Privacy · AI cameras

AI camera privacy policy.

How the AI-enabled CCTV systems we install handle footage: retention, storage, access, deletion and facial recognition.

Last updated 16 July 2026

1. Scope of this policy

This policy explains how the AI-enabled CCTV systems DJC Engineering installs are configured with respect to data retention, access and deletion. It is maintained by DJC Engineering as the installer and is intended to help our customers understand the defaults we apply and the choices they can make.

Ownership of the recorder, the footage on it and any resulting personal information remains with the customer (the property owner or operator). DJC Engineering does not view, download or retain customer footage as part of a normal install.

2. What the AI cameras record

The CCTV systems we install capture video, and optionally audio where the customer has requested it and where local law permits. The AI component runs on the camera or recorder itself and classifies motion into event types such as person, vehicle and animal so that recordings can be filtered and unimportant motion can be ignored.

The AI produces metadata (event tags, bounding boxes, timestamps) that is stored alongside the video on the customer’s recorder. No video, audio or AI metadata is sent to DJC Engineering.

3. Retention

Our default configuration is a 14-day rolling retention on the on-site NVR (network video recorder). Once the recorder’s storage is full, the oldest footage is automatically overwritten by new footage, so recordings older than roughly 14 days no longer exist on the system.

Customers can ask us to shorten or extend this window at any time, subject to the storage capacity of the NVR. Longer retention periods may require additional drives and are commissioned in writing.

4. Where footage is stored

By default we store footage locally on the customer’s NVR only. There is no cloud upload, no manufacturer account and no third-party viewing account created as part of a standard install.

Remote viewing on a phone is provided by a direct, password-protected connection to the customer’s own recorder over their internet connection. If a customer later asks for cloud backup or off-site storage, we discuss the provider, the account ownership and the additional privacy implications before making any change.

5. Who can access footage

Only the accounts the customer creates on their own recorder can view footage. On handover we:

  • Set a unique administrator password on the NVR and remove factory defaults.
  • Create user accounts at the customer’s request, with per-user permissions.
  • Enable HTTPS / encrypted connections where the hardware supports it.
  • Document the accounts in the as-built handover pack.

DJC Engineering technicians only access a customer’s system when the customer requests support and provides the credentials, or when performing scheduled maintenance under a support agreement. We do not retain a “master” password to customer systems.

6. Facial recognition

Facial recognition is disabled by default on every system we install. We only enable it when a customer explicitly requests it and we have confirmed the use is lawful for the site (for example, in a private commercial premises with appropriate signage and staff notification).

Where facial recognition is enabled, the face database is stored on the customer’s recorder, is managed by the customer, and can be cleared at any time.

7. Deletion and customer controls

Customers can, at any time and without our involvement:

  • Delete individual recordings or event clips from the recorder’s interface.
  • Format the recorder’s hard drive to remove all footage in one action.
  • Disable specific cameras, disable audio, or narrow AI detection zones.
  • Change or revoke user accounts and passwords.

If a customer wants us to attend site and securely wipe or physically destroy the drive at the end of the system’s life, we can do that as a paid service and provide a certificate of destruction.

8. Requests from third parties

Because footage lives on the customer’s recorder, requests from third parties (neighbours, insurers, private investigators, media) should be directed to the property owner, not to DJC Engineering. We do not release customer footage.

Law-enforcement requests are the customer’s responsibility as the data controller. Queensland Police can request footage directly from the customer under standard investigatory processes.

9. Signage and notification

For commercial sites we recommend visible CCTV signage at each entry point, and for workplaces we recommend written notification to staff. We supply compliant signage on request. Signage is the customer’s legal responsibility but we’ll help you get it right.

10. Privacy questions and requests

For questions about how a system we’ve installed is configured, or to request access to, correction of, or deletion of information related to your DJC Engineering install, contact us at info@djcengineering.com.au.

This page is maintained by DJC Engineering to answer common privacy questions about the AI CCTV systems we install. It describes our install defaults and is not a legal certification. Where a specific system has been configured differently at the customer’s request, that configuration overrides the defaults described here.