Data Protection Policy
Last updated: 23 June 2026
This Data Protection Policy describes how ReVision Africa protects personal and sensitive data processed through the ReVision Vision API, and the measures we expect from developers who integrate our services.
Our commitment
ReVision Africa builds assistive technology for blind and low-vision users. We treat data protection as essential to trust, especially where visual content, location context, or accessibility-related information may be involved in third-party integrations.
Scope
This policy covers:
- Developer account and billing data stored on ReVision systems.
- API usage logs (metadata about requests, not full image archives).
- Transient processing of images, questions, and generated text or audio through the Vision API.
- Live demo usage metadata (unbilled requests identified by demo header or demo page).
- The public live demo and documentation site at
/visionapi/.
Data classification
| Category | Examples | Handling |
|---|---|---|
| Account data | Name, email, organization | Encrypted in transit; access restricted to authorized staff |
| Credentials | API keys (rv_live_…) |
Stored hashed or protected server-side; never logged in full in usage tables |
| Usage metadata | IP, user-agent, question preview, image byte size | Retained for security and billing; limited fields only |
| Vision content | Photos, questions, AI answers | Processed in memory / by processors; not persisted as files in the API database |
| Audio output | Generated MP3 (base64 in API response) | Returned to caller; not stored by the API after the response is sent |
| Demo usage | Session id, question preview, IP, user-agent | Logged separately from billed developer usage; not linked to an API key |
Technical safeguards
- Transport encryption: all API and web traffic must use HTTPS (TLS).
- Access control: production databases and configuration are not publicly web-accessible; implementation files are blocked from direct HTTP access.
- Authentication: vision endpoints require a valid API key or an explicit demo header; keys can be disabled by administrators.
- Minimal logging: usage logs store question previews (truncated), not full images or complete API keys.
- Error responses: client-facing errors do not expose internal upstream payloads, stack traces, or secrets.
- Least privilege: administrative access to partner data is limited to authorized ReVision staff via the admin dashboard.
Organizational safeguards
- Staff with access to developer or usage data are bound by confidentiality obligations.
- Processors are selected for reliability and security; agreements require appropriate data handling where applicable.
- Security incidents are investigated promptly; affected developers will be notified when legally required or when risk warrants it.
Developer obligations
If you integrate the Vision API, you agree to:
- Keep API keys on your servers: never in mobile app binaries or public JavaScript.
- Inform end users that images and questions are sent for AI analysis and optional speech synthesis.
- Collect only images and data you are permitted to process under applicable law.
- Honor data-subject requests for apps you control; contact us if you need assistance regarding data processed on our side.
- Not use the Service to identify individuals without lawful basis or to process illegal content.
International transfers
Data may be processed on servers or by subprocessors in jurisdictions other than your own. We take steps to ensure appropriate safeguards where required by applicable data-protection law.
Retention and deletion
- Account deletion requests can be sent to support@revisionafrica.com.
- We will disable API keys and remove or anonymize personal account data within a reasonable timeframe, subject to legal retention requirements.
- Usage logs may be retained in anonymized or aggregated form for analytics.
Data Protection Impact
Integrators deploying the Vision API in high-risk contexts (for example, continuous camera capture in public spaces) should conduct their own Data Protection Impact Assessment (DPIA) and implement controls appropriate to their users and jurisdiction.
Breach notification
If we become aware of a personal data breach affecting developer account data, we will notify affected developers and relevant authorities as required by applicable law, without undue delay.
Related documents
See also our Privacy Policy and the security section of the integration guide.
Contact & data requests
For data protection enquiries, access requests, or processor information:
ReVision Africa. support@revisionafrica.com