Product-Specific Terms
One schedule per product. Each states what the product does, what it is licensed for, what it is not, and the conditions that attach to running it.
These Product-Specific Terms are incorporated into the Terms and Conditions and apply to each Product listed on an Order Form. Where a schedule conflicts with the Terms and Conditions, the schedule prevails for that Product. Every schedule is subject to the Acceptable Use Policy without exception.
Three obligations run through every schedule and cannot be varied by any Order Form: outputs are probabilistic; a human must review before any adverse action; and retention is bounded by the Data Retention Schedule.
Schedule A — FaceTrack
Facial recognition and identification.
A.1 Function. Detects faces in a video stream, derives a biometric template, and compares it against a Customer-defined gallery to return ranked candidates with confidence scores.
A.2 Licensed for. Access control at Customer-controlled premises; locating a person reported missing; investigating a specific documented security incident; identifying a person subject to a lawful exclusion from Customer's premises.
A.3 Not licensed for. Identification of the general public; enrolment of any person not covered by a documented basis under clause 9.2 of the Biometric, ANPR and Facial Recognition Policy; demographic classification; any inference beyond identity.
A.4 Conditions. Site signage disclosing facial recognition specifically, not merely "CCTV in operation". A completed and retained privacy impact assessment before go-live. Recorded lawful basis — consent under section 6 DPDP or APP 3.3, or a recorded statutory exception. Certification training for every user with search or enrolment privileges. Ambient unmatched templates expire at 72 hours and this is not configurable upward.
Schedule B — FaceLink
Cross-camera person re-identification.
B.1 Function. Associates the same person across camera views within a bounded session using appearance features. It does not resolve identity and does not require a name.
B.2 Licensed for. Reconstructing a person's path through a site during an active incident; establishing dwell and flow for operational planning; supporting a documented investigation.
B.3 Not licensed for. Linking a track to an identity except through FaceTrack under Schedule A; persisting a track beyond the session; building a movement history of an individual across days.
B.4 Conditions. Tracks expire at session end and in any event at 24 hours. Cross-site linkage requires each site to be on the same Order Form and under the same Customer's control. There is no cross-customer linkage and the capability does not exist.
Schedule C — CrowdSense
Crowd density, flow and anomaly detection.
C.1 Function. Estimates occupancy, density and flow direction; detects crush risk, sudden dispersal and counter-flow. Outputs are aggregate and non-identifying.
C.2 Licensed for. Public safety at venues, transport hubs, religious gatherings and events; capacity and evacuation management; operational planning.
C.3 Not licensed for. Identification of participants; counting or characterising an assembly by the protected characteristics of those present; monitoring a gathering because of its political, religious or industrial character.
C.4 Conditions. Individual-level records are not produced or retained. Aggregate metrics retained per the Data Retention Schedule. Where CrowdSense runs alongside FaceTrack on the same feed, Schedule A conditions apply to that feed in full.
Schedule D — Eyezon
Intrusion, perimeter and behavioural alerting.
D.1 Function. Detects line crossing, loitering, object left behind or removed, and defined restricted-zone entry, and raises an alert.
D.2 Licensed for. Perimeter and asset protection at Customer-controlled sites; after-hours monitoring; safety-zone enforcement in industrial settings.
D.3 Not licensed for. Behavioural inference beyond the defined geometric and temporal rules; "suspicious behaviour" scoring; any classification of intent.
D.4 Conditions. Alerts are rule outputs, not judgements about a person. Alert thresholds and zones must be documented. DECTIFY does not monitor alerts or dispatch a response unless a monitoring service is purchased on the Order Form; see clause 11.5 of the Terms and Conditions.
Schedule E — DriveCheck
Driver behaviour and in-cab safety.
E.1 Function. Detects fatigue indicators, distraction, phone use, seatbelt non-use and following distance, and raises in-cab and fleet alerts.
E.2 Licensed for. Fleet safety programmes; coaching; compliance with a Customer's own duty of care to drivers and the public.
E.3 Not licensed for. Automated disciplinary or termination decisions; productivity monitoring; continuous recording of the cab interior outside a detected event; emotion inference.
E.4 Conditions. Drivers must be notified in writing before deployment, and where a workplace surveillance statute applies — including the Workplace Surveillance Act 2005 (NSW) and the Workplace Privacy Act 2011 (ACT) — with the notice period and signage that statute requires. Event clips only; no continuous cab recording by default. Audio disabled by default and, in Australia, not to be enabled without written legal advice held by Customer. Any coaching or disciplinary process must include human review of the underlying clip.
Schedule F — DriveLink
ANPR, vehicle identification and fleet linkage.
F.1 Function. Reads registration plates and observed vehicle characteristics, and compares against a Customer-defined list.
F.2 Licensed for. Access control at Customer-controlled sites; parking and yard management; investigating a documented incident; fleet movement records for vehicles Customer operates.
F.3 Not licensed for. Building a movement history of a vehicle Customer does not operate outside an active documented investigation; sharing plate reads with any party other than a lawful authority under Government and Law Enforcement Requests; resolving a plate to a keeper.
F.4 Conditions. DECTIFY holds no registration database in either jurisdiction and performs no keeper lookup. Non-alerted reads expire at 30 days by default. Low-confidence reads are flagged to the user and must not be actioned without visual verification of the plate image.
Schedule G — Traffic Detection
Junction analytics and signal optimisation.
G.1 Function. Counts and classifies vehicles by type, measures queue length, turning movements and pedestrian presence, and feeds signal timing.
G.2 Licensed for. Traffic management, signal optimisation, junction design, and road safety analysis by a road authority or its contractor.
G.3 Not licensed for. Identifying drivers or pedestrians; enforcement, unless the Customer holds the statutory authority and the device meets any applicable type-approval and calibration requirement.
G.4 Conditions. Outputs are aggregate and non-identifying by default. Where a Customer enables plate capture at a junction, Schedule F applies to that feed. Enforcement use requires the road authority's written confirmation of its authority, recorded on the Order Form.
Schedule H — SkyResponder / AERION
Autonomous aerial response.
H.1 Function. Dispatches an aerial platform to a triggered location, streams to the HUB, and returns to base.
H.2 Licensed for. Situational assessment of an alert at a Customer-controlled site; search support in a documented safety incident; infrastructure inspection.
H.3 Not licensed for. Patrol of areas outside Customer's control; overflight of residential property without authority; persistent observation of any location; carriage of anything other than the sensor payload on the Order Form.
H.4 Conditions. India: Drone Rules 2021 — UIN per aircraft, type certification, Remote Pilot Certificate per operator, Digital Sky airspace zones, no-permission-no-takeoff enforced in software, geofencing to the published map, third-party insurance. Australia: CASR Part 101 — ReOC and RePL where required, standard operating conditions unless a CASA approval is held, airspace authorisation for controlled airspace, drone registration. In both: State, Territory and local surveillance devices law applies to what is recorded, independently of the aviation regulator. Unless the Order Form records DECTIFY as operator, Customer is the operator and holds the certificates, the approvals and the insurance.
Schedule I — DECTIFY HUB
The platform.
I.1 Function. Tenancy, identity, camera and site management; alert triage; case files; search; export; audit; reporting.
I.2 Non-negotiable platform behaviour. The following cannot be disabled, defaulted away, or bypassed through the API, on any tier, under any Order Form:
- Multi-factor authentication on every administrative and search-privileged account.
- The mandatory purpose and case-reference field before a search executes.
- Append-only audit logging of every search, review, enrolment, export and administrative change.
- Display of the confidence score alongside every match.
- The human-review step before an adverse action can be recorded against an individual.
- Watchlist entry requirements — documented basis, named owner, review date, expiry date.
I.3 Administration. Customer designates administrators, who are responsible for access grants, quarterly log review and watchlist governance.
I.4 Export. Exports are logged with the exporting user, purpose and destination. Bulk export of biometric templates is not available through any interface.
General
Beta capabilities within any Product are governed by clause 3.5 of the Terms and Conditions and must not be used to make or support a decision affecting an individual.
Changes. These schedules may be updated on thirty (30) days' notice; a change materially adverse to Customer takes effect at the next renewal. Changes are recorded at Compliance and Security Updates.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India