Privacy policy

This policy covers two groups. Clients are the organisations that hold a Facenition account and call the API. End users are the people whose faces are presented to the service through a client's application. What we hold about each is very different, so both are set out separately.

1. The face, in full

Facenition exists to verify a person without building a biometric database. Because that involves a camera and a face, this section comes before everything else and says exactly what happens.

What happens during a call

What is never stored

This is a property of how the product is built, not only an undertaking about what we choose to keep. Neither we nor anyone who compromised us can produce an image of an end user's face, because none was ever written down. That is the whole point of the design, and it is why a breach of Facenition cannot expose the people who used a client's application.

Consent and the client's role

The camera is opened by the client's application, under wording the client controls. Clients are responsible for having a lawful basis, for telling their end users what is happening, and for offering a workable route through for anyone who cannot or will not present a face.

2. What we collect from clients

Unlike end users, account holders do leave a record with us. It is short.

Registration asks for an email address and a phone number because both are confirmed before an account is issued, one by emailed code and one by text message. That is the only reason a phone number is held.

3. How that information is used

It is not used for advertising, for profiling, or for building any picture of a person beyond running the service they asked for.

4. No sale, no sharing, no third parties

We do not sell, rent, trade or otherwise disclose personal information to anyone. We do not share it with advertisers, data brokers or partners.

There is no third-party analytics on this site or in the service. No Google Analytics, no product analytics, no session recording, no heat maps, no advertising pixels, no social widgets, no error reporting service. There are no behavioural tracking cookies. Cookies are used only where one is needed to operate the service, and for nothing else.

Fonts, scripts and the verification engine are served from infrastructure we operate, so loading a page or making a call does not tell a third party that you were here.

5. How long anything is kept

6. Roles under data protection law

For anything concerning an end user, the client decides why a verification happens and Facenition acts on that client's instructions. The client is responsible for the lawful basis, for informing its own users, and for handling requests from them.

For client account information, Facenition decides how it is handled and is answerable for it directly.

Because no face image and no reusable biometric is stored, there is no biometric record for either party to disclose, correct or erase. There is nothing to hand over, because nothing was kept.

7. Your rights

Subject to the law where you are, you may ask to see the information held about you, correct it, have it deleted, receive a copy, withdraw consent, or object to how it is handled.

End users should approach the organisation whose application asked them to verify, since that organisation holds the account and the token. Clients can contact us directly at the address below.

8. Security

No system connected to the internet can be guaranteed secure, and we do not claim otherwise. What we can say is narrower and more useful: the material people most fear losing in a breach of a face verification service is not held here to lose.

9. Where the service runs

Our servers are located in Australia. Using the service from elsewhere means the information described in this policy is handled there.

10. Legal disclosure

We disclose information only where we are required to comply with the law, to answer a valid legal request, to protect our rights, or to prevent fraud or a threat to safety. In every one of those cases there is no face image and no biometric record to disclose, because none exists.

11. Changes

We may update this policy. Material changes will be posted here and, where appropriate, emailed to account holders.

12. Contact

Facenition
Email: office@facenition.com
Website: facenition.com