Skip to main content
Home Legal
Biometric, ANPR and Facial Recognition Policy

Biometric, ANPR and Facial Recognition Policy

Version 2.0 · Effective 22 August 2026

This is the most consequential thing we publish. It sets out what our facial recognition, re-identification and number-plate systems actually do, what they record, how long any of it survives, and the uses we refuse to support.

Global FaceTrack FaceLink DriveLink / ANPR DPDP Act 2023 Privacy Act 1988

Contents

  1. Scope and definitions
  2. Purpose, and the purposes we exclude
  3. What each system captures
  4. Lawful basis and notice
  5. Access, authorisation and audit
  6. Accuracy, confidence and human review
  7. Retention and deletion
  8. Security of biometric data
  9. Watchlists and enrolment
  10. Prohibited uses
  11. Individual rights
  12. Testing, bias evaluation and publication
  13. Custodian and contact

1. Scope and definitions

This policy governs DECTIFY's facial recognition (FaceTrack), cross-camera person re-identification (FaceLink) and automatic number plate recognition (DriveLink) capabilities, wherever deployed. It binds DECTIFY and, through the Terms and Conditions, every customer operating those capabilities.

Biometric template
A mathematical representation — a feature vector or embedding — derived from a facial image. It is not a photograph and cannot be viewed as one, but it identifies an individual and is treated as biometric data under the Digital Personal Data Protection Act, 2023 and as sensitive information under section 6 of the Privacy Act 1988 (Cth).
Facial recognition
Comparison of a probe facial image against a gallery of enrolled templates to produce candidate matches with confidence scores. It answers "who might this be", never "who this is".
Re-identification
Association of the same person across camera views within a bounded time window, using appearance features. Re-identification does not resolve identity and does not require a name.
ANPR
Optical recognition of a vehicle registration plate, together with observed vehicle characteristics, converted into machine-readable data.
Alert
A notification that a capture exceeded a configured similarity threshold against an entry on a customer-defined watchlist. An alert is a prompt to look, not a finding.
Gallery / watchlist
A customer-defined set of enrolled templates or plates against which captures are compared. DECTIFY supplies no gallery and no watchlist content.

2. Purpose, and the purposes we exclude

These systems exist to help customers protect people and premises: detecting unauthorised access, locating a missing person, investigating an incident after it happened, and managing vehicle movement at controlled sites.

They are not built for, and are not licensed for, mass identification of the public, political or religious profiling, immigration enforcement without lawful authority, workplace productivity monitoring, emotion or intent inference, or any commercial purpose unrelated to security and safety. Section 10 states this as binding prohibition.

3. What each system captures

SystemCapturedDerivedNot captured
FaceTrack Facial image crop, source video frame, timestamp, camera identifier and location Biometric template, match confidence score, candidate ranking Name, age, gender, ethnicity, emotion, health or any inferred characteristic
FaceLink Person bounding box, appearance descriptor, timestamp, camera identifier Track identifier valid within a bounded session, dwell time, direction of travel Identity, biometric template, cross-customer linkage
DriveLink Plate image, vehicle image, timestamp, camera identifier and location Plate characters, issuing jurisdiction, vehicle colour, make and body type, read confidence Registered keeper, driver identity, occupant faces, vehicle interior

DECTIFY does not hold, license or query any vehicle registration database, electoral roll, identity register, or government photographic record, and does not resolve a plate to a keeper. Any such lookup is the customer's own act under its own legal authority, using its own systems.

4. Lawful basis and notice

4.1 The customer decides. The customer is the Data Fiduciary (India) and APP entity (Australia) for all captures at its sites. It must establish a lawful basis before any capture and must be able to evidence it.

4.2 India. Under the Digital Personal Data Protection Act, 2023, processing generally requires the free, specific, informed, unconditional and unambiguous consent of the Data Principal, given after a notice meeting section 5, or must fall within a legitimate use under section 7. A customer relying on section 7 must record which limb it relies on. Section 9 restrictions on processing children's data apply in full and cannot be contracted around.

4.3 Australia. Biometric templates and facial images used for biometric identification are sensitive information. Australian Privacy Principle 3.3 requires consent for collection unless an exception applies — such as a permitted general situation under section 16A, or an enforcement-related activity by or on behalf of an enforcement body under APP 3.4. A customer relying on an exception must record it. The OAIC's guidance on facial recognition in commercial settings applies, and Customer should complete a privacy impact assessment before deployment.

4.4 Notice at the site. The customer must post conspicuous signage at every covered entrance and monitored zone stating that video and, where applicable, facial recognition or number-plate recognition is in operation, who operates it, the purpose, and how to contact them. Signage must be in English and the locally prevalent language. DECTIFY supplies a compliant template; using it does not transfer responsibility for its adequacy.

4.5 Surveillance devices legislation (Australia). State and Territory Surveillance Devices Acts operate independently of the Privacy Act and may prohibit recording a private activity or conversation without consent regardless of any privacy basis. Audio capture is disabled by default on DECTIFY hardware supplied to Australian sites and must not be enabled without written legal advice held by the customer.

5. Access, authorisation and audit

5.1 Administrators. Each customer designates one or more administrators as custodians of the deployed system. Customer data is accessible only to those administrators and the Authorised Users they name.

5.2 DECTIFY access. A restricted DECTIFY support team may access a customer's system solely to diagnose a reported fault, to address a security incident, or at the customer's request. Access is time-bound, approved under a documented process, and written to the customer's own audit log.

5.3 What is logged. Every interaction is recorded: the querying user, date and time, the stated purpose and case reference, the search parameters (plate string, uploaded probe image hash, time window, camera set), the results returned, whether a match was confirmed or rejected, and any export. The log is append-only. Neither the customer nor DECTIFY can edit or delete an entry.

5.4 Mandatory justification. The purpose field is required before a search executes. It cannot be turned off, defaulted, or bypassed via the API.

5.5 Review. Customers must review their audit logs at least quarterly and keep each review record for the term plus one year. DECTIFY provides a review report that highlights out-of-hours access, high query volumes for a single user, repeat queries against the same individual, and searches without a case reference.

6. Accuracy, confidence and human review

6.1 Every result is probabilistic. FaceTrack returns ranked candidates with confidence scores, never a determination. DriveLink returns a read with a confidence value; low-confidence reads are flagged to the user rather than silently accepted.

6.2 What degrades accuracy. Lighting, camera angle and elevation, distance, motion blur, occlusion by masks, helmets, glasses or headwear, plate damage, non-standard plates, weather, and image compression all reduce accuracy. Performance measured in a laboratory does not transfer to a field deployment, and DECTIFY does not represent that it does.

6.3 Human review is mandatory. No enforcement, detention, denial of access, disciplinary, employment, financial or other adverse action may be taken against an individual on the basis of a system output alone. A trained human reviewer must examine the underlying imagery, reach an independent conclusion, and record the basis for it. This obligation is contractual, is not waivable, and applies to every product covered by this policy.

6.4 Thresholds. DECTIFY sets a conservative default similarity threshold. A customer may raise it. A customer may lower it only with a written record of who authorised the change and why; the change is logged and surfaced in the review report.

7. Retention and deletion

Data classDefault retentionMechanism
Video and facial images30 days from captureRolling automated deletion
Biometric templates from ambient capture (not matched)72 hoursRolling automated deletion
Biometric templates matched to an active watchlist entry90 days, or until the investigation is closed if shorterRolling deletion, plus closure trigger
Enrolled gallery templatesUntil the customer removes the entry, or its expiry date, whichever is firstCustomer-initiated and expiry-triggered
Plate reads (no alert)30 days from captureRolling automated deletion
Plate reads associated with an alert90 days, or until the matter is closedRolling deletion, plus closure trigger
Re-identification tracksSession duration, maximum 24 hoursAutomatic expiry
Evidence exported to a case fileSet by the customer's own legal obligationCustomer-controlled, with the basis recorded
Audit logs180 days minimum (CERT-In Direction), then per customer configurationAppend-only, retained in-jurisdiction

7.1 Deletion is deletion. Expiry removes the record from production storage and from search indices. Backup copies age out within a further ninety (90) days. DECTIFY does not retain a shadow copy of expired biometric data for any purpose, including model improvement.

7.2 Shortening. A customer may configure shorter periods than those above. A customer may extend a period only where its own law requires it, and must record the provision relied on. DECTIFY will not extend biometric template retention beyond ninety (90) days on commercial request.

7.3 Certification. On request, DECTIFY provides written confirmation that a specified data set has been deleted, with the date and the mechanism.

The full picture across every data class is at Data Retention Schedule.

8. Security of biometric data

  • Biometric templates are stored separately from imagery and account data, in an encrypted store with its own access control and its own key.
  • Encryption in transit from camera to cloud, and at rest, using industry-validated cryptography.
  • Multi-factor authentication is mandatory on every administrative and search-privileged account, and cannot be disabled.
  • Role-based access control on least privilege; enrolment, search and export are separately grantable.
  • Continuous vulnerability scanning of internet-facing infrastructure, with remediation targets published at Vulnerability Disclosure Policy.
  • Append-only audit logging with anomaly detection.
  • Templates are not exportable in bulk. There is no interface — UI or API — that returns the full gallery.

9. Watchlists and enrolment

9.1 The customer builds it. DECTIFY supplies no watchlist, no gallery and no reference imagery, and has no access to any law enforcement or government database.

9.2 Every entry needs four things. A documented basis for inclusion; a named owner; a review date no more than ninety (90) days out; and an expiry date. The platform will not accept an entry without them.

9.3 Children. A minor may be enrolled only for a bona fide missing-child or child-safeguarding matter, under the direction of a competent authority or the child's lawful guardian, and the entry must be removed when the matter closes.

9.4 Review. Entries past their review date are suspended automatically until reviewed. Entries past expiry are deleted.

10. Prohibited uses

The following are prohibited absolutely, and DECTIFY will suspend the capability on reasonable belief that any of them is occurring. This section supplements, and does not narrow, the Acceptable Use Policy.

  • Identifying, sorting or alerting on individuals by race, caste, tribe, religion, ethnicity, Indigenous status, sex, gender identity, sexual orientation, disability or political affiliation — or inferring any of those from a face.
  • Monitoring participation in lawful assembly, protest, industrial action, worship, journalism or legal representation.
  • Persistent identification of the general public with no articulable, documented and time-bounded security purpose.
  • Building a longitudinal movement history of an identified person outside an open, documented investigation.
  • Emotion, intent, deception or criminal-propensity inference. The capability does not exist in our products and must not be approximated from outputs.
  • Automated adverse action without human review, contrary to clause 6.3.
  • Deployment in washrooms, changing rooms, medical treatment areas, places of worship, or residential interiors the customer does not control.
  • Enrolling a minor other than as clause 9.3 permits.
  • Processing feeds from cameras the customer neither owns, operates, nor holds documented authority over.
  • Disclosing captures or outputs to a data broker, advertiser, insurer, credit bureau, tenancy database or employment screening service.

11. Individual rights

Individuals may ask whether they appear in a DECTIFY-processed system, ask for a copy, ask for correction, ask for deletion, and complain.

The request goes to the organisation operating the cameras, because it holds the lawful basis and decides. Its details should be on the site signage. If you cannot identify it, write to privacy@dectify.in with location, date and approximate time; we will identify the responsible customer and route your request, or tell you no DECTIFY system operates there. We will not search a customer's data on your behalf without that customer's instruction, and we will not create a search of you in order to answer a question about you.

Statutory routes: in India, the Data Protection Board of India, after exhausting the customer's grievance process and ours at Grievance Redressal. In Australia, the Office of the Australian Information Commissioner.

12. Testing, bias evaluation and publication

12.1 Pre-release evaluation. Every model release is evaluated for differential error rates across demographic groups, using held-out evaluation sets that are not drawn from Customer Data. Results are recorded in the model card.

12.2 Model cards. DECTIFY publishes, for each model in a released Product, the intended use, the evaluation methodology, measured performance including error rates by group where the evaluation set supports it, known failure modes, and the conditions under which performance degrades.

12.3 Field monitoring. Confirmed false positives reported by customers are logged, categorised and reviewed. Where a pattern emerges, DECTIFY will notify affected customers and, if warranted, raise the default threshold or withdraw the affected configuration.

12.4 Independent testing. DECTIFY submits models for third-party evaluation where a credible programme is available and publishes the result whether or not it is favourable. Current status is at Compliance and Security Updates.

The governance framework behind this is at India AI and Responsible Technology and Australia AI and Responsible Technology.

13. Custodian and contact

The official custodian of this policy is [named officer and title], contactable at privacy@dectify.in.

A match is an investigative lead. It is not identification, not evidence, and not a basis for action on its own. Every deployment of these systems that has gone badly wrong, anywhere in the world, has gone wrong at this point.

Contact

Questions about this document: legal@dectify.in

DECTIFY Technologies Pvt. Ltd., New Delhi, India