Contact ussales@ventavid.com
VentaVid
Home / Product / Security and privacy
Venta Capture · Feature

Kept as long as you say, seen only by who you say

The first questions a privacy officer and an IT reviewer ask are what you keep, for how long, and who can reach it. Venta Capture, a product of VentaVid, is a guided visual capture platform: your customer, tenant, driver or contractor films what you need on their own phone, guided step by step, with no app and no account, and it arrives as a sealed, structured case in your team’s inbox. This page describes what happens to that data, without marketing language.

Encrypted in transit and at rest. Retention you configure. Raw IP address deleted after 14 days by default. Consent before the first frame.

Data handling · this account

Case retentionauto-purge when it ends365 days
Raw IP addressthen a non-identifying fingerprint14 days
Locationdeclined = neutral, counted nowhereOptional
Encryptionin transit and at rest

Before the first frame

I agree that my recording is processed as described in the privacy statement.

Without it

Video of a customer’s living room, a driver’s licence plate, a tenant’s voice. This is personal data, and today it sits in WhatsApp threads on private phones, in mail attachments and in a shared drive nobody cleans up. Nothing is ever deleted, because nothing was ever scheduled to be.

Insurers, housing associations and public bodies cannot answer "where is this footage and who has seen it?"

Consent is assumed, not asked, and the privacy statement the customer should have read is nowhere near the camera.

The person who sees invoices is automatically the person who sees cases, because there is one login for everything.

How it works

01

Send the link with consent built in

The customer opens a secure personal link; the token in that link is personal to the capture request. Before the first step, they see your consent line with a link to your own privacy statement, and a tick is required to start.

02

Guided capture, with the customer in control

The flow asks for the camera and the microphone in the browser. Recording is only possible on the phone itself: a visitor on a computer sees a QR code to continue on the phone. Location is optional; if the customer declines, the case says so plainly and treats it as neutral.

03

A sealed case, encrypted on the way and at rest

The submission travels encrypted and is stored encrypted. Every file gets a SHA-256 fingerprint, the submission a signed seal with a server-verified receipt time, and every action on it is logged with an account and a time.

04

Retained, then purged

The case is kept for the period you configure and auto-purged afterwards. The raw IP address goes earlier: after a configurable number of days, 14 by default. Nothing is kept "just in case" beyond the term you chose.

What it delivers

Your privacy officer says yes

Encryption in transit and at rest, GDPR-ready processing, a configurable retention period with auto-purge and an audit log are the answers to the first four questions on the checklist.

Your IT reviewer sees the controls

Single sign-on through your own identity provider, two-factor authentication per user, roles with only the permissions a job needs, and visibility per flow for sensitive processes.

Your customer knows what you keep

The consent screen names your organisation, links to your privacy statement and explains what recordings may be processed for. The customer ticks before filming, and what was shown is stored with the case.

Send the consent screen to your privacy officer before you send a single link.

In the product

Four things a reviewer wants to see: consent, retention, access and the record of who did what.

Consent and notices

Your consent line, your privacy statement

The landing page carries a configurable consent line with a link to your own privacy statement, a mandatory tick before the flow starts, and a disclaimer that recordings may be processed with AI and external services for analysis and transcription.

Notices at the moment that matters

Notices can be shown right before filming or at the start of the flow, with "ask for a tick" and "store what was shown", so the consent moment is part of the record. Consent texts are edited in the flow builder and follow the language of the customer.

Purpose in your own words

The screen names your organisation and what the recording is for. The customer is asked by you, not by a platform they have never heard of.

The consent screen on the phone before filming starts
Retention, purge and location

Retention per organisation, enforced by auto-purge

You set the retention period, and expired cases are purged automatically by a scheduled job. If your processes need different periods, discuss it on the setup call so the account is set up around them.

The raw IP address goes first

Raw IP retention runs from 1 to 30 days, 14 by default. After that the raw address is deleted; a non-identifying network fingerprint stays, used only for "seen before" signals.

Location is optional and never a penalty

When a submitter declines it, the case states it as a neutral fact with no effect on any signal or score. A location that is shared is labelled as shared by the customer, not verified by us.

When location is refused, the case says so plainly
Access control

Single sign-on and two-factor authentication

Enterprise SSO through Google Workspace, Microsoft Entra ID, Okta, or another SAML or OIDC provider. Two-factor authentication per user with an authenticator app. Users see their active sessions per device and can sign out everywhere else.

Roles with only the permissions a job needs

A set of system roles from read-only to platform owner, plus custom roles you compose yourself. Finance, operations and platform administration are separate, so the person who sees invoices is not automatically the person who sees cases.

Teams, tenants and visibility per flow

Users are grouped in teams; several environments (brands, branches, departments) sit under one organisation with their own users. A flow can be visible to everyone in the organisation or to named people only, for sensitive processes.

View links and API keys

A case can be shared with someone without a login; treat a view link as you would any link to a document. API access uses bearer tokens with scopes, shown once at creation, so an integration receives only the data it needs. Credentials for external systems are stored encrypted.

Sign in · Your Company

SSOContinue with your organisationGoogle Workspace, Microsoft Entra ID, Okta, SAML or OIDC
2FAAuthenticator codeper user, active sessions per device

Roles

OwnerTenant adminOperationsFinanceSupportRead-only+ Create new role
The seal and the audit log

The seal

Every file receives a SHA-256 fingerprint on arrival, and the submission carries a signed seal with a version number and a downloadable manifest. Anyone holding the manifest can check, outside our systems, whether a file is still exactly the file that was received. The receipt time states when the system received the submission, and nothing more.

Who did what, when, on whose account

The capture link created, each time the customer opened it (logged server side), the submission received, who claimed, assigned or escalated it, every note, every status change. Escalations carry the reason and the manager’s approval or rejection.

GDPR, without certifications on this page

Venta Capture is operated by VentaVid, a European company, and is built to run inside a GDPR process: consent captured before the first frame, purpose stated in your own words, retention limited to what you configure, deletion on schedule, and an audit log of who accessed what. Ask us for the current documentation during procurement and we will send what applies.

The audit trail: cases remember what people forget

Questions

How is the data protected?

Encrypted in transit and at rest, processed in a GDPR-ready way, with a retention period you set and auto-purge when it ends. Every action on a case is in the audit log.

Where is the data stored?

Encrypted at rest on our infrastructure, retained for the period you configure and purged automatically afterwards. Ask us for the current hosting and sub-processor documentation during procurement.

Which certifications does Venta Capture hold?

We do not list certifications on this page. Request the current security documentation and we will send what applies to your review.

Can we enforce SSO and two-factor authentication for our users?

SSO is available through Google Workspace, Microsoft Entra ID, Okta or another SAML or OIDC provider. Two-factor authentication is set per user with an authenticator app. Talk to us about enforcement settings for your organisation.

How long do you keep the raw IP address?

A configurable number of days between 1 and 30, 14 by default. After that it is deleted; a non-identifying network fingerprint remains for reuse signals.

Does the customer have to share their location?

No. Location is optional. A refusal is recorded as a neutral fact in the case and never counts against the submission.

Does the customer consent to anything?

Yes, before filming: a consent line you write, linked to your own privacy statement, with a mandatory tick, plus a disclaimer that recordings may be processed with AI and external services. What was shown can be stored with the case.

Can we set different retention for different processes?

Retention is configured for the organisation and enforced by auto-purge. If your processes need different periods, discuss it on the setup call so the account is set up around them.

Related features

Sectors that ask these questions first: insurers and property managers and housing associations. Background: our post on insurance claim documentation.

Set the retention before the first link

Consent up front, encryption throughout, deletion on schedule. Then send the first flow.

Live in 10 minutes. Stuck? Book a free setup call and we build your first flow together.