1. Who this policy covers
This policy describes how OurVision AI Group Ltd. ("OurVision AI," "we," "us") handles personal and biometric data encountered through our border and identity platform — the Traveler Verification Service (TVS), eTA and Digital Embarkation services, and the Digital Travel Credential (DTC) service — and through this website.
In most deployments, OurVision AI acts as a data processor on behalf of the government authority or airline that operates the service ("the Customer"). The Customer determines why and how data is processed; this policy explains our role and practices as their processor, alongside our practices as a controller for this website itself.
2. Information we process
- Biometric data: a live facial capture converted to a biometric template at the point of verification, and the reference photo used for matching.
- Travel document data: passport or travel document number, nationality, date of birth, issuing country, document type and expiry.
- Trip data: flight or voyage number, arrival/departure dates, purpose of visit, length of stay, accommodation details.
- Declarations: customs, health, and lodging declarations submitted through digital embarkation forms.
- Screening results: watchlist check outcomes and risk indicators generated during pre-arrival screening.
- Website data: standard technical data (IP address, browser type) if you visit ourvision.ai, and any information you submit through a contact form or email.
3. Why we process it
Data is processed to perform the specific government or airline function the Customer has deployed us for: verifying a traveler's identity against a staged reference photo, screening trip data against watchlists ahead of arrival, issuing and verifying a Digital Travel Credential, and supporting the Customer's own border or boarding decision. We do not use this data for advertising, and we do not sell personal or biometric data to any third party.
4. Data residency and sovereignty
Our default position is that data stays within the jurisdiction of the deploying Customer. See our full data residency & sovereignty statement for the operating principles that govern this — in short: hosting within the Customer's designated jurisdiction, no cross-border transfer without the Customer's authorization, Customer-controlled access, and retention set by the Customer's own law and policy rather than a default OurVision AI schedule.
5. Retention and deletion
Transient verification data — a live capture and its resulting match score — is designed to purge automatically once its immediate purpose (a single walk-through, a single screening) is complete. Longer-term records, such as an issued credential or a case file tied to an admit/refer decision, are retained according to the schedule set by the Customer, consistent with their own legal obligations.
6. Sharing
Data is shared only with: (a) the Customer that operates the deployment, (b) subprocessors under written contract who support the platform's operation (e.g. cloud infrastructure providers), and (c) authorities the Customer is itself legally required to share data with (for example, a watchlist screening result shared with the relevant border authority). We do not share biometric or travel data with any other party, and never for marketing purposes.
7. Security measures
We apply industry-standard technical and organizational measures appropriate to biometric and travel data, including encryption in transit and at rest, access controls scoped to least privilege, and audit logging of access to verification records. We maintain SOC 2 Type II and ISO/IEC 27001 certification; audit reports are available to Customers under contract.
8. Your rights
If a government authority or airline has processed your data through this platform, requests to access, correct, or delete your data should generally be directed to that authority or airline in the first instance, as they control the underlying record. Where OurVision AI is the appropriate contact, you may reach us at info@ourvision.ai.
9. International transfers
Data is not transferred across a jurisdictional or regional boundary except with the deploying Customer's explicit authorization and appropriate safeguards, consistent with our data residency position above.
10. Children's privacy
Our platform processes travel document data for travelers of all ages where a government's own travel and immigration requirements apply to minors, but this website is not directed at children, and we do not knowingly collect data from children through the website itself.
11. Changes to this policy
We may update this policy as our services or applicable law change. Material changes will be reflected with an updated date at the top of this page.
12. Contact
Questions about this policy can be sent to info@ourvision.ai.