...

SaaS Terms of Service

Version 1.0 · Updated October 1, 2026

Contents

1 Universal Service Terms
2 Age Verification API
3 Additional Services

These ROC SaaS Terms of Service (the “SaaS Terms of Service”) govern your use of the cloud services and APIs (the “Services”) offered by Rank One Computing Corporation d/b/a ROC (“ROC”), and are part of and incorporated into the ROC SaaS Customer Agreement (the “Agreement”). Capitalized terms used but not defined here are defined in the Agreement. If a service-specific section below conflicts with the Universal Service Terms (Section 1), the service-specific section controls for that Service; the order of precedence in the Agreement otherwise applies.

1 Universal Service Terms

These Universal Service Terms apply to all Services.

1.1 Your Content and instructions. You are responsible for Your Content and for having all rights, notices, and consents necessary for ROC to process it. You instruct ROC to process Your Content to provide the Services and as set out in the Agreement, these SaaS Terms of Service, and the Data Processing Addendum.

1.2 Service data handling. ROC processes Your Content only to provide and maintain the Services and as permitted by the Agreement and the DPA. Certain Services process inputs transiently and do not retain them (see the applicable service section).

1.3 Machine learning; no training on Your Content. ROC will not use Your Content to develop, train, retrain, or improve any ROC or third-party machine-learning or artificial-intelligence models, except under a separate written agreement with you that establishes an independent lawful basis and any required consent. ROC may create and use aggregated, de-identified operational data (such as accuracy, latency, and error metrics) that does not identify you or any individual and is not derived from retained images.

1.4 End-user notices and consent. Where you make a Service available to your end users, you are responsible for providing all legally required privacy notices to, and obtaining all required consents from, those individuals, including any notices and consents required under the Biometric Notice and Consent Terms.

1.5 Data protection addenda. The Data Processing Addendum (roc.ai/legal/dpa) applies to ROC’s processing of personal data within Your Content and includes GDPR, UK GDPR, Swiss, and US state (CCPA) terms and the Standard Contractual Clauses.

1.6 Acceptable use. Your use of the Services is subject to the Acceptable Use Policy (roc.ai/legal/acceptable-use-policy).

1.7 APIs, keys, and limits. You will access the Services only through the documented Permitted Interfaces (APIs/SDKs/portal) using your organization’s credentials. ROC may apply rate limits, quotas, and throttling, and may meter usage. You will keep credentials and API keys secure and are responsible for activity under them.

1.8 Betas, previews, and Sandbox. Services or features identified as beta, preview, evaluation, or “Sandbox” are provided “as is,” may be changed or discontinued, and are excluded from any service-level commitment. You will not submit real personal data in Sandbox.

1.9 Free tiers and trials. Free tiers, trial credits, and promotional usage are subject to the applicable limits and may be modified or withdrawn. They do not carry warranties or service-level commitments.

1.10 Reserved.

1.11 Third-party content. The Services may make available third-party content or integrations, which are subject to their own terms; ROC is not responsible for third-party content.

1.12 Documentation. You will use each Service in accordance with its Documentation, including any Instructions for Use.

2 Age Verification API

This Section 2 applies to your use of our Age Verification API (the facial age-estimation Service), in addition to the Universal Service Terms.

2.1 Service description. Our Age Verification API estimates an approximate age or age band, or returns a threshold decision, from a facial image submitted through the Permitted Interfaces. It is made available as a metered API and developer portal.

2.2 Nature of output – estimate, not identity. Output is a statistical estimate (or a threshold decision), not a determination of an individual’s true age or identity. Our Age Verification API does not identify individuals, does not perform one-to-one or one-to-many biometric matching, and does not create or retain a facial template capable of recognition. Output carries an inherent error margin that varies with image quality, environment, and demographic factors.

2.3 Your configuration and oversight. You are responsible for selecting the age threshold and a challenge-age buffer appropriate to your risk, for maintaining meaningful human oversight of decisions affecting individuals, and for providing a fallback (human review or an alternative age-assurance method) for near-threshold or low-confidence results. You will not use Output as the sole basis for a legal or similarly significant decision about a person without such oversight and a means of redress.

2.4 Biometric notice and consent. Your use of the Age Verification API is subject to the Biometric Notice and Consent Terms (roc.ai/legal/biometric-notice). You will provide the required notices to, and obtain the required consents from, individuals before submitting their images, and will identify ROC as your service provider where required.

2.5 Data handling; process-and-discard; no training. ROC processes each facial image only to produce the estimate and deletes it immediately afterward (process-and-discard); ROC does not store the image or a template and does not use images to train its models. Where you submit an image by URL (imageUrl), you authorize ROC to retrieve that image solely to perform the estimate; you are responsible for the lawfulness of the source and for not directing ROC to internal or unauthorized endpoints.

2.6 Sandbox and Production. Sandbox access is for testing with synthetic or your own test images only; you will not submit real personal data in Sandbox. Real personal data may be processed only after you enable Production, which requires acceptance of the DPA and acknowledgement of the current Sub-processor List. ROC may enforce this technically, including by refusing Production requests until these conditions are met.

2.7 Acceptable use (age estimation). In addition to the AUP, you will not use our Age Verification API: (a) to identify, re-identify, verify the identity of, locate, surveil, profile, or track any individual; (b) to infer any characteristic other than age; (c) to create or enrich any facial-recognition or biometric-identification database; or (d) to represent that the Service satisfies a specific statutory age-verification standard unless ROC has confirmed suitability in writing for that standard and jurisdiction.

2.8 EU AI Act. For our Age Verification API, ROC is the provider and you are the deployer of the AI system. You will use the Service for its intended purpose (age estimation), meet the Article 50(3) transparency obligation to individuals, follow the Instructions for Use, and not deploy the Service in a prohibited or high-risk context or to infer sensitive attributes without ROC’s prior written agreement.

2.9 Accuracy and fairness information; suitability. ROC makes available accuracy and demographic-fairness benchmarking information for the Service. You are responsible for determining that age estimation is an appropriate and, where relevant, legally sufficient age-assurance method for your use case and jurisdiction (for example, whether it qualifies as “highly effective age assurance” under the UK Online Safety Act, or as an accepted method under a US state age-verification law).

3 Additional Services

3.1 Reserved. ROC may add sections to these SaaS Terms of Service for additional Services (for example, other ROC cloud APIs). Each such Service is governed by the Universal Service Terms and its own service-specific section when published.

Build with ROC.
Schedule a free trial or demo.

FormWithSteps NEW
Which capabilities are you interested in?