Solution by Industry
Physical security solutions designed for specific industries and real-world operating environments.
Solution by Application
Surveillance and security solutions designed for specific use cases and security challenges.
Solution by Technology
Integrated technologies powering intelligent security solutions across environments.
Video Management Platforms
On-premise and cloud-based VMS platforms for unified video management.
Network Cameras
Network cameras offering flexible options for different environments and industry needs.
Onboard Security
Onboard security designed for real-time surveillance in transit and transportation.
Network Video Recorder and Appliance
Recording appliances for secure storage and cloud-connected management.
Integration Plug-ins
Integration plug-ins that connect management software with third-party platforms and tools.
Networking
Networking products provide network connectivity & power supply for stable transmission.
Accessories
Accessories designed for various installations, integration, and operation of surveillance products.
Legacy Products
Legacy products maintained for reference and existing deployments.
Learning
Explore the latest physical security insights through cases, articles, videos, and webinars.
Download Center
Download software, firmware, datasheets, QIGs, manuals, and technical documents.
Management Tools
Support resources for warranty, service requests, cybersecurity, and customer assistance.
Design Tools
Management tools for device setup, maintenance, and compatibility verification.
Support
Planning tools to design, calculate, and deploy surveillance system projects.
VPP Ecosystem
Find the VPP Program, platforms, and resources that help you work, learn, and grow.
Technology Partners
Technology partners and programs offering VADP collaboration and exclusive A&E/C support.
Where to Buy
Find authorized distributors and resellers for our products in your country.
The latest Version V 4.1 (Current)
Full title: VORTEX Data Processing Addendum
Document ID: ISMS-DPA-001
Version: 4.1
Effective Date: July 28, 2026
Classification: Public
Standards Alignment: GDPR, UK GDPR (DUAA 2025), Swiss FADP (2023), Canada PIPEDA / Quebec Law 25, Taiwan PDPA (2025), Japan APPI, Australian Privacy Act 1988 (2024); EU AI Act (Regulation 2024/1689), NZ Privacy Act 2020 + Biometric Code 2025, ISO/IEC 27701:2025, ISO/IEC 27018:2025, ISO/IEC 27017:2015, ISO/IEC 27001:2022
This Data Processing Addendum (“DPA”) is incorporated by reference into the VORTEX End User Agreement v2.1 (“EUA”) pursuant to EUA Section 5. For all matters relating to the processing and protection of personal data, this DPA prevails over the EUA (per EUA Section 9.8, Order of Precedence).
Data Controller: The VORTEX customer (“User” as defined in the EUA), who determines the purposes and means of processing.
Data Processor: VIVOTEK Inc., 6F, No. 192, Lian-Cheng Rd., Zhonghe Dist., New Taipei City 235, Taiwan (R.O.C.), provider of the VORTEX VSaaS service.
VIVOTEK processes personal data exclusively upon documented instructions from the Data Controller. To the extent VIVOTEK processes personal data for its own legitimate purposes (billing, account management, anonymized analytics), VIVOTEK acts as an independent Data Controller; these purposes are disclosed in the VIVOTEK Privacy Policy (VIV-ISP-PL01).
1.1 Applicable Regulations
This DPA ensures compliance with: EU GDPR (incl. Digital Omnibus where adopted); UK GDPR (DUAA 2025); Swiss Federal Act on Data Protection (FADP, revised 2023); Canada PIPEDA and Quebec Law 25; Taiwan PDPA (2025 amendments, PDPC); Japan APPI; Australia Privacy Act 1988 (as amended 2024); New Zealand Privacy Act 2020 and Biometric Processing Privacy Code 2025; and ISO/IEC 27701:2025, 27018:2025, 27017:2015, 27001:2022.
The Data Controller retains primary responsibility for the lawfulness and appropriateness of all surveillance activities. The Data Controller represents and warrants that:
VORTEX is a cloud-based Video Surveillance as a Service (VSaaS) platform. Surveillance content data is stored both locally on the Data Controller’s equipment (camera SD card, NVR) and in VIVOTEK’s cloud infrastructure in the Data Controller’s selected regional data center.
The Data Controller selects a cloud data center during onboarding. VIVOTEK recommends selecting the DC region matching where the Data Controller’s cameras and NVR are physically located (e.g., Frankfurt for EU-based cameras). The detailed storage architecture, data center options, cloud services, remote access paths (direct streaming vs. relay service), AI/analytics processing, license tier profiles, retention periods, and data categories are set forth in Annex A.
VIVOTEK also provides an optional Embeddings/Vector Data Processing Service through which AI-generated embeddings and Vehicle Identification Numbers (VINs) are transferred to Cloud Database Service Provider (USA) for vector similarity search. Details are in Annex A, Section A.5.
Processing is solely for: cloud hosting and storage of surveillance content; security monitoring and event detection; AI analytics (where enabled); service operation, maintenance, and technical support; and content retrieval, playback, and export. No processing for commercial profiling, behavioral analysis, or advertising. Consent for marketing use shall NOT be a condition of providing VORTEX. VIVOTEK may create and use fully anonymized, aggregated data from which no individual is or can be identified (GDPR Recital 26 standard) for service improvement, security research, and statistical purposes; such data is no longer personal data and falls outside this DPA. Biometric templates, facial recognition feature vectors, and embeddings derived from facial images (Annex A, Sections A.5 and A.9) are excluded from this carve-out and shall not be used to create such anonymized datasets.
VIVOTEK may engage sub-processors to process personal data on behalf of the Data Controller under a general written authorization model. The current sub-processor list is set forth in Annex C and maintained at https://www.vivotek.com/user_agreement/data_processing_addendum?tab=Sub-Processor_List.
VIVOTEK implements appropriate technical and organizational measures to protect personal data from accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. Key commitments include: encryption at rest and in transit; multi-factor authentication; role-based access control; comprehensive audit logging; regular vulnerability scanning and penetration testing; multi-tenant data isolation; personnel training and confidentiality obligations; and third-party certifications (ISO 27001, ISO 27701, ISO 27018, IEC 62443-4-1). The specific measures are detailed in Annex B.
Annex B may be updated by VIVOTEK to reflect improvements in security measures. Updates shall not degrade the overall level of protection.
VIVOTEK shall assist the Data Controller in fulfilling data subject rights obligations. Response within fifteen (15) days. The Data Controller is responsible for verifying the data subject’s identity before instructing VIVOTEK to act. Where a DSR is manifestly unfounded or excessive (GDPR Art. 12(5)), VIVOTEK may charge a reasonable fee for administrative costs or decline to act, subject to agreement with the Data Controller. Technical mechanisms for video-specific DSRs (identify, export, delete footage) subject to the Data Controller’s identity verification. VIVOTEK shall not respond to direct DSRs without Data Controller authorization unless legally required. Standard self-service tools at no charge; manual processing at professional services rates with advance estimates.
The cross-border transfer profile depends on the Data Controller’s selected cloud data center and service configuration:
9.1 Prohibited Intentional Uses. The Data Controller shall not use VORTEX for: (a) systematic profiling based on special category data attributes; (b) covert workplace surveillance without employee notification; (c) mass biometric identification without a valid lawful basis and documented DPIA; (d) real-time facial recognition for law enforcement without written authorization; (e) social scoring, emotional analysis for discrimination, or predictive policing; (f) processing of minors’ biometric data without parental/guardian consent where required.; (g) real-time remote biometric identification in publicly accessible spaces, except where explicitly authorized under EU AI Act Art. 5(1)(h) exceptions and documented in a signed processing instruction; (h) using facial recognition whitelist/blocklist features for discriminatory access control based on race, ethnicity, religion, gender, disability, or any other protected characteristic
9.2 Incidental Capture. The parties acknowledge that video surveillance inherently involves incidental capture of special category data. VIVOTEK’s processing is limited to storage, transmission, transcoding, indexing, and display — VIVOTEK does not classify or profile based on special category attributes. The Data Controller is solely responsible for assessing DPIA requirements.
9.3 Data Type Restrictions. The Data Controller shall not transmit to VORTEX any data unrelated to the surveillance service (medical records, criminal records, unrelated financial records, personnel files, privileged data). If such data is transmitted in violation of this clause, VIVOTEK shall not be liable and the Data Controller shall indemnify VIVOTEK per Section 18.
This DPA remains valid as long as the EUA is active. Retrieval: thirty (30) days post-termination for data export at no charge. Deletion: within thirty (30) additional days (sixty (60) total). Written certification of deletion upon request. Non-standard export formats may incur reasonable fees. The anonymized data carve-out (Section 3) and Sections 2, 6, 14, 17, 18 survive termination.
One (1) audit per twelve-month period with thirty (30) days’ advance written notice. Third-party auditors: NDA required, no competitors, business hours. VIVOTEK may satisfy requests via ISO 27001 certificates, ISO 27701/27018 certificates (where available), or SOC 2 Type II reports. VIVOTEK shall cooperate with regulatory inspections under applicable law.
VIVOTEK shall provide reasonable assistance for DPIAs, particularly for public/semi-public surveillance, biometric processing, and large-scale monitoring. The Data Controller retains primary DPIA responsibility.
All personnel bound by confidentiality obligations. Need-to-know access only. Annual privacy-specific training. Mutual confidentiality: Data Controller shall treat VIVOTEK security information as confidential. Survives termination for three (3) years.
VIVOTEK shall maintain accessible complaint channels, acknowledge within thirty (30) days, and respond without undue delay.
16.1 If the Data Controller is located in the European Union, United Kingdom, Switzerland, Japan, Australia, New Zealand, or Canada, this DPA is governed by the laws of Ireland, without regard to its conflict of law provisions.
16.2 If the Data Controller is located in Taiwan (R.O.C.), this DPA is governed by the laws of the Republic of China (Taiwan).
16.3 For all other jurisdictions, this DPA is governed by the laws of the State of California, United States, without regard to its conflict of law provisions.
16.4 Where an applicable Schedule (Schedule 1, 2, or 3) specifies a different governing law for matters within that Schedule’s scope, the Schedule’s governing law provisions prevail for those matters.
16.5 Disputes arising from this DPA shall be subject to the dispute resolution provisions of the EUA (Section 9.4). Where this DPA survives termination of the EUA (during the data deletion period), disputes shall be resolved by the courts corresponding to the governing law specified above.
16.6 This section is without prejudice to mandatory data protection laws applicable in the Data Controller’s jurisdiction. Nothing in this section limits the rights of data subjects or supervisory authorities under applicable law.
17.1 General Cap. Except as provided in Sections 17.2 through 17.4, each party’s aggregate liability arising out of or related to this DPA shall not exceed the total fees paid by the Data Controller for VORTEX in the twelve (12) months immediately preceding the event giving rise to the liability.
17.2 Enhanced Cap for Data Protection Claims. For claims arising from VIVOTEK’s breach of this DPA, VIVOTEK’s failure to implement the security measures described in Annex B, or a personal data breach caused by VIVOTEK, VIVOTEK’s aggregate liability shall not exceed two (2) times the amount described in Section 17.1. VIVOTEK’s indemnification obligations under Section 18 are subject to this Section 17.2.
17.3 Administrative Fines. Each party is solely responsible for administrative fines imposed on it by a competent supervisory or regulatory authority in respect of its own infringement. A party may recover amounts corresponding to such fines from the other party only to the extent the fine directly and primarily resulted from the other party’s breach of this DPA; any such recovery from VIVOTEK is subject to the cap in Section 17.2. The Data Controller’s indemnification obligations under Section 18 (including for unlawful instructions, non-compliant deployments, and prohibited uses) are not subject to the caps in this Section 17.
17.4 Uncapped Liabilities. Nothing in this Section 17 limits or excludes liability for: willful misconduct or gross negligence; fraud; death or personal injury; or any liability that cannot be limited or excluded under applicable law, including liability to data subjects under Clause 12 of an applicable Schedule (EU SCCs).
17.5 Exclusive Channeling. Claims arising from unauthorized access to, or unauthorized disclosure of, User Personal Data (as defined in the EUA) are governed exclusively by this DPA, including this Section 17 and Section 18, and shall not be characterized as breaches of confidentiality obligations under the EUA or this DPA for the purpose of avoiding the caps in this Section 17.
17.6 Damages Exclusion. Neither party shall be liable for indirect, incidental, special, consequential, or punitive damages.
Data Controller indemnifies VIVOTEK from claims arising from: unlawful instructions, non-compliant deployments, prohibited uses, or violation of applicable law. VIVOTEK indemnifies Data Controller from claims arising from: VIVOTEK’s breach of this DPA, failure to implement Annex B security measures, or unauthorized access/disclosure caused by VIVOTEK’s negligence or willful misconduct. Conditioned on prompt notice, reasonable control of defense, and cooperation.
Neither party liable for failures beyond reasonable control. Affected party shall notify promptly. Sixty (60) day trigger for termination.
VIVOTEK designates the IT ISMS Manager as the primary privacy contact for VORTEX Data Controllers.
Email: privacy@vivotek.com
Address: 6F, No. 192, Lian-Cheng Rd., Zhonghe Dist., New Taipei City 235, Taiwan (R.O.C.)
Where required by law, VIVOTEK shall appoint a DPO and communicate contact details. For Swiss Data Controllers: a Swiss representative will be designated if required under FADP Art. 14.
This DPA body shall be reviewed annually or upon material regulatory changes. Annexes A through D may be updated by VIVOTEK to reflect changes in processing activities, technical measures, sub-processors, or regulatory requirements. VIVOTEK shall provide at least thirty (30) days’ notice of material changes to any Annex. The current version of each Annex is maintained at https://www.vivotek.com/user_agreement/data_processing_addendum. For sub-processor changes specifically, the notification and objection mechanism in Section 4 applies.
Next Review: July 2027 or upon material regulatory change.
(Annexes of DPA and related Schedules upon request)
Current version — last updated July 28, 2026 (maintained in accordance with the VORTEX Data Processing Addendum v4.1, Annex C)
This page lists the sub-processors engaged by VIVOTEK Inc. to process personal data contained within the User Data on behalf of the Data Controller in connection with the VORTEX service, where VIVOTEK acts as Data Processor. This list constitutes Annex C of the VORTEX Data Processing Addendum (available at https://www.vivotek.com/user_agreement/data_processing_addendum) and is governed by its Section 4 (Sub-Processor Management). Recipients of Service Data, for which VIVOTEK acts as Data Controller, are separately listed in the VORTEX Privacy Policy (available at https://www.vivotek.com/user_agreement/vortex?tab=Privacy_Policy).
Sub-Processor |
Service |
Processing Locations |
DPA/Certification |
Amazon Web Services, Inc. 410 Terry Ave North, Seattle, WA 98109, USA |
Cloud Infrastructure |
Germany; Japan; Australia; United States |
ISO 27001, 27017, 27018, SOC 2 Type II |
Cloud Database Service Provider |
Vector Database |
United States |
DPA in place with VIVOTEK |
VIVOTEK engineering and support personnel located in Taiwan (R.O.C.) may access personal data in any regional data center for troubleshooting, maintenance, and support via encrypted VPN. This access is subject to RBAC, audit logging, MFA, and confidentiality obligations.
Advanced AI Add-On (Data Processing Addendum, Annex A, Section A.11): inference executes on the Data Controller's camera hardware (edge) and does not involve any sub-processor beyond those listed above. Any future engagement of a third-party AI model provider will be subject to the Section 4 notification and objection mechanism (30 days' notice) before taking effect.
Per Section 4 of the Data Processing Addendum, VIVOTEK may engage sub-processors under a general written authorization model, and this list may be updated to reflect changes in sub-processors. Such updates are subject to the following mechanism:
International transfers to the sub-processors listed above are conducted under the transfer mechanisms set forth in the Data Processing Addendum (Section 7 and Annex B) and its transfer Schedules.
Effective date of this Annex: April 29, 2026. Last updated: July 28, 2026.
For questions regarding this list, please submit DSAR and contact Privacy@vivotek.com.