VisionGuard Software

VisionGuard is a saudi developed software in which we can find all the option for the live streaming, video and audio recording as well. 

SmartFocus Privacy Policy

This Privacy Policy explains how Smart Way Group (“Smart Way”, “we”, “us”, or “our”) collects, uses, stores, shares, transfers, and protects personal data in connection with the SmartFocus mobile application, related web portals, dashboards, customer support channels, IoT integrations, monitoring systems, analytics services, alert management, and associated digital services.

This Policy applies to users of the SmartFocus platform, including customers, authorized users, administrators, support requestors, enterprise representatives, operators, and service partners interacting with the platform.

We process personal data in accordance with applicable laws and regulations of the Kingdom of Saudi Arabia, including the Saudi Personal Data Protection Law and its implementing framework, and we aim to maintain privacy practices that are also consistent with widely accepted international transparency and accountability standards.


1. Controller Details

The controller of personal data processed under this Policy is Smart Way Group, Kingdom of Saudi Arabia.

For privacy requests, complaints, or questions relating to personal data, users should contact the company through the official support or privacy contact channel published in the application or on the company website. Before publication, Smart Way Group should insert its official legal entity name, commercial registration details, business address, and designated privacy contact email.


2. Definitions

Personal Data means any information that identifies an individual directly or indirectly.

Processing means any operation performed on personal data, including collection, recording, storage, use, disclosure, transfer, deletion, or destruction.

Controller means the entity that determines the purpose and manner of processing personal data.

Processor means a third party that processes personal data on behalf of the controller.

Sensitive Data, where applicable, shall be handled with heightened safeguards in accordance with applicable law.


3. Personal Data We May Collect

Identity and Account Data

Such as full name, mobile number, email address, username, password credentials or login verification data, company information, user role, and profile information.

Device and Monitoring Data

Such as device identifiers, camera or IoT device information, hardware serial numbers, IP addresses, network identifiers, operating system details, firmware versions, connectivity status, logs, event records, and associated monitoring metadata.

Location and System Data

Such as GPS location, site location, branch information, installation coordinates, timestamps, access records, system activity logs, and operational status data where required for service delivery and system management.

Alerts and Incident Data

Such as alarm notifications, event triggers, incident reports, captured logs, system alerts, escalation records, and related operational notes.

Payment and Transaction Data

Such as invoice references, subscription details, payment status, refund records, order values, and transaction metadata. SmartFocus should avoid storing full payment card data unless strictly required and lawfully handled through compliant payment providers.

Customer Support and Communication Data

Such as support tickets, emails, call or chat records, complaint details, feedback submissions, and communication history.

Usage and Analytics Data

Such as feature interactions, session information, diagnostics, application performance metrics, aggregated analytics, crash reports, and de-identified statistical insights used to improve the platform.


4. Sources of Personal Data

We may collect personal data directly from users, automatically from devices and connected systems, from enterprise customers, from IoT or monitoring hardware, from payment service providers, from technical integration partners, and from legal or regulatory sources where required.


5. Purposes of Processing

We process personal data only for legitimate, specific, and documented purposes, including to:

  • Create and manage user accounts
  • Deliver SmartFocus monitoring and management services
  • Operate connected IoT and surveillance infrastructure
  • Monitor devices, systems, alerts, and incidents
  • Process subscriptions, invoices, and payments
  • Provide technical and customer support
  • Protect system integrity and cybersecurity
  • Detect, investigate, and prevent misuse, fraud, or unauthorized access
  • Improve system performance, reliability, and operational efficiency
  • Maintain service continuity and disaster recovery capabilities
  • Comply with legal and regulatory obligations
  • Generate operational, technical, and analytical insights in a lawful manner

Where analytics are used, we seek to minimize the data collected and prefer aggregated, de-identified, or pseudonymized forms where feasible.


6. Legal Grounds for Processing

We process personal data on one or more lawful grounds permitted by applicable law, which may include performance of a contract or requested service, compliance with legal or regulatory obligations, implementation of legitimate operational purposes that do not override the rights of the data subject, and consent where consent is required.

Where consent is used, users may withdraw consent for future processing to the extent permitted by law; however, withdrawal does not affect processing already carried out on a lawful basis before withdrawal.

Where specific processing is optional and not necessary for service delivery, we should clearly identify it in the app and obtain any required permissions or consents, such as for location tracking, notifications, or marketing-related functions.


7. Disclosure and Sharing of Personal Data

We may share personal data only on a need-to-know and lawful basis with:

  • Enterprise customers and authorized administrators
  • Cloud or hosting providers
  • IoT and infrastructure service providers
  • Technical support and maintenance providers
  • Payment service providers
  • Communications providers
  • Analytics and cybersecurity service providers
  • Professional advisers, auditors, insurers, and legal consultants
  • Competent public authorities where legally required

We do not sell personal data.

All third-party processing should be governed by appropriate contractual and security obligations, and processors should act only under documented instructions where required.


8. International Transfers

If personal data is transferred or disclosed outside the Kingdom of Saudi Arabia, such transfers shall be carried out only in accordance with applicable Saudi requirements, including the conditions, safeguards, and assessments applicable to cross-border transfers.

Where relevant, Smart Way Group should use approved contractual safeguards and internal risk assessment procedures before transferring personal data outside the Kingdom.


9. Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, to provide the service, maintain accurate records, resolve disputes, prevent fraud, enforce our terms, and satisfy legal, accounting, tax, contractual, and regulatory retention requirements.

Because retention periods may differ by data type, Smart Way Group should maintain an internal retention schedule covering account records, monitoring logs, alerts, subscriptions, payment references, support cases, security logs, analytics data, and deleted-account data.


10. Data Security

We implement reasonable and appropriate technical, administrative, and organizational safeguards designed to protect personal data against unauthorized access, disclosure, alteration, loss, misuse, or destruction.

These measures may include:

  • Encryption in transit and at rest where appropriate
  • Role-based access controls
  • Privileged access restrictions
  • Logging and monitoring
  • Secure development practices
  • Backup and disaster recovery procedures
  • Vulnerability management and patching
  • Staff confidentiality obligations
  • Incident response procedures
  • Vendor security due diligence
  • Network and infrastructure protection controls

Where payment functionality is involved, payment account data environments should be handled through compliant providers and controls appropriate to the applicable payment-security framework.


11. Personal Data Breaches

If a personal data breach occurs, we will assess the incident promptly, take containment and remediation measures, maintain appropriate records, and notify the competent authority and affected individuals where required by applicable law.


12. Data Subject Rights

Subject to applicable law, users may have rights to:

  • Be informed about processing activities
  • Request access to their personal data
  • Request correction or completion of inaccurate data
  • Request destruction or deletion in circumstances permitted by law
  • Withdraw consent where processing is based on consent
  • Raise objections or complaints through the available channels

Certain rights may be limited where retention or continued processing is required by law, regulation, contractual necessity, evidentiary needs, fraud prevention, cybersecurity protection, or the protection of public interest or legal claims.

Cart (0 items)

Create your account