GDPR and data protection
A summary of how Dheeram Innovations Private Limited (Cams Biometrics) handles personal and biometric data on the Biometric Gateway. It restates our privacy policy; where the two differ, the privacy policy applies.
Our role: processor, not controller
- For biometric data captured by your devices, Dheeram Innovations acts as a data processor providing technical infrastructure.
- The organisations that deploy the devices and receive the data are independent data controllers. They give end users notice, obtain consent, decide the purpose, set retention schedules and handle end-user requests.
- We do not collect consent from end users and do not decide why biometric data is collected.
- We help clients with deletion and data-subject access requests on their instruction.
No permanent storage of raw biometric data
- The Gateway is a pass-through: devices send transactions to the Gateway, and the Gateway forwards them to the callback URL the client sets.
- Raw biometric templates are never stored on our servers, and the Gateway does not cache them.
- Templates travel only over encrypted channels and are stored encrypted on the devices and on client servers.
- Access to biometric transaction logs is controlled and audited, and biometric data is kept separate from other system data.
Retention on the Gateway
| Data | Kept for | Purpose |
|---|---|---|
| Transaction queue | Until delivered, at most 30 days | Reliable delivery to client servers |
| Device metadata | Duration of the service relationship | Device management and licensing |
| Transaction logs | 90 days (configurable per client) | Troubleshooting and analytics |
| Connection logs | 30 days | Monitoring and diagnostics |
| Error logs | 180 days | Technical support and system improvement |
Security measures
- TLS encryption in transit and AES-256 encryption at rest.
- Multi-factor authentication, role-based access control and least-privilege access.
- Firewalls, intrusion detection, 24/7 security monitoring and audit logging of access to sensitive data.
- MCP (AI agent) requests require authentication; sensitive data is filtered before it reaches AI agents, and AI interactions are logged.
Breach notification
If a breach affects personal or biometric data, we investigate and contain it, notify affected users within 72 hours of discovery, and report it to the relevant regulatory authorities as the law requires.
Your rights
- Access your personal data and receive a copy in a structured, machine-readable format.
- Correct inaccurate data.
- Ask us to delete your account and personal data, device records and AI interaction logs (some records may be kept where the law requires).
- Restrict or object to processing, and withdraw consent (marketing, optional analytics, MCP/AI agent access) at any time.
- We respond within 30 days and may need to verify your identity. Write to compliance@camsbiometrics.com.
End users of a client's devices should send requests to that organisation, which controls their data; we support the client in answering them.
International transfers
Our application and engine servers are dedicated servers from netcup and Server4You in the EU region. Customer data copied out of them for backup is fully masked with dummy values before our team accesses it. Our engineering team, based in India, has access to these servers for operations and support and works in a secured environment.
Our services are operated from India, and data may be processed in India or in other countries where we or our service providers operate. Section 11 of the privacy policy lists the safeguards we use for international transfers, including Standard Contractual Clauses.
Other laws named in our policy
Besides the GDPR rules for special-category data, the policy names India's Digital Personal Data Protection Act (DPDPA), the Illinois BIPA, the Texas CUBI Act and the biometric provisions of the CCPA.
Full details: privacy policy (sections 6, 8, 9, 11 and 13). Data-processing questions: compliance@camsbiometrics.com.