NoldusViso

HIPAA, GDPR, and FERPA compliant video recording for research and clinical labs

NoldusViso, the Noldus AV recording tool, is used across psychology, healthcare, education, user experience research, and more. In every one of these fields, NoldusViso is built to protect your data.

Data protection is a fundamental right to privacy. On a practical level, it's what makes trust between people and organizations possible.

Data protection in NoldusViso
verified_user

Noldus Information Technology, Wageningen is ISO/IEC 27001 certified. Our information security management system is independently audited by an accredited certification body.

ISO 27001 Certification arrow_forward
Your data stays on your own network

Your data never leaves your control

NoldusViso is a hybrid system. It's installed locally, connects to your own network, and connects to the internet only if you want it to. Your recordings stay on your infrastructure, inside your security perimeter, under your administrators' control. Noldus never receives, stores, or processes the data you collect. It is never on a Noldus server and never in Noldus storage.

Noldus does not require access to any video files, secure health information, or educational records. Even when we provide technical support or perform upgrades, all our activities are carried out independently of participant information access.

Noldus does not maintain an active connection to any NoldusViso system at any time. Such a connection can only be initiated, authorized, and supervised by NoldusViso users.

Because your research data never reaches us, there's no third-party cloud in the chain, no data transfer to authorize, and no list of external processors to review.

How NoldusViso is secured

password

Password encryption

NoldusViso can integrate with your own LDAP or generate encrypted local credentials. Passwords must contain at least 8 characters with at least one uppercase, one lowercase, one number, and one special character. They must not contain your username nor match any of your last three passwords. Two-factor authentication protects every account, including administrators.

manage_accounts

Sophisticated user management

Configurable, role-based access control and user roles determine who can see, play, export, or delete each recording.

lock

Encryption in transit

All traffic between clients, cameras, and the server is protected with strong encryption in transit.

enhanced_encryption

Encryption at rest

NoldusViso facilitates encryption at rest, so recordings can be protected on your own storage under your own key management.

schedule

Retention policies

Your administrator sets retention periods. Recordings and audit data are removed automatically when the period expires. There is no manual clean-up and no forgotten archives.

history

Audit trails

Every login, view, export, and administrative change is logged and time-stamped, with configurable retention. A complete log of all activity regarding video creation, deletion, and access. The retention period can be set to comply with GDPR and HIPAA.

videocam_off

Privacy switches

Physical privacy switches let participants and staff see, and control, when a room is live. Turn on a black mask within the camera itself and use an optional light to indicate live or recording feed status.

memory

Modern technology stack

NoldusViso is built on a modern technology stack, easy to update and upgrade to meet the latest security demands, and easy to support and maintain. If necessary, and only after customer approval and coordination, a remote connection can be made to provide technical support.

Applicable legislations

Noldus complies with the governing laws presiding over our customers' data protection. The legislation of the European Union (EU) and the United States (US) is most prominent.

gavel

GDPR

In the EU, the General Data Protection Regulation (GDPR) went into effect on 25 May 2018. GDPR applies to all forms of data that target or are collected in relation to people in the EU. As a global professional IT company, Noldus complies with all GDPR regulations.

Under the GDPR, your organization is the controller of the recordings you make. Because NoldusViso runs on your own infrastructure and Noldus never receives your data, we are not a processor of your research data. There's no transfer outside your organization to safeguard and no external processor in the chain. You set retention periods, you control access through role-based permissions, and every access is logged.

Noldus has an appointed Data Protection Officer for the personal data we hold as a company, such as contact details. See our Privacy Policy.

health_and_safety

HIPAA / HITECH

HIPAA protects patients' medical records with rules on collecting and storing patient information. HITECH supports health information management across computerized systems and the secure exchange of health information.

For HIPAA and HITECH, the architecture does most of the work. Protected health information (PHI) stays inside your network: NoldusViso is installed locally, connects to your own systems, and reaches the internet only if you allow it. Noldus never receives recordings or health information.

On top of that, technical safeguards are built in: two-factor authentication (2FA), role-based access control down to the individual recording, strong encryption in transit, facilitated encryption at rest, automatic logout, administrator-set retention periods, and a complete, time-stamped audit trail of every access and export.

Do you need a Business Associate Agreement (BAA)?

No. Because NoldusViso runs on your infrastructure and Noldus doesn't access recordings or health information, Noldus is not normally a Business Associate under HIPAA. If your organization's policy requires an agreement, contact us and we'll review it with you.

school

FERPA

Recordings of students are education records under FERPA. NoldusViso keeps them inside your institution's own network, restricts access through role-based permissions, logs every view and export, and lets you set automatic retention periods per study.

Three layers of security

admin_panel_settings

Administrative

Policies and procedures for selecting, developing, and maintaining security measures, plus employee training on identifying protected data.

lock

Physical

Facility, workstation, and mobile device security is the responsibility of NoldusViso users, since Noldus never collects or transfers data.

shield

Technical

Built-in user management with access levels, TLS encryption in transit, audit trail functionality, and automatic logout.

upcoming Coming soon

VPAT and EU AI Act statement

We are preparing a Voluntary Product Accessibility Template (VPAT) and a statement on how NoldusViso relates to the EU AI Act. These will be published here. Need them for a review already in progress? Contact us and we'll help.

Certifications

verified_user

ISO/IEC 27001

Noldus Information Technology is ISO/IEC 27001 certified, independently audited by an accredited certification body. Read more.

gavel

GDPR

GDPR has no statutory compliance certification. All Noldus software and activity, including NoldusViso, is carefully screened against GDPR requirements.

health_and_safety

HIPAA

HIPAA rules don't certify software or off-the-shelf products. Every Noldus employee who may be exposed to protected health information completes a training course.

fact_check

Risk assessment documentation

Completing a security questionnaire or a vendor risk assessment? Send it to us — we're happy to help.

Contact us arrow_forward

Last reviewed: August 2026 · Version 2.0

shopping_bag
check_circle

Thank you!

We'll get back to you shortly.

error

Please correct the following errors:

error

error

error

error

By clicking Submit, you consent to Noldus processing your data as described in our privacy policy.