Visigolf privacy notice
Last updated: 19 September 2026
This notice explains how Visivo AS (“Visivo”, “we”, “us”) processes personal data when we provide the Visigolf camera and streaming service. It covers the Fleet platform, on-course hole cameras, club CCTV / NVR cameras connected to Fleet, club pages, QR watch links, and related operations.
It is written to meet the information duties in the EU/EEA General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act. It is not legal advice to clubs, and it does not replace the processing agreement we enter into with a club.
1. Who is responsible
Controller (for the processing described as ours below)
- Visivo AS
- Organisation number: 924 345 861
- Depotgata 20, 2000 Lillestrøm, Norway
Privacy contact
- Email: post@visigolf.no or kontakt@visivo.no
- Phone: +47 40 00 90 44
- Managing director: Sigurd Østerbø Søbye, sigurd@visivo.no
The marketing website at visivo.no has a separate notice. This document is for the Visigolf system.
2. How responsibility is split with golf clubs
Visigolf is used on golf courses that have contracted with us.
- The golf club decides that cameras are installed on its course, where they point, who may watch live video (for example via a printed QR code or a public club page), whether a CCTV camera may be relayed on public Fleet URLs, how long the on-site NVR keeps recordings, and which areas are hidden with privacy blur or exclude zones. For that filming, live display, and on-site CCTV recording, the club is the controller. We act as the club’s processor and process video and related delivery on the club’s documented instructions.
- Visivo is the controller for Fleet user accounts, technical operation of the platform, viewer-session and usage records we need to run and secure the service, and the limited further use described in section 7 (service improvement and our own models).
If you are on a course or watching a hole, the club should also tell you about the cameras (typically by signage and the club’s own privacy information). You can exercise rights against the club, against us, or both, depending on the processing.
3. Who this notice applies to
We may process personal data about:
- people who appear in camera views on a participating course (players, staff, guests, and others in view)
- people who open a watch link, club page, or embedded stream
- club and installer users of the Fleet dashboard
- people who contact us about Visigolf
We do not try to identify people in camera views by name. Images can still be personal data when a person can be recognised.
4. Categories of personal data
Depending on how you interact with Visigolf, we may process:
| Category | Examples |
|---|---|
| Account and club data | Fleet username, password hash, role, club name, camera labels, contact details you or the club give us |
| Viewer and usage data | Watch-session identifiers, approximate watch time, which camera was opened, IP address, browser user agent, cookie identifiers, coarse viewer counts |
| Camera stills | JPEG (or similar) frames captured from a hole camera or a CCTV camera, including auto-captured training stills, operational snapshots, and CCTV timeline thumbnails. These may show people, clothing, bags, vehicles, and the hole or club grounds |
| Live video | Time-limited live streams delivered to authorised viewers, including hole cameras and, where the club has connected it, CCTV. Live video is processed to provide the service; it is not our long-term archive |
| CCTV recordings and clip metadata | Recordings held on the club’s NVR or camera disk; clip names and firmware flags (for example person, vehicle, animal, motion, or that a face was present); short-lived working copies we hold on Fleet when someone plays a clip |
| Device and telemetry data | Camera identifiers, connectivity and uptime, cellular or Wi-Fi status, person-present signals, sleep/outage history, SIM inventory identifiers (for example ICCID), CCTV host addresses, and encrypted camera login secrets |
| Correspondence | Emails and messages you send us |
| Security logs | Access logs and similar records needed to operate and protect the service |
We do not ask viewers for name, payment card, or date of birth to watch a hole. We do not use camera stills to create an identity database or to recognise a named individual.
Special-category data (GDPR Art. 9), including biometric data used to uniquely identify a person, is not our purpose. Hole-camera models and CCTV firmware flags mark general features such as whether a person (or a face) is present. We do not use them to recognise a named individual.
5. Club CCTV and what reaches our cloud
Some clubs also connect on-site CCTV / NVR cameras (typically club-owned units) to Visigolf Fleet. These are separate from the Visigolf hole cameras.
What stays on the course. Continuous recording, if the club has turned it on, is stored on the camera or NVR at the club. That archive is overwritten according to the device’s own disk policy. We do not copy the CCTV archive to Amazon S3. The club gateway (a Pi on the local network) also keeps a working cache of stream thumbnails so the live picture can be previewed without sending every still through our cloud.
What can be reached from our cloud. Our cloud Fleet hosts cannot open a club’s private LAN by themselves. A gateway at the club, reached through our mesh VPN, lets Fleet talk to those cameras. Through that path, part of the CCTV data can be made available on our cloud Fleet servers and, if the club turns on public relay, on the public Fleet stream URLs:
- Live video for signed-in Fleet users (club staff and our operators who have access). If the club enables public relay, the same live view can be offered on QR links, embeds, and the club page — live only.
- Recorded clips that a signed-in user chooses to play or download. We pull that clip from the NVR and keep a short-lived working copy on the Fleet host (a small rotating cache, not a second archive) so playback and seeking work.
- Thumbnails and stills used in the live preview, timeline, and search screens. Stream thumbnails are cached on the local Pi gateway. Fleet may still fetch a still when a signed-in user opens the CCTV screens. Neither cache is a second video archive.
- Search metadata and event flags the camera already attaches to clips or live state (for example that a clip was tagged as person, vehicle, animal, motion, or that a face was present). We use those flags to find recordings. We do not keep a gallery of identified faces.
- Device credentials and network identifiers needed to operate the cameras (stored encrypted on Fleet), plus gateway discovery of cameras on the club LAN.
Public relay is off unless the club turns it on. Guest and club-page access is live-only. Playback, camera movement, alarm settings, and clip download stay behind a Fleet login.
Manufacturer cloud. We reach the cameras through the club gateway and the camera’s local interfaces. We do not use the manufacturer’s consumer cloud as our video store. If the club separately uses a manufacturer app or cloud service, that processing is the club’s (and the manufacturer’s), not this notice.
6. Purposes and lawful bases
| Purpose | Typical data | Lawful basis |
|---|---|---|
| Provide the contracted camera and streaming service to the club | Live video, device telemetry, club configuration | Art. 6(1)(b) contract with the club; for people on the course, the club’s basis (often legitimate interests in pace of play and safety) |
| Let the club operate CCTV through Fleet (live, search, playback, settings) | Live and selected clips, event flags, camera credentials | Art. 6(1)(b) with the club; people on camera: the club’s basis (often legitimate interests in site security and operations) |
| Authenticate Fleet users and apply access control | Account data, session cookies | Art. 6(1)(b) and 6(1)(f) |
| Issue QR/watch sessions and enforce viewer limits | Viewer and usage data, cookies | Art. 6(1)(f) — run a working, abuse-resistant stream |
| Security, fault-finding, and continuity | Telemetry, logs, limited stills | Art. 6(1)(f) |
| Service improvement and our own models (section 7) | Usage statistics and hole-camera stills | Art. 6(1)(f) |
| Legal obligations (accounts, claims, authority requests) | Relevant records | Art. 6(1)(c) |
Where we rely on legitimate interests, you may object (section 13). We do not sell personal data and we do not use Visigolf data to build advertising profiles.
7. Service improvement and our own models
We may use information generated by the service — including aggregated or individual usage statistics and still images from hole cameras — to operate, maintain, secure, and improve Visigolf and related technologies. CCTV / NVR footage, playback caches, and CCTV event flags are not used for this model training.
That further use may include developing, training, testing, and evaluating our own machine-learning models and similar analytical methods (for example so cameras can more reliably detect whether a playing area is occupied). We carry out this work ourselves. We do not send these stills or usage records to consumer generative-AI providers for them to train their models.
Storage. Stills used for this purpose, and the resulting model files, are stored with Amazon Web Services object storage (S3), in addition to copies held on our Fleet hosts as needed to run the service.
What a finished model is. A deployed model is a set of statistical parameters used to recognise general visual features. It is not a photo album, not a searchable index of people, and it is not designed to store, retrieve, or identify any particular individual. We take reasonable technical steps so that a finished model does not contain personal data. The source stills remain personal data for as long as we keep them.
We do not use this processing to decide anything legal or similarly significant about a named person (no automated individual decision-making of the kind described in GDPR Art. 22).
8. Recipients and subprocessors
We disclose personal data only where a legal basis allows it: to the club that operates the relevant cameras; to processors who host or transmit the service for us; to professional advisers or authorities when required; or if a successor takes over the Visigolf business.
Processors who may process personal data on our behalf in this system:
| Provider | Role | Location | What they may process |
|---|---|---|---|
| Amazon Web Services EMEA SARL (and affiliated AWS entities) | Object storage (S3) | Configured AWS region; we aim to use an EEA region (typically `eu-north-1`, Stockholm) | Camera stills, training images, model artefacts, and related backups |
| Hetzner Online GmbH | Application hosting for Fleet | EEA (Germany / Finland) | Fleet application data: accounts, configuration, viewer sessions, telemetry, operational records and, where a club has connected CCTV, encrypted camera credentials, detection-event flags, and short-lived playback copies of selected NVR clips |
| NetBird GmbH | Overlay VPN / device mesh used to reach cameras, CCTV gateways, and internal hosts | Germany (EEA) | Device hostnames, peer IP addresses, and connection metadata for cameras, club-LAN CCTV gateways, and authorised staff devices. Video is encrypted peer-to-peer; NetBird is used to form the mesh, not to host a public video archive |
| Internet Security Research Group (Let’s Encrypt) | TLS certificates | United States | Domain name and ACME contact email needed to issue HTTPS certificates |
| Google Ireland Limited (Google Fonts) | Web fonts on public club pages | Ireland / possible US access | IP address and user agent of visitors whose browser loads fonts from Google |
| Mobile network operators used on camera SIMs (varies by club and country) | Cellular connectivity | EEA operators as deployed | Connectivity metadata and SIM identifiers required to keep a camera online |
| Email delivery providers we configure from time to time | Operational alerts | EEA where we can choose the provider | Staff or club contact details in alert messages, if email alerts are enabled |
The following are not separate subprocessors for golfer footage. We run them on our own hosts: the Fleet application, MediaMTX stream relay, Caddy reverse proxy, the club-LAN CCTV gateway (including its thumbnail cache), and the on-device camera software (including optional privacy blur / exclude zones).
Ordinary internal tools (for example source hosting or project tracking) are used by our staff. They are not used as a store of course video or training stills.
We remain responsible for our processors and require them to process data only on our instructions and with appropriate security.
9. Transfers outside the EEA
We host the core service and, when configured as intended, the AWS S3 bucket in the EU/EEA.
Some supporting services may involve a transfer (in particular Let’s Encrypt and, if a browser loads Google Fonts, Google). Where a transfer is not covered by an adequacy decision, we rely on the European Commission’s standard contractual clauses or another GDPR Chapter V mechanism, plus any supplementary measures the provider documents.
Live video between a camera and a viewer is delivered over encrypted connections. A viewer’s own network (for example a mobile operator) will of course carry the stream they requested.
10. How long we keep data
We keep personal data only as long as needed for the purposes above, including security and legal duties. Indicative periods in the current system:
| Data | Typical retention |
|---|---|
| Live video (hole cameras and CCTV) | Transient — delivered to current viewers, not kept as a Visivo archive |
| CCTV recordings on the club NVR / SD | Controlled by the club’s device; overwritten on disk. Not archived by Visivo |
| CCTV clips temporarily held on Fleet for playback | A small rotating working cache (on the order of the last few clips played), then replaced |
| CCTV stream thumbnails on the club Pi gateway | A local working cache on the gateway, then replaced. Not copied to Amazon S3 |
| CCTV detection-event flags on Fleet | Operational records of recent detections; not a video archive |
| Watch-session rows | About 7 days after the session is finished |
| Watch / scan logs (including IP and user agent) | About 30 days, used for abuse prevention and service statistics |
| Device presence / outage history | About 45 days |
| Camera telemetry | On the order of days (Fleet default telemetry window is 7 days) |
| Fleet account data | For the life of the account / club contract, then as required for legal claims and statutory bookkeeping |
| Camera stills used for section 7 | For as long as they are needed to develop, evaluate, or maintain the service and our models, and then deleted or anonymised. There is no public “keep forever” rule; we review this library |
| Finished model files | For as long as that model version is used or reasonably needed as a fallback |
| Correspondence | As long as the enquiry and any follow-up require |
Cookies expire as described in section 11.
11. Cookies and similar identifiers
We use cookies that are necessary to run the service. We do not use advertising cookies.
| Cookie | Purpose | Typical lifetime |
|---|---|---|
| `session` | Keep a Fleet user signed in | Until sign-out, or the configured session length |
| Watch credential / watch-session cookies | Remember a QR or guest watch grant and a stable viewer id so viewer limits work | The watch window (often about 30 minutes) or a longer safety cap if the camera is open |
| `fleet_club` | Remember that the browser opened a public club page, so the player can apply club-page rules | 8 hours |
Your browser also sends a user agent and IP address with ordinary HTTP requests. Club pages may request fonts from Google (section 8).
12. Security
We use HTTPS, access-controlled Fleet accounts, network isolation of cameras (mesh VPN), and optional on-stream privacy blur / exclude zones that a club can configure. AWS objects and Fleet hosts are access-controlled. No method of transmission or storage is perfect; we work to keep residual risk proportionate to a golf-course camera service.
13. Your rights
Subject to the GDPR’s conditions and exceptions, you may ask us to:
- access your personal data
- correct inaccurate data
- delete data
- restrict processing
- receive data you provided to us in a portable format
- object to processing based on legitimate interests, including the further use in section 7
- withdraw consent, if we ever asked for it (withdrawal does not affect processing already carried out)
Send requests to post@visigolf.no. We will answer without undue delay and within one month, unless the GDPR allows a longer period.
If you appear only as an unrecognised person in a still, we may need extra information (time, hole, and a description) to locate relevant images. We will not collect more identifying data than needed to handle the request.
If the club is the controller for the live cameras, you may also contact the club. We will help the club where we are the processor.
14. Complaints
You may lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), www.datatilsynet.no, or with the supervisory authority in the EEA country where you live or work.
15. Children
Visigolf is a course-operations tool. We do not aim it at children and we do not try to identify juniors. A camera on a course may still record anyone in view, including minors. Clubs should take that into account in their own information to members and guests.
16. Changes
We may update this notice when the service or the law changes. The “Last updated” date at the top will change. The current version is always available at `/privacy` (English) and `/personvern` (Norwegian) on the Fleet host you are using, and in our product documentation.
17. Contact
- Visivo AS, Depotgata 20, 2000 Lillestrøm, Norway
- post@visigolf.no · kontakt@visivo.no · +47 40 00 90 44