RIZLYTICS
HomeCatalogDeliveryAssuranceContact
Request sample

Rizlytics / Legal

Privacy Policy

How Rizlytics collects, uses, shares, and protects personal and dataset-related information.

Effective Date: September 9, 2026
Last Updated: September 27, 2026

This Privacy Policy (“Policy”) describes how Rizlytics LLC (“Rizlytics,” “Company,” “we,” “us,” or “our”), collects, uses, processes, stores, discloses, and protects personal, biometric, and telemetry data in connection with our website (Rizlytics), our B2B data licensing services, and our cross-border multi-modal egocentric artificial intelligence (AI) dataset collection operations.

This Policy applies to:

  1. Website Visitors and Commercial Clients: Representatives, researchers, and enterprise buyers interacting with our platform or licensing datasets.
  2. Field Participants & Data Subjects: Consented field actors, specialists, technicians, and individuals participating in data collection captures executed directly by Rizlytics or through our operational subsidiaries and vendor networks in Pakistan and globally.

1. REGULATORY COMPLIANCE FRAMEWORK

Rizlytics operates a global AI data supply chain. Our data collection, anonymization, and licensing architecture are designed to strictly comply with worldwide privacy standards, including:

  • EU/UK GDPR: The European Union General Data Protection Regulation (Regulation (EU) 2016/679) and the UK Data Protection Act 2018.
  • CCPA / CPRA: The California Consumer Privacy Act, as amended by the California Privacy Rights Act.
  • Illinois BIPA: The Illinois Biometric Information Privacy Act (740 ILCS 14/).
  • HIPAA De-Identification Standards: Health Insurance Portability and Accountability Act of 1996 Safe Harbor De-Identification Protocol (45 CFR § 164.514(b)).
  • PECA 2016: Pakistan's Prevention of Electronic Crimes Act 2016 and associated cross-border transfer directives.
  • U.S. Comprehensive State Privacy Statutes: Including VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah), and CDPA (Indiana).

2. CATEGORIES OF DATA WE COLLECT

Depending on your interaction with Rizlytics, we collect and process the following categories of information:

A. Enterprise Client & Website Visitor Data

  • Contact & Account Information: Name, professional email address, corporate phone number, job title, company name, and billing address.
  • Commercial Metrics & Usage Data: API access keys, dataset download logs, IP addresses, browser types, interaction telemetry, and session analytics collected via essential cookies.

B. Multi-Modal AI Dataset & Sensor Telemetry Data

In connection with our primary business—capturing egocentric (first-person POV) datasets to train computer vision, spatial computing, and humanoid robotics models—we collect:

  • 4K/HD Video Footage: First-person and multi-angle optical streams capturing physical tasks, industrial workflows, procedural care, and daily human environments.
  • Multi-Axis Inertial Sensor Telemetry: High-frequency Inertial Measurement Unit (IMU) telemetry streams (.csv format sampled at up to 200 Hz) recording synchronized accelerometer and gyroscope coordinates.
  • Audio Telemetry: Ambient, spatial, or directional audio streams recorded concurrently with video capture.
  • Spatial & Annotation Sidecar Metadata: JSON sidecar files (.json) containing task taxonomy, capture alignment, release and provenance records, and environmental telemetry.

C. Sensitive & Biometric Data (BIPA / GDPR Special Categories)

Where explicitly authorized by written consent, we collect and process sensitive biometric features, including:

  • Hand & Finger Motion Keypoints: Mathematical extraction of hand/finger geometry and motion vectors from egocentric video, produced only where a capture session's release specifically authorizes biometric extraction.

3. BIOMETRIC DATA HANDLING & BIPA COMPLIANCE

Pursuant to the Illinois Biometric Information Privacy Act (BIPA) and international biometric standards, Rizlytics enforces strict safeguards regarding the collection and retention of biometric identifiers:

  1. Informed Written Consent: Prior to any capture session involving the extraction of biometric features, data subjects execute a legally binding Model & Data Subject Consent Release Agreement. This agreement explicitly discloses the specific biometric identifiers collected, the exact purpose of extraction, and the duration of processing.
  2. Commercial Licensing Scope: Written releases explicitly authorize a license to use hand/finger motion keypoints solely for AI/ML model training, fine-tuning, and evaluation, consistent with the Permitted Use terms of our Terms of Service.
  3. Prohibition on Sale of Raw Biometrics: Rizlytics does not sell, lease, trade, or profit directly from raw, un-anonymized biometric identifiers. Biometric data is converted into mathematical keypoint vectors, and each keypoint file is traceable to the specific release authorizing it.
  4. Biometric Retention & Destruction Schedule:
    • Hand/finger keypoint files are permanently deleted or fully anonymized when the specific training pipeline or commercial purpose is fulfilled, or within three (3) years of the individual's last interaction with Rizlytics, whichever occurs first.
    • Fully anonymized keypoint data stripped of any remaining identifying association is retained perpetually for AI model validation.

4. ANONYMIZATION, DYNAMIC BLURRING, AND HIPAA DE-IDENTIFICATION

Rizlytics captures data through closed, fully-released sessions: recording locations are closed to the general public during capture, and only individuals who have executed a Model Release are recorded. Where a non-consenting bystander is nonetheless incidentally captured, Rizlytics applies manual or automated blurring or pixelation to obscure that individual's face and any visible vehicle license plates before the affected dataset is licensed to a client.

  • HIPAA Safe Harbor De-Identification (45 CFR § 164.514(b)): Where a dataset depicts a clinical, surgical, dental, or workplace care environment, Rizlytics reviews the dataset for the 18 categories of Protected Health Information (PHI) identified under the HIPAA Safe Harbor standard — including patient names, geographic subdivisions smaller than a state, specific dates (birth/admission/discharge), medical record numbers (MRNs), device serial numbers, and IP addresses — and removes or obscures any such information found before licensing the dataset.

5. PURPOSES OF PROCESSING & LEGAL BASES (GDPR)

We process personal and telemetry data for the following legitimate commercial purposes, supported by specific legal bases under GDPR Article 6 & Article 9:

Processing PurposeCategories of Data InvolvedGDPR Legal Basis
Dataset Ingestion, Transformation & Anonymization4K Video, IMU CSVs (200 Hz), JSON metadata, Audio.Contractual Necessity (Art. 6(1)(b)) & Legitimate Interests (Art. 6(1)(f)).
Biometric Extraction & Keypoint GenerationHand/finger motion keypoints.Explicit Written Consent (Art. 6(1)(a) & Art. 9(2)(a)).
Enterprise B2B Licensing & Cloud DeliveryAnonymized or consent-cleared multi-modal datasets, client account details.Contractual Necessity (Art. 6(1)(b)).
Legal Compliance & Release ManagementSigned Model Release Agreements, ID verifications, audit trails.Legal Obligation (Art. 6(1)(c)).
Independent Consent Verification (Audit)Signed release records, government-ID references, for audit purposes only.Legitimate Interests (Art. 6(1)(f)) — verifying our own compliance.

6. CROSS-BORDER DATA TRANSFERS (US LLC ↔ PAKISTAN OPERATIONS)

Rizlytics LLC is headquartered in the United States, in New York, with field collection, sensor calibration, and preliminary data intake operations executed through our registered operational entity in Pakistan (registered under the Pakistan Software Export Board - PSEB).

  • Cross-Border Transfer Authorization: Personal Data, raw video footage, and telemetry captured in Pakistan or other international locations are transferred securely to Rizlytics's primary AWS cloud infrastructure in the United States.
  • EU Standard Contractual Clauses (SCCs): For data origin or transfers involving the European Economic Area (EEA) or UK, Rizlytics incorporates Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor) of the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914).
  • Local Law Compliance (PECA 2016): All international data transfers originating from Pakistan comply with PECA 2016 guidelines, supported by explicit consent releases executed by local data subjects authorizing cross-border transmission to US cloud servers.

7. DISCLOSURE & SHARING OF DATA

Rizlytics does not monetize personal data outside the scope of its commercial enterprise dataset licensing agreements. We share data strictly with the following entities:

  1. Enterprise Dataset Buyers & Sublicensees: Commercial clients acquiring or licensing our multi-modal AI datasets receive dataset files (.mp4, .csv, .json) for consenting participants under explicit, signed Model Release Agreements; where a non-consenting bystander was incidentally captured, that individual is blurred before delivery.
  2. Authorized Sub-processors: Third-party infrastructure vendors who process data on our behalf under strict Data Processing Agreements (DPAs):
    • Cloud Storage & Compute Providers: AWS (Amazon Web Services), Google Cloud Platform (hosting AES-256 encrypted dataset repositories).
    • Anonymization & Blurring Vendors: Third-party endpoints used, where needed, for face and license plate blurring.
    • Operational Field Subsidiaries: Local data intake teams in Pakistan operating under Intercompany Master Services Agreements.
  3. Independent Compliance Auditors: Solely to verify the authenticity of a participant's signed consent, we may share a participant's government-issued ID reference with an independent auditor bound by a written confidentiality agreement. The auditor may use the ID reference only to confirm the validity of a release and may not retain it beyond that purpose or disclose it further.
  4. Legal & Regulatory Authorities: We may disclose personal data if required by law, subpoena, court order, or to enforce our legal agreements or defend against liability.

8. TECHNICAL & ORGANIZATIONAL SECURITY MEASURES

Rizlytics enforces robust technical, physical, and administrative security measures to safeguard data against unauthorized access, destruction, loss, or alteration:

  • Data Encryption:
    • At Rest: All raw/processed video, IMU CSV sidecars, biometric keypoint files, and JSON sidecars are encrypted using AES-256 standard encryption across cloud S3 buckets and local storage devices.
    • In Transit: All API communications, dataset downloads, and field uploads are secured using TLS 1.3 encryption protocols.
  • Access Minimization & RBAC: Access to un-anonymized raw video or biometric archives is strictly restricted to authorized engineers and technicians via Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA).
  • Metadata Indexing & Integrity: Every clip is correlated to its corresponding release reference and to a SHA-256 hash of every file in its bundle, maintaining an auditable chain of custody.

9. YOUR DATA SUBJECT RIGHTS (GDPR / CCPA / BIPA)

Depending on your jurisdiction, you possess specific legal rights regarding your personal and biometric data:

  • Right of Access & Portability: Request a copy of the personal or biometric data we hold about you, delivered in a structured, machine-readable format (.json or .csv).
  • Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of your personal data or un-blurred video clips, subject to applicable contractual or legal retention requirements.
  • Right to Rectification: Request correction of inaccurate or incomplete personal records.
  • Right to Opt-Out of Data Sale/Sharing (CCPA): California residents may opt out of the commercial licensing or sharing of their personal information.
  • Right to Withdraw Consent: Where processing is based on consent (e.g., Model Release Agreements), you may withdraw your consent at any time for future dataset distribution. Note: Withdrawal of consent does not affect the lawfulness of processing or model training executed prior to withdrawal, and does not affect copies of Data already delivered to enterprise licensees prior to withdrawal.

Exercising Your Rights (DSAR Process)

To submit a Data Subject Access Request (DSAR) or exercise your privacy rights, email our Data Protection Officer at privacy@rizlytics.com. We will respond within thirty (30) days (or forty-five (45) days for CCPA requests).


10. DATA RETENTION POLICY

Rizlytics retains personal and telemetry data only for as long as necessary to fulfil the purposes outlined in this Policy, satisfy contractual obligations to enterprise clients, or comply with statutory requirements:

  • Anonymized & Release-Cleared Datasets: Retained perpetually for AI model validation, research, and enterprise licensing.
  • Raw, Un-blurred Video & Audio Archives: Retained for up to twenty-four (24) months post-capture to facilitate ongoing ML model training, after which raw files are permanently overwritten or anonymized.
  • Biometric Identifier Keypoints: Retained for a maximum of three (3) years post-capture or post-last interaction, whichever occurs first, consistent with BIPA guidelines.
  • Client Account & Financial Records: Retained for seven (7) years following contract termination to comply with US IRS and tax regulations.

11. CHILDREN'S PRIVACY

Rizlytics does not knowingly collect, capture, process, or license personal or biometric data from individuals under the age of eighteen (18). All field participants in dataset capture sessions must present valid government-issued photo identification confirming majority status prior to executing a Model Release.


12. CHANGES TO THIS PRIVACY POLICY

We reserve the right to update or modify this Privacy Policy at any time to reflect operational changes, technical enhancements, or legal updates. Material modifications will be announced on Rizlytics.com or communicated directly to enterprise clients via email.


13. CONTACT INFORMATION & DATA PROTECTION OFFICER

If you have questions, concerns, or complaints regarding this Privacy Policy or our cross-border data handling practices, please contact us at:

Rizlytics LLC
Attn: Privacy & Legal Compliance Dept.
Email: privacy@rizlytics.com
Website: https://rizlytics.com

RIZLYTICS

Real-world perspective.
Model-ready intelligence.

HomeDataset catalogContactTerms of servicePrivacy Policydata@rizlytics.com
© 2026 Rizlytics · Continuous egocentric data