Your CCTV design tool changed hands. Who holds your client's site plans now?
In August 2026 the browser-based service CCTV Design Tool was acquired outright, customer base included. A camera plan is not an ordinary SaaS document: it states where every camera points and, by implication, where your client is blind. When the company holding that file changes, the paperwork obligation lands on you, not on the vendor. Here is exactly what to check, and the five questions to send before your next renewal.
What this article is not
Buying a SaaS business together with its customer base is an ordinary transaction, and nothing in the public record suggests any party did anything improper. This is not an allegation against the buyer, the seller or the product, and the nationality of anyone involved is not a criterion here. What follows is about the duties that an acquisition creates for you, the integrator, because under GDPR you are the controller of your client's data and those duties do not transfer with the shares. We are a competitor of the product discussed, which is why every factual claim below is linked to its source.
Πίνακας Περιεχομένων
1. What happened, with sources
On 20 August 2026 the Ukrainian software company TechMagic announced that it had acquired the browser-based SaaS product CCTV Design Tool. It is the first deal of the company's new venture-builder arm, and the first time it has bought a product business rather than a services firm.
The reported facts
- TechMagic acquired 100 percent of the product and all rights to it.
- The price was not disclosed by the parties. The Ukrainian tech outlet DOU estimated it at 500,000 to 700,000 US dollars.
- Paid licences are reported as being in use at more than 2,000 companies worldwide.
- TechMagic is based in Lviv, Ukraine, and says it will put its own engineers, AI specialists, designers and marketers on the product and pursue partnerships with equipment manufacturers.
None of that is unusual, and none of it is a criticism. Small SaaS products change hands constantly. What makes this one worth a page of your attention is not the deal, it is the cargo: the accounts of more than two thousand integrators, and inside them the surveillance layouts of their clients' buildings.
2. Why a camera plan is not an ordinary file
Think about what a finished design actually contains. The floor plan of the building. The position and mounting height of every camera. The direction each one faces and how far it can resolve a face or a plate. The cable routes and the recorder location. And, as the exact inverse of all that, the places nobody is watching.
For a house that is uncomfortable. For a bank branch, a school, a pharmacy distribution centre, a substation or a data centre, it is the single most useful document an attacker could hold. Your client gave it to you under a contract. You put it in a SaaS account. Under GDPR you are the controller of the personal data in it and the vendor is your processor, which means the questions in this article are aimed at you, and your client is entitled to aim them at you too.
This is also why the tender documents you fill in ask where the design software runs. It is not bureaucratic decoration. Somebody on the client side worked out that the plan of their blind spots should not be an afterthought.
3. What changes legally when a SaaS vendor is sold
An acquisition is not a breach and does not invalidate anything by itself. What it does is make three documents stale at the same moment, and all three are yours to keep current.
- Your Article 30 record. It names the processors you use. If the entity behind the tool has changed, the record now names a company that is no longer the one processing the data.
- Your Article 28 processing agreement. Article 28(2) gives you the right to be informed about intended changes to sub-processors and to object to them. New owners bring new engineers, new support desks and new tooling. Ask for the current list.
- Your privacy information under Articles 13 and 14. It tells people who processes their data and where it goes. If either answer moved, the notice you hand your client is out of date.
In practice most integrators never learn that a vendor changed owner, because nobody is required to send you a letter about it. The renewal invoice arrives, it looks the same as last year, and the paperwork quietly stops describing reality. That is the actual risk here, and it applies to every tool you use, not only this one.
4. The transfer question, stated precisely
Here is where people reach for the wrong argument, so let us be exact. Where a company's owners come from is not a legal criterion and is nobody's business. Establishment is a legal criterion, and it is the one GDPR Chapter V runs on.
Articles 44 to 49 apply whenever personal data is transferred to, or is merely accessible from, a country outside the European Economic Area. Remote access by a support engineer counts as a transfer; the data does not have to move servers. If the destination country has an adequacy decision from the European Commission, that is the end of the analysis. If it does not, you need an Article 46 safeguard, in practice the standard contractual clauses, plus a transfer impact assessment that looks at local law and government access powers.
Ukraine is not on the Commission's adequacy list. Neither are the United States as a general matter, India, or most other places your SaaS vendors operate from, so this is not a special burden aimed at anyone: it is the ordinary compliance work that follows any non-EEA processing. The only vendors it does not apply to at all are the ones established and hosted inside the EEA, where there is no transfer to assess in the first place.
One thing we deliberately do not claim
We do not know where CCTV Design Tool hosts its data today, and we have not asserted anywhere in this article that it moved. Hosting frequently stays exactly where it was after an acquisition. The point is that you are the one who has to be able to answer the question, and the answer you wrote down before August 2026 was written about a different company.
5. Five questions to send before you renew
Copy these into an email to your vendor's support address. Send them to every design tool you pay for, ours included. A vendor that has done the work answers in a day with documents attached.
Who is the controller on the account today?
Name the legal entity, the registration number and the country of establishment. The name you signed with may no longer be the name that holds the data. Article 13 and Article 14 require that data subjects be told who the controller is, and you cannot pass that on to your client if you do not know it yourself.
Where is the data stored, and who can reach it?
Storage location and access location are two different questions, and only the second one usually gets left out of the answer. Data hosted in Frankfurt but administered by an engineering team outside the EEA is a Chapter V transfer all the same, because remote access counts.
Has the sub-processor list changed, and were you told?
Article 28(2) gives you the right to be informed of intended changes to sub-processors and to object. A new owner usually brings its own engineers, its own support desk and its own tooling. Ask for the current list and the date it was last updated, and compare it with the version attached to your contract.
What is the transfer safeguard, in writing?
If any processing happens outside the EEA, ask which Article 46 instrument covers it, which module of the standard contractual clauses, and whether a transfer impact assessment exists that you may see. A vendor that has done the work will send you a document. A vendor that has not will send you reassurance.
How do you get your projects out?
Ask for the export format and try it on a real project before you need it. If the only way your work leaves the tool is a PDF, you do not have portability, you have a picture of your work. A tool that exports DXF gives your drawing a life outside the vendor that owns it this year.
Keep the replies. If a tender ever asks how you assured yourself about your design toolchain, that email thread is the answer, and it took you fifteen minutes to create.
6. How we answer the same five questions
It would be poor form to hand you a questionnaire and then dodge it. CCTVplanner is operated by DEFENSAR, a sole proprietorship registered in Poland, VAT PL5562789202. The application and the database run on EU infrastructure, with Supabase in EU-West. There is no non-EEA leg to disclose, which means Chapter V has nothing to bite on and there is no transfer impact assessment for you to collect from us.
On the fifth question, portability, our answer is the export button. Every project leaves as a full CAD-grade DXF with layered camera positions, FOV cones, DORI zones, cable routes and an ISO 7200 title block, alongside the multi-page PDF with the bill of materials and an auto-generated DPIA worksheet. If we ever stop being the right tool for you, your drawings walk out of the door in a format your electrical contractor can open.
And on the first question, there is no ownership puzzle to solve. CCTVplanner has one owner, the founder who builds it, registered in Poland with an address, a VAT number and a name on the byline of this article. Nobody is going to acquire it out from under you between one renewal and the next.
The full comparison of the two tools, feature by feature and price by price, sits on our CCTV Design Tool alternative page.
7. Sources
- AIN, 20 August 2026: TechMagic has acquired the SaaS service CCTV Design Tool and launches its own venture builder
- dev.ua: TechMagic has acquired a ready-made SaaS product for the first time
- InVenture: Lviv-based TechMagic invests up to $700,000 in SaaS business with 2,000 customers worldwide
- European Commission adequacy decisions and Article 45 GDPR, for the list of third countries recognised as adequate.
Facts about the transaction are as reported by the publications linked above and were checked on 28 August 2026. This article is general information about compliance housekeeping, not legal advice; for a binding view on your own processing, ask your data protection counsel. CCTVplanner competes with the product discussed here. Product names are used nominatively, for identification and honest comparison, under the EU Comparative Advertising Directive 2006/114/EC.
Συχνές Ερωτήσεις
Was CCTV Design Tool really acquired?
Yes. In August 2026 the Ukrainian software company TechMagic announced it had acquired 100 percent of the browser-based SaaS product CCTV Design Tool, as its first venture-builder project. The parties did not disclose the price; the Ukrainian tech outlet DOU estimated it at 500,000 to 700,000 US dollars. Public reporting puts the installed base at more than 2,000 paying companies. Sources are linked at the end of this article.
Is an acquisition a data breach or a GDPR violation?
No, and it is important to be precise about this. Selling a SaaS business together with its customer base is an ordinary commercial transaction, and nothing in the public record suggests any party did anything improper. What an acquisition does trigger is a set of housekeeping duties, and most of them fall on you as the controller of your client's data rather than on the vendor: keeping your Article 30 record accurate, checking the processor contract under Article 28, and reviewing whether the transfer basis you relied on still describes reality.
Does it matter that the acquirer is established outside the EEA?
The nationality of a company's owners is not a legal criterion and should not be treated as one. Establishment is. GDPR Chapter V applies whenever personal data is transferred to, or made accessible from, a country outside the European Economic Area. Ukraine is not covered by a European Commission adequacy decision, so such transfers need an Article 46 safeguard, usually standard contractual clauses, plus a transfer impact assessment covering local law and government access. That is a documentation burden, not an accusation.
What exactly is sensitive about a camera plan?
A finished CCTV design states where the cameras are, which way they point, what each one can resolve at what distance, and by direct implication where the blind spots are. For a bank branch, a school, a pharmacy warehouse or a data centre, that document is the map somebody would want in order to defeat the system. Treat it as security documentation about your client's premises, because that is what it is.
Do I have to migrate away from a tool after it changes owner?
Not automatically. You have to be able to answer, in writing, where your client's data now sits, who processes it, and under what safeguard. If the vendor answers those questions clearly, you update your records and carry on. If you cannot get a straight answer, that is your signal, and it is the same signal regardless of who the vendor is or where they are.