presence.tools ← Back
Legal

Biometric Acceptable Use Policy

Last updated: 2 June 2026

This Biometric Acceptable Use Policy ("Biometric AUP") applies to all Customers of Presence Tools who use any feature of the platform that involves the collection, storage or processing of biometric data, including face matching through the FACE challenge type.

This Biometric AUP forms part of and is incorporated into the Presence Tools Terms of Service. By enabling face matching or enrolling biometric data through the Services, you agree to this Biometric AUP.

Special category data. Biometric data used for the purpose of uniquely identifying a natural person is special category data under Article 9 of the UK GDPR. Processing it requires an explicit lawful basis and carries heightened obligations. This policy sets out what Alpaka requires of Customers who process such data through the Presence Tools platform.

1. What this policy covers

This policy applies to the use of the Presence Tools FACE challenge, which compares a live capture against an enrolled reference photograph to produce a confidence score. It covers:

  • the enrolment of reference photographs via the identity API;
  • the submission of live captures during a session;
  • the storage of captured photographs referenced in session results;
  • any downstream use of confidence scores or session data derived from face matching.

2. How Alpaka processes biometric data

2.1 Face matching is performed at the point of session challenge completion. Alpaka compares the live capture against the enrolled reference photograph using computer vision. The result is a numerical confidence score between 0 and 1.

2.2 Alpaka does not retain biometric template data. No facial geometry, face embeddings or derived biometric templates are stored. Captured photographs are stored as object files in AWS S3 and referenced by a key returned in the session result. The Customer controls whether and how long those photographs are retained through project-level data retention settings in the Console.

2.3 Biometric data is processed exclusively within AWS eu-west-1 (Dublin, Ireland). It is not transferred to third parties for any purpose other than the face matching computation itself.

Architectural separation. Identity records and biometric data are architecturally separated. An identity record contains an S3 key reference to the enrolled photograph — not the photograph itself. Session responses contain a confidence score and an S3 key reference to the captured photograph — not the photograph itself. The Customer is the only party that can link the two.

3. Customer obligations

3.1 Lawful basis

You must have a valid lawful basis under Article 9 UK GDPR to process biometric data through the Services before enrolling any reference photograph or initiating a FACE challenge. Acceptable bases include:

  • Explicit consent — the Data Subject has given explicit consent to the processing of their biometric data for a specific purpose.
  • Substantial public interest — processing is necessary for reasons of substantial public interest under Schedule 1 of the Data Protection Act 2018, with an appropriate policy document in place.
  • Employment, social security and social protection — where processing is necessary in the context of employment law and an appropriate policy document is in place.

Alpaka does not prescribe which basis you rely on. You are responsible for determining the appropriate basis and maintaining records of it.

3.2 Transparency

You must provide End Users with a clear and prominent privacy notice before collecting their biometric data. That notice must explain:

  • that their photograph will be captured and used for face matching;
  • the purpose for which presence verification is being carried out;
  • how long their data will be retained;
  • their rights in respect of their biometric data, including the right to withdraw consent where that is the basis relied upon.

3.3 Purpose limitation

You may only use the FACE challenge and resulting data for the purpose of verifying the physical presence of the enrolled individual. You must not:

  • use face matching for surveillance, tracking or monitoring individuals without their knowledge;
  • use confidence scores or session data to infer characteristics about an individual beyond their presence at a given time and place;
  • share captured photographs or session data with third parties for purposes unrelated to the verification for which consent or another lawful basis was obtained;
  • use the Services to build a facial recognition database for general identification purposes.

3.4 Data minimisation and retention

You must configure data retention periods in the Console that are proportionate to the purpose. You should not retain biometric data for longer than is necessary. Where consent is the lawful basis, you must delete an individual's data promptly if they withdraw consent.

3.5 Data subject rights

You must have a mechanism for End Users to exercise their rights under UK GDPR, including the right to access the data held about them, the right to rectification, and the right to erasure. The Presence Tools API provides endpoints to delete identity records and session data; you are responsible for using them in response to valid Data Subject requests.

3.6 Data Protection Impact Assessment

Processing biometric data is likely to constitute high-risk processing under Article 35 UK GDPR. You are responsible for carrying out and documenting a Data Protection Impact Assessment (DPIA) prior to commencing biometric processing through the Services, where required by applicable law.

4. Prohibited uses

The following uses of the FACE challenge and biometric capabilities are expressly prohibited:

  • verifying the presence of individuals without their knowledge or without a lawful basis;
  • processing biometric data of children under 13 without verified parental consent;
  • using face matching to discriminate on the basis of race, ethnicity, religion, disability or any other protected characteristic;
  • attempting to identify anonymous individuals or to de-anonymise data sets;
  • using the Services in connection with law enforcement, border control, or public surveillance without explicit regulatory authorisation;
  • attempting to reverse-engineer, extract or reconstruct biometric templates from the API or its responses.

5. Security

5.1 You are responsible for the security of your API keys and project credentials. Compromised credentials must be rotated immediately via the Console.

5.2 You must not transmit captured photographs or S3 keys referenced in session results to unauthorised third parties.

5.3 You must report any suspected breach of biometric data to Alpaka at hello@presence.tools without undue delay.

6. Consequences of breach

Breach of this Biometric AUP constitutes a material breach of the Terms of Service. Alpaka reserves the right to suspend or terminate access to the FACE challenge or to the Services as a whole where a Customer is found to be in breach of this policy, without prejudice to any other remedy available to Alpaka.

7. Changes to this policy

Alpaka may update this Biometric AUP from time to time to reflect changes in law, technology or best practice. Notice of material changes will be provided via the Console or by email. Continued use of the FACE challenge after notice of a change constitutes acceptance of the updated policy.

8. Contact

For questions about this policy or biometric data processing, contact Alpaka at hello@presence.tools.

presence.tools
Powered by Alpaka
  • Console
  • About
  • Terms
  • Privacy
  • DPA
  • Biometric AUP
  • Contact