Running gestural-AI surveillance found non-compliant by the CNIL — notified 6 June 2024, final June 2025 after Veesion withdrew its appeal.
Behavior detection
that never leaves the box.
Mindora's Box plugs into your existing CCTV and detects theft, robbery, and risk behaviors in real time — entirely on-device. No cloud. No exported video. GDPR-native by architecture.

Europe's leading AI surveillance vendor was ruled GDPR non-compliant.
Raised. 5,000+ stores. Cloud architecture ruled non-compliant on the right to object.
Confirmed 2025: it can already enforce against AI under GDPR — ahead of the AI Act transposition.
The market needs a GDPR-native alternative — especially in small high-value formats.
Detection happens in the store.
Not in the cloud.
Five vision specialists run in parallel on the box. An on-device LLM agent fuses their evidence into a single, explainable alert. Cameras feed in. Only metadata flows out.
- 01
Open-vocabulary specialist ensemble
Five specialists running in parallel: HOI (Qwen2.5-VL), social, individual/skeleton, spatio-temporal, anomaly.
- 02
Configurable agent runtime
Pydantic AI v1.0 + Qwen2.5-3B-Instruct AWQ INT4. Reasoning cycle under 1.5 seconds on AGX Orin.
- 03
Multi-camera orchestration
DeepStream 7.1 + Triton in-process. 8+ cameras at sustained 15 FPS.
“Video never leaves the box.”
Hand-to-pocket gesture detected. Concealment posture sustained 1.4 s. Subject paused at shelf 2 prior. Recommend operator review.
Three technical forces opened the window. Regulation closed the alternative.
The homepage covers the regulatory case for edge-only behavior detection. This section covers why the technical stack to deliver it became viable in 2025–2026 — and what specifically opened up.
CNIL opened a vacuum. AEPD enforces.
~700 French pharmacies are a capturable churn pool. Spain has confirmed it can already enforce against AI under GDPR.
Jetson Orin made the math work.
Multi-model on-device is finally viable. 43 tok/s for 3B INT4 LLMs in €700–€900 of hardware (NVIDIA, Dec 2024).
Open-source made distillation viable.
Qwen2.5-VL, InternVideo2, RT-DETR, RTMPose. Confidence-gated KD holds the loss to 3–5 pp.
Same hardware, same ensemble.
~80% surface area shared.
Marginal cost of a new vertical: about three weeks of prompt-pack and agent configuration.
Pharmacy
Tobacco
Jewellery
Supermarket
The category exists. The defensible position inside it does not — yet.
Veesion was the leader in AI-driven retail loss prevention until the CNIL notified non-conformity on 6 June 2024. The Conseil d'État rejected Veesion's référé on 21 June 2024; the decision became final in June 2025 when Veesion withdrew its appeal. The vacuum is now structural: cloud-architected behavior detection is uneconomic and indefensible under the EU compliance stack converging in 2026.
| Vendor | Architecture | Vertical reach | Audit posture | EU posture |
|---|---|---|---|---|
Mindora Barcelona, ES | Edge-only | Open vertical | On-device, signed | EU-built · EU-hosted |
Veesion Paris, FR | Cloud-architected | Single vertical (retail) | Cloud | EU · DPF risk on transfers |
AnyVision / Oosto Tel Aviv / NYC | Cloud + on-prem | Face-recognition focused | Cloud-managed | Non-EU |
BriefCam Israel · Canon-owned | Server / VMS plug-in | Forensic search | Server logs | EU instances available |
Bosch IVA / Hikvision AcuSense DE / CN | On-camera | Single device + camera | Per-camera | Hikvision: ENISA cautions |
- Mindora
Specialist ensemble + agent. Same Box across Retail, Care, Cities.
- Veesion
CNIL non-conformity notified 6 Jun 2024; final Jun 2025 (Veesion withdrew appeal). €53M raised.
- AnyVision / Oosto
Heavy face-rec. Schrems-exposed transatlantic transfers.
- BriefCam
Post-hoc analysis, not real-time edge behavior detection.
- Bosch IVA / Hikvision AcuSense
Camera-locked. No prompt-pack composability across verticals.
Compiled May 2026 from public filings, CNIL decisions, AEPD enforcement records and vendor product pages. Mindora's defensible position is the combination of (a) edge-only by architecture, (b) open vertical reach via prompt-pack composability, and (c) EU-built EU-hosted, aligned with AI Act Article 50 transparency from 2 Aug 2026 and architecturally ready for standalone Annex III high-risk obligations effective 2 Dec 2027 (Digital Omnibus).
Compliance is the architecture, not the policy page.
- Video never leaves the box
Frames are processed and discarded on-device. Egress is structurally impossible.
- Outbound data is metadata only
JSON event records, alert IDs, timestamps. No imagery, no embeddings of bodies.
- Optional skeleton-only privacy mode
Pose-only inference path; pixels never reach downstream specialists.
- Customer-controlled retention
Evidence-clip lifetime is set by the operator. Default is short.
- EU-hosted MLOps stack
Hugging Face Paris · Scaleway Paris · Mender Oslo. No US transfer.
- CE-ready hardware platform
Industrial fanless chassis, mounted in the back-of-house cabinet.
The EU AI Act classifies behavior-monitoring systems in retail as high-risk where they enable inference about persons. The compliance burden — legal basis, right to object, data-minimisation, transparency — falls on the controller, i.e. the retailer.
A cloud architecture cannot meet that burden cleanly: video crosses jurisdictions, recipients multiply, and the right to object becomes administratively intractable. The CNIL's non-conformity notification to Veesion on 6 June 2024 — final in June 2025 after Veesion withdrew its appeal — turned this from theory into enforcement.
Mindora's Box answers the burden at the architectural layer. Personal data is processed locally, retained briefly, and never transmitted as imagery. What leaves the box is a record of an event, not a record of a person.
We've already smoke-tested the thesis on out-of-distribution footage.
VadCLIP on UCF-Crime. Baseline random = 0.5.
VadCLIP, out-of-distribution clips (n=44). Holds the open-vocabulary thesis zero-shot.
Athlete-brand detection pipeline + camera-quality model on a VMS, shipped by the founding team.
Bridge revenue covering operations during pre-seed. Not Mindora product revenue.
Smoke test conducted April 2026 on consumer hardware (RTX 5070 Ti), 26 UCF-Crime clips + 18 OOD clips. Validates the open-vocabulary thesis zero-shot on out-of-distribution behavior.
Three founders. One prior exit. Production CV/ML at scale.
Adrià
Miquel
Artur
MINDORA TECHNOLOGIES, S.L. · BARCELONA, SPAIN · FOUNDED MAY 2025
Twenty minutes.
We'll show you the box.
On-premise AI for retail loss prevention. Built in Barcelona.
- contact@mindoratechnologies.com
- C/ de Sant Agustí, 21 3
- 43003 Tarragona · España
- CIF B22478242
Built in the EU.
Hosted in the EU.
Compliant by design.