Children’s biometric data, handled carefully.

Recognition means holding data about people, and about children in particular, so how it is captured, stored, kept apart from other customers, exported and destroyed matters more than any feature on this site. The short version: matching happens on your own hardware, and no photos leave your site. This page is written for schools because that is the strictest case; every commitment on it applies to staff and visitor data at a business too.

Matched on your hardware. No photos leave the school.

This is the commitment the rest of the page rests on, and it is the one DYCH states plainly in its own materials: all face data is matched and encrypted on-device, and no photos ever leave the school. Recognition happens on a unit on your site, not on a server somewhere else, so there is no upload of children’s faces to anywhere.

Enrolment does not keep a photograph
It produces a mathematical template used for matching, and the template is what the system holds. It exists to recognise a pupil at an entry point and to mark a register, and it is not put to any other purpose.
What is actually held
A matching template derived from the face, the pupil record the school already keeps, and the entry and exit events that matching produces. Face images are stored in a folder the school chooses on its own machine.
What it is never used for
It is not sold, not shared with advertisers, and not used to build or improve anything for another customer.
Why this also makes the gate more reliable
Because matching does not depend on a round trip to a distant server, the gate keeps reading through an internet outage. The privacy decision and the reliability behaviour are the same decision.

What enrolment produces, and what it does not.

The commitment above rests on a distinction worth seeing rather than taking on trust.

  1. 1A face is found

    The camera takes a frame and locates the face in it. At this point nothing has been identified - the system knows only that a face is there.

  2. 2Its geometry is measured

    The distances and angles between landmarks - the corners of the eyes, the nose, the mouth - are measured. The measurements are what matter; the picture they came from is not kept.

  3. 3Numbers are what is stored

    Those measurements become the template: a string of numbers held on the unit at your gate. It can be compared against a face at the gate. It cannot be turned back into one.

Enrolment is arranged between the school and the guardian, not between DYCH and the family. A school should hold recorded consent for every pupil before a template is created, and should be able to act on a withdrawal the same day it arrives.

Consent comes first
A pupil is enrolled after the school records the guardian’s agreement, not before it.
Withdrawing it costs the pupil nothing
The school deletes the template from the console, and attendance for that pupil continues by card or by the class teacher. No child is shut out of school for being withdrawn from recognition.
Who can enrol
Named staff accounts only, and every enrolment is written to a log the school can read. That log is filterable and exports to a spreadsheet, so it is evidence rather than a screen someone has to sit and watch.
A parent account sees nothing until you say so
Parents register themselves, and then wait. Until an administrator approves the account it can sign in and see no pupil data at all - not their own child's. Approval is a deliberate act by a named member of staff, not something that happens because a form was filled in correctly.
Sessions do not stay open forever
An idle dashboard signs itself out on a timeout the school sets, and no session survives past eight hours whatever that timeout says. Opening the account and permissions screen asks for the password again even mid-session.

Faces the system does not know

A recognition system has to do something when it sees somebody it has never seen. Ours can be told to remember them, and that setting is off unless a school turns it on deliberately.

What the setting actually does
With visitor auto-registration on, a face that is unrecognised and stays in view long enough is saved as a numbered placeholder, so the same person is recognised as the same person on a return visit. No name is attached. A member of staff can give it one later, or leave it.
What it deliberately does not do
It does not mark attendance for that person, and it does not notify any parent. It is a record that somebody came back, not an accusation and not a register entry.
The school sets the thresholds, and cannot forget it is on
How similar a return sighting must be, how long a face must be in view before it is kept, and how many days it is kept for are all yours to set. While the feature is enabled a warning banner stays visible on every gate screen, which is deliberate: a setting this consequential should not be quietly on.
Our recommendation
Leave it off unless there is a specific reason. A school that wants to know about repeat unknown visitors at the gate has a real use for it; a school that just wants attendance does not, and should not be holding face records for people who are not part of the school.

Isolation between schools

One school’s records are not visible to another. A deployment is scoped to the school that owns it, and there is no shared roll across customers that anyone could query.

No pooled register
Templates and pupil records belong to one school. They are not combined into a wider index.
Accounts are scoped
A staff account reaches its own school and nothing beyond it.
Support access is visible
Where our staff need access to diagnose a fault, it is requested from the school and recorded, rather than standing open.

Export and deletion

The records are the school’s, not ours. A school can take them out in a form it can actually use, and can require that our copies be destroyed.

Taking the records out
Attendance, entry logs and gate records export in a readable format, without a request to us and without a charge.
Ending a contract
On request we delete the school’s data and confirm in writing what was removed and when.
A single pupil leaving
A leaver’s template can be destroyed while the attendance record the school is required to keep stays intact.

Uptime and offline resilience

A system that stops when the connection does is worse than paper, because staff stop trusting it. The gate keeps reading and the register keeps writing through an outage.

Local first
Entry events are written on site as they happen, not queued in the hope of a connection.
Catching up
When connectivity returns, records synchronise on their own. Nobody re-keys a morning.
Power
Battery backup at the entry point, so a cut does not leave a gate that cannot tell anyone who came through it.

Questions worth putting to us, and to anyone else.

If a supplier cannot answer these plainly, that is worth knowing before a single camera goes up. Ask us at a site assessment and hold us to the answers.

  1. Where is the matching performed, and what happens to recognition when our connection is down?

  2. What exactly is stored for each pupil, and can you show us one record end to end?

  3. How do we withdraw a pupil from recognition, and what does that pupil’s day look like afterwards?

  4. If we leave, what do we get back, in what format, and how do you prove your copies are gone?

  5. Who at your company can see our data, under what circumstances, and where is that recorded?

  6. Does the system ever record a face belonging to someone who is not enrolled, and if so, who switched that on and when does it expire?

Bring your data protection questions to the site assessment.

We would rather answer them in front of your board than after an installation. A site assessment costs nothing and ends with a written scope.