Your details, and your building’s footage. Two different questions.
This page answers both: what this website collects when you contact us, and what happens to recordings, door logs and administrator credentials on a system we install. The second half is the one that actually matters.
The short version
Last updated: 5 August 2026.
Two kinds of information exist here and they are governed by completely different rules, so this page keeps them apart.
- Website data: what you type into a form on
gothamaccesscontrolny.com, plus the ordinary technical records any web server keeps. - Customer system data: video, door events, credential lists and administrator accounts on the equipment we install in your building. This is not our data. It is yours, and the section below says exactly how we keep it that way.
The four things most people want to know, up front: we do not keep copies of your video. We do not sell, rent or trade anything about you to anybody. Administrator accounts on cloud platforms are created in your name from the first day, not transferred to you later. And you can remove our access to your own system in about five minutes, without asking us and without telling us why.
What this website collects
Short list, because the site is deliberately plain.
The contact and quote forms. Your name, phone number, email address, the building or business address, the borough or town, and whatever you write in the message box, usually a description of what the system is doing and how long it has been doing it. Some people attach a photograph of a panel or a door. That is everything. There is no account to create, no password to set, and nothing on this site takes a payment.
Web server logs. Like every website, ours records the IP address that requested a page, the browser string, the page requested and the time. We use those records for two things only: working out why a page failed to load, and blocking traffic that is hammering the server. We do not join them to form submissions, and we could not build a profile from them if we wanted to.
Analytics. We use Google Analytics 4 to count page views and see which pages people actually read, configured with IP anonymization on. It sets first-party cookies in your browser (named _ga and _ga_ plus an identifier) that let it tell a returning visit from a new one. It does not know your name, and we never upload anything you typed into a form into it. If you would rather not be counted, any browser-level tracking block or Google’s own opt-out extension stops it, and nothing on the site breaks when it is blocked.
Fonts, and why they matter here. The two typefaces on this site are served from our own server. They are not pulled from Google Fonts or any other font service. That sounds like a trivial engineering detail and it is not: a page that loads a font from a third party hands that third party your IP address and the address of the page you are reading, on every single page load, before you click anything. This site makes no such request.
What is deliberately absent. No embedded map, no chat widget, no social media pixel, no advertising or retargeting tag, no session recording or heatmap tool, no accessibility overlay, no gated download that trades a PDF for your email address. If any of those are ever added, this page changes first and the date at the top changes with it.
What we keep, why, and for how long
| Information | Why we hold it | How long |
|---|---|---|
| Quote and contact enquiries: name, phone, email, address, what you described | To answer you, price the work, and pick the thread back up when a board finally votes on it | 24 months from the last time we spoke, then deleted |
| Site survey photographs: risers, panels, door hardware, cable routes, ceiling voids | They are the evidence behind the number we quoted. When a price is questioned six months later, these are the answer | Enquiries that never became a job: 90 days. Jobs we completed: 7 years, filed with the as-builts |
| As-built documentation, cable labeling maps, equipment lists | So whoever works on the system next (us or somebody else) can do it without opening every wall again | 7 years from completion |
| Email and message correspondence about a job | A written record of what was asked for and what was agreed | 7 years from completion |
| Web server logs: IP address, browser, page, timestamp | Diagnosing outages and blocking abusive traffic | Short retention set by the host, typically around 30 days; never joined to a form submission |
| Analytics: page views, referring site, coarse region, device class | Knowing which of these pages are worth writing more of | 14 months, then Google deletes it automatically |
Where a retention period looks long, it is because the document is the answer to a question somebody asks years afterward, almost always “why is this cable here, and what is on the other end of it?”
Who we share it with
Nobody, in the sense that matters. There is no marketing list, no data broker, no lead-generation network. You will not be called by three other contractors because you filled in our form. We do not buy leads and we do not sell them, and if you have ever asked one company for a boiler quote and then fielded a week of phone calls, you already know why that sentence is here.
Three service providers necessarily touch the data because the site could not work otherwise, and each of them sees only what their job requires: the company that hosts the website, the service that receives the contact form and relays it to us by email, and our email provider. None of them is permitted to use what passes through for their own purposes. The one other case is a legal one (a court order or a lawful demand from an agency), which we would comply with and, unless we were forbidden from doing so, tell you about.
We also treat your building as a security secret. We do not publish client names, addresses, floor plans, camera positions, door schedules or panel locations. No photograph of a job appears anywhere in our marketing without written permission, and even with permission we will not publish an image that shows a camera angle, a lock type, a unit number or a panel location that could be read as a map of where the building is weak. That rule costs us the most persuasive photographs we own. It stays.
Customer system data: footage, door logs and credentials
This is the section people are actually looking for when they land on a security company’s privacy page.
We do not retain your video
Recordings live where they were designed to live: on the recorder in your closet, or in the cloud tenancy that is registered to you. We do not operate a viewing station. We do not keep a copy, a clip, a backup or a “sample for our records.” There is no background account streaming your cameras to us, and there is nothing on our side to subpoena, breach or leak, because it does not exist.
The only time we see footage is when you show it to us: typically on your screen, during a service call, because a camera has gone soft or a recorder has stopped writing. If you send us an exported clip so we can diagnose something, tell us and we will delete it as soon as the fault is closed.
Door events and credential lists
Access control produces a running record of who opened which door at what time. Depending on how the system is configured, that record can contain unit numbers, resident or employee names, fob and card numbers, and in mobile systems a phone identifier. It is one of the more sensitive datasets a building will ever own. It lives inside your system, under your administrator account, on a retention setting we agree with you at commissioning rather than a manufacturer default of “keep everything forever.”
Admin accounts are registered in your name from day one
When a job needs a cloud platform, the tenancy is created against your organization and your email address, and the owner role is yours before the first credential is issued. It is not created in ours and handed over later, because “handed over later” is exactly how a building ends up discovering that removing a former tenant’s fob requires a service call to a contractor it fired two years ago. That is not a technical limitation of any platform we install. It is a business model, and we do not run it.
What credentials we hold while a job is running
Commissioning a system genuinely requires elevated access for a period, and pretending otherwise would be dishonest. During a job we typically hold: the local administrator password on the controller or recorder, a technician-level account in the cloud platform you own, the manufacturer default passwords on cameras and readers, and the site network or WiFi credentials where the equipment has to join a network.
- Every default manufacturer password is changed at commissioning. Nothing is left on
admin/admin,1234, or the number printed on the sticker. This is the single most common way a small camera system ends up on a public scanning site, and it takes ten minutes to prevent. - The new passwords are handed to you in writing at handover, along with the as-builts and the labeling map, not read out once and forgotten.
- Passwords are unique per client and stored in a password manager. They are never written on a work order, kept in a spreadsheet, or reused across buildings.
- We stay in your system only if you want us there. If you want us on call for service, we ask you to keep one named technician account for us, which you can see in the user list and delete at any moment. If you do not, we come out at handover and the account is removed in front of you.
How to revoke our access
You do not need our cooperation for any of this, and you do not owe us an explanation.
- Sign in to the platform as owner, open the users or administrators list, and delete or disable any account carrying our name or our email domain.
- Change the local administrator password on the controller and on the recorder. A cloud user list does not show local accounts on the panel itself, so this step is separate and it is the one people skip.
- If we hold a fob, card or credential for the building, ask for it back, and then delete its number from the credential list. Deleting the number is what actually locks the door. The plastic is nothing.
- Rotate the site network or WiFi password if the equipment used it to get online.
- Ask us in writing to confirm that we retain nothing. We will confirm in writing, and we will say what we deleted.
Camera audio is disabled unless there is a specific, lawful reason for it
New York is a one-party consent state for recording a conversation, which sounds permissive until you apply it to an unattended camera. A microphone left running in a hallway, recording a conversation between two other people, has nobody consenting to it. That is mechanical overhearing by a person who is not present, and under NY Penal Law §250.05 eavesdropping is a class E felony. It is not a technicality and it is not theoretical. So we ship cameras with audio off, and we turn it on only where there is a documented, lawful basis and, where appropriate, posted notice.
Where a camera cannot go
We will not install one, and we will put the refusal in writing if that is useful to you with a landlord or an employer:
- NY GBL §395-b: no camera or other viewing device observing the interior of a fitting room, restroom, toilet, washroom, shower, or a hotel or motel guest room. Each device is a separate violation.
- NY Labor Law §203-c: no video recording of an employee in a restroom, locker room, or a room designated for changing clothes. Recordings made in violation cannot be used for any purpose, and there is a private right of action.
Biometrics
If a job involves a fingerprint, face or hand-geometry reader in a New York City retail store, entertainment venue, or food and drink establishment, NYC Admin Code §22-1201 requires a clear and conspicuous sign at every customer entrance disclosing that biometric identifier information is being collected, and it absolutely bans selling, leasing, trading or otherwise profiting from that information. We will tell you about the signage before you buy the reader, not after an inspector does. As for the ban: we hold no biometric data at all, so there is nothing for us to profit from.
Smart access in residential buildings
New York City law places real duties on the owner of a residential building that operates a smart-access system: key fobs, cards, mobile apps or biometrics. In outline: restrict the categories of tenant data collected, obtain individual express consent, publish a privacy policy, keep the data safe, destroy it on a schedule, and never sell or disclose it outside the vendor that runs the system. Tenants can sue over it. Those obligations sit with the building, not with us, and we are not your lawyer.
What we can do is configure the system so that meeting them is possible instead of impossible: collect a unit-and-credential record rather than a name-and-phone record where the platform allows the choice, set event retention to a defined number of days rather than the default of indefinite, and make sure there is a working export path for a tenant who asks what the system holds about them. Getting that decided at commissioning costs nothing. Retrofitting it onto a live building with 180 credentials issued costs a great deal.
The one line worth remembering
We do not keep your footage and we do not keep a key to your system. If we ever need to get back in, you let us in, and you can shut that door in five minutes without calling us first.
Safeguards on our side
New York requires any business holding private information about New York residents to keep reasonable administrative, technical and physical safeguards, and to give notice if that information is exposed. Here is what that means for a company this size, rather than a paragraph of abstractions.
Administrative. One named person is responsible for this, not a committee. Anyone who works on a job (employee or subcontractor) is bound to the same rules in writing before they set foot in a building, including the ones about photographs and about not discussing one client’s security posture in front of another.
Technical. Survey photographs, as-builts and credential documents live in an access-controlled store, not in a phone camera roll and not in a personal email account. Multi-factor authentication is on every account that can reach a client system or the mailbox those systems email. Client passwords are unique, generated, and kept in a password manager.
Physical. Devices that go into buildings are encrypted and screen-locked. Paper survey notes get scanned and then destroyed, because a notebook with a riser diagram and a door schedule in it is a genuinely dangerous object to leave in a van.
If something goes wrong. If private information we hold is exposed, we will tell the people affected and make the notifications New York law requires of us, promptly, without waiting to be asked and without waiting to work out how it looks. Then we will tell you what we changed so it does not happen twice.
Your rights, and how to use them
New York does not currently have a single comprehensive consumer privacy statute of the kind California has. That is not a reason to give you less, so here is what we will do on request regardless of whether a statute compels it:
- Tell you what we hold about you and send you a copy of it.
- Correct anything that is wrong: a misspelled name, a wrong address, a phone number that reaches someone else.
- Delete it. The only exception is documentation tied to a job we actually completed, which we keep for the period in the table above, because it is the record of work performed on a building and deleting it would hurt you more than it helps you. We will say specifically what is being kept and why.
- Stop contacting you, acted on the same business day, permanently, with no “are you sure” sequence.
New York’s consumer protection law also lets a consumer bring a claim over a materially misleading business practice without having to prove that the business intended to mislead. That standard is one of the reasons there is no claim anywhere on this website that we cannot substantiate on request.
Making a request
Email info@gothamaccesscontrolny.com with “Data request” in the subject line, or call (917) 353-9599 during business hours. We acknowledge within 2 business days and answer within 10 business days. If the request means pulling records from a completed job out of archive, we will tell you at the acknowledgement how long it will realistically take. There is no charge.
We will ask you to establish that you are who you say you are, and for anything touching a building system we will take instructions only from the account owner or a managing agent named on the job, not from someone who tells us over the phone that they live there. That is not bureaucracy. An access control database is a list of exactly who can get into a building, and handing it to a confident caller is how people get hurt.
Changes to this page
This page carries a date at the top and that date is meaningful: it changes when the page changes, not on a schedule. If we add anything that alters what is collected or who sees it (a new analytics tool, an embedded widget, a different form provider), the change goes here before it goes live, and a note stays at the top of the page for 90 days saying what moved.
Questions about any of it go to info@gothamaccesscontrolny.com or (917) 353-9599. A real person answers, during business hours.
Common questions
Do you keep a copy of our camera footage?
No. Recordings stay on your recorder or in the cloud tenancy registered to you. We do not operate a monitoring center, we do not run a viewing station, and there is no account on our side pulling streams in the background.
The practical consequence is worth stating plainly: if we were breached tomorrow, there would be no client video in the breach, because there is no client video. The only footage we ever handle is a clip you deliberately send us to diagnose a fault, and that gets deleted when the fault is closed.
We think our previous contractor still has access to our system. How do we find out?
Three places to look, in this order. First, sign in to the cloud platform as owner and read the full user and administrator list. Not the resident list, the admin list. Any account on an email domain that is not yours deserves an explanation. Second, check the controller or recorder itself: local accounts on the panel do not appear in the cloud user list, which is why this is the one people miss. Third, look at the credential list for enabled fob or card numbers that are not assigned to anybody. An installer’s test credential left active is common and it opens your front door.
If you cannot sign in as owner at all, you already have your answer: you do not control the system. Recovering it usually means an ownership-transfer ticket with the manufacturer, supported by proof that the building owns the hardware. It is slow, it is doable, and it is a good reason to insist on owner-level accounts in your own name on the next system rather than the current one.
Can you get into our system after handover?
Only if you choose to leave a technician account in place so we can support you, and that account is visible to you in the user list. Delete it and we are out. There is no hidden second account, no manufacturer backdoor we hold, and no master credential across our client base.
If you would rather have no standing access at all, that is a perfectly normal way to run a building. Service calls then start with you creating a temporary account or letting us in on site, which adds a few minutes to a visit and removes a category of risk entirely. Plenty of our commercial clients work exactly that way.
Will our building appear in your marketing?
Not without written permission, and not in a form that shows anything operationally useful even then. No addresses, no floor plans, no camera positions, no door schedules, no panel locations, no unit numbers.
This is a real cost to us: a photograph of a finished lobby panel in a recognizable building is far more persuasive than a photograph of a lobby panel in an anonymous one. We would rather have the weaker photograph. Publishing a picture that tells somebody which door in a building has the weakest hardware is not marketing, it is reconnaissance.
Why do you turn camera audio off by default?
Because an unattended microphone is a different legal object from a camera. New York is a one-party consent state, which means recording a conversation is lawful if one participant consents. A camera microphone in a hallway recording two other people talking has no participant consenting to anything. Under NY Penal Law §250.05, eavesdropping is a class E felony.
Audio also almost never earns its keep. It rarely produces usable evidence at the distances a hallway or storefront camera works over, it adds a discovery headache the first time there is a dispute, and it multiplies the sensitivity of an archive somebody now has to secure. Where there is a real reason for it (an intercom station, a point of sale with posted notice, a specific documented need), we will enable it and we will say in writing why it is lawful there.
Does this website use cookies?
Only the first-party cookies that Google Analytics 4 sets to tell a returning visit from a new one. Nothing on the site sets an advertising cookie, and there is no third-party tracker embedded in the pages: no chat widget, no social pixel, no retargeting tag, no map iframe, and no third-party font request.
The site works completely with all of it blocked. If you use a content blocker, a strict privacy browser setting, or Google’s own opt-out, every page still loads, the menus still work and the quote form still submits. Nothing here is gated behind consent to being measured.
Want to know what we hold?
Ask, and you get a straight list back, not a form to fill in and a 30-day wait. Email or call during business hours.
Sun to Thu 9am to 5pm · Fri 9am to 12pm · Sat closed