...

Privacy Policy

Version 1.0 · Updated October 1, 2026

Contents

1 Introduction and scope
2 Our two roles: when we are a “controller” and when we are a “processor”
3 Effective date and changes to this Policy
4 Children’s data
5 Personal Information we collect
6 How we use Personal Information
7 Legal bases for processing
8 Automated processing
9 How we disclose Personal Information
10 Cookies and similar technologies
11 Data retention
12 Data security
13 International data transfers
14 Your privacy rights and choices
15 Region-specific disclosures
16 Third-party websites and services
17 How to contact us (Privacy Contact)

1 Introduction and scope

Rank One Computing Corporation d/b/a ROC (“ROC”, “we”, “us”, or “our”) respects your privacy and is committed to protecting your Personal Information. This Privacy Policy (this “Policy”) explains how we collect, use, disclose, transfer, and otherwise process Personal Information in connection with our websites (including roc.ai), our cloud services and APIs, our marketing, and our other business dealings (collectively, the “Services”).

“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. It does not include de-identified, aggregated, or publicly available information as defined under applicable law.

This Policy does not apply to: (a) information that is not Personal Information; (b) our employees and job applicants, whose information is handled under separate notices; or (c) third-party websites, products, or services that we do not control, even if they link to or from the Services.

2 Our two roles: when we are a “controller” and when we are a “processor”

3 Effective date and changes to this Policy

This Policy is effective as of the effective date stated above. We may update it from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will revise the “Last updated” date and, where required by law, provide additional notice or obtain your consent. Your continued use of the Services after a revised Policy takes effect means you accept the changes, except where we are required to obtain consent. We encourage you to review this Policy periodically.

4 Children’s data

The Services are intended for businesses and are not directed to children. We do not knowingly collect Personal Information directly from children. Our Age Verification API is frequently used by our customers precisely to help them protect children online. When our customer’s use involves children, the customer is responsible for any parental-consent and child-protection obligations (for example, under the U.S. Children’s Online Privacy Protection Act (COPPA) or the UK Age Appropriate Design Code), and we support the customer’s associated requirements. Because we estimate age without identifying the individual and delete the image immediately, we do not knowingly retain any child’s Personal Information. If you believe a child’s Personal Information has been provided to us other than as described, please contact us (Section 17) and we will take appropriate steps.

5 Personal Information we collect

The Personal Information we collect depends on how you interact with us and in which role we are acting (Section 2). The categories below reflect the last 12 months and our current practices.

5.1 Information you provide to us directly

We collect Personal Information you provide when you (or your organization) interact with us as a customer, prospect, partner, or website visitor, including when you:

  • create or administer an account, request a trial, or subscribe to or purchase the Services (e.g., name, business email, business address, phone number, job title, organization, and account credentials);
  • make a payment or set up billing (payment and billing information is processed by our payment providers; we generally receive limited billing details and do not store full card numbers);
  • correspond with us or request support, sales information, or documentation (e.g., by email, web form, phone, chat, or at an event), including the contents of your communications;
  • register for a webinar, event, or mailing list, or respond to a survey; or
  • otherwise submit information to us, including any content you choose to include in your communications.

5.2 Information we collect automatically

When you visit our website or use our developer portal, we and our service providers automatically collect certain information using cookies and similar technologies, including: device and browser type, operating system, IP address, unique device or application identifiers, pages and features you view, referring/exit pages, dates and times of access, and other usage and diagnostic data. We use these technologies as described in Section 10 and in our Cookie Notice (roc.ai/legal/cookie-notice). This automatic collection relates to our own website and portal, not to end users of our customers’ applications.

5.3 Information we obtain from other sources

We may obtain Personal Information about our business contacts from other sources, such as: our customers and partners; resellers and referral partners; marketing, sales, and lead-generation providers; social media and professional networking platforms; and publicly available or government sources. We combine this information with information we collect directly for the purposes described in this Policy.

5.4 Information we process on behalf of our customers (Age Verification API)

When a business customer uses our Age Verification API, we process the following on the customer’s behalf and instructions, as a processor:

  • A facial image, submitted to our API by the customer (as a file or by URL). The image is processed only to produce an age estimate and is deleted immediately afterward. We do not store the image, we do not create or retain a facial template capable of recognizing the individual, and we do not use the image to train our models.
  • The age output we return to the customer (an estimated age, age band, or threshold decision).
  • Technical metadata associated with the API request (such as request identifiers, timestamps, and coarse device/session data), used to operate, secure, meter, and troubleshoot the Service. This metadata does not include the facial image.

We do not receive from our customers, and do not seek, the identity of these individuals. Estimating age from an image, without identifying the person, does not process “special category” data under the GDPR or “biometric identifiers” used to identify a person under some U.S. biometric laws; we nonetheless treat facial images as sensitive and apply heightened protections. Notice and consent for this processing are the responsibility of our customer under the Biometric Notice and Consent Terms (roc.ai/legal/biometric-notice).

5.5 Categories of Personal Information

The following table summarizes the categories of Personal Information we process, common sources, and purposes.

6 How we use Personal Information

6.1 Provide, operate, and secure the Services

We use Personal Information to make the Services available; authenticate and administer accounts and API keys; meter usage and process payments; provide API results to the submitting customer; and operate, maintain, secure, and support the Services.

6.2 Provide customer support

We use Personal Information to respond to your inquiries and requests, provide technical support, diagnose and resolve issues, and monitor and improve the quality of our support.

6.3 Improve and develop the Services

We use information to understand how the Services are used, to analyze, maintain, and improve them, and to develop new products and features. We do not use facial images or other Personal Information within customer content to train, retrain, or improve our models. We may create and use aggregated and de-identified operational data (such as accuracy, latency, and error metrics) that does not identify any individual and is not derived from retained images.

6.4 Communicate with you

We use business-contact information to send administrative and transactional communications (such as confirmations, invoices, security and service notices, and changes to terms or policies) and to respond to communications you send us.

6.5 Marketing

We market our Services to current, past, and prospective business customers and their personnel. We do not use the facial images or other data of our customers’ end users for marketing. You may opt out of marketing communications at any time (Section 14).

6.6 Safety, security, and fraud prevention

We use Personal Information to protect the security and integrity of the Services, detect and prevent fraud, abuse, and unlawful activity, and enforce our terms and policies (including the Acceptable Use Policy).

6.7 Legal and compliance

We use Personal Information to comply with applicable laws, regulations, and legal process; to respond to lawful requests from public authorities; to establish, exercise, or defend legal claims; and to comply with our contractual and record-keeping obligations.

6.8 With your consent

We use Personal Information for any other purpose disclosed to you at the time we collect it or with your consent.

7 Legal bases for processing

Where the GDPR, UK GDPR, or Swiss FADP applies, we rely on the following legal bases (Section 15.1 provides further detail):

For Personal Information we process as a processor through our Age Verification API, our customer is the controller and is responsible for establishing the legal basis for the processing and for providing notice and obtaining any consent required.

8 Automated processing

Our Age Verification API uses automated means to estimate age from an image. ROC does not itself make any decision that produces legal or similarly significant effects about an individual; it returns an estimate to the customer. The customer (as deployer) is responsible for how the estimate is used, for maintaining meaningful human oversight, and for offering a fallback or human-review route for near-threshold or low-confidence results. Individuals who wish to contest a decision should contact the organization that performed the age check.

9 How we disclose Personal Information

9.1 Service providers and sub-processors

We disclose Personal Information to service providers and sub-processors that perform functions on our behalf, such as cloud hosting and infrastructure, content delivery, monitoring, customer support, billing and payments, and sales and marketing, under contracts that require them to protect the information and use it only to provide services to us. A current list of sub-processors for the Services is available at roc.ai/legal/subprocessors.

9.2 Our customers

Where we process Personal Information as a processor, we disclose it (for example, the age output) to the customer that submitted the request, who is the controller of that information.

9.3 Corporate transactions

If ROC is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its assets, Personal Information may be transferred as part of that transaction, subject to this Policy or a successor policy.

9.4 Legal, safety, and government requests

We may disclose Personal Information where we believe in good faith it is necessary to comply with a legal obligation, court order, subpoena, or lawful request by public authorities (including for national security or law-enforcement purposes); to protect the rights, property, or safety of ROC, our customers, or others; or to enforce our terms. Where we receive a government or law-enforcement request for data we process on a customer’s behalf, we handle it in accordance with the Data Processing Addendum, including by seeking to redirect the request to the customer and challenging overbroad requests.

9.5 With your consent

We disclose Personal Information for any other purpose with your consent or at your direction.

9.6 We do not sell or share your Personal Information

We do not sell your Personal Information, and we do not “share” it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. In the preceding 12 months, we have not sold or shared Personal Information.

10 Cookies and similar technologies

On our website and portal, we and approved third parties use cookies, web beacons, pixels, and similar technologies to enable functionality and security, remember your preferences, analyze traffic and performance, and, where applicable, support marketing. Strictly necessary technologies operate without consent because they are required for the site to function; other categories may be set when you use our website and portal, as described in our Cookie Notice. You can manage cookies through your browser settings and the third-party opt-out tools described in our Cookie Notice (roc.ai/legal/cookie-notice).

11 Data retention

We retain Personal Information for as long as necessary to fulfill the purposes described in this Policy, unless a longer period is required or permitted by law. In particular:

  • Facial images (Age Verification API): not retained, processed and deleted immediately after the estimate is produced.
  • Age outputs: returned to the customer; retention of the output is controlled by the customer under its own policy.
  • Operational logs and metadata (no images): retained for 90 days for security, billing, and troubleshooting, then deleted or de-identified.
  • Account, billing, and business records: retained for the life of the relationship and for the period required to meet legal, tax, accounting, and dispute-resolution needs.

To determine retention periods we consider the amount, nature, and sensitivity of the information, the potential risk of harm, the purposes for which we process it, and applicable legal requirements.

12 Data security

We maintain administrative, technical, and physical safeguards designed to protect Personal Information against accidental or unlawful loss, misuse, and unauthorized access, disclosure, alteration, and destruction, consistent with our ISO/IEC 27001 / SOC 2 program. These include encryption in transit and, for stored data, at rest; access controls and least-privilege; network and application security; monitoring; and a documented incident-response process. Facial images are processed transiently and are not persisted. No method of transmission or storage is completely secure, so while we work to protect your information we cannot guarantee absolute security; you are responsible for keeping your credentials confidential.

13 International data transfers

ROC is based in the United States, and we and our service providers may process Personal Information in the United States and other countries whose data-protection laws may differ from those of your country. Where we transfer Personal Information from the European Economic Area (EEA), the United Kingdom, or Switzerland to a country not recognized as providing adequate protection, we use an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. Where applicable, we intend to pursue certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions (Section 15.1). Because our Age Verification API is process-and-discard, the volume of data transferred is minimized. Additional information about our safeguards is available on request (Section 17).

14 Your privacy rights and choices

Depending on where you live, you may have rights regarding your Personal Information, described in the regional supplements in Section 15. In addition, everyone may exercise the following choices:

  • Marketing opt-out. You may opt out of marketing emails at any time using the unsubscribe link or by contacting us. You may still receive transactional or service messages.
  • Cookies. You may manage cookies as described in Section 10 and our Cookie Notice.
  • Declining to provide information. You may choose not to provide certain information, though this may prevent us from providing parts of the Services.

To exercise the rights in Section 15, contact us through our Privacy Contact (Section 17). We will respond within the timeframe required by applicable law and may need to verify your identity. There is no charge to exercise your rights, subject to legal limits for excessive or repetitive requests. We do not accept requests through channels not designated in Section 17 (for example, social media).

15 Region-specific disclosures

15.1 European Economic Area, United Kingdom, and Switzerland

This section supplements the Policy for individuals in the EEA, the UK, and Switzerland, and applies where ROC processes Personal Information as a controller. Where ROC processes Personal Information as a processor on a customer’s behalf, that customer is the controller and its privacy information governs; direct your requests to the customer.

Controller

ROC is a business-to-business provider and does not operate a consumer-facing interface. We interact directly only with our business customers and with visitors to our own website. We do not collect information directly from the individuals whose facial images, videos or other data our customers submit to our cloud services and APIs.

When we act as a controller: For Personal Information about visitors to our website, our business contacts, prospects, and the personnel of our customers and partners, the controller is Rank One Computing Corporation d/b/a ROC, 1290 Broadway, Suite 1200, Denver, Colorado 80203. You may contact us directly by mail at the above address or by email at legal@roc.ai.

Legal bases

We process Personal Information on the legal bases in Section 7, performance of a contract, legitimate interests, legal obligation, and consent. Our legitimate interests include providing and securing the Services, responding to communications, marketing to business contacts, preventing fraud, and maintaining the confidentiality, security, and integrity of information; we balance these against your rights and freedoms.

Your rights

Subject to applicable law, you have the right:

  • to be informed about how we process your Personal Information (this Policy);
  • to access your Personal Information and obtain a copy;
  • to rectification of inaccurate or incomplete Personal Information;
  • to erasure (“right to be forgotten”) in certain circumstances;
  • to restrict processing in certain circumstances;
  • to object to processing, including processing based on legitimate interests and processing for direct marketing;
  • to data portability, to receive certain Personal Information in a structured, commonly used, machine-readable format;
  • to withdraw consent at any time where we rely on consent, without affecting prior processing; and
  • to lodge a complaint with your supervisory authority (in the EEA), the UK Information Commissioner’s Office, or the Swiss FDPIC.

International transfers

We transfer Personal Information to the United States and other countries using the safeguards described in Section 13, including the Standard Contractual Clauses and the UK IDTA. Where applicable, we intend to pursue certification under the EU-U.S. Data Privacy Framework and its UK and Swiss extensions. Where we rely on the Data Privacy Framework, we remain responsible for Personal Information we transfer onward to third parties acting as our agents, and the U.S. Federal Trade Commission has jurisdiction over our compliance. You may obtain a copy of the relevant safeguards by contacting us.

How to exercise your rights

Contact us through our Privacy Contact (Section 17). We will respond as required by law.

15.2 United States (state privacy laws)

This section supplements the Policy for U.S. residents and addresses the California Consumer Privacy Act (as amended) and comparable state laws (such as those of Virginia, Colorado, Connecticut, Utah, Texas, and others), to the extent they apply. Where ROC processes Personal Information as a service provider/processor on a customer’s behalf, direct your requests to that business.

Categories collected and disclosed

In the preceding 12 months, we have collected the categories of Personal Information described in Section 5.5 (identifiers and contact data; commercial information; internet/network activity; professional information; and, as a processor, audiovisual data and inferences/outputs). We disclose these categories to service providers/sub-processors and, for processor data, to the submitting customer, for the business purposes described in Section 6. We do not sell Personal Information and do not share it for cross-context behavioral advertising.

Sensitive Personal Information

We do not use or disclose sensitive Personal Information for purposes that require offering a right to limit under applicable law. Facial images processed for age estimation are handled as sensitive, on the customer’s behalf, and deleted immediately.

Your rights

Subject to applicable law and verification, you may have the right to: confirm whether we process your Personal Information and access it; obtain a portable copy; delete it; correct inaccuracies; opt out of the sale or sharing of Personal Information and of targeted advertising and certain profiling (note: we do not engage in these); limit the use of sensitive Personal Information; and not receive discriminatory treatment for exercising your rights. Where provided by law, you may appeal a decision on your request by contacting us; if your appeal is denied you may contact your state attorney general.

Authorized agents; verification

You may use an authorized agent to submit a request, subject to proof of authorization and, where required, verification of your identity. We will take reasonable steps to verify your request by matching information you provide with information we hold.

California “Shine the Light”

We do not disclose Personal Information to third parties for their own direct-marketing purposes. California residents may request confirmation via our Privacy Contact (Section 17).

15.3 Canada

For individuals in Canada, we process Personal Information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws. We are accountable for Personal Information in our custody, obtain consent where required, limit collection and use to identified purposes, and provide rights of access and correction. You may make an access or correction request, or a complaint, through our Privacy Contact (Section 17), and you may also contact the Office of the Privacy Commissioner of Canada. Personal Information may be processed in the United States and other countries and may be accessible to authorities under the laws of those countries.

15.4 Other jurisdictions

As additional jurisdictions enact privacy rights for their residents, we will comply with those laws to the extent applicable to our processing. Contact us with any questions about your rights in your jurisdiction.

16 Third-party websites and services

The Services may link to or integrate third-party websites, products, or services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review their privacy notices.

17 How to contact us (Privacy Contact)

If you have questions, comments, or requests regarding this Policy or our privacy practices, or if you need this Policy in an alternative accessible format, contact us:

Submitting a privacy request

This Policy is the home of ROC’s Privacy Contact. To exercise any of the rights described in Sections 14–15, email us at legal@roc.ai with “Privacy Request” in the subject line, or write to the Privacy Office at the address above. Where we offer an online request form or an in-portal “Privacy & data” option, you may also use those. We do not accept requests through channels we have not designated here (for example, social media).

Please include your name and how to reach you, the right you wish to exercise, enough detail for us to locate the relevant information, and the state, country, or region you are in so we can apply the right law. To protect your information, we will take reasonable steps to verify your identity before acting, usually by matching the details you provide against information we already hold; any additional information you give is used only for verification. You may use an authorized agent, subject to proof of authority and, where permitted, verification of your own identity.

We will acknowledge your request and respond within the time required by the law that applies to you — generally within 45 days for U.S. state privacy requests (extendable once, with notice) and within one month for EU/UK GDPR requests (extendable by two further months for complex or numerous requests, with notice). There is no fee unless a request is manifestly unfounded, excessive, or repetitive, and we will not discriminate or retaliate against you for exercising your rights. If we decline a request and you are in a U.S. state that provides an appeal right, you may appeal as described in Section 15.2; individuals in the EEA, UK, Switzerland, and Canada may also complain to the authorities listed in Sections 15.1 and 15.3.

Requests about age-check data go to our customer. Because ROC processes the facial images and age outputs used in the Age Verification API only as a processor on our customer’s instructions, and deletes the image immediately, please direct requests about that data to the organization that performed the age check; we will assist it as required by law (see Sections 2 and 14).

Build with ROC.
Schedule a free trial or demo.

FormWithSteps NEW
Which capabilities are you interested in?