Zedcor Privacy Policy
1. Introduction
Zedcor Inc. and its affiliated entities, referred to in this Privacy Policy as Zedcor, we, us, or our, are committed to protecting personal information and confidential business information. This Privacy Policy explains how Zedcor collects, uses, stores, protects, discloses, retains, and disposes of information in connection with our websites, customer relationships, contracts, billing, mobile and fixed video surveillance services, live verified monitoring, incident handling, customer communications, customer portals, vendors, and related business operations.
This Privacy Policy is intended to support Zedcor obligations under applicable privacy laws, including Canada privacy laws, applicable provincial privacy laws, applicable U.S. state privacy laws, contractual privacy obligations, and customer security requirements. It is also written to support Zedcor privacy and security control commitments by describing notice, data handling, access control, vendor oversight, retention, security, incident response, and individual rights practices.
2. Scope
This Privacy Policy applies to personal information and customer business information collected, used, disclosed, or retained by Zedcor in connection with:
- Zedcor websites, online forms, inquiries, and communications.
- Customer contracting, billing, account management, sales, support, and service delivery.
- Mobile surveillance towers, fixed surveillance systems, live verified monitoring, video review, alarm validation, incident reporting, and customer-designated alerting.
- Customer portals, authentication, account access, audit logging, cybersecurity monitoring, and operational support.
- Vendor, supplier, and service provider relationships.
- Employment, governance, investor, and business administration activities where applicable.
If a customer contract, data processing agreement, statement of work, or applicable law imposes stronger privacy or security requirements than this Privacy Policy, Zedcor will follow the stronger applicable requirement.
Employees, contractors, applicants, directors, and investors may receive separate or supplemental privacy notices where required or appropriate.
3. Zedcor Roles and Customer-Controlled Surveillance Locations
Zedcor may act as a business that determines certain purposes and means of processing, such as for website inquiries, employee administration, billing, security, and corporate operations. Zedcor may also act as a service provider or processor when it processes surveillance footage, incident information, site contact information, and alert instructions on behalf of customers under contract.
For customer-controlled surveillance locations, customers are generally responsible for determining the lawful basis for surveillance, site selection, signage, notices, employee and visitor communications, site-specific monitoring requirements, and customer-authorized recipients of alerts or reports, unless the contract states otherwise. Zedcor processes customer surveillance information according to the customer contract, customer instructions, and applicable law.
Where required by law, Zedcor provides notice at or before the point of collection through this Privacy Policy, customer contracts, website notices, service documentation, site signage, supplemental privacy notices, or other appropriate notices.
4. Information We Collect
Zedcor limits collection to information reasonably necessary for identified business, contractual, security, legal, or operational purposes. The following table describes the main categories of information Zedcor may collect or process.
| Information Category | Examples | Primary Purpose |
|---|---|---|
| Customer contact information | Customer name, business address, primary contact, billing contact, email address, phone number, customer-designated contacts at monitored sites, escalation contacts. | Contract administration, billing, account management, monitoring, alerting, incident response, support. |
| Customer business and site information | Billing information, credit approval information, customer site address, legal land description for remote sites, site schematics, safety plans, emergency response information, orientation information, access information. | Service setup, monitoring configuration, billing, safety, emergency response, site-specific operations. |
| Video surveillance and monitoring information | Live video, recorded video, still images, faces captured by cameras, license plates, GPS or site location, motion events, alarm events, AI or analytic event metadata where used, incident notes, incident evidence. | Video surveillance, live verified monitoring, alarm validation, incident investigation, customer reporting, and security services. |
| Visitor information | Name, email, license plate, photo, access or visit details where required. | Site security, access management, incident investigation, customer security requirements, and Zedcor security requirements. |
| Website and communication information | Website form submissions, inquiry details, email communications, phone communications, IP address, browser or device information, cookies, and analytics data where used. | Respond to inquiries, provide information, maintain website functionality, improve services, and maintain security. |
| Employee, director, investor, and business relationship information | Information collected during hiring, employment, governance, payroll, administration, board appointment, investor onboarding, or other business relationships. | Employment administration, corporate governance, payroll, tax, benefits, compliance, safety, and business administration. |
| Vendor and supplier information | Vendor contact information, business address, billing information, contract information, service details, compliance documentation. | Vendor management, procurement, billing, contract management, risk management, and compliance. |
| Security and audit information | Account IDs, authentication records, access logs, audit logs, device identifiers, IP addresses, security alerts, administrative activity, vulnerability and monitoring information. | Access control, security monitoring, fraud prevention, incident detection, incident response, compliance, and audit support. |
| Printed or exported information | Printed reports, contracts, invoices, incident records, site lists, contact lists, screenshots, exported records. | Business use only when required, subject to secure handling, storage, and destruction requirements. |
5. Sensitive Information, Video, Audio, Biometrics, and AI
5.1 Video surveillance
Zedcor video surveillance services may capture individuals, vehicles, license plates, images, behavior visible to cameras, motion events, alarm events, GPS or site location information, and incident-related evidence. Zedcor personnel access video and incident records only as necessary to provide services, investigate events, support customers, maintain systems, meet legal requirements, or satisfy contractual obligations.
5.2 Audio
Zedcor does not intentionally collect audio through surveillance systems unless audio collection is expressly approved, contractually authorized, legally reviewed, and configured for a lawful purpose. If audio is enabled for a customer environment, additional notice, consent, or legal requirements may apply.
5.3 Faces and biometric identification
Zedcor surveillance systems may capture images of faces as part of ordinary video footage. Unless expressly stated in a customer contract and legally approved, Zedcor does not use facial recognition or biometric identification to identify individuals.
5.4 Analytics and artificial intelligence
Zedcor may use motion detection, object detection, alarm analytics, video analytics, or similar technologies to support monitoring, alerting, incident detection, service quality, and operational efficiency. These tools may generate event metadata or alerts. Zedcor does not use customer data to train public AI models. New AI, analytics, or automated processing uses involving personal information are subject to privacy, security, vendor, and legal review before production use.
6. How We Use Information
Zedcor may use information to:
- Provide products and services, including video surveillance, mobile surveillance towers, fixed surveillance systems, live verified monitoring, incident reporting, alarm validation, and customer support.
- Set up and manage customer contracts, billing, credit approval, site onboarding, alert lists, service instructions, and customer-designated escalation contacts.
- Monitor customer-designated areas and alert proper customer-designated contacts for security events or operational issues.
- Create, review, store, and share incident reports and incident evidence according to customer contracts and applicable law.
- Operate and secure customer portals, accounts, identity systems, networks, cloud services, and approved service platforms.
- Perform cybersecurity monitoring, access reviews, vulnerability management, logging, auditing, investigation, incident response, and fraud prevention.
- Comply with legal obligations, court orders, regulatory requirements, insurance requirements, audit requests, customer requirements, and dispute resolution needs.
- Manage employment, vendor, supplier, finance, governance, investor, and other business administration processes.
- Improve products, services, websites, monitoring quality, customer support, and security controls.
7. Consent and Legal Authority
Zedcor collects, uses, and discloses personal information with consent where consent is required. Consent may be express or implied depending on the circumstances, the sensitivity of the information, the relationship, the notice provided, and applicable law.
Zedcor may also process information where permitted or required by law, including where processing is necessary to perform a contract, provide requested services, protect security, comply with legal obligations, respond to emergencies, prevent fraud or misuse, manage employment or business relationships, or pursue legitimate business purposes permitted by law.
Individuals may withdraw consent where consent is the basis for processing, subject to legal or contractual restrictions. Withdrawal of consent may affect Zedcor ability to provide certain services.
8. Limiting Collection, Use, Disclosure, and Retention
Zedcor collects only the amount and type of information reasonably necessary for identified purposes. Zedcor uses information only for the purposes described in this Privacy Policy, communicated at collection, authorized by contract, or otherwise permitted or required by law.
Zedcor does not sell or rent personal information. Zedcor does not disclose personal information to third parties for their own marketing purposes without consent. If Zedcor intends to use or disclose information for a materially different purpose, Zedcor will obtain additional consent or rely on another legal basis where permitted by law.
9. How We Share Information
Zedcor may disclose information to the following categories of recipients where appropriate and lawful:
- Customers and customer-authorized recipients, including customer-designated contacts, account contacts, and escalation contacts.
- Service providers and vendors that support hosting, identity, cybersecurity, monitoring, communications, billing, accounting, customer management, storage, backup, analytics, and other business operations.
- Professional advisors, insurers, auditors, legal counsel, consultants, and compliance advisors.
- Law enforcement, courts, regulators, government authorities, or other parties where required by law, court order, subpoena, warrant, emergency, or lawful request.
- Purchasers, successors, or parties involved in a business transaction, merger, financing, restructuring, or transfer of assets, subject to appropriate confidentiality and legal safeguards.
For customer surveillance information, Zedcor generally provides information to law enforcement, insurers, or third parties only at the customer request, with customer authorization, under contract, or when legally required.
10. Approved Systems and Vendor Controls
Customer information may only be stored or processed in systems operated, approved, and controlled by Zedcor IT and Cyber Security. Zedcor does not permit customer information to be entered, uploaded, stored, copied, printed, or processed in unapproved systems or unmanaged locations.
Third-party systems that store or process customer information must be reviewed and approved before use. Zedcor vendor oversight may include security and privacy review, contractual confidentiality and data protection terms, Zedcor-approved single sign-on where applicable, employee provisioning and deprovisioning controls where applicable, audit log availability, incident notification commitments, data return or deletion requirements, and review of a current SOC 2 report or equivalent security assurance where appropriate.
Zedcor maintains internal records of approved systems and vendor reviews. Those internal records are not published in this Privacy Policy for security reasons.
11. Security Safeguards
Zedcor uses administrative, technical, and physical safeguards designed to protect personal information and customer information against unauthorized access, use, disclosure, alteration, loss, theft, or destruction. Safeguards are selected based on the sensitivity of information, business purpose, legal obligations, customer requirements, and operational risk.
- Administrative safeguards, including policies, procedures, training, privacy governance, vendor review, access approval, retention requirements, and incident response procedures.
- Technical safeguards, including encryption where appropriate, identity and access controls, multi-factor authentication, conditional access, audit logging, monitoring, endpoint protection, vulnerability management, backup controls, and secure network controls.
- Physical safeguards, including facility access controls, secure storage, device controls, and secure handling of printed records.
- Least privilege access, need-to-know access, account provisioning and deprovisioning processes, and periodic access review where appropriate.
- Monitoring and auditing of systems, access, and security events to detect, investigate, and respond to suspected unauthorized activity.
No security program can guarantee absolute security. Zedcor works to continuously improve safeguards based on risk, business changes, customer requirements, technology changes, and evolving threats.
12. Printed Customer Information
Customer information should only be printed when there is a valid business need. Printed customer information must be protected the same way as electronic customer information.
- Do not leave printed customer information on desks, printers, conference tables, vehicles, or other unsecured areas.
- Pick up printed documents from the printer immediately.
- Store printed customer information in a secure location when not actively being used.
- Do not place printed customer information in regular trash or recycling.
- Shred printed customer information or place it in an approved secure destruction container when no longer needed.
- Notify Cyber Security immediately if printed customer information is lost, left unsecured, or improperly disposed of.
13. Retention and Disposal
Zedcor retains information only for as long as necessary to fulfill the purpose for which it was collected, satisfy contractual obligations, comply with legal or regulatory requirements, resolve disputes, enforce agreements, maintain security, support audits, or comply with legal hold requirements. Retention may vary by customer contract, data type, jurisdiction, system, legal requirement, and investigation need.
| Information Type | Typical Retention Approach |
|---|---|
| Raw video surveillance footage | Typically retained on a rolling basis, often approximately 30 days, unless a contract, incident, legal hold, investigation, customer instruction, or law requires a different period. |
| Incident reports and incident evidence | Retained according to customer contract, legal requirements, investigation needs, and business requirements. Incident records may be retained for up to 7 years where required or justified. |
| Customer contracts, billing records, and financial records | Typically retained for 7 years or as otherwise required by law, contract, tax, audit, or business requirements. |
| Security logs and audit logs | Typically retained for at least 1 year unless a contract, investigation, legal hold, security need, or law requires a different period. |
| Backups | Retained according to backup lifecycle and disaster recovery requirements. Information may remain in backup media until backups expire or are overwritten according to normal backup retention. |
| Website inquiries and communications | Retained for the period necessary to respond, manage the relationship, support business records, comply with legal obligations, or maintain security. |
| Employee, director, investor, vendor, and supplier records | Retained according to applicable employment, corporate, tax, regulatory, contractual, and business record requirements. |
| Printed customer information | Securely stored while needed and shredded or placed in an approved secure destruction container when no longer required. |
Zedcor may suspend deletion where information is subject to legal hold, regulatory inquiry, litigation, investigation, insurance matter, customer dispute, security incident, or contractual preservation requirement.
14. Accuracy
Zedcor takes reasonable steps to keep personal information in active records accurate, complete, and up to date for the purposes for which it is used. Customers, employees, vendors, and individuals are encouraged to notify Zedcor promptly of changes or inaccuracies in information provided to Zedcor.
15. Individual Privacy Rights
Depending on applicable law and the nature of the information, individuals may have the right to request access to personal information, correction of inaccurate personal information, deletion of personal information, a copy of personal information, restriction or objection to certain processing, withdrawal of consent, information about disclosure of personal information, or complaint review.
Zedcor will verify the identity and authority of the person making the request before disclosing or changing personal information. Zedcor will respond to verified privacy requests within the time required by applicable law. Where no specific legal timeframe applies, Zedcor will use commercially reasonable efforts to respond within 30 days.
For personal information contained in customer-controlled surveillance footage or customer-owned incident records, Zedcor may refer the request to the customer or coordinate with the customer because the customer may control the purpose of surveillance and determine how requests should be handled under the contract and applicable law.
If applicable law provides an appeal right and Zedcor denies a privacy request, the individual may appeal by replying to the decision notice or contacting the privacy contact listed in this Privacy Policy.
16. U.S. State Privacy Notice
Depending on state of residence and applicable law, U.S. residents may have rights to know or access personal information, correct inaccurate information, delete personal information, obtain a portable copy, opt out of sale, opt out of sharing for cross-context behavioral advertising, opt out of targeted advertising, opt out of certain profiling, limit certain uses of sensitive personal information, appeal a denied request, and be free from unlawful discrimination for exercising privacy rights. This section is intended to address state privacy rights where applicable, including California, Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Florida, Delaware, New Hampshire, New Jersey, Kentucky, Nebraska, Minnesota, Maryland, Rhode Island, and other states with applicable comprehensive privacy laws.
| Topic | Zedcor Statement |
|---|---|
| Sale of personal information | Zedcor does not sell personal information for money. |
| Sharing for cross-context behavioral advertising | Zedcor does not share personal information for cross-context behavioral advertising unless a separate notice and opt-out process is provided where required by law. |
| Targeted advertising | Zedcor does not use customer surveillance information for targeted advertising. |
| Sensitive personal information | Zedcor may process sensitive information where necessary for security services, video surveillance, incident response, customer contracts, legal compliance, employment, or business administration. |
| Biometric identification | Zedcor does not use facial recognition or biometric identification unless expressly approved, contractually authorized, and legally reviewed. |
| Non-discrimination | Zedcor will not unlawfully discriminate against individuals for exercising privacy rights. |
| Appeals | Where required by state law, individuals may appeal a denied privacy request through the privacy contact listed in this Privacy Policy. |
| Authorized agents | Where applicable law allows an authorized agent to submit a privacy request, Zedcor may require proof of authorization and identity verification before acting on the request. |
| Profiling with legal or similarly significant effects | Zedcor does not use customer surveillance information for profiling that produces legal or similarly significant effects unless separately disclosed and legally reviewed. |
Where state-specific disclosures or procedures are required, including California-specific or Texas-specific notices, Zedcor will provide those disclosures in this Privacy Policy, a supplemental notice, a customer contract, or another legally appropriate notice. Zedcor does not sell personal information for money, does not use customer surveillance information for targeted advertising, and does not use facial recognition or biometric identification unless expressly approved, contractually authorized, and legally reviewed.
17. Canadian Privacy Rights and Provincial Requirements
Zedcor complies with applicable Canadian privacy requirements, including PIPEDA where applicable and applicable provincial private-sector privacy laws. These requirements include accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and complaint handling.
Where provincial privacy laws apply, including Alberta, British Columbia, Quebec, or other provincial requirements, Zedcor will comply with those laws in addition to PIPEDA where applicable. For Quebec-related processing, Zedcor will assess whether a privacy impact assessment is required before implementing new systems involving personal information or transferring personal information outside Quebec, maintain confidentiality incident records where required, notify required parties where required by law, and evaluate French-language, transparency, cross-border transfer, and privacy officer requirements.
18. Cross-Border Processing
Zedcor may process or store information in Canada and the United States. For video surveillance services, processing may occur in the United States and Canada, while incident data and long-term storage may occur in Canada depending on the service, system, customer contract, and operational need. Zedcor does not knowingly process customer surveillance service information outside North America unless approved, contractually permitted, and legally supported.
When information is processed or stored outside the province, state, or country where it was collected, it may be subject to the laws of the jurisdiction where it is processed or stored. Zedcor uses contractual, technical, administrative, and vendor oversight measures intended to protect information during cross-border processing.
19. Privacy Breaches and Security Incidents
Zedcor maintains incident response processes to investigate suspected or actual unauthorized access, disclosure, loss, misuse, alteration, destruction, or compromise of personal information or customer information. Zedcor evaluates incidents based on the type of information involved, sensitivity, encryption status, likelihood of misuse, potential harm, affected individuals, affected customers, contractual obligations, legal obligations, and province or state notification requirements.
Where required by law or contract, Zedcor will notify affected customers, individuals, regulators, or other required parties. In Canada, Zedcor will assess whether a breach creates a real risk of significant harm and will maintain breach records as required by law. In the United States, Zedcor will evaluate applicable state breach notification requirements. Customer notification will also follow applicable contract requirements.
20. Cookies, Analytics, and Website Technologies
Zedcor websites may collect technical information such as IP address, browser type, device information, pages viewed, referring URLs, form submissions, and similar information. Zedcor may use cookies or analytics technologies to operate websites, improve website functionality, understand website usage, respond to inquiries, and maintain security.
Website visitors may control cookies through browser settings. Some website features may not work properly if cookies are disabled. If Zedcor uses marketing cookies, third-party analytics, or advertising technologies that require consent or opt-out, Zedcor will provide notice and choice as required by applicable law.
21. Children
Zedcor services are not directed to children, and Zedcor does not knowingly collect personal information from children through its websites for marketing purposes. Surveillance footage may incidentally capture children if they are present at a monitored site. Such footage is handled according to this Privacy Policy, the applicable customer contract, and applicable law.
22. Training, Awareness, and Employee Responsibilities
Zedcor employees and authorized personnel are responsible for protecting personal information and customer information. Zedcor provides privacy and security awareness appropriate to employee roles and access. Employees must use approved systems, follow access control requirements, protect printed information, report suspected incidents, and notify Cyber Security if customer information is found in an unapproved system.
23. Privacy Governance
Zedcor maintains internal privacy governance records and processes that may include privacy impact assessments, data inventories, vendor reviews, access control evidence, audit logging evidence, retention evidence, incident records, training records, and control review documentation. These records support privacy governance, security reviews, customer due diligence, and audit readiness, but are not published in this public Privacy Policy.
24. Changes to This Privacy Policy
Zedcor may update this Privacy Policy periodically. The updated policy will include a revised effective date or last updated date. Material changes may be communicated through Zedcor websites, customer communications, contractual notices, or other appropriate methods.
25. Contact Us
Privacy questions, privacy requests, complaints, appeals, or concerns may be submitted to Zedcor using the contact information below:
| Contact Type | Contact Information |
|---|---|
| Privacy Contact | Kyle Doenz, Chief Technology Officer |
| privacy@zedcor.com | |
| Mailing Address | 6806 Willowbrook Park, Houston, Texas 77066 |
| Security Incident Reporting | Report suspected privacy or security incidents to privacy@zedcor.com or through approved Zedcor Cyber Security reporting channels. |
| Phone | (877) 511-9332 |