Overview
If you are reading this, it is likely because your employer, school, bank, airport, or another organization uses Rock X, Rock, or RockOS (together, the Rock). The Rock is an all-in-one device that combines facial biometrics and AI to prevent unauthorized access, detect tailgating, increase efficiency, and comply with privacy laws such as BIPA, CCPA, and GDPR.
Our approach uses a Facial Signature, a one-way encrypted mathematical code derived from facial geometry, not a photograph. While this design means the Facial Signature cannot independently identify a person, and recent case law suggests such signatures may not constitute biometric identifiers under certain statutes, we interpret the law broadly and treat Facial Signatures as biometric data. We apply the same rigor and safeguards required for traditional biometrics under laws such as BIPA, CCPA and CPRA, GDPR, and CUBI.
This policy explains:
- What biometric data we process, and what we do not
- How consent is obtained and enforced before enrollment
- How and where Facial Signatures are stored
- Retention limits and deletion procedures
- Security measures that protect your data
- How your rights are respected under applicable data laws
Key terms
How the Rock authenticates you
The Rock uses 1:1 and 1:Few verification matching. Your face is only checked against the Solution Owner's private database of enrolled users, never against external or government databases of unknown individuals. In practice, the Rock answers one question: are you who you claim to be, and are you allowed in here?
Enrollment (opt-in only)
Before any authentication can occur, you must be enrolled. Enrollment is always opt-in and requires explicit consent confirmed by the Solution Owner. The Rock cannot capture or store a Facial Signature without this confirmation.
- Consent first. You agree to be enrolled through your Solution Owner's process, such as onboarding, visitor registration, or a consent form.
- Scan and convert. The Rock captures a live scan of your face and instantly converts it into a Facial Signature.
- Delete the photo. The original image is deleted immediately and never stored.
- Link to badge number. The Facial Signature is linked only to an anonymized badge number in the ACS, not to your name, email, or photo.
If you do not enroll, the Rock will not recognize you, and you will use an alternate access method such as a badge or PIN.
Authentication (1:1 verification)
Once enrolled, authentication happens in real time at the access point:
- Live scan. The Rock captures your facial features when you approach.
- Local match. Your live scan is compared only against your own stored Facial Signature, never against other people.
- Liveness check. The system confirms the scan is of a real, live person, not a photo or video.
- Grant or deny. If the live scan matches, the Rock sends a grant signal to the ACS to unlock the door. If not, access is denied.
The Rock does not mine or search public images, operate in surveillance mode, or track movement outside of ACS event logs. Because matching is limited to the Solution Owner's private database, your Facial Signature is checked only within your organization's records, no third-party or government databases are ever involved, and cross-system reuse of Facial Signatures is technically impossible.
Consent
Enrollment is always opt-in and requires affirmative, explicit consent. The Rock's architecture prevents enrollment or creation of any Facial Signature without documented permission and proper notice, as required by California law (CCPA and CPRA), Illinois law (BIPA), and other applicable regulations. There is no silent or automatic enrollment. Before collection, you receive clear notice of the specific purpose and duration of use, and consent must be confirmed before any biometric data is captured.
Role of the Solution Owner
The Solution Owner is responsible for confirming your consent before enrollment. This may occur through:
- Onboarding processes for employees or contractors
- Visitor registration systems
- Electronic consent forms, including DocuSign or similar platforms
The Rock will not proceed until it receives an explicit approval signal from the Solution Owner's integrated system.
Technical safeguards
Consent is not only a policy, it is built into the system's architecture:
- ACS integration. Enrollment cannot begin unless consent is flagged as approved in the Solution Owner's ACS.
- Consent modules. If enabled, the enrollment process presents a clear and conspicuous consent form before any biometric data is captured.
- No self-enrollment. Individuals cannot bypass consent by self-enrolling. Only the Solution Owner's authorized administrator can approve enrollment.
Withdrawing consent and alternatives
You may withdraw your consent at any time by notifying the Solution Owner. Once withdrawn, your Facial Signature is deleted from the Rock and related storage, you will no longer be recognized, and you will use an alternative access method such as a badge or PIN. The Solution Owner must provide alternate means of access for anyone who does not enroll or who withdraws consent, so access is never conditioned on providing biometric data.
Compliance with privacy laws
This consent process is designed to meet or exceed the requirements of applicable biometric privacy laws, including:
- Illinois BIPA. Written, informed consent before collecting biometric identifiers.
- Texas CUBI. Consent before capturing biometric identifiers, with retention limits.
- California CPRA and CCPA. Notice, purpose limitation, and the right to opt out of certain uses.
- EU GDPR. Treats biometric data as a special category requiring explicit consent and lawful processing.
Data collection, storage, and retention
What the Rock collects
When you enroll, the Rock captures a live facial scan for the sole purpose of creating a Facial Signature, a one-way encrypted mathematical representation of your facial geometry, not a photograph.
- No photos are stored. The enrollment image is deleted automatically after the Facial Signature is created.
- No personal details are stored with your signature. It is paired only with an anonymous badge number from the ACS.
- No continuous scanning. The Rock only scans when you present yourself at an access point.
- No cookies or tracking. The Rock does not use cookies, web beacons, or other tracking technologies.
Where data is stored and how it is protected
Facial Signatures are stored in encrypted form on the Rock device, and, depending on configuration, within the Solution Owner's secure servers or ACS database. Alcatraz does not keep a master database of Facial Signatures, and we cannot access, sell, or repurpose your biometric data. Protection includes:
- At rest. Encryption using AES-256, the industry standard for sensitive data.
- In transit. Data uses TLS 1.2 or higher.
- Access controls. Only authorized Solution Owner administrators, under role-based access, can manage enrollment or deletion.
- No identity linkage. Biometric data is never stored alongside names or photos. Any linkage exists only in the Solution Owner's ACS.
Retention and deletion
Facial Signatures are retained only as long as necessary to provide access control, and never longer than the retention period set by the Solution Owner's policy, the period required by applicable law, or three years from your last interaction, whichever is shortest. When you withdraw consent or leave the organization, the Solution Owner must delete your Facial Signature. The Rock supports on-demand deletion and automatic purging, and its admin interface logs the date and time of last use to support compliance audits.
Data sharing and cross-system use
The Rock platform is architected with a strict "one system, one purpose" principle. Each Facial Signature is cryptographically bound to a single Solution Owner's deployment and cannot be used elsewhere:
- No exporting or importing. Facial Signatures cannot be exported from one deployment or imported into another.
- No sharing across entities. Templates cannot be shared, copied, or merged between customers, sites, or environments.
- No centralized database. Alcatraz does not maintain a master repository of Facial Signatures, eliminating the risk of large-scale correlation or misuse.
Facial Signatures are never sold, licensed, or shared with third parties by Alcatraz. Only the Solution Owner can decide to share data, and only in accordance with applicable law and their own privacy policies. Alcatraz cannot comply with requests for individual access history, because it does not store names or personal identifiers alongside biometric templates. Any such requests must be directed to the Solution Owner and will only be honored if legally required.
Your rights to biometric data
Your rights over your biometric data depend on where you live and the privacy laws that apply to you. Alcatraz is the Data Processor. We process biometric data only under the instructions of the Data Controller, your Solution Owner, which means Alcatraz cannot directly fulfill requests to access, delete, correct, or withdraw consent for your biometric data, in part because we have no ability to identify you. Those requests must be made to your Solution Owner. If your Solution Owner fails to respond within the timeframe required by applicable law, you can contact us at privacy@alcatraz.ai for assistance, appeals, or help identifying the correct contact.
Depending on your jurisdiction, you may have the right to:
- Know and access. Confirm whether your biometric data is processed, and learn its categories, sources, purposes, recipients, and retention periods.
- Deletion. Request deletion of your biometric data, subject to legal retention requirements. Deletion uses secure methods that meet NIST standards for data sanitization.
- Correction. Because templates cannot be corrected, you can request deletion and re-enrollment through your Solution Owner.
- Withdraw consent. Withdrawal stops all further processing and deletes your Facial Signature.
- Object or restrict. Object to processing not based on legal obligations, or restrict processing in certain cases, such as while an objection is under review.
- Non-discrimination. You will not receive retaliatory or discriminatory treatment for exercising your privacy rights.
Alcatraz will never sell your biometric data or share it for cross-context behavioral advertising. Facial Signatures are proprietary, encrypted templates tied only to the Rock system, and cannot be exported for use in other systems.
All rights requests must first be directed to your Solution Owner, who alone has access to and control over your biometric data. If you have questions about this section or need help identifying your Solution Owner, contact us at privacy@alcatraz.ai and legal@alcatraz.ai.





