Trust

This product does not use biometrics — and it is not offered as an option either

Most school access products count fingerprints as a feature. We write it down as the product's refusal: there is no field in the schema, the endpoint rejects it and the adapter drops it.

The three layers of the refusal

The canonical event defines no field carrying a fingerprint, face vector or template; a field that does not exist cannot be filled.

A request carrying a biometric field in its body is not accepted and is returned with its reason.

If the panel emits biometric events, the connector drops those fields before they reach us and writes the drop into its ledger.

Why

The board does not treat consent as freely given, because of the power imbalance between school and parent, and between employer and employee.

Converting biometric data into a mathematical code does not remove its status as special category personal data.

If the data is still reachable, processing is considered to continue; turning the system off is not enough.

Card numbers never travel raw

The card number travels as a salted digest scoped to the institution; the same card does not produce the same value in two institutions and the number cannot be derived back from the records.

Who owns the data

If the institution chooses the cloud, the data sits on infrastructure we operate and the institution can export it at any time; the data is still theirs, we are the processor.

Retention and destruction

The institution sets the retention period and the record is destroyed when it expires. Destruction means actual deletion; deactivation does not count as destruction.

Audit trail

Who changed what and when is written down and cannot be edited retroactively. When an attendance row is corrected, the old value is not lost.

Anonymity in internal reports

Density, occupancy and absence reports are produced over totals, not at the level of individuals.

A parent sees only their own child

When another student's record is requested the product says no record was found. Even saying you are not authorised reveals that the record exists; we do not write leaking messages.