Data Processing Addendum
Version 1.0 · Updated October 1, 2026
Contents
1 Data Processing
2 Customer Instructions
3 Confidentiality of Customer Data
4 Confidentiality Obligations of ROC Personnel
5 Security of Data Processing
6 Sub-processing
7 Assistance with Data Subject Requests
8 Data Protection Impact Assessments
9 Personal Data Breach Notification
10 Certifications and Audits
11 Customer Audits
12 International Transfers of Personal Data
13 Government and Law-Enforcement Requests
14 United States State Privacy Terms
15 Return or Deletion of Personal Data
16 Duties to Inform
17 Term; Entire Agreement; Conflict
18 Definitions
Annex 1 Security Standards
Annex 2 Details of Processing
Annex 3 Sub-processors
Annex 4 Standard Contractual Clauses — completion
This Data Processing Addendum (“DPA”) supplements and forms part of the ROC Customer Agreement (the “Agreement”) between Rank One Computing Corporation d/b/a ROC (“ROC”) and the customer accepting it (“Customer”), and governs ROC’s processing of Personal Data within Customer Data when Customer uses the Services. Capitalized terms not defined here have the meaning in the Agreement or in Section 18.
1 Data Processing
1.1 Roles. ROC will act as processor to Customer, who may act as controller or processor of Customer Data. Each party will comply with its obligations under Applicable Data Protection Law. Where Customer is itself a processor, Customer warrants that its instructions and actions are authorized by the relevant controller.
1.2 Processing details. The subject-matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subjects are described in Annex 2. In summary: ROC processes facial images to return an estimated age, age band, or threshold decision, on a process-and-discard basis, without identifying any data subject.
1.3 Accuracy. If ROC becomes aware that Customer Data transferred under the Standard Contractual Clauses is inaccurate or outdated, it will inform Customer without undue delay. Because ROC returns an estimate and retains no image, correction is generally effected by Customer re-submitting or by the data subject’s fallback route.
2 Customer Instructions
2.1 This DPA, the Agreement, and Customer’s configuration and use of the Services (including through the Permitted Interfaces) are Customer’s complete and final documented instructions to ROC. ROC will process Customer Data only in accordance with those documented instructions, unless required by law, in which case ROC will inform Customer unless legally prohibited. ROC will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Additional instructions require written agreement.
3 Confidentiality of Customer Data
3.1 No secondary use. ROC will not access, use, or disclose Customer Data except as necessary to maintain and provide the Services, or to comply with law or a valid governmental order (subject to Section 13). ROC will not use facial images or other Customer Data to train, retrain, evaluate, or improve any model, and will not use Customer Data for its own purposes. ROC processes facial images transiently and deletes them promptly after producing the estimate.
4 Confidentiality Obligations of ROC Personnel
4.1 ROC restricts its personnel from processing Customer Data without authorization, limits access consistent with the Security Standards (Annex 1), and binds personnel with access to appropriate confidentiality and data-protection obligations.
5 Security of Data Processing
5.1 ROC measures. ROC will implement and maintain the technical and organizational measures set out in Annex 1 (Security Standards), designed to protect Customer Data as required by Article 32 GDPR, consistent with its ISO/IEC 27001 / SOC 2 program. The process-and-discard design and the absence of stored images or templates are core measures.
5.2 Customer measures. Customer is responsible for its own security in using the Services, including securing its credentials and API keys, configuring the Services appropriately, and any pseudonymization or encryption of data before submission that Customer requires.
6 Sub-processing
6.1 Authorized sub-processors. Customer provides general authorization for ROC to engage sub-processors. ROC lists its current sub-processors at roc.ai/legal/subprocessors (see Annex 3) and will give at least 30 days’ notice before engaging a new sub-processor, during which Customer may object on reasonable data-protection grounds by (i) terminating the Agreement, (ii) ceasing use of the affected Service, or (iii) where offered, moving to another data region.
6.2 Sub-processor obligations. ROC restricts each sub-processor’s access to what is necessary, imposes data-protection terms no less protective than this DPA, and remains responsible for its sub-processors’ compliance.
7 Assistance with Data Subject Requests
7.1 Taking into account the nature of the processing, ROC will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to data subjects exercising their rights. ROC will promptly forward to Customer any request it receives that identifies as being from a data subject relating to Customer Data. Because the Services are process-and-discard, ROC generally holds no Personal Data to which such a request would attach after the estimate is returned; ROC will confirm this to Customer where relevant.
8 Data Protection Impact Assessments
8.1 ROC will provide Customer, on request, with information reasonably necessary (such as this DPA, the Security Standards, and available accuracy and fairness documentation) to assist Customer with data protection impact assessments and prior consultations under Articles 35–36 GDPR.
9 Personal Data Breach Notification
9.1 Notice. ROC will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Data, and will take appropriate measures to mitigate and remediate it.
9.2 Assistance. ROC will provide Customer with information reasonably necessary to enable Customer to meet its own breach-notification obligations to authorities and data subjects.
9.3 Exclusions. Unsuccessful Security Incidents (e.g., pings, port scans, or failed log-in attempts that do not result in unauthorized access) are not Security Incidents. ROC’s notification is not an acknowledgement of fault or liability.
9.4 Contact. ROC notifies via the administrator contact information on Customer’s account; Customer is responsible for keeping it current.
10 Certifications and Audits
10.1 Reports. On Customer’s written request and subject to confidentiality, ROC will make available its then-current audit reports and certifications (such as its SOC 2 report and ISO 27001 / ISO 42001 certifications, if held) and independent age-estimation accuracy/fairness test reports from the National Institute of Standards and Technology.
10.2 Audits. ROC will make available information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits. ROC may satisfy audit requests by providing the reports in Section 10.1; a Customer may request an on-site or third-party audit no more than once per year (absent a Security Incident or regulator requirement) on reasonable notice and subject to confidentiality and security conditions.
11 Customer Audits
11.1 Customer may fulfill its audit rights through the reports and measures in Section 10. If ROC declines a reasonable audit instruction required by Applicable Data Protection Law, Customer may terminate the Agreement as its remedy.
12 International Transfers of Personal Data
12.1 Regions. Where offered, Customer may specify a data-processing region. ROC will not transfer Customer Data outside the selected region except to provide the Services or comply with law.
12.2 EU Standard Contractual Clauses. For Customer Data subject to the GDPR that is transferred to a Third Country, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated: Module Two (controller-to-processor) where Customer is a controller, and Module Three (processor-to-processor) where Customer is a processor. Annex 4 completes the SCC options.
12.3 UK and Switzerland. For Customer Data subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs applies. For Customer Data subject to the Swiss FADP, the EU SCCs apply as adapted for Switzerland: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC); the term “member state” is read to include Switzerland so that Swiss-domiciled data subjects may enforce their rights as third-party beneficiaries; and, until the revised Swiss data-protection regime is fully reflected, the clauses also protect the data of legal entities. Where ROC’s receiving entity is certified under the EU-US Data Privacy Framework and its UK and Swiss extensions, the parties may rely on that mechanism instead.
12.4 Precedence. If there is any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail. The process-and-discard design materially limits the transfer footprint because images are not stored.
13 Government and Law-Enforcement Requests
13.1 Handling. If ROC receives a request from a government body or law-enforcement authority for Customer Data (a “Request”), ROC will: (a) use every reasonable effort to redirect the requesting party to obtain the data directly from Customer; (b) promptly notify Customer of the Request to allow Customer to seek a protective order or other remedy, unless legally prohibited (and if prohibited, use all reasonable and lawful efforts to obtain a waiver of the prohibition); (c) challenge any overbroad or inappropriate Request, including where it conflicts with the law of the European Union or a Member State; and (d) if compelled to disclose, disclose only the minimum Customer Data necessary to satisfy the Request.
13.2 Warranty. ROC has no reason to believe that laws applicable to it prevent it from fulfilling Customer’s instructions under this DPA, and will inform Customer if it becomes aware of any change in law that would substantially affect this warranty. The process-and-discard design means ROC generally holds no stored facial images that could be the subject of a Request.
14 United States State Privacy Terms
14.1 Service provider status. With respect to Personal Information subject to the CCPA/CPRA, ROC acts as a service provider. ROC will not sell or share such Personal Information, will not retain, use, or disclose it except to provide the Services (or as permitted by the CCPA), will not combine it with other data except as permitted, and certifies that it understands and will comply with these restrictions.
14.2 Biometric and children’s laws. The Biometric Notice and Consent Terms (roc.ai/legal/biometric-notice) govern notice and consent for facial-image processing under state biometric laws. Where Customer processes data of children under 13, Customer is the COPPA operator and is responsible for verifiable parental consent and its written retention policy; ROC will support the associated retention and deletion requirements.
15 Return or Deletion of Personal Data
15.1 On termination, or on Customer’s request, ROC will delete or return Customer Data and delete existing copies, unless retention is required by law. Given the process-and-discard design, facial images are already deleted after each estimate; any operational logs (which contain no facial images) are deleted per ROC’s retention schedule.
16 Duties to Inform
16.1 If Customer Data becomes subject to confiscation during any bankruptcy or insolvency proceedings, or a comparable measure by a third party, ROC will inform Customer without undue delay and notify relevant parties that the data is Customer’s property and responsibility.
17 Term; Entire Agreement; Conflict
17.1 This DPA is effective for as long as ROC processes Customer Data and terminates with the Agreement. This DPA incorporates the Standard Contractual Clauses by reference. If there is a conflict between the Agreement and this DPA, this DPA controls on data-protection matters; the Standard Contractual Clauses control over both on transfer matters. This DPA does not modify the Standard Contractual Clauses.
18 Definitions
18.1 “Applicable Data Protection Law” means all laws applicable to the processing of Customer Data, including the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and applicable US state privacy and biometric laws. “Customer Data” means Personal Data within data submitted to the Services under Customer’s account, including facial images and the age results returned. “Personal Data”, “controller”, “processor”, “data subject”, and “processing” have the meanings in Applicable Data Protection Law. “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data. “Standard Contractual Clauses” means Commission Implementing Decision (EU) 2021/914. “Third Country” means a country not recognized by the EU as providing adequate protection.
Annex 1 Security Standards
ROC maintains an information-security program consistent with SOC 2 and Article 32 GDPR, reviewed and updated periodically. It includes the measures below.
1. Logical security
- Access controls. Least-privilege access, firewalls and authentication controls, and segregation of tenants; MFA for administrative/remote access; periodic access reviews.
- Vulnerability & application security. Regular vulnerability assessments and penetration testing with timely remediation; pre-launch security reviews for new Services and features; secure change management with logging and approval.
- Data integrity & minimization. Controls for integrity in transmission, storage, and processing; process-and-discard of facial images; no persistently stored image or template.
- Resilience. Business continuity and disaster-recovery program with defined activation, recovery, and reconstitution phases (excluding transient images, which are not retained).
- Incident management & media. Documented incident-response plan; secure decommissioning of storage media (erasure, purging, or destruction) before disposal.
2. Physical security
- Physical access controls, intrusion detection, logging and periodic review for facilities; redundant systems and failover for availability.
3. Personnel
- Confidentiality obligations, security-awareness training, and background checks where permitted by law.
4. Continued evaluation
- ROC periodically reviews and updates its security program to address new risks and technologies.
Annex 2 Details of Processing
| Item | Detail |
|---|---|
| Subject-matter | Age estimation of individuals from facial images, provided as a cloud service by ROC to Customer. |
| Duration | For the term of the Agreement and any wind-down/deletion period. |
| Nature & purpose | Automated inference of an approximate age, age band, or threshold decision from a facial image to enable Customer’s age assurance; no identity verification or unique identification. |
| Categories of data subjects | Customer’s End Users whose facial image is submitted for age estimation, including, where applicable, children. |
| Types of Personal Data | Facial image (transient); age or age-band result / threshold decision; associated technical metadata (device/session identifiers, timestamps). Not special-category data on the position that estimation does not uniquely identify. |
| Special-category data | Not intended; Customer must not submit data revealing sensitive attributes, and the Services infer only age. |
| Frequency | Continuous / on-demand as individuals are checked. |
| Retention | Facial images: process-and-discard (deleted after each estimate). Logs (no images): 90 days. |
Annex 3 Sub-processors
ROC’s current sub-processors are published at roc.ai/legal/subprocessors and maintained under Section 6. Because the Services are process-and-discard, sub-processors do not receive stored facial images; they support hosting, delivery, monitoring, and support functions. The published list identifies each sub-processor, its purpose, location, and transfer safeguard.
Annex 4 Standard Contractual Clauses — completion
| SCC element | Selection |
|---|---|
| Modules | Module Two (Controller → Processor) where Customer is controller; Module Three (Processor → Processor) where Customer is processor. |
| Clause 7 (docking) | Included |
| Clause 9 (sub-processors) | Option 2, general authorization; 30-day notice. |
| Clause 11 (redress) | Independent dispute-resolution option not elected. |
| Clause 17 (governing law) | Law of Ireland. Option 1 (a fixed member-state law) is elected. |
| Clause 18 (forum) | Courts of Ireland (Dublin). |
| Annex I (parties, transfer, competent authority) | Per DPA Annex 2; competent supervisory authority Irish Data Protection Commission. Where the data exporter is established in another EEA state, the competent authority is that state’s supervisory authority. |
| Annex II (security) | Per DPA Annex 1. |
| UK Addendum | EU SCCs as modified by the UK IDTA Addendum (ICO version); Tables 1–4 completed. Table 4: only the data importer (ROC) may end the Addendum if the ICO issues a revised Approved Addendum with which ROC cannot comply. |
| Clause 8.9 (audits) | Satisfied through the reports and audit procedure in DPA Sections 10–11: audit reports and certifications on request; on-site or third-party audits no more than once per year absent a Security Incident or regulator requirement. |
| Switzerland (Swiss FADP) | EU SCCs as adapted for Switzerland (see Section 12.3): GDPR references read as the FADP; competent authority the Swiss FDPIC; “member state” read to include Switzerland; data of legal entities protected during the transitional period. |
| EU-US Data Privacy Framework | Where ROC’s receiving entity self-certifies to the EU-US DPF (with the UK Extension and Swiss-US DPF), the parties may rely on the DPF as an alternative transfer mechanism; the SCCs remain in place as a fallback. |
Build with ROC.
Schedule a free trial or demo.