Acceptable Use Policy
DECTIFY builds systems that watch public and semi-public space. This policy states the uses we will not support, on any deployment, for any customer, at any price.
This Acceptable Use Policy (the "AUP") is incorporated into and forms part of the Terms and Conditions between DECTIFY Technologies Private Limited ("DECTIFY") and each customer ("Customer"). Capitalised terms not defined here carry the meaning given in the Terms and Conditions. Breach of this AUP is a material breach of the Agreement.
DECTIFY may update this AUP on thirty (30) days' notice. A change that is materially adverse to Customer takes effect at Customer's next renewal, except where a change is required by law.
1. Scope of permitted use
Customer may use the Services solely for the lawful security, safety, operational and investigative purposes described on the applicable Order Form, and only within premises, sites and jurisdictions for which Customer holds documented legal authority to conduct video surveillance and, where applicable, biometric or vehicle-data processing.
Authority to deploy at one Site is not authority to deploy at another. Authority to operate one Product is not authority to operate another. Where a Product is subject to additional conditions, those conditions are recorded in the Product-Specific Terms and apply in addition to this AUP.
2. Prohibited uses
Customer shall not, and shall not permit any Authorised User, affiliate, contractor or third party to, use the Services:
2.1 Against protected characteristics
To identify, classify, sort, track, score or generate alerts on individuals on the basis of race, caste, tribe, religion, ethnicity, national or Indigenous origin, sex, gender identity, sexual orientation, disability, health status, pregnancy, trade union membership, or political or philosophical affiliation; or to infer any such characteristic from facial, gait, body, dress or voice analysis. DECTIFY does not supply this capability and Customer shall not attempt to construct it from Outputs.
2.2 Against protected activity
To monitor, identify or track individuals on the basis of their participation in lawful assembly, protest, industrial action, worship, journalism, legal representation, healthcare-seeking, or the exercise of any constitutional or statutory right.
2.3 For untargeted mass surveillance
To conduct persistent, indiscriminate monitoring of the general public absent a specific, articulable and documented security purpose; or to construct a longitudinal movement profile of an identified individual outside an active, documented investigation or safety incident with a recorded opening and closing date.
2.4 For emotion, deception or predisposition inference
To infer emotional state, truthfulness, criminal propensity, trustworthiness, intent, or any psychological or behavioural trait of an individual. DECTIFY does not provide such capability.
2.5 For automated adverse action
To effect any legal, employment, financial, custodial, educational, insurance or access-denial consequence for an individual on the basis of an Output alone. A qualified human reviewer must independently assess the underlying material and record the basis for the decision before any adverse action is taken.
2.6 In prohibited settings
In washrooms, changing rooms, locker rooms, medical examination and treatment areas, places of worship, residential interiors not owned or controlled by Customer, or any location where an individual holds a reasonable expectation of privacy under applicable law. In Australia, Customer shall additionally comply with the Surveillance Devices legislation of the relevant State or Territory, including restrictions on recording private activities and private conversations.
2.7 Against children
To enrol a minor into any watchlist, person-of-interest list or biometric gallery, except where required for a bona fide missing-child or child-safeguarding matter under the direction of a competent authority or the child's lawful guardian. In India, Customer shall observe section 9 of the Digital Personal Data Protection Act, 2023, including the prohibitions on tracking, behavioural monitoring and targeted advertising directed at children.
2.8 Outside the Customer's authority
To process footage, plates, faces or telemetry originating from cameras, vehicles or aircraft that Customer does not own, does not operate, or does not hold documented contractual authority to process.
2.9 Technical misuse
To reverse engineer, decompile or disassemble the Services; to extract model weights, embeddings or training data; to benchmark for competitive publication without consent; to circumvent rate limits, quotas or access controls; to introduce malicious code; or to develop a competing product or service.
2.10 Onward disclosure
To sell, licence, broker or otherwise commercially disclose Customer Data or Outputs to any data broker, advertising network, insurer, credit bureau, tenancy database or employment-screening service.
2.11 Unlawful or harmful conduct
To stalk, harass, intimidate, defame or endanger any individual; to facilitate any offence; or in any manner that infringes the intellectual property, privacy or publicity rights of another.
3. Deployment obligations
Customer shall:
- Give notice. Post conspicuous notice of video, biometric and number-plate monitoring at each covered entrance and monitored zone, in English and the locally prevalent language, and give any further notice or obtain any consent that applicable law requires.
- Publish an internal policy. Maintain a written internal use policy that names the responsible officer, states the permitted purposes, and sets the review cadence.
- Control access. Restrict Platform access to trained, named Authorised Users, with unique credentials and multi-factor authentication enabled. Shared accounts are prohibited.
- Revoke promptly. Revoke access within twenty-four (24) hours of an Authorised User's separation or role change.
- Train before granting. Complete DECTIFY's certification training before any Authorised User is granted search, enrolment or export privileges. Training covers system limitations, bias awareness, verification protocol and audit obligations.
- Justify every search. Record a purpose and case reference for each query, match review and export. The Platform requires this field and it cannot be disabled.
- Bound every watchlist. Give each watchlist or person-of-interest entry a documented basis, an owner and an expiry date, and review the list at least quarterly.
4. Audit and enforcement
4.1 Logging. Every query, match review, enrolment, export and administrative change in the DECTIFY HUB is recorded in an immutable audit log available to Customer's administrator and, on request, to Customer's auditor. DECTIFY does not provide a mechanism to disable, edit or purge the audit log.
4.2 Customer review. Customer shall review its audit logs no less than quarterly and retain each review record for the term plus one (1) year.
4.3 DECTIFY action. Where DECTIFY reasonably believes this AUP has been breached, it may require Customer to provide the relevant audit records, suspend the affected capability or account, or terminate the Agreement for material breach. Where the suspected breach creates a risk of harm to an individual, DECTIFY may suspend immediately and investigate afterwards.
4.4 Proportionality. DECTIFY will limit any suspension to the capability, account or Site concerned wherever technically feasible, will tell Customer what triggered it, and will restore service promptly once the cause is resolved or Customer demonstrates the belief was mistaken.
4.5 No obligation to monitor. DECTIFY does not routinely monitor Customer Data or Customer's queries, and nothing in this clause creates an obligation to do so. Absence of enforcement action is not approval of any use.
5. Reporting misuse
Anyone who believes the Services are being used in breach of this AUP may report it to abuse@dectify.in. Reports may be made anonymously. DECTIFY acknowledges reports within three (3) business days and will not disclose the identity of a reporter to the Customer concerned without the reporter's consent, except where compelled by law.
DECTIFY does not retaliate against, and will not permit a Customer to require the identification of, a person who reports a suspected breach in good faith.
A match is a lead, not a conclusion. Every DECTIFY Product returns probabilistic results with confidence scores. Treating an Output as proof of identity, presence or intent is the single most common way these systems cause harm, and it is a breach of this policy.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India