This Biometric Acceptable Use Policy ("Biometric AUP") applies to all Customers of Presence Tools who use any feature of the platform that involves the collection, storage or processing of biometric data, including face matching through the FACE challenge type.
This Biometric AUP forms part of and is incorporated into the Presence Tools Terms of Service. By enabling face matching or enrolling biometric data through the Services, you agree to this Biometric AUP.
Special category data. Biometric data used for the purpose of uniquely identifying a natural person is special category data under Article 9 of the UK GDPR. Processing it requires an explicit lawful basis and carries heightened obligations. This policy sets out what Alpaka requires of Customers who process such data through the Presence Tools platform.
This policy applies to the use of the Presence Tools FACE challenge, which compares a live capture against an enrolled reference photograph to produce a confidence score. It covers:
2.1 Face matching is performed at the point of session challenge completion. Alpaka compares the live capture against the enrolled reference photograph using computer vision. The result is a numerical confidence score between 0 and 1.
2.2 Alpaka does not retain biometric template data. No facial geometry, face embeddings or derived biometric templates are stored. Captured photographs are stored as object files in AWS S3 and referenced by a key returned in the session result. The Customer controls whether and how long those photographs are retained through project-level data retention settings in the Console.
2.3 Biometric data is processed exclusively within AWS eu-west-1 (Dublin, Ireland). It is not transferred to third parties for any purpose other than the face matching computation itself.
Architectural separation. Identity records and biometric data are architecturally separated. An identity record contains an S3 key reference to the enrolled photograph — not the photograph itself. Session responses contain a confidence score and an S3 key reference to the captured photograph — not the photograph itself. The Customer is the only party that can link the two.
You must have a valid lawful basis under Article 9 UK GDPR to process biometric data through the Services before enrolling any reference photograph or initiating a FACE challenge. Acceptable bases include:
Alpaka does not prescribe which basis you rely on. You are responsible for determining the appropriate basis and maintaining records of it.
You must provide End Users with a clear and prominent privacy notice before collecting their biometric data. That notice must explain:
You may only use the FACE challenge and resulting data for the purpose of verifying the physical presence of the enrolled individual. You must not:
You must configure data retention periods in the Console that are proportionate to the purpose. You should not retain biometric data for longer than is necessary. Where consent is the lawful basis, you must delete an individual's data promptly if they withdraw consent.
You must have a mechanism for End Users to exercise their rights under UK GDPR, including the right to access the data held about them, the right to rectification, and the right to erasure. The Presence Tools API provides endpoints to delete identity records and session data; you are responsible for using them in response to valid Data Subject requests.
Processing biometric data is likely to constitute high-risk processing under Article 35 UK GDPR. You are responsible for carrying out and documenting a Data Protection Impact Assessment (DPIA) prior to commencing biometric processing through the Services, where required by applicable law.
The following uses of the FACE challenge and biometric capabilities are expressly prohibited:
5.1 You are responsible for the security of your API keys and project credentials. Compromised credentials must be rotated immediately via the Console.
5.2 You must not transmit captured photographs or S3 keys referenced in session results to unauthorised third parties.
5.3 You must report any suspected breach of biometric data to Alpaka at hello@presence.tools without undue delay.
Breach of this Biometric AUP constitutes a material breach of the Terms of Service. Alpaka reserves the right to suspend or terminate access to the FACE challenge or to the Services as a whole where a Customer is found to be in breach of this policy, without prejudice to any other remedy available to Alpaka.
Alpaka may update this Biometric AUP from time to time to reflect changes in law, technology or best practice. Notice of material changes will be provided via the Console or by email. Continued use of the FACE challenge after notice of a change constitutes acceptance of the updated policy.
For questions about this policy or biometric data processing, contact Alpaka at hello@presence.tools.