Trust Centre

Your data is yours. Here is exactly where it lives and what happens to it.

The most important trust question is the simplest: who owns your data, and where does it go? This page answers it directly - what Performance Hub does and does not do with your information, where it is stored, and what happens to it over its life and at the end of it.

Your data belongs to you.

  • Your organisation's information is held within your Performance Hub account, facility and appliance contexts, and is governed by the access controls you configure.
  • Performance Hub does not make your content available to other customers or organisations without your authorisation.
  • Performance Hub never uses your data to train AI models. Content the agent sends to a model is processed to answer your request, and when we call a third-party model on your behalf we opt out of provider training on every request (see AI, models & responsible AI).
  • For video and biometric features, Performance Hub acts as a service provider / data processor; your organisation is the data controller.

What the cloud platform stores and processes.

Cloud platform data

  • Account, user and facility records needed to provide the service, including roles, access rights and configuration.
  • Operational metadata and logs used to run, secure and support the platform.
  • Online status and health metrics for your device (CPU, memory, temperature, disk, software version, connection state).
  • Backup metadata: that restore points exist, when they were taken, their size and regions.
  • Spend metering: model usage against your facility's key.

Content that is not warehoused by the cloud platform

  • A live feed of your conversations. Conversation content lives on your device and is not warehoused as content.
  • The content of your AI prompts or model responses. Request logging records operational metadata only - which model, token usage, cost, latency, status - not the content.

Where your data lives.

Performance Hub uses both edge and cloud storage. The split depends on the feature and the job the data is doing. We keep data and processing on the appliance where practical, while the cloud platform stores and processes the information needed to provide shared account, management, visibility and storage services.

  • On your appliance: the AI Agent's conversations, memory, files, wiki, skills and schedules; local video capture and buffering; and supported on-device AI workloads.
  • In your Performance Hub cloud account: user and facility records, roles and access rights, configuration, operational metadata, audit and activity logs, device telemetry, usage and billing metadata, synced integration data, and information used by cloud-delivered views and services.
  • In configured cloud storage: encrypted backups, footage, imagery, vectors and analytics where the relevant feature uses them. Regional storage follows your per-facility choices where those controls apply.

AI model requests may also leave the device when you use cloud inference. The content needed for the request is sent through your facility's AI Models & Access account for processing. It is metered, and we opt out of provider training on every request. Private and on-premise inference options are available when model processing must remain within an approved environment.

Video and vision data is captured and processed on the Edge Processor at your site where supported, while footage, imagery, vectors, analytics and management metadata may be stored or made available through the cloud platform. Stored media follows the cloud storage region you choose for that facility.

Where the platform itself runs.

Choosing where your stored data lives is separate from where the platform's core services run. The control-plane services behind the Performance Hub interface - the APIs the apps and dashboards talk to - operate from a small number of core regions.

  • Core platform regions: Sydney, Singapore, London and the United States. You are automatically routed to the nearest core region for your location.
  • Device connectivity is managed for you. Which regions your appliances connect to is handled automatically under the hood; there is nothing to configure.
  • Content delivery uses a CDN (CloudFront) where possible, so static assets are served from close to the user.

This is distinct from the per-facility storage-region choice below, which governs where your backups, footage and related stored data reside.

Data residency: you choose the region.

Backups and footage are stored with a cloud storage provider in the region or regions you choose. By default this is Automatic, resolving to the region nearest your facility. If you have data-residency requirements, or want geographic redundancy, you can choose one or more specific regions.

Available regions (16): United States (Virginia Ashburn, Virginia Manassas, Texas, Oregon, San Jose), Canada (Toronto), Netherlands (Amsterdam), Germany (Frankfurt), United Kingdom (London Slough, London Chessington), France (Paris), Italy (Milan), Japan (Tokyo, Osaka), Singapore, and Australia (Sydney).

  • Residency is per facility. Each facility's data is stored in the region you set for it.
  • People and biometric data follow the same residency choice as footage: they live in the storage region configured for that facility.
  • Selecting multiple regions holds a complete, independent copy in each.
  • For European facilities, the platform surfaces an explicit warning if a non-European region is selected, because of GDPR implications.

Backups and retention.

SettingValue
Automatic backupsHourly, around the clock, on by default
EncryptionEncrypted on the device before upload; per-facility key
Default retention90 days
Retention options7, 14, 30, 60, 90 days, 1 year, 2 years, 5 years
PinningKeep individual restore points indefinitely
DeduplicationIncremental and deduplicated to limit storage and traffic

Backups make sure that if hardware fails, is stolen, or something goes wrong, none of your agent's state is lost. A device replacement restores the latest backup onto new hardware and carries on, typically losing at most an hour of state.

Data lifecycle.

EventWhat happens to your data
Software updateNothing. Data persists across all updates.
Full restoreDevice state replaced by your chosen restore point, with an automatic safety backup taken first.
Remove & resetDevice storage erased (factory reset); credentials revoked immediately; cloud backups retained under your facility and retention policy.
Retention expiryRestore points removed automatically past your window (pinned points exempt).
Move to another facilityDevice data moves with the device; backup history remains at the original facility.

Video and AI metadata have their own, separate retention policies (see Video, vision & facial recognition), each organisation-configurable, with automatic deletion that does not rely on anyone remembering.

Deleting your data.

  • Removing a device erases its local storage (factory reset) and revokes its credentials immediately. Cloud backups are retained under your facility and retention policy until they age out, then removed automatically.
  • End-user deletion. The self-service account deletion flow is intended for consumer end-users (for example someone using the Door & Gate Access app), and applies additional identity checks before a request is processed.
  • Organisation account deletion. Deleting an organisation's entire Performance Hub account is also available.
  • Data offboarding is customer-driven. We do not provide a managed offboarding service, but you can use the AI Agent over MCP to export or offboard your data from the platform if you need to.
  • Some records must be retained where required by law (for example legal, tax or accounting obligations), in some cases for up to seven years; where retention is not required, data is deleted, destroyed or de-identified, and any retained backups are isolated and securely stored until deletion is feasible.
  • For people and biometric data synced from a third-party system, a genuine right-to-be-forgotten request must be actioned in the source system too (see Integrations, partners & data sharing).

Further reading.