Legal

Privacy Policy

Last updated: 26 August 2026

1. Who we are

Untamed Data B.V. ("Untamed Data", "we", "us") is a company registered in the Netherlands under Chamber of Commerce (KVK) number 91169143, with its registered office at Singel 4, 4357 BW Domburg, the Netherlands. We operate the Untamed Data platform for wildlife monitoring using trail cameras.

This policy explains what personal data we collect, why, and what rights you have — in line with the EU General Data Protection Regulation (GDPR / AVG).

It covers both the Untamed Data platform at app.untameddata.com and our public website at untameddata.com.

2. What data we collect

Account data. Your email address, name, phone number, and organization details (name, type, address) that you provide when you sign up or edit your Account settings.

Login data. When you sign in via Magic Link, we generate a short-lived, single-use login token and record when it was issued and used. If you choose to set a password, we store a salted, irreversible hash of it — never the password itself.

Wildlife monitoring data. Photos and videos uploaded from your cameras (by hand, SD card, or automatic FTP/FTPS upload), together with metadata such as capture time, the camera and project they belong to, GPS coordinates you provide for a camera, and the species detections our system generates from that footage.

People who appear in footage. A wildlife camera sometimes captures a person — a hiker, a farmer, a member of your own team — who never chose to be photographed. Our system locates people and vehicles in incoming footage and permanently obscures them before anything else is made from the image: the stored photo or video is overwritten, and every thumbnail and preview is generated from the obscured version. The obscuring is irreversible by design — the underlying detail is discarded, not merely smoothed over. When a clip is obscured, its audio track is removed as well, because a recorded voice identifies a person just as an image does.

Two limits we would rather state than gloss over. First, if someone moves across so much of the frame that obscuring them would leave nothing usable, we do not obscure the file; we mark it instead, so your organization can decide what to do with it. Second, automatic detection is not perfect, and a person who is small, distant, or partly hidden can be missed. This reduces the chance that footage identifies a passer-by; it does not eliminate it. Organization administrators can switch this off, and it is on unless they do.

That a person passed, without who. From 21 August 2026 we also record the bare fact that a camera was triggered by a person or a vehicle: the time, the camera, and the rectangle in the frame. No image, no crop, no name — by the time this record is written the picture has already been obscured beyond recovery, and nothing links the record to an identity.

Why we changed this. Before, a photo containing only a walker produced nothing at all, so an exported dataset could not be told apart from one where the camera fired at nothing. For research into disturbance — how recreation affects where animals go — human presence is the measurement, not noise. And for a landowner investigating poaching, a dataset that silently omits every person is the wrong answer.

What it is not. It is not a record of who, and it cannot become one: the underlying pixels are gone. We do not link these records across cameras or across time to follow anybody, and a clip is never tracked frame to frame to reconstruct a route.

Technical logs. Standard server logs (IP address, timestamps, requests) needed to operate, secure, and troubleshoot the platform.

Access log. We keep an audit record of actions that move data out of an organization or destroy it: sharing a detection by email, exporting data as CSV, PDF, or a full download, and deleting media, an account, or an organization. Each entry records what happened, when, which account did it, and the IP address it came from. Ordinary viewing of your own photos and videos is not logged. This record exists so that you — and any auditor you answer to — can establish afterwards who moved what, and from where.

3. Legal basis for processing

  • Contract — processing your account and wildlife monitoring data is necessary to provide the service you signed up for.
  • Consent — you actively agree to this policy when creating an account, and can withdraw consent at any time by closing your account.
  • Legitimate interest — technical logs and basic security monitoring, to keep the platform reliable and secure.

4. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Correct inaccurate data;
  • Erase your data ("right to be forgotten");
  • Receive a copy of your data in a portable format;
  • Object to, or request restriction of, certain processing.

You can view and edit your personal and organization details at any time from Settings. You can also delete your account yourself from Settings → Your data.

The full export on that page covers everything the organization owns — every project, camera, detection and original file, including material recorded by colleagues. Because it reaches well beyond any one person's own data, it can only be started by an organization admin. If you are not an admin and want a copy of your own personal data, email us and we'll provide it — that right is yours regardless of your role here.

To exercise any other right, contact us at info@untameddata.com — we'll respond within one month, as required by law.

5. Data retention

We keep your account and wildlife monitoring data for as long as your account is active. If you delete your account, your personal data and uploaded media are permanently deleted within 30 days, except where we are legally required to retain certain records for longer.

Access log entries are kept for 12 months and are then deleted automatically. This is one such exception: an entry recording that an account or organization was deleted outlives the account itself, because a record of a deletion that disappears with the deletion proves nothing. Those entries no longer identify the person — only that the action took place, and when.

6. Security

Cameras upload over encrypted FTPS where supported, or plain FTP with a login unique to each camera. Passwords are stored as salted hashes, never in plain text. Access to the underlying infrastructure is restricted to authorized personnel, and all data is hosted on servers we control.

7. Third parties

We use a limited number of service providers to operate the platform. All of them store data in the European Union. We do not sell your data to third parties.

  • Vimexx (the Netherlands) — server infrastructure for the platform and your uploaded media.
  • Backblaze B2 (EU Central region, Amsterdam) — encrypted off-site backups of the database and your media, so your data survives a server failure.
  • Migadu (EU) — email for addresses on untameddata.com. Outgoing: sign-in links, invitations, digests and notifications. Incoming: anything sent to an address on the domain, because the mail servers for untameddata.com are theirs.
  • Cloudflare — DNS, and hosting of our public website.
  • Sentry (EU data region, Germany) — error monitoring, so we find and fix faults. It records the technical details of an error: what failed, where in the code, and which request triggered it. We have explicitly switched off the collection of IP addresses, cookies and request contents, and we do not use it for performance tracking or session recording.
  • Simple Analytics (the Netherlands) — visitor statistics for our public website only, never inside the platform. It sets no cookies and does not collect or store IP addresses (see section 8).
  • Open-Meteo — historical weather for your detections. We send an approximate camera location (rounded to roughly 11 km) and a date; no personal data is shared.
  • Esri (United States) — map imagery. The satellite and label layers on our maps are loaded by your browser directly from Esri, which means Esri sees your IP address and which map tiles you request. No footage, detections or account details are sent.

If you choose to share a detection by email, the recipient address you enter is used only to deliver that one message (as an image attachment or a secure link that expires after 48 hours). We do not store shared recipient addresses or use them for any other purpose. You are responsible for who you share detections with.

8. Cookies and website analytics

In the platform we use a single, strictly necessary session cookie to keep you logged in. We do not use tracking or advertising cookies, and there is no analytics or tracking of any kind inside the platform.

On our public website (untameddata.com) we use Simple Analytics, a Dutch, privacy-focused alternative to the usual tracking tools, to see which pages people find useful. It sets no cookies, collects no IP addresses, and cannot follow you across pages or websites. It records only aggregate information: the page visited, where the visit came from, the approximate country (determined from your browser timezone, not your IP address), screen size and browser type. Data is stored on servers in the Netherlands.

Because none of this identifies you, no consent banner is required under the GDPR. If your browser sends a Do Not Track signal, nothing is recorded at all.

9. Using your data to improve species recognition (opt-in)

With your explicit permission, we use the detections your organization has reviewed (confirmed or corrected in the Review Queue) to train and improve our own species-recognition model. Each review is a high-quality label that helps the model recognize European and regional wildlife more accurately over time — which means fewer corrections and more confident detections for you.

This is off by default and entirely optional. An organization admin can turn it on or off at any time under Settings → Improve recognition. The legal basis is your consent (Art. 6(1)(a) GDPR), and declining never affects your access to any feature.

What we use: the cropped animal image, the species label you confirmed or corrected, and the model's confidence scores. What we never use: your camera locations, your organization or camera names, or any images of people or vehicles — these are excluded automatically.

You can withdraw consent at any time by switching the setting off; we then stop using your data for any new training immediately. Labels that were already incorporated into a previously trained model version cannot be removed from that version retroactively, but no new data is used after you opt out.

10. Changes to this policy

We may update this policy from time to time. Material changes will be communicated by email or through the platform before they take effect.

11. Contact

Questions about this policy or your data? Contact us at info@untameddata.com.