Last updated: 29 September 2026 · StomatoBot Technologies Private Limited (“StomatoBot”, “we”, “us”)
This policy explains how we collect, use, store, and protect information when you use Digital WatchMan (our CCTV video-analytics service) and the stomatobot.com website. It is written to align with India’s
Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together, the “DPDP law”).
The one thing to understand first. Digital WatchMan involves two different kinds of personal data, and different people are responsible for each.
Your account — your name, mobile number, email, billing. We decide how this is handled, so StomatoBot is the Data Fiduciary for it.
Your camera footage and the people in it — you decide where your cameras point, what they record, and why. You are the Data Fiduciary for that footage; StomatoBot acts as your Data Processor, handling it only on your instructions and only to provide the service to you.
1. Roles under the DPDP law
- StomatoBot is the Data Fiduciary for account, billing, support and website data — the data we collect because you are our customer. You are the Data Fiduciary for the video your cameras capture and for every person who appears in it. You chose the cameras, their placement, and the purpose of recording.
- StomatoBot is your Data Processor for that video and everything derived from it — detections, alerts, evidence snapshots, clips and face templates. We process it under these terms and your instructions, for the sole purpose of providing Digital WatchMan to you. We do not decide what your cameras record.
Practically, this means obligations toward the people your cameras record — notice, signage, lawful basis, and answering their requests — rest with you. We will assist you in meeting them, and section 9 explains how.
2. Information we collect
- Account data: your name, mobile number (used for OTP login), email address, and organisation details you provide.
- Camera and video data: video streams from cameras you connect are processed by our detection engine to generate alerts. Short evidence snapshots i.e. a still photograph at the moment of an alert, and — if you subscribe to daily summaries — a short summary video built from the day’s events.
- Service telemetry: camera health metrics (frame rate, brightness, motion levels, connectivity) used to learn each camera’s normal behaviour and detect anomalies; and standard website/app usage logs.
- Payment data: processed by our payment partner (Razorpay). We do not store your card or banking credentials.
3. Face data — what it is, and how we treat it
Face recognition is optional and off unless you enable it. While it is off, no face templates are created and no face images are stored — for anyone, known or unknown. Because face data is the most sensitive category Digital WatchMan touches, we set it out separately.
- What we store. When face recognition is on, the system detects faces in your footage and computes a face template — a numeric vector, commonly called an “embedding”, derived from the image of a face. We store the template, a small cropped image of the face, and any name or category you assign to it.
- What a template is not. A template is a mathematical representation used for comparison. It cannot be converted back into a photograph of the person. It is nonetheless personal data derived from a person’s face, and we treat it as the most sensitive data in the system.
- An identity grows over time. When a known person is seen at a new angle, a further template may be added to that person’s identity so recognition improves. This means one named person may be represented by several templates.
- Strict isolation. Face data is stored separately for each customer. We do not share it between customers. We do not sell it. The single exception is a binding legal order, set out in section 8a.
- Children’s faces are blurred. Where the system judges a face to belong to a child, that face is blurred in the stored image and no face template is created for it. A face the system estimates to be under 18 is treated as a child — 18 being the age the DPDP law itself uses. Age judged from a camera image is approximate, so a face close to that line may be judged either way. The DPDP law requires verifiable parental consent to process a child’s personal data, and that cannot be obtained from a child walking into a shop; so we do not process it. The only exception is a child of your own family, whom you name yourself and for whom you are able to give that consent as a parent or guardian.
- This runs on every camera, whether or not you subscribe to face recognition. Finding a face in order to blur it is a different thing from recognising whose face it is: the first protects a child and happens for everyone, the second is the paid feature and happens only if you have bought it. On a camera without face recognition no face is ever identified, named or stored as a template — the system looks for faces solely so that a child’s can be blurred before the picture is saved.
- What this cannot promise. Redaction depends on the child’s face being found in the picture at all. A face turned away from the camera, too small, too dark, or hidden behind something is not detected, and what is not detected cannot be blurred — such a picture may show a child. We blur the faces we judge to be children’s; a face whose age we cannot judge is left as it is, so that a picture of an adult is not destroyed on a possibility. We blur what we find, and we do not claim more than that. Lighting matters to this judgement. Daylight gives the clearest picture of a face. Under artificial light, and after dark when the cameras switch to infrared and the picture loses its colour, there is less for the system to go on, and its reading of a person’s age is correspondingly less certain — so a child’s face may sometimes be left unblurred. We measure this on our own cameras rather than assume it, and we are continuing to improve it. If you find a stored image showing a child’s face, tell us at support@stomatobot.com and we will delete that image.
- Who can see face data. At your premises it is available to you as the account holder and to the staff operators you authorise on your account — the people who run the system day to day. On our side, StomatoBot staff may access it only to operate or support the service, for example to investigate a fault you have reported to us.
- You control naming. Names attached to faces are yours. We do not supply identities, and Digital WatchMan does not attempt to identify anyone against any external database, watchlist or public source. The single exception is a binding legal order, set out in section 8a.
4. How we use it
- To operate the service: detect events, deliver alerts, show live view and history to authorised users of your account.
- To secure the service: authentication, fraud prevention, abuse detection.
- To improve reliability: aggregate, diagnostics that do not include footage.
5. Where your data is stored
We tell you this precisely, because “the cloud” is not an answer:
- Account data, camera configuration, alerts and detection records — stored in our database in the Mumbai, India region.
- Processing (detection engine and servers) — runs on servers located in India.
- Evidence media — snapshots, clips and face crops — stored with established third-party object-storage providers. These providers operate facilities in several countries, and we place media where capacity, cost and reliability allow, which may be within or outside India. Your account records, camera settings, detections and alert history remain in India regardless.
Where any personal data is stored or processed outside India, we do so only as permitted by the DPDP law, which allows transfer except to territories the Central Government restricts. If a restriction is notified that affects us, we will relocate the affected data and update this policy.
6. Retention and deletion
- Alerts and evidence snapshots: retained for the period in your plan, then deleted.
- Video clips: per your plan’s cloud-recording retention. Camera-health telemetry: up to 90 days; longer only as aggregates that identify no one.
- Unnamed face templates: discarded on your instruction, and automatically once they are no longer needed for the retention period of the alerts they belong to.
- Named face templates: retained while the identity is in use in your account, because recognition of a named person is the purpose you enabled the feature for — and retained through a paused subscription, so resuming does not mean re-teaching the system everyone it already knows. A named identity is kept for as long as your account is open. You can curate one at any time — remove individual photos from it, move a photo to the right person, or merge duplicates — and you can delete an unnamed face outright. To have a named identity itself erased, ask our Grievance Officer (section 11) and we will do it.
- Account data: for the life of the account, and afterwards only where a law requires us to keep it.
A paused subscription is not a closed account. If your subscription lapses, the service pauses — but nothing is deleted at that moment. While an account is paused we keep your evidence media and video for 90 days, after which that media is deleted; your face identities and the names you gave them are kept indefinitely, so that recognition still works the day you resume. Resuming a paused account restores the service; you do not start again from nothing.
On official closure of your account — which you request, and which is distinct from a pause — we erase your footage, evidence media and unnamed face data. Named identities are retained for 90 days after closure, so that resuming the service does not mean teaching the system everyone it already knew. After that period we will erase them on your explicit request — email our Grievance Officer (section 11). Erasure is done by hand, not by an automatic sweep due to the sensitivity of the nature of this data: we begin the procedure within a week of your request and work through it according to how much data is involved. We may retain billing records where tax or company law requires.
7. Sharing and our sub-processors
We do not sell or rent personal data. We share it only with the service providers needed to run Digital WatchMan, each bound to use it solely to provide their service to us: our cloud database and hosting providers, our object-storage providers, our SMS provider (login OTP only), our push-notification delivery (browser and device notification services), and our payment gateway (Razorpay). We also disclose data where required by law or valid legal process.
8. Your rights as an account holder
Under the DPDP law you may ask us to give you access to your personal data, correct or complete it, erase it, and you may withdraw consent (which may end the service). You may also nominate another person to exercise your rights if you die or become incapacitated. Write to our Grievance Officer (section 11). We respond within the timelines the law prescribes.
8a. Law enforcement, courts and government requests
We disclose personal data to the police, a court or a government authority only where a law or a valid legal process requires it. We ask for the request in writing, satisfy ourselves that it is properly authorised, and disclose the minimum necessary to answer it rather than a whole account. Where we are permitted to tell the customer that their data has been requested, we do.
Comparison across accounts. Face data is held separately for each customer and is not searched across customers in the ordinary course. Where we are lawfully directed to do so by a court, a judicial order or a competent authority acting under statutory powers — typically in connection with the prevention, detection, investigation or prosecution of an offence — we may carry out a comparison across accounts to the extent, and only to the extent, that the direction requires. We do this only under such a direction, never on request alone.
We keep a record of every such direction we act on.
9. If you were recorded by a customer’s camera
Notice at the premises. Our customers agree, as a condition of using Digital WatchMan, to display a clear notice at the entrances to their premises stating that the area is under camera monitoring and, where they have switched it on, that face recognition is in use. That notice is how you are told, and putting it up is the customer’s responsibility as the Data Fiduciary for their own cameras — not ours. We supply the wording; we cannot put up their signs.
If you believe you appear in footage captured by a Digital WatchMan customer and you want access, correction or erasure, the request goes to that customer — they are the Data Fiduciary for their cameras, not us. If you do not know who operates the camera, or you cannot reach them, write to our Grievance Officer (section 11): we will identify the customer where we can, pass your request on, and act on their instruction to correct or erase. We will not disclose one customer’s footage to another person on our own initiative, because doing so would itself be a breach of their data.
10. Security and breach handling
We protect data with row-level access controls so each customer can reach only their own data, encrypted transport, credential-free camera URLs in our cloud (camera passwords stay on your premises equipment where applicable), least-privilege service keys, and audit logging.
If a personal data breach occurs, we will notify affected customers without undue delay with what we know, what is affected, and what we are doing, and we will make the intimations the DPDP law requires to the Data Protection Board. Where we act as your Processor, we will notify you promptly so that you can meet your own obligations as Data Fiduciary.
11. Grievance Officer
For any question, request or complaint about personal data:
Grievance Officer: Rajashri ·
ask(at)stomatobot(dot)com
StomatoBot Technologies Private Limited, 12-A, 3rd Floor, RM Corner,
VS1 Building, Near Maharaja Complex, Paud Road, Kothrud, Pune 411038, Maharashtra.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
12. Consent and withdrawal
Where we rely on your consent, you may withdraw it at any time, as easily as you gave it. Withdrawal does not affect processing already carried out, and may mean we can no longer provide part or all of the service.
13. Website cookies and embedded content
The stomatobot.com website and the Digital WatchMan app use only essential cookies — session/login state and security — and set no advertising or cross-site tracking cookies. Pages may occasionally embed content from other websites (for example, a product video); such embeds behave as if you visited that website directly and may set their own cookies under that provider’s privacy policy.
14. Children
The service is intended for account holders aged 18 or over. We do not knowingly collect children’s personal data as account holders, and we do not create face identities for children on our own initiative.
Children who are recorded by a customer’s cameras are covered by the redaction rule in section 3: their faces are blurred in stored images and no face template is made for them, on every camera, whether or not that customer subscribes to face recognition. Section 3 also states plainly what that protection cannot reach — a face the system does not detect cannot be blurred.
15. Changes
We will post updates here and, for material changes, notify account holders.
16. Contact
StomatoBot Technologies Private Limited ·
U72300PN2015PTC156223 ·
12-A, 3rd Floor, RM Corner, VS1 Building, Near Maharaja Complex, Paud Road, Kothrud, Pune – 411038, Maharashtra, India ·
support(at)stomatobot(dot)com