A POINT OF VIEW FROM QUIVIDIPRIVACY-BY-DESIGN SINCE 2006
← Back to Quividi

Privacy is the
architecture.

Stores are not just commercial environments. They are everyday spaces where families shop, people meet, and life happens. VidiReports, our sensor-based audience measurement, works in those environments, and any system that does must earn its right to be there: not through policy alone, but through how it is built.

FOUNDED
2006
Privacy-by-design since day one
INFERENCE
On-device
No raw image leaves the player
IDENTIFIERS
None
No biometric template · no re-identification
RECORDS
Anonymous
Event-level or aggregated, never identifying
VIDIREPORTS · PRIVACY IS THE ARCHITECTURE

What VidiReports measures,
and what it never collects.

Most privacy commitments are policies that sit on top of systems that could, technically, work differently. The system is capable of collecting more than the policy allows; the policy promises it won’t.

VidiReports was designed the other way around. The hardware-software architecture itself makes intrusive data collection impossible not by promise, but by construction.

01

No image of an individual ever leaves the player.

The video sensor beside the screen captures video. VidiReports analyses it in real time, on-device, and the raw image is never stored, never transmitted, never accessible to Quividi, the retailer, or any third party. What flows up to the cloud is a stream of anonymous audience events: counts, attention durations, demographic distributions.

02

No biometric template is ever created.

VidiReports does not perform face recognition. It does not generate a numerical signature of a person's face that could later be matched to another image. The computer-vision models classify what they see and immediately discard the underlying data. There is no biometric record to leak, breach, or subpoena, because there isn't one in the first place.

03

No tracking.

VidiReports does not assign IDs to people, so no individual is followed between visits, between stores, or between screens. It cannot tell you whether the person standing in front of a screen is the same person who walked past five minutes ago, or who shopped at the same store yesterday. Every observation is independent and instantly anonymous.

04

Data is anonymous by construction, at every level.

Each audience event that leaves the VidiReports player is a measurement, not a person: a presence, a dwell duration, an attention time, an age-and-gender estimate, with no identifier and no image attached, so nothing can be traced back to an individual. Networks can use those events at event level or aggregated by time window; reports, dashboards and APIs work at the level of screen, daypart, store, segment and network.

THREE SENSING TYPES

Three ways to measure. One privacy contract.

VidiReports runs on video sensors, Lidar or mmWave radar, chosen per use case and privacy context. Each approaches privacy differently; none of them identifies anyone.

VIDEO SENSOR

Sees the most, keeps none of it.

Video is analysed on the player the instant it is captured and discarded. No frame is stored or transmitted, no face template or identifier is created, and no re-identification is possible. Face detection, which enables attention and demographics, is optional per deployment; body detection alone never looks at the face.

LIDAR

No image exists to protect.

An active, eye-safe laser measures distance to shapes in a scan plane. It produces geometry, not pictures: there is no image to store, leak or subpoena, because none is ever formed. The natural choice for the most privacy-sensitive contexts.

MMWAVE RADAR

Radio waves, not optics.

Millimetre-wave radar senses presence and movement from reflected radio signals. Like Lidar it forms no image at all, and it works through the enclosures and lighting conditions that limit optical sensors.

AUDIENCE INTELLIGENCE PLATFORM

What the platform uses, and what it doesn't.

The Audience Intelligence Platform works from data your network already holds: sales tickets, footfall counts, loyalty, Wi-Fi and operational data. It models audiences from that data aggregated by screen, location and time window. It does not need names, contact details or individual customer profiles, and it does not identify or track individuals. How each source is connected and processed is set out in the Data Processing Agreement.

FOR DPOs, SECURITY REVIEWS & PROCUREMENT

Technical documentation.

If you are a Data Protection Officer, security reviewer, or procurement team evaluating Quividi for deployment, the documents below are what you’ll need. Most are available on request to qualified parties.

AVAILABLE ON REQUEST
with NDA where appropriate
  • Data Processing Agreement (DPA)
  • Data Protection Impact Assessment (DPIA)
  • Security & infrastructure documentation
Privacy questions? We welcome them.

Talk to our team about your deployment.

Your jurisdiction, your procurement requirements, your privacy review. We have two decades of answers waiting.