Compliance
Written for the people who have to sign off: council privacy officers, WHS managers and enterprise security reviewers. This page sets out what our technology does, what it deliberately does not do, and what we will give you before anything is installed.
Last updated: August 2026
Our Compliance Position
CrowdSense measures crowds without identifying anyone. Detection runs on the device, counts and events leave the device instead of video, and no part of the product performs facial recognition, number-plate recognition or biometric identification. That is a design decision, not a configuration setting — which means the privacy question you are assessing is a narrow one, and we can answer it in writing.
CrowdSense (crowdsense.events) is an Australian business operated by Artefact Group. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. This page sits alongside ourPrivacy Policy, which is the binding statement of how we handle information.
Privacy by Design
- Processing happens on the device. Sense Nodes read anonymous Bluetooth (BLE) signals already present in a crowd. Vision Nodes are built so imagery never becomes a live video stream — the 301 runs detection on board at video rate using an on-device neural accelerator; its smaller sibling, the 101, captures on a battery-friendly schedule and reports keyframes, with detection applied in the platform. Vision applied to a customer's existing IP or CCTV cameras works the same way.
- Counts and events leave, not video. What crosses the network is structured data — counts, object classes, zone events, timestamps — published over MQTT. There is no video stream to intercept, store or subpoena.
- Retrospective review is anonymised. Timelapse and X-Ray Vision keep periodic keyframes, not continuous footage. Keyframes render "frosted": anonymised silhouettes with no readable faces or number plates.
- Retention is yours to set. Keyframe retention is configurable per site and set by the customer operating that site. Metrics can outlive imagery.
- No identification, anywhere in the product. No facial recognition, no number-plate recognition, no biometric identification, no matching a person between sites, no re-identification of anonymous readings.
Australian Privacy Principles
Most deployments collect little or no personal information. Where they do, the platform is built to support your obligations rather than complicate them.
- Collection limitation (APP 3). Nodes collect what is needed to produce a count and nothing more. Anonymous signal readings and structured detections are not linked to accounts, tickets or customer records.
- Notification (APP 5). We help you produce the on-site notice that tells people measurement is taking place — see Notification and Signage below.
- Use and disclosure (APP 6). Deployment data is used to deliver the service to the commissioning customer. We do not sell it, trade it, or combine anonymous crowd measurements with contact records.
- Security (APP 11). Encryption in transit and at rest, scoped tokens and audited access, detailed under Security below. Data never captured cannot be exposed.
- Access and correction (APP 12 and 13). Requests can be made toprivacy@crowdsense.events. Where the request concerns a specific site, the customer operating it is the controlling entity and we support their response.
- Cross-border disclosure (APP 8). Where a provider stores or processes data outside Australia, we take reasonable steps to ensure it is handled consistently with the APPs, and we will tell you which providers those are.
GDPR and Overseas Customers
For deployments in the EU or UK we additionally commit to handling personal data consistently with the GDPR.
- The customer is the controller for their deployment; we act as processor under a written data processing agreement.
- We support data subject rights including access, erasure, restriction, portability and objection, and will act on instructions from the controller.
- Because detection runs on the device and imagery is anonymised, most deployments involve no special category data and no automated decision-making about individuals.
- Transfers outside the EEA or UK are made under standard contractual clauses, and processing location can be constrained where a deployment requires it.
- We will contribute the technical detail needed for your data protection impact assessment, and support your records of processing.
Supporting Your Privacy Impact Assessment
Before anything is installed we will give you, in writing and specific to your site design, the following.
- What each node captures — by model, sensor type and configured mode.
- What is processed locally on the device and what is discarded there.
- What is transmitted, in what form, over which network path.
- Where it is stored, and by which providers.
- Retention periods for metrics, keyframes and logs, as configured for your sites.
- Who can access it — your roles, our roles, and any integration holding a token.
We will also help draft the wording for public notification signage, so the notice matches what the equipment actually does rather than a generic CCTV warning.
Notification and Signage
We recommend that customers notify people that measurement is taking place, even where the measurement is anonymous and notification is not strictly required. It is good practice, it pre-empts complaints, and it is usually the first thing a regulator asks about.
Effective wording says what is measured, what is not, who operates it and how to ask a question. We will supply draft text, help you size and place it, and where CrowdSense Signage is deployed the notice can be carried on screen alongside your other messaging.
Workforce and WHS Considerations
Crew features are workforce data and should be assessed separately from attendee measurement. The Companion App and Travla use named accounts for crew check-in and, where a customer enables it, live crew position during a shift. ConstructionSense features such as worker headcount, PPE and exclusion-zone checks and after-hours monitoring sit in the same category.
The employing customer must inform workers about what is collected, why, and for how long. We recommend covering it at induction before accounts are issued, and documenting it in the WHS management plan on construction sites alongside the other site-monitoring controls. We hold workforce data on the customer's behalf and use it for no other purpose.
Security
- Encryption in transit and at rest across the platform.
- Access to The Brain — via the MCP server, REST API or webhooks — uses scoped tokens that the customer issues and can revoke at any time.
- Read and write permissions are separated, so an integration that only reads cannot write.
- Calls are logged and auditable, and the Control Room maintains an automatic timestamped decision log.
- Our staff work on a least-privilege basis: access to customer environments is limited to personnel who need it, granted for a purpose and removed when it ends.
- An AI agent connected by a customer only ever sees what that customer's token permits. It cannot reach another customer's data and cannot widen its own scope.
Hardware Certification
The modules our nodes and signage players are built on carry CE, FCC and RoHS marks, and conformity documentation can be supplied for a specific build on request.
Radio equipment is supplied in the variant legal for the market it ships to — including the correct LoRa frequency plan for Australian deployments and the appropriate cellular bands for players on a managed data plan. We will not ship a radio variant into a market it is not approved for.
Data Residency and Sub-Processors
Platform data is hosted on secure infrastructure. We use a small number of sub-processors — cloud hosting, email delivery, mobile connectivity and the form-to-email relay behind this website's enquiry forms. Each acts under contract, is limited to what it needs, and is not permitted to use the data for its own purposes.
A current sub-processor list, naming each provider, its role and its processing locations, is available on request. Where a deployment has residency requirements, tell us early and we will confirm what can be constrained before you commit.
Incident Response
On a suspected breach we contain first, then investigate: isolate the affected system, revoke or rotate the tokens and credentials involved, and preserve logs for analysis. We assess what data was involved, whose it was, and whether serious harm is likely.
We notify affected customers promptly so they can meet their own obligations, and we give them the technical facts they need to do it. Where a breach is likely to result in serious harm we notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. For EU and UK deployments we support the controller's 72-hour notification obligation. Every incident closes with a written summary of cause, remediation and the change made to prevent recurrence.
Accessibility
This website targets WCAG 2.1 Level AA — colour contrast, keyboard operability, visible focus, text alternatives and a logical heading structure. Reduced-motion preferences are respected across the site: when a visitor's system asks for less motion, reveal and transition effects are suppressed. If you strike an accessibility barrier, tell us and we will fix it.
Requesting Documentation
For a security or privacy pack — data flow descriptions, the sub-processor list, our processing terms, hardware conformity documentation and answers to your standard vendor questionnaire — emailcompliance@crowdsense.events. Tell us who needs to sign off and we will write to that audience.
For an individual privacy request or complaint, useprivacy@crowdsense.events, orget in touch for anything else.