examine the technical metadata carried by a submitted file, including the container and stream metadata written by the recording device, in order to verify that a submission is consistent with what was declared about it and with the requirements of the mission concerned. That examination is not carried out systematically or exhaustively. It rests on EgoVista’s legitimate interest in the integrity of the datasets it licenses (Article 6(1)(f) GDPR). Neither the carrying out of that examination nor its result constitutes a certification by EgoVista of the place where a recording was made.
3.4 Status of the skeletal keypoints under Article 9 GDPR
Skeletal keypoints describe the geometry of a human body in a frame. Whether such data falls within the special categories of Article 9 GDPR depends on the purpose of the processing. Recital 51 GDPR and the EDPB Guidelines 3/2019 on the processing of personal data through video devices confirm that biometric data falls under Article 9 only when processed for the purpose of uniquely identifying a natural person. EgoVista processes keypoints solely to characterise the action being performed in the video; the data is not used, and is not technically configured, to identify the individual filmer, and no identification template is created or stored.
EgoVista nonetheless applies, as a matter of internal policy, safeguards of the kind that would be required under Article 9 GDPR if the data were within scope: explicit consent of the contributor for the production of keypoint annotations, restricted access, encryption at rest, and a documented retention period.
The written analysis supporting this qualification, including what weakens it and the events that would reopen it, is set out in EgoVista’s combined data protection and AI Act assessment. It is available on request at privacy@egovista.app, and the qualification will be revised should the EDPB or the CNIL adopt a position bringing pose data within Article 9 irrespective of purpose.
3.5 Status of facial occultation under the GDPR
EgoVista uses the term “visual occultation” rather than “anonymisation”. Under Opinion 05/2014 of the Article 29 Working Party (WP216) and the work of the EDPB on pseudonymisation, true anonymisation requires that no individual remain identifiable by any means reasonably likely to be used. Because a video may contain residual identifiers other than the face (voice, gait, clothing, surroundings, identifying objects), the application of a facial blur is a measure of pseudonymisation and data minimisation. The processed video therefore remains personal data within the meaning of Article 4(1) GDPR, and all GDPR obligations continue to apply.
As part of its data protection by design approach, EgoVista separates source videos (constituting the additional information referred to in Article 4(5) GDPR) from the annotated datasets delivered to business customers, with restricted access. The reinforcement of this separation through further cryptographic and organisational measures is described in section 9 among the measures currently being deployed.
4. Purposes and legal bases
The table below summarises, for each processing operation, the purpose, the categories of data, the legal basis under the GDPR, the retention period, and the principal recipients. Buyers receive only the annotated dataset (after visual occultation and quality control) and never receive contributor identity data, IP addresses, or any item linking the footage to a named individual.
| Operation | Data | Legal basis | Retention | Recipient |
|---|---|---|---|---|
| Contributor account | Name, email | Performance of the contributor agreement, Art. 6(1)(b) | Duration of the relationship + 3 years | EU-region database |
| Buyer enquiry handling | Name, business email, organisation, message | Pre-contractual measures, Art. 6(1)(b); legitimate interest in commercial development, Art. 6(1)(f) | 3 years from last contact | EU-region database |
| Video upload and storage | Video file, metadata, IP | Performance of the contributor agreement, Art. 6(1)(b) | See section 6 | EU-region object storage |
| Visual occultation of faces | Detected face regions, occulted frames | Data minimisation, Art. 5(1)(c) GDPR; legitimate interest in protecting third parties, Art. 6(1)(f) | Performed as a pipeline stage; intermediate data not retained | EgoVista-controlled infrastructure |
| Skeletal keypoint extraction | Body and hand keypoints | Explicit consent of contributor, Art. 6(1)(a) and, by analogy, Art. 9(2)(a) | Lifetime of the dataset version | EgoVista-controlled infrastructure |
| Hand-object segmentation | Segmentation masks computed on occulted frames | Legitimate interest in developing annotation services, Art. 6(1)(f); CNIL recommendations on AI development | Lifetime of the dataset version | GPU compute provider, EU region |
| Action labelling | Textual labels computed on occulted frames | Legitimate interest, Art. 6(1)(f); CNIL recommendations on AI development | Lifetime of the dataset version | Cloud provider hosting the action-labelling model (see section 5) |
| Site security and abuse prevention | Fingerprinted IP or email, user-agent, rate-limit counters | Legitimate interest, Art. 6(1)(f) | 13 months (CNIL recommendation) | Rate-limiting and error-monitoring providers |
| Payment execution | Beneficiary identity, banking details or electronic address, amount, currency, payment reference | Performance of the contributor agreement, Art. 6(1)(b) | Duration of the active relationship, then erased, subject to accounting and tax obligations | EU-region database; payment providers named in the sub-processor list |
| Detection of duplicate bank accounts | Cryptographic fingerprint of the normalised banking identifier | Legitimate interest in the integrity of the contributor base, Art. 6(1)(f) | Same as the banking details | EU-region database, no recipient |
| Identity, age or residence verification | Document produced by the contributor | Legal obligation and performance of the contributor agreement, Art. 6(1)(c) and 6(1)(b) | Deleted on completion of the check, 30 days maximum; a record of the check is retained | EgoVista-controlled infrastructure |
| Verification of a submission against its declarations | Technical metadata of the file, declarations made at submission | Legitimate interest in dataset integrity, Art. 6(1)(f) | Lifetime of the submission record | EgoVista-controlled infrastructure |
The legitimate interest pursued by EgoVista is the development and operation of a commercial annotation service for egocentric data, which the CNIL has recognised, in its published guidance on artificial intelligence, as a legitimate interest capable of supporting Article 6(1)(f) when accompanied by appropriate safeguards. EgoVista maintains a Legitimate Interest Assessment addressing the three-step test (legitimacy, necessity, balancing). That assessment forms Part II of EgoVista’s combined data protection and AI Act assessment, revised on 6 August 2026; the version in force is available on request at privacy@egovista.app.
The safeguards applied by EgoVista include: visual occultation of faces as the first pipeline stage; exclusion of footage filmed in inherently private contexts (toilets, intimate situations, identifiable medical settings); restricted internal access; data minimisation in datasets published openly; and an effective right to object (Article 21 GDPR), which a data subject may exercise at any time as described in section 7.4, as the central safeguard accompanying any processing based on legitimate interest.
5. Transfers outside the European Union
Storage and the main processing run in the European Union. A number of our suppliers are established outside the EEA, and their support, administration and control-plane access constitute transfers under Chapter V. Each is covered by the European Commission’s standard contractual clauses or by the guarantee regime applicable to that supplier.
The table below describes EgoVista’s sub-processors by functional category, with the region of processing and the transfer safeguard in place. The names of the specific sub-processors corresponding to each category are maintained in an up-to-date, dated list at egovista.app/legal/sub-processors. EgoVista may, with a thirty-day prior notice published on that page, change the sub-processor used within a category; substantial changes (in particular changes affecting the country of processing) are notified by email to registered users.
| Functional category | Region of processing | Data concerned | Transfer safeguard |
|---|---|---|---|
| Object storage | European Union | Video files, dataset artefacts | EU jurisdiction selected; Standard Contractual Clauses concluded with the supplier |
| Database | European Union | Accounts, metadata, contact-form messages | EU region selected; Standard Contractual Clauses concluded with the supplier |
| Application hosting | European Union | Application traffic; no video content transits this layer | Standard Contractual Clauses concluded with the supplier |
| GPU compute for segmentation | European Union | Occulted frames for segmentation | EU data centres selected at endpoint level; Standard Contractual Clauses concluded with the supplier |
| Action labelling | Stated in the sub-processor list | Occulted frames for action labelling | Guarantee regime applicable to that supplier, described in the sub-processor list |
| Rate limiting | European Union | Fingerprinted identifiers, rate-limit counters | EU region selected; Standard Contractual Clauses concluded with the supplier |
| Transactional email | European Union / United States | Email addresses for transactional emails | Standard Contractual Clauses concluded with the supplier |
| Error monitoring | European Union | Aggregated error reports | EU storage region selected at account creation and not modifiable; Standard Contractual Clauses concluded with the supplier |
| Payment execution | Stated in the sub-processor list, by provider | Beneficiary identity, banking details or electronic address, amount, currency, payment reference | Standard Contractual Clauses or the guarantee regime applicable to that provider, stated in the sub-processor list |
Payment providers are named individually in the sub-processor list rather than by category alone, because the country in which a contributor is paid determines which provider executes the payment and therefore where the data is processed. A change of provider for a given corridor is notified as a substantial change under section 15.
Where a supplier certified under the EU-U.S. Data Privacy Framework is used, EgoVista treats that certification as a complement to the Standard Contractual Clauses and not as a standalone transfer mechanism. Data subjects should be aware that the adequacy decision underpinning the Framework is the subject of a pending appeal before the Court of Justice of the European Union, which is a factor of legal uncertainty; if the Framework were invalidated, EgoVista would rely on the Standard Contractual Clauses already in place and would notify registered users.
A copy of the Standard Contractual Clauses applicable to any specific sub-processor can be requested at privacy@egovista.app. Where those clauses are concluded between a supplier and its own sub-processors rather than between EgoVista and the supplier, EgoVista will say so and will point to the supplier’s published transfer documentation. Where a transfer takes place to a recipient outside the European Economic Area that is not covered by an adequacy decision, EgoVista takes reasonable supplementary measures consistent with the EDPB Recommendations 01/2020.
6. Retention periods
EgoVista applies the following retention periods, which reflect the CNIL’s general recommendations on the duration of personal data storage.
- Identification data of contributors and buyers: duration of the relationship, plus three years from the last meaningful interaction.
- Connection logs and rate-limit data: up to 13 months.
- Aggregated audience-measurement data, if such a tool is deployed: up to 26 months.
- Video files that are rejected during quality control: deleted within 90 days of the rejection decision.
- Video files that are accepted but not yet integrated into a delivered dataset: deleted within 30 days of a withdrawal request by the contributor.
- Video files that are integrated into a dataset already delivered to a buyer: the underlying raw file is retained on EgoVista’s infrastructure for the period necessary to honour quality and audit obligations toward the buyer, and is then deleted. EgoVista cannot unilaterally retrieve copies of the dataset that have already been integrated into a buyer’s training pipeline; EgoVista’s contracts with buyers require the buyer to give effect to erasure requests notified by EgoVista (notification made in discharge of EgoVista’s obligation under Article 19 GDPR), but EgoVista cannot guarantee an outcome that depends on the action of a third party.
- Banking details retained for payment: duration of the active contractual relationship, then erased, subject to the retention required by accounting and tax obligations.
- Cryptographic fingerprint of a banking identifier: same duration as the details it is computed from.
- Documents produced to verify identity, age or residence: deleted on completion of the verification, and in any event within thirty days of receipt. The record of the verification is retained for as long as the relationship, plus three years.
- Evidence of a payment (identity of the beneficiary, amount, currency, payment reference): the period prescribed by accounting and tax obligations.
Deletion at the end of a retention period is currently carried out as a documented manual operation. The automation of this purge is among the measures described in section 9 as currently being deployed.
Records kept as evidence of the lawfulness of a processing operation (proof of consent, deposit attestation, quality-control verdict) are retained for as long as the data they document, and are then either deleted or stripped of the elements linking the record to an identified person.
7. Your rights
Within the scope of the GDPR, contributors, buyers, visitors and third parties captured in footage have the following rights. EgoVista uses reasonable efforts to respond to requests within one month, extendable by two months for complex requests, in accordance with Article 12(3) GDPR.
7.1 Right of access (Article 15)
You may obtain confirmation that EgoVista processes your personal data and receive a copy of that data, together with the information listed in Article 15(1) GDPR.
7.2 Right to rectification (Article 16)
You may request the correction of inaccurate data or the completion of incomplete data.
7.3 Right to erasure (Article 17)
Personal data that EgoVista no longer needs for the purpose for which it was collected is erased. For video files, the following rules apply:
- A video that has not yet been integrated into a delivered dataset can be fully erased within thirty days of a request.
- For a video already integrated into a delivered dataset, EgoVista erases the file from its own systems within thirty days, and notifies each business customer having received the dataset of the erasure request (notification made in discharge of EgoVista’s obligation under Article 19 GDPR), so that the customer may give effect to it under its own GDPR compliance procedure (Article 17(3) GDPR exceptions may apply on the customer side, in particular for scientific research). EgoVista cannot guarantee an outcome that depends on the action of a third party, but remains responsible for the effective notification.
- Datasets sold to business customers are commercialised under an irrevocable licence for their intellectual property dimension (cf. Contributor Terms of Service). The right to erasure applies to the personal data layer (Articles 17 and 7(3) GDPR) and is independent of the IP licence.
- Data retained to comply with a legal obligation (in particular accounting and tax obligations) is kept for the period prescribed by that obligation.
7.4 Right to restriction (Article 18) and right to object (Article 21)
You may ask EgoVista to restrict the processing of your data in the cases listed in Article 18 GDPR, or object to any processing based on legitimate interest. EgoVista will stop the processing unless it demonstrates compelling legitimate grounds that override your interests.
7.5 Right to portability (Article 20)
Data provided directly by you and processed on the basis of consent or of a contract is provided, on request, in a structured, commonly used and machine-readable format. Requests are currently fulfilled by a documented manual export; a self-service export is among the measures described in section 9 as currently being deployed.
7.6 Withdrawal of consent
Where processing is based on consent (typically for the production of skeletal keypoint annotations), you may withdraw your consent at any time, in one click, from the Settings page of your contributor account. Withdrawal is as simple as giving consent, as required by Article 7(3) GDPR: it takes effect immediately, no reason is required, and it has no consequence for your access to campaigns, your remuneration, or your account. You may also write to privacy@egovista.app. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
7.7 Right to lodge a complaint
You have the right to lodge a complaint with the CNIL (3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, www.cnil.fr) or with the data protection authority of the Member State of your habitual residence.
7.8 How to exercise these rights
Write to privacy@egovista.app and indicate which right you wish to exercise. EgoVista may ask for additional information if necessary to verify your identity, and will limit such verification to what is strictly necessary. EgoVista does not require a copy of an identity document as a matter of course, and will request one only where a reasonable and documented doubt exists as to the identity of the requester.
Where EgoVista requests a document to verify a contributor’s identity, age or residence under the Contributor Terms, that document is deleted as described in section 3.1 and section 6. EgoVista does not require a copy of an identity document as a matter of course, and requests one only where a reasonable and documented doubt exists.
8. Protection of third parties incidentally captured
Egocentric footage may capture the image of third parties who are not contributors (passers-by, household members, colleagues). EgoVista takes reasonable measures to protect these third parties, including:
- Visual occultation is applied to detected faces as the first stage of the pipeline, before any frame is transmitted outside EgoVista’s infrastructure and before any dataset is delivered to a buyer. The visual occultation step uses a face-detection model with high recall settings; no detection model is perfect and EgoVista does not warrant exhaustive detection.
- The contributor agreement (Conditions Générales d’Utilisation des Contributeurs) requires the contributor to obtain consent from any person who is filmed knowingly and at close range, to avoid intentionally filming minors, and to avoid filming inherently private settings.
- Where the technical and practical impossibility of contacting incidentally captured third parties individually triggers the exception of Article 14(5)(b) GDPR (“disproportionate effort”), EgoVista compensates by providing public information at egovista.app/privacy and by offering an effective right to object.
Any person who recognises themselves in footage that has been delivered to a buyer may request the removal of their image by writing to privacy@egovista.app. EgoVista will use reasonable efforts to action the request within thirty days and, if the footage is part of a delivered dataset, notify the buyer of the request as described in section 7.3.
Any third party who recognises themselves in footage being processed by EgoVista may exercise their rights under the GDPR (in particular Article 17 erasure and Article 21 objection) by writing to privacy@egovista.app. EgoVista will action such requests with the same diligence as requests from Contributors, and will notify business customers having received the relevant dataset where applicable, in accordance with section 7.3 of this Policy.
9. Security measures
EgoVista implements technical and organisational measures in accordance with Article 32 GDPR. No security measure can guarantee absolute protection against all possible threats; EgoVista applies an approach proportionate to the risk and to the means available to a company at its current stage.
This section distinguishes the measures currently in place from those that are being deployed. That distinction is deliberate: describing a measure that is not yet operative would be a false statement rather than an incomplete one.
9.1 Measures in place
- Encryption in transit: all traffic uses HTTPS with TLS 1.3 (or higher when supported by the client).
- Encryption at rest of personal data stored in the database and in object storage.
- Row Level Security policies are enabled on the database tables.
- Access to video files in object storage is granted exclusively through short-lived signed URLs (default one-hour expiration), and each access is logged.
- Video files transit directly from the contributor’s browser to object storage by way of a pre-signed URL; the application server never handles the file content.
- Server-side validation of uploaded file MIME types.
- Rate limiting on public endpoints, backed by an EU-region service. The identifiers transmitted to that service are fingerprinted rather than sent in clear text.
- Error monitoring via a service whose storage region is set to the European Union and cannot be changed, with stack traces configured to exclude personal data.
- Evidence tables are append-only: a quality-control verdict, a deposit attestation or a consent event cannot be rewritten once recorded.
- Model-improvement settings are disabled at every supplier where EgoVista data could otherwise be used for that purpose.
9.2 Measures currently being deployed
The following measures are engaged and not yet complete. They are listed here rather than omitted.
- Multi-factor authentication on all administrative access to production systems.
- Automated backups of the production database.
- A secrets vault replacing the storage of sensitive environment variables in the hosting provider’s configuration.
- Automated purge of data having reached the end of its retention period.
- A self-service export fulfilling portability requests without manual intervention.
- A written and tested personal data breach response procedure.
- Periodic review of access rights.
9.3 Personal data breaches
In the event of a personal data breach within the meaning of Article 4(12) GDPR, EgoVista will notify the CNIL within seventy-two hours where the breach is likely to result in a risk to the rights and freedoms of natural persons, and will notify affected data subjects where the risk is high, in accordance with Articles 33 and 34 GDPR.
10. Automated decision-making and profiling
EgoVista does not carry out any solely automated decision-making producing legal effects, or similarly significantly affecting the data subjects, within the meaning of Article 22 GDPR. The annotations generated by AI models are computational labels used as training material; they are not used to make any decision concerning a contributor and they are not represented as reference human annotations.
Decisions affecting a contributor’s submission, in particular the acceptance or rejection of a video and the resulting remuneration, involve human review. A refusal is never taken by automated processing alone: whenever an automated assessment points to a refusal, a person examines the submission and takes the decision. That examination is a real one, and may reach a different conclusion from the automated assessment in either direction. A contributor may contest any decision and obtain a human re-examination, as described in the Contributor Guidelines; where a decision is changed, the submission is restored and the contributor is paid as if the correct decision had been taken initially.
11. EU AI Act
EgoVista’s processing is also relevant under Regulation (EU) 2024/1689 (the “AI Act”). This section describes EgoVista’s position under the AI Act for transparency, even though most AI Act obligations are not addressed to EgoVista directly.
EgoVista qualifies its activity as follows under the AI Act:
- Deployer (Article 3(4) AI Act) of third-party AI models used internally in its annotation pipeline.
- Non-provider (Article 3(3) AI Act): EgoVista does not develop or place on the market any AI system. The datasets sold to business customers are training data, not AI systems within the meaning of Article 3(1) AI Act.
- Outside the scope of Annex III: EgoVista does not deploy any high-risk AI system listed in Annex III. In particular, EgoVista does not engage in remote biometric identification, emotion recognition or biometric categorisation.
- Outside the scope of GPAI (Article 51 AI Act): EgoVista does not develop a general-purpose AI model.
Business customers using EgoVista datasets to train, fine-tune, evaluate, test or deploy their own AI systems are responsible for the AI Act qualification of those systems (including high-risk classification under Annex III, where applicable). EgoVista uses reasonable efforts to cooperate with such customers in the implementation of the data-governance obligations of Article 10 AI Act, including the documentation of data origin, representativeness and quality.
The action labels produced by the pipeline are textual metadata used as training material; they are not synthetic content that could falsely appear to be authentic for the purpose of Article 50(2) or Article 50(4). The provider of the underlying generative model is responsible for the machine-readable marking obligations of Article 50(2).
EgoVista applies, at organisational level, the AI-literacy expectation of Article 4 of the AI Act.
12. Cookies
EgoVista uses one cookie, set only when you sign in, which keeps your session open and applies the access rules protecting your account. It is strictly necessary to a service you have expressly requested and is exempt from prior consent under Article 82 of the French Loi Informatique et Libertés. It is a persistent cookie with a lifetime of up to 400 days, not a session cookie. EgoVista deploys no audience measurement tool, no advertising cookie and no third-party tracker, and stores nothing in your browser’s local storage. Our Cookie Policy sets out the detail. If a tracker requiring consent is ever deployed, a consent mechanism will be introduced and both this Policy and the Cookie Policy will be updated before that deployment, not after.
13. Minors
The Platform is reserved for users aged 18 or above, or the age of majority in the user’s country of residence where that age is higher. EgoVista does not knowingly process personal data of minors and instructs contributors, through the contributor agreement, not to film minors deliberately and not to upload footage in which minors are clearly identifiable. If EgoVista becomes aware that personal data of a minor has been collected, the account and the footage are deleted without undue delay. Any person who believes that a minor appears in delivered footage can contact privacy@egovista.app and the procedure described in section 8 will apply.
14. Data protection impact assessment
Given that the processing relies on innovative technology (pipelines combining computer-vision and large multimodal models) and involves data which, although not used for identification, displays characteristics close to biometric data, EgoVista has carried out a Data Protection Impact Assessment (“DPIA”) under Article 35 GDPR, as part of its data protection by design approach.
That assessment was revised on 5 August 2026 and again on 6 August 2026. It is now a combined document covering the data protection impact assessment, the legitimate interests assessment and the evaluation under Regulation (EU) 2024/1689. A summary can be requested at privacy@egovista.app, subject to the redaction of confidential technical details.
15. Changes to this Policy
EgoVista may modify this Policy from time to time. Substantial modifications (changes in legal basis, in sub-processors located outside the EEA, or in retention periods) are notified by email to registered users at least thirty days before they take effect. Editorial corrections or updates not affecting the rights of data subjects may be made without prior notice but are reflected in the version number and effective date displayed at the top of this Policy. The version in force is always available at egovista.app/privacy. Previous versions are retained and can be supplied on request.
Version 2.3 is an editorial revision. It corrects statements that did not accurately describe the state of the processing, resolves an internal contradiction regarding payment data, and separates the security measures in place from those being deployed. It does not change any legal basis, any retention period, or any right of a data subject.
Version 2.4 records decisions taken since. The applicability of Article 37(1) GDPR has been assessed and no Data Protection Officer is required, replacing the earlier statement that the question was under review. The reference to a separate internal position note on skeletal keypoints is replaced by a reference to the combined data protection and AI Act assessment, which now contains that analysis. The action-labelling step is described as running on a single processing path, the second path having been aligned. It does not change any legal basis, any retention period, or any right of a data subject.
Version 2.5 records the payment mechanism now in operation and corrects three statements that had ceased to be accurate. The previous version stated that EgoVista collected and stored no banking data and that no contributor payment had been executed; both were inaccurate. This version describes the three payment methods, states what is retained under each, and adds the legal basis and retention period for banking details and for the fingerprint used to detect duplicate accounts. It states the retention period for documents produced to verify identity, age or residence, and describes the examination of technical file metadata. It records that a contributor may obtain the re-examination of a decision and be paid where that decision is changed. It does not restrict any right of a data subject.
16. Limitation of liability
EgoVista undertakes the obligations set out in this Policy as a controller within the meaning of the GDPR. To the maximum extent permitted by applicable law, and without prejudice to mandatory provisions of the GDPR and of consumer law, EgoVista’s liability is limited to direct damages resulting from a proven breach of its obligations under this Policy. EgoVista cannot be held liable for incidents resulting from the actions of a third party (in particular a buyer or sub-processor) that EgoVista could not reasonably have prevented, nor for incidents resulting from a contributor’s failure to comply with the contributor agreement (in particular the obligation not to film minors deliberately or not to film inherently private settings).
17. Applicable law and jurisdiction
This Policy is governed by French law and by the European Union data protection framework. The competent courts are the courts of Paris, without prejudice to the right of a consumer contributor to bring proceedings before the courts of his or her place of domicile under Article 18 of Regulation (EU) No 1215/2012.