Privacy Policy
Last updated: 21 August 20261. Who We Are (Data Controller)
DSJ Holdings MB ("CONCAM", "we", "us", "our") is the data controller responsible for your personal data processed through the CONCAM platform.
- Company: DSJ Holdings MB
- Registration No.: 306983891
- Address: Spaudos g. 9, LT-05132 Vilnius, Lithuania
- Email: info@dsj.lt
2. Scope and Applicable Law
This Privacy Policy applies to all personal data we process in connection with the CONCAM construction site monitoring platform (the "Service"). We process personal data in compliance with:
- EU General Data Protection Regulation (GDPR) — Regulation 2016/679
- Republic of Lithuania Law on Legal Protection of Personal Data
- Norwegian Personal Data Act (Personopplysningsloven), implementing GDPR via EEA Agreement
- Swedish Data Protection Act (Dataskyddslagen 2018:218)
- Danish Data Protection Act (Databeskyttelsesloven)
- Finnish Data Protection Act (Tietosuojalaki 1050/2018)
- Latvian Personal Data Processing Law (Fizisko personu datu apstrādes likums)
- Estonian Personal Data Protection Act (Isikuandmete kaitse seadus)
- Polish Personal Data Protection Act (Ustawa o ochronie danych osobowych)
3. Data We Collect
3.1 Account Data
When you create an account or are invited to the platform, we collect your name, email address, and organisation membership. Authentication is handled by our identity management provider (see Section 6).
3.2 Client Contact Data
When a construction project is set up on the platform, our administrators record contact details for the client representative — typically their name, email address, phone number, company name, and project location. These details are used solely to administer the contract and to contact the client about service operations. Where the contact is also a platform user, the data overlaps with the Account Data described above.
3.3 Usage Data
Standard web server access logs are recorded for security monitoring and abuse prevention, including IP address, request URL, response status, and timestamp. Application logs are limited to error traces and operational events and do not contain identifying information beyond what is necessary to diagnose the issue. Logs are not used for profiling or behavioural advertising.
3.4 Site Imagery
We process several categories of construction site imagery: (a) periodic photographs captured automatically by fixed cameras installed on site, (b) drone photographs uploaded by the client, and (c) 360° panoramic images uploaded for site walk navigation. Any of these may incidentally contain images of workers, visitors, or other individuals on site. Site operators are responsible for displaying appropriate notices on-site and informing affected individuals in accordance with applicable national law. All imagery is stored on EU-based cloud storage infrastructure.
3.5 Cookie Data
We use strictly necessary cookies for session management and authentication. See our Cookie Policy for details.
3.6 Device Identifiers
We assign and store technical identifiers for camera devices connected to the platform, including a private VPN address, a hostname, and a physical site location label. These identifiers refer to hardware, not to individuals, and are used to route monitoring traffic and display device status.
3.7 Advertising Measurement and Website Statistics
When you visit our public marketing site (concam.lt) and have given consent for marketing cookies via the cookie banner, Google Ads receives a limited set of measurement data: a click identifier (gclid) if you arrived from one of our ads, the URL of the page visited, technical browser information (user agent, screen size), and the occurrence of conversion events (such as opening the customer-portal sign-in page). Without your consent, the Google tag operates in Consent Mode v2 default-denied state and only the conversion event count is sent in an anonymised, aggregated form. No advertising data is processed when you are signed in to the customer portal — the marketing tag only loads on the public marketing site. Separately from advertising, we measure how the public website is used with a self-hosted, cookieless statistics tool (Umami) running on our own server in the EU. It records, per page view, the page address, the referring site, the browser, operating system and device type, the screen size, the language and the country (estimated from the IP address, which itself is not stored) and an anonymous daily-rotating visit identifier that cannot be linked to you across days or sites. It sets no cookies, stores no IP addresses and no personal data, is not shared with anyone, honours the browser's Do-Not-Track signal, and is loaded on the public marketing site only — never in the customer portal or on share links. Because no personal data is stored and no information is read from your device beyond what your browser sends with every request, this does not require your consent.
3.8 Administrative Audit Log
When a user with an administrative or moderator role performs a privileged operation in the platform (for example, creating, modifying, or deleting devices, projects, scrapers, schedules, organisations, or user roles), we record an audit-log entry. Each entry contains the actor's user identifier (issued by our authentication provider) and email address, the IP address, user-agent string and approximate location (city or country level, derived from the IP address as described in Section 3.15 — never a street address) of the request, the action name, a reference to the affected object (type and identifier), a JSON description of the change, and a timestamp. These entries are only created for privileged operations and are not generated by ordinary client use of the platform.
3.9 Share Link Access Data
When a project administrator creates a public share link, anyone in possession of the link can view photographs the administrator has chosen to share. For each share link we record: the link's opaque token, the date and time it was last accessed, and a running count of accesses. In addition, for security and abuse detection we keep a short-lived access log of share-link events — page views, downloads, failed password attempts and rejected requests — including the visitor's IP address, browser user-agent string and approximate location (city or country level, derived from the IP address as described in Section 3.15). These visitor events are deleted automatically after 90 days. The information is used to detect misuse of share links (for example password guessing or attempts to reach content outside the link's scope) and to provide administrators with usage telemetry for revocation decisions. Share-link records are deleted 30 days after the link is revoked or expires.
3.10 Issue Reports
When you submit an issue report via the in-app 'Report an issue' button, we record the category you selected (bug, translation, UX, other), the description you typed, the URL of the page you were on, your browser's user-agent string and viewport size, the locale you were using, your IP address, and a timestamp. If you are signed in, we also associate the report with your Clerk user identifier and email address. The information is used solely to investigate and resolve the reported problem. Issue reports are retained for 12 months from submission and then deleted automatically.
3.11 Image Processing — Privacy Masks
Project administrators may configure 'privacy masks' on individual cameras to blur portions of every photograph captured by that camera before it is displayed in our platform. This serves data minimisation under GDPR Art. 5(1)(c) by reducing the personal data contained in each photograph at the point of viewing. The mask itself (a set of polygon coordinates and a blur intensity) is stored in our database. The original, unblurred photograph remains on our storage box and is accessible only to authenticated administrators of the project through the privacy-mask configuration interface. Blurred outputs are cached on our servers to avoid recomputing on every view; the cache is invalidated when the mask is changed and is bounded in size.
3.12 Permanent Privacy Masks (Bake-in)
Project administrators with appropriate organizational permissions may convert a soft privacy mask into a 'permanent' privacy mask. When this is done, our servers process every existing photograph from the affected camera, apply the blur, and overwrite the original photograph on disk. After this operation: (a) the original (unblurred) photographs are no longer recoverable; (b) all future photographs uploaded from this camera will be automatically blurred at the same coordinates before being stored. This option exists for organizations whose privacy requirements (e.g., contractual obligations to data subjects) demand that no unblurred copy ever exist on our infrastructure. The choice between 'soft' and 'permanent' mode is configured by an organization administrator and may be globally constrained or required by the platform operator (CONCAM).
3.13 Consent and Acceptance Records
When you accept our Terms of Service and Privacy Policy, and when you make a cookie-consent choice, we record the fact of your acceptance or choice together with the name and version of the policy accepted (or the cookie categories selected), the date and time, your IP address, and your browser's user-agent string. For acceptances made while you are signed in, we also associate your account identifier and email address. These records exist so that we can demonstrate that valid consent was obtained, in accordance with our accountability obligations under GDPR Art. 7(1). We also archive the exact text of each policy version in each language, so that we can show precisely what you accepted.
3.14 Contract Acceptance and Signing Evidence
When an administrator of your organisation accepts or declines a contract we have issued to your organisation through the dashboard, we record evidence of that decision: the decision itself and, for a refusal, any comment provided; the full name and job position entered by the signer; the signer's confirmation that they are authorised to act for the organisation; the account identifier and email address of the signer; a reference to the exact document signed and the versions of our Terms and this Privacy Policy in force at the time; the IP address, browser user-agent, browser time-zone and language of the signing session; the identity-provider session identifier; whether the signing account had multi-factor authentication enabled and when a fresh identity re-verification was completed; and the times at which the document was opened and signed. We keep this evidence to demonstrate who agreed to which exact document and when. Where we require it, or where the signer chooses to provide it, we also store a document evidencing the signer's authority to act for the organisation — for example a power of attorney, a board resolution or an extract from the company register — which may contain the names, roles and signatures of company officers. It is stored alongside the signature evidence, is visible only to administrators of your organisation and to CONCAM administrators, and is kept for the same period as the acceptance record it supports.
3.15 Security and Activity Logs
For the security of the platform and the accountability of access to client imagery, we keep activity logs: when you sign in, we record your account identifier and email address, the time of the sign-in, the IP address, the browser and device type, and the approximate location derived from the IP address; when a signed-in user downloads a photograph or an image archive, we record who downloaded what and when, together with the IP address, browser user-agent and approximate location of the request. The approximate location is an estimate at the level of a city or country only: it is derived from the IP address using a geolocation database held on our own server, it is never more precise than that, it does not identify a street address or an exact position, and the IP address is not sent to any third party for this purpose. These activity records are deleted automatically after 12 months. Our web server additionally keeps standard traffic logs (IP address, requested URL, browser user-agent, timestamp), which are rotated automatically and retained for at most 14 days. These logs exist to detect unauthorised access and abuse (for example a sign-in from an unexpected country), to investigate security incidents, and to answer who accessed what; they are not used for marketing or profiling.
4. Legal Basis for Processing
| Processing Activity | Legal Basis (GDPR Art. 6) |
|---|---|
| User authentication and account management | Art. 6(1)(b) — performance of a contract |
| Delivery of the monitoring platform to clients | Art. 6(1)(b) — performance of a contract |
| Security logging and abuse prevention | Art. 6(1)(f) — legitimate interests |
| Compliance with legal obligations | Art. 6(1)(c) — legal obligation |
| Site photography (construction documentation) | Art. 6(1)(b) or 6(1)(f) — contract / legitimate interests of the site operator |
| Conversion measurement and online advertising | Art. 6(1)(a) — your consent |
| Administrative audit logging (security, accountability, abuse detection) | Art. 6(1)(f) — legitimate interests (IT security and demonstrability of compliance) |
| User-submitted issue reports (operational quality improvement) | Art. 6(1)(f) — legitimate interests (diagnosing and resolving reported defects) |
| Image processing — soft and permanent privacy masks (data minimisation) | Art. 6(1)(f) — legitimate interests (data minimisation under GDPR Art. 5(1)(c); meeting controller-determined privacy obligations) |
| Recording and retaining proof of consent and policy acceptance (IP address, user-agent, account email) | Art. 6(1)(c) — legal obligation (demonstrable consent under GDPR Art. 7(1)) and Art. 6(1)(f) — legitimate interests |
| Recording proof of contract acceptance or refusal (signer identity, IP address, user-agent, session identifier, MFA status, any authority document provided) | Art. 6(1)(b) — performance of a contract, and Art. 6(1)(f) — legitimate interests (demonstrating and defending the agreements we rely on) |
| Security and activity logging (sign-in events, download records, share-link access events, web-server traffic logs) | Art. 6(1)(f) — legitimate interests (network and information security, abuse detection, and accountability of access to client imagery; Recital 49) |
5. Retention Periods
- Account data: Retained for the duration of the active account. Deleted within 30 days of account termination unless required by law.
- Site photography: Retained for the duration of the client contract and a 30-day archival period thereafter, unless the client requests earlier deletion. Where an organization has elected the 'permanent privacy mask' option (see Section 3.12), the photographs retained for this period are the blurred copies; the unblurred originals are deleted at the moment of conversion and are not recoverable thereafter.
- Security & server logs: Retained for a maximum of 90 days.
- Device telemetry, alerts, and downtime records: Up to 90 days for actively monitored (enabled) devices. For devices that have been disabled, the corresponding telemetry, alerts, and downtime are deleted after 7 days, since these devices are no longer monitored. Cleanup runs automatically on an hourly schedule.
- Camera capture logs: Per-snapshot success/failure records (timestamp, outcome, error reason, and image size) used to monitor whether each camera captured on schedule. These contain no personal data. Retained for 400 days and then deleted automatically; cleanup runs on an hourly schedule.
- Cookie consent records: Retained in your browser's local storage. Cleared when you clear browser data.
- Advertising measurement data: Click identifiers and conversion events processed by Google Ads are retained according to Google's policies — typically 90 days for click identifiers (cookies _gcl_aw, _gcl_dc, _gcl_au) and up to 13 months for behavioural identifiers (IDE). You can withdraw consent at any time, after which no further data is collected.
- Administrative audit log: Entries in the AdminAction log are retained for 12 months from the date of the recorded event, after which they are deleted. Entries may be retained beyond this period only where, and for as long as, this is necessary to investigate or defend a specific security incident or legal claim.
- Issue reports: Retained for 12 months from submission and then deleted automatically.
- Original (unblurred) photographs after permanent-mask conversion: Deleted immediately at the point of conversion. Only the blurred output is retained thereafter, under the same site-photography retention as above.
- Consent and acceptance records: Cookie-consent logs are retained for 13 months. Your acceptance of the Terms of Service and Privacy Policy is retained for the life of your account, as evidence of the consent we rely on, and for up to 10 years after your account is deleted, where necessary for the establishment, exercise or defence of legal claims (GDPR Art. 17(3)(e)); superseded acceptances (kept after you accept an updated version) are removed after 3 years. Cleanup runs automatically.
- Contract acceptance and refusal records (including any document evidencing the signer's authority): Kept for the life of your organisation's account as evidence of the agreement, and for up to 10 years after account deletion where necessary for the establishment, exercise or defence of legal claims (GDPR Art. 17(3)(e)); refusals are retained as an append-only history. Cleanup runs automatically.
- Security and activity logs: Sign-in and download records are kept for 12 months; share-link visitor events (views, downloads, failed password attempts, rejected requests) for 90 days; web-server traffic logs for at most 14 days. Cleanup runs automatically.
- Backups: Encrypted backups of the database and stored imagery are kept on a geographically separate storage system; content deleted or permanently anonymised from the live system is removed from all backup copies within 45 days at the latest.
- Project invitations: When an administrator grants project access to an email address without an account, we store that email until the invitation is accepted; pending invitations not accepted within 30 days are deleted automatically.
6. Third-Party Processors
| Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Clerk Inc. | Authentication, user identity, and organisation management | United States (with EU data region available) | Standard Contractual Clauses (SCCs); Clerk DPA |
| Hetzner Online GmbH | Cloud storage for site imagery, hosting infrastructure, and database storage | Germany (EU) | EU jurisdiction — GDPR applies directly; Hetzner DPA |
| Svix Inc. | Webhook signature verification and delivery for authentication events | United States | Standard Contractual Clauses (SCCs) |
| Google Ireland Limited / Google LLC | Advertising measurement, conversion tracking, ad delivery on public marketing site (concam.lt only) | Ireland (EU) / United States | EU jurisdiction (Google Ireland) / EU-US Data Privacy Framework + Standard Contractual Clauses (Google LLC); Google Ads Data Processing Terms |
| Google Fonts (self-hosted) | Web fonts (Geist Sans, Geist Mono), downloaded once at build time and served from our own infrastructure | In-process on our EU-hosted VPS | Not a third-party transfer — fonts are self-hosted via next/font; no request is made to Google and no end-user data is sent when you use the site |
| sharp (libvips) | Server-side image processing for privacy-mask blur | In-process on our EU-hosted VPS | Not a third-party processor — runs entirely within our infrastructure |
| Teltonika Networks UAB (RMS) | Remote management and connectivity monitoring of the on-site 4G/5G routers that carry camera data — device status, SIM data usage, and secure remote access to the router for support | Lithuania (EU) | EU jurisdiction — GDPR applies directly; Teltonika DPA |
| Hostinger International Ltd. | Email hosting for our support and data-subject-rights correspondence (e.g. info@dsj.lt) and DNS for our domains | Lithuania / Cyprus (EU) | EU jurisdiction — GDPR applies directly; Hostinger DPA |
| UAB „Rivilė“ | Accounting and invoicing — processes the billing-contact details of client organisations to meet our statutory accounting obligations | Lithuania (EU) | EU jurisdiction — GDPR applies directly |
Our processors may engage their own sub-processors to deliver their services. Clerk, for example, uses Cloudflare, Inc. (US/global) for bot protection and challenge verification on authentication flows. A current list of sub-processors is available from each processor and on request from us at info@dsj.lt.
We do not sell, rent, or share your personal data with any other third parties for marketing purposes.
7. International Data Transfers
Some personal data (account and authentication data) is processed by our identity management provider, headquartered outside the EU. These transfers are subject to Standard Contractual Clauses (SCCs) approved by the European Commission pursuant to GDPR Article 46(2)(c). All site imagery and metadata are stored exclusively on EU-based cloud infrastructure.
8. Your Rights
Under the GDPR and applicable national laws, you have the following rights:
- Right of access (Art. 15): Request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate data.
- Right to erasure (Art. 17): Request deletion of your data where there is no legitimate basis for continued processing.
- Right to restriction (Art. 18): Request that we limit how we use your data.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
Erasure requests directed at entries in our administrative audit log may be restricted under GDPR Article 17(3)(e) and (b) where retention is necessary for the establishment, exercise, or defence of legal claims, or for compliance with a legal obligation. In place of deletion, and on request, we will pseudonymise such entries by replacing the actor's email address with a one-way hashed value, while preserving the operational record needed for security and accountability.
Visual Protection on Share Links
Photographs displayed via public share links carry a CSS watermark overlay and the browser's right-click context menu is suppressed. These are visual deterrents intended to discourage casual saving and reuse. They are not cryptographic protections — a viewer using browser developer tools can remove the overlay and read the image directly from the network response. If your project contains imagery whose redistribution requires strong technical protection, do not use the public share link feature for it; share via authenticated dashboard access instead.
To exercise any of these rights, including data access requests, data export, or account deletion, contact us at info@dsj.lt. All requests are handled manually by our team and we will respond within 30 days in accordance with GDPR Article 12.
9. Right to Lodge a Complaint
If you believe your personal data is being processed in breach of applicable law, you have the right to lodge a complaint with the supervisory authority in your country of residence. Our primary supervisory authority is:
State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija — VDAI)
https://vdai.lrv.ltResidents of other EEA/EU countries may also lodge complaints with their local supervisory authority (e.g., IMY in Sweden, Datatilsynet in Norway/Denmark, Tietosuojavaltuutettu in Finland, Datu valsts inspekcija in Latvia, AKI in Estonia, UODO in Poland).
10. Security
We implement appropriate technical and organisational measures to protect personal data, including encrypted data transfer, server-side authentication, role-based access control, secured camera connections, and firewall hardening on all infrastructure. Access to project imagery is controlled by the owning organization: administrators decide which of their members may view each project and may additionally grant named individuals — including people from other organizations — access to specific projects. An administrator may also designate a named person as a project administrator, who can manage access to that specific project (adding or removing viewers and other project administrators) and can see who has access; project administrators cannot change project content or settings.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, in accordance with GDPR Article 33. Where the breach is likely to result in a high risk to your rights, we will also notify you directly without undue delay, as required by Article 34.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to registered users by email or via a notice in the client portal at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
12. Contact
For any privacy-related queries, please contact our data protection contact at: info@dsj.lt