Biometric Notice and Consent Terms
Version 1.0 · Updated October 1, 2026
Contents
1 Definitions
2 Your compliance responsibilities
3 ROC’s commitments
4 Indemnification
5 Remedy for non-compliance
These Biometric Notice and Consent Terms (“Biometric Terms”) supplement the ROC Customer Agreement and apply to your use of our Age Verification API and any other ROC Service that processes facial images (each, a “Covered Service”). Capitalized terms not defined here have the meaning in the Customer Agreement.
1 Definitions
1.1 “Biometric Data”. means any biometric identifiers or biometric information, and the collection, possession, processing, use, disclosure, storage, or deletion of such data, as those or similar terms are defined under Applicable Biometric Laws, including, where relevant, generation of a biometric template derived from a facial image.
1.2 “Applicable Biometric Laws”. means laws governing Biometric Data applicable to your use, including the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), the Washington biometric statute (RCW 19.375), the California Consumer Privacy Act (CCPA/CPRA), the EU and UK GDPR, and any other applicable biometric or data-protection law.
1.3 “Data Subject”. means an individual whose facial image is submitted to a Covered Service (referred to elsewhere as an End User individual).
2 Your compliance responsibilities
If you use a Covered Service, you represent, warrant, and covenant that you will:
(a) Comply with law. Comply with all Applicable Biometric Laws and other laws governing your processing of facial images and Biometric Data.
(b) Provide notice. Provide legally adequate notice to all relevant Data Subjects informing them of the processing of their facial images and, where applicable, Biometric Data, before submitting their images to the Covered Service.
(c) Obtain consent. Obtain any necessary consents (including informed written consent and explicit consent, where required) from Data Subjects for such processing.
(d) Identify ROC as your service provider. Where required, identify ROC (as your service provider/processor) in the notices and consents you provide to Data Subjects.
(e) Honor deletion. Instruct ROC (through the means ROC specifies) to delete a Data Subject’s data when required by law. Because Covered Services process images on a process-and-discard basis and do not retain images or templates, deletion of the image occurs automatically after each estimate.
(f) Cooperate and verify. Cooperate with ROC to confirm your compliance and, on request, provide verification that you have obtained any required notices and consents.
(g) Maintain a retention/destruction policy. Where required (e.g., under BIPA), maintain and follow a publicly available written retention-and-destruction schedule for Biometric Data.
3 ROC’s commitments
3.1 For Covered Services, ROC processes facial images only to provide the Service (age estimation), does not use them to train or improve its models, does not generate or retain a biometric template capable of unique identification, and deletes images promptly after producing the estimate, as further described in the Data Processing Addendum and Privacy Policy.
4 Indemnification
4.1 You will defend, indemnify, and hold harmless ROC and its affiliates and licensors from and against any Losses arising out of or related to any third-party claim concerning your direct or indirect failure to meet the requirements of these Biometric Terms or Applicable Biometric Laws, including any failure to provide required notice or obtain required consent. This is in addition to the indemnity in the Customer Agreement.
5 Remedy for non-compliance
5.1 If you do not comply with these Biometric Terms or Applicable Biometric Laws, you may not use the Covered Service, and ROC may suspend or terminate your access to it under the Customer Agreement.
Build with ROC.
Schedule a free trial or demo.