Data Privacy & Security
At VivaCity, privacy is at the heart of everything we do.
We believe strongly that the future of the Smart City has to be citizen-centric, and that keeping citizens’ data safe and private is critical to the success of this technology. As such, we have designed our solutions from the ground up to guarantee the privacy of every citizen, utilising privacy-by-design principles.
Privacy-by-design
Our sensors are designed to provide accurate data on the usage statistics of road environments in a completely anonymous way. The system was developed using data protection-by-design principles and is fully compliant with GDPR. Our sensors do not collect personal data, and none of our clients can use our technologies to gather personal data or for enforcement purposes.
Our sensors do not record or stream video footage. Under normal operation, the system processes video locally, produces anonymous data feeds, and discards the video within milliseconds. The system therefore presents no personal data risk.


Data Security
The software cannot identify anything unique about individual vehicles. We have never done any work involving facial recognition and never will, because it violates our commitment to privacy.
The sensor software and memory are encrypted, and all communication to and from the sensor is encrypted using industry-standard HTTPS TLS 1.3 security. During setup, a limited amount of video may be temporarily stored for configuration and calibration, then deleted.
Download the VivaCity solution PDF now and discover what makes our solution unique.
Download now
Privacy Notice to the Public
This is a Privacy Notice for VivaCity sensors. These sensors look like on the image (Left: 2nd generation / right: 3rd generation).
A sign is located on the post mounting the sensor to direct the public to this web page.
These sensors are not CCTV Cameras.
VivaCity sensors are designed to produce Anonymous Traffic Data (see an example below) on how roads are being used to support transport operation and planning. During normal operations, no personal data is produced by these sensors.


This Privacy Notice explains how, during short periods of system development and testing, video may be recorded. While this video is classed as personal data, it will not be used for the purpose of identifying any individual.
A typical sensor will record less than 1 hour of Video Data during its lifetime.
The short video data captured by these sensors are processed by Vivacity Labs Limited.
We take the protection of your data very seriously and have implemented appropriate technical and organisational measures to ensure its security. Only authorised personnel have access to the data and it is stored on secure servers.
Categories of Data: video data of public roads.
Categories of Data: video data of public roads
Data Sharing – Anonymous Traffic Data: We share data with our customers, including government agencies and transport planning authorities for the purposes of supporting and improving traffic flow and transportation planning. Some customers choose to open this data or share it further.
Data Sharing – Video Data: We blur any video data prior to sharing with our customers, including government agencies and transport planning authorities. This data is only shared to provide contextual information about the environment around the sensors, or to validate the accuracy of the Anonymous Traffic Data.
Data Retention – Video Data: A 10 minute video from each sensor is retained for the lifetime of the sensor deployment to test software updates. A subset of Video Data is retained for testing and developing the sensors.
Your Rights: You have the right to access, rectify or erase your personal data. You also have the right to object to the processing of your personal data and to lodge a complaint with the supervisory authority.
Changes to Privacy Notice: We may update this privacy notice from time to time in order to reflect changes to our data collection and processing activities. The latest version will always be available on our website.
If you have any questions about our privacy notice, please contact the Data Protection Officer at dataprotection@vivacitylabs.com.
This notice is in compliance with the General Data Protection Regulation (GDPR).
Cybersecurity
1. Privacy at our core
At VivaCity, privacy and cybersecurity are fundamental to our company principles and product design. We understand the importance of public trust, which is why our products are designed not to routinely store or transmit personal information. Our smart city sensors anonymise data at source, helping customers understand transport networks while protecting the privacy of the communities they serve.
Data governance and privacy controls
VivaCity maintains a formal data protection governance framework, including documented data protection policies, data classification, access control standards, and data handling processes. Information is classified according to sensitivity, with stronger controls applied where information requires additional protection. We also carry out Data Protection Impact Assessments where appropriate. Where customer data is processed, we apply appropriate technical and organisational controls to protect confidentiality, integrity, and availability.
Your data, protected
Our products are built using secure-by-design principles across both our sensors and our cloud systems. Data is protected using encryption in transit and at rest, aligned with modern industry standards.
We apply the principle of least privilege across our systems, ensuring that employees, contractors, and trusted third parties can only access the systems and data required for their role. Access is role-based, reviewed, and protected using strong authentication controls. VivaCity maintains Cyber Essentials Plus certification and undergoes regular independent security assessments aligned with recognised frameworks, including NIST-based controls.
Continuous threat detection and resilience
We operate continuous monitoring across our cloud and edge systems to help detect malicious activity, suspicious access attempts, anomalous configuration changes, and potential operational risks.
Our systems are subject to regular penetration testing and vulnerability assessment, helping us identify and remediate weaknesses before they can affect customers. Our distributed sensor fleet is also governed through automated device monitoring, anomaly detection, and fleet management controls, supporting the ongoing integrity, safety, and reliability of deployed infrastructure.
Secure product development
Security is integrated into our software development lifecycle. We use structured design reviews, risk-based security assessment, peer review, and mandatory code and hardware revision review processes before changes are released. Third-party software dependencies are monitored using automated vulnerability scanning. Security updates are prioritised according to risk, with critical and high-risk vulnerabilities addressed through defined patch management processes.
Access control and authentication
Internal access is managed through centralised identity systems, strong multi-factor authentication, and role-based access controls. Customer-facing systems support secure authentication controls, including two-factor authentication where appropriate. Access permissions are granted on a least-privilege basis and are reviewed to ensure users retain only the access they need.
Audit logging and monitoring
We maintain audit logging across key systems, including authentication events, configuration changes, system activity, and data access events. Logs are retained and monitored using cloud-native security tooling and automated alerting, enabling our teams to investigate suspicious activity and maintain operational oversight.
Endpoint, network, and infrastructure security
Company devices are managed through centralised endpoint management processes, with anti-malware protections and security configuration controls applied across supported platforms.
Network and infrastructure protections are designed to reduce exposure to malicious traffic, brute-force attacks, unauthorised access attempts, and denial-of-service activity. Our infrastructure is managed using repeatable deployment practices, helping ensure consistency, resilience, and rapid recovery where required.
Incident response and business continuity
VivaCity maintains a formal Cyber Incident Response Plan covering detection, triage, containment, investigation, remediation, and customer communication. If a security incident affects customer data or services, we will notify affected customers without undue delay and, where applicable, within required regulatory timeframes. Our systems are designed with resilience and recoverability in mind. We use managed cloud infrastructure, backup controls, point-in-time recovery for key data stores, and infrastructure-as-code practices to support service continuity and disaster recovery.
Clear Communication.
We provide temporary signage near a sensor before gathering images for setup, calibration, or optional software training. The images captured are low resolution and do not contain personal data as defined by the ICO.
ICO & GDPR.
VivaCity is registered with the ICO of the UK and Jersey to collect and hold image data for software development. We act as the data controller for the software training process and have carried out Privacy Impact Assessments for this work.
