presence.tools ← Back
Legal

Privacy Policy

Last updated: 2 June 2026

This Privacy Policy explains how Alpaka Ltd, a company incorporated in England and Wales under company number 10461680 whose registered office is at 6 The Leys, Northampton, NN2 6QZ ("Alpaka", "we", "us" or "our"), handles personal data in connection with the Presence Tools platform.

Presence Tools is designed with separation of data as a core architectural principle. This policy explains what that means in practice and how it affects the privacy of the different people whose data flows through the platform.

1. How this policy is structured

There are three distinct groups of people whose data we process, in different ways and for different purposes:

  • Developers and customers - individuals who create and manage a Presence Tools account, build integrations, and use the developer console.
  • End Users - individuals whose physical presence is verified through sessions created by a customer. Their data is controlled by the customer, not by Alpaka.
  • Website visitors - people who visit presence.tools without signing up.

This policy covers all three groups. Where Alpaka processes End User data on behalf of a customer, Alpaka acts as processor and the customer acts as controller. End Users with questions about their data should contact the organisation that ran their presence verification session in the first instance.

2. Contact

For any questions about this policy or how we handle personal data:

Alpaka Ltd
6 The Leys, Northampton, NN2 6QZ
Email: hello@presence.tools

3. Developer and customer accounts

What we collect

When you sign up for a Presence Tools account, we collect:

  • your email address, used to authenticate your account via Clerk;
  • your name, if you provide it;
  • billing and payment information, processed by Stripe on our behalf;
  • account activity and API usage data, for quota tracking, billing, support and security.

Minimal account data by design. We do not require you to provide a phone number, postal address, or any information beyond what is needed to operate your account and process payment. Authentication is handled by Clerk, which means we do not store your password.

Lawful basis

PurposeLawful basis
Account creation, authentication and managementPerformance of a contract
Billing, invoicing and payment processingPerformance of a contract; legal obligation
API usage monitoring, quota enforcement, rate limitingPerformance of a contract; legitimate interests
Security monitoring and incident responseLegitimate interests; legal obligation
Product communications and service noticesPerformance of a contract; legitimate interests
Improving the platformLegitimate interests

Retention

We retain account data for the duration of your account and for a reasonable period thereafter for legal, accounting and support purposes. API logs are retained for up to 90 days for security and debugging purposes.

4. End User data

End Users are the people whose physical presence is verified through the Presence Tools API. Their data is submitted by customers - the businesses and developers who build on our platform. Alpaka processes this data as a processor, under the customer's instructions.

The separation principle

Identity and biometrics are architecturally separated. An identity record in Presence Tools contains only what the customer chooses to include - typically a name, an email address, and optionally a reference to an enrolled photo. The photo itself is stored in isolated object storage (AWS S3) and is referenced only by a key. At no point does a session response contain raw biometric data - it contains a confidence score and a storage key. The two can only be linked by the customer who created them.

What End User data looks like

An identity record may contain:

  • a customer-assigned external reference (typically the customer's own internal ID);
  • a name and optionally an email address or mobile number;
  • a reference to an enrolled photo, stored as an S3 object key - not the photo itself;
  • a PIN or password hash for challenge purposes, if set by the customer.

A completed session record contains:

  • the session ID, event ID, and identity ID;
  • the challenges completed, with pass/fail, timestamp, and for GEO challenges, the coordinates and distance;
  • for FACE challenges, a confidence score and an S3 key pointing to the photo captured during the session - not the photo itself in the response payload;
  • no raw biometric data is returned through the API.

Biometric data

Face match processing uses computer vision to compare a live capture against an enrolled reference photo. This processing is transient - it occurs at the point of challenge completion and the result is a numerical confidence score. Alpaka does not retain biometric template data derived from face images. Captured photos are stored at the S3 key returned in the session result and are subject to the data retention period configured by the customer for that project.

Customer control

Customers configure data retention on a per-project basis in the Console. When the retention period expires, identity records and associated session data are deleted. Customers can also delete individual identity records or sessions via the API at any time.

Alpaka's role

For End User data, Alpaka is a processor. We do not use End User data for our own purposes, do not sell it, do not analyse it for advertising, and do not share it with third parties except as necessary to operate the infrastructure (AWS) or comply with a legal obligation.

The customer who created the identity and the event is the data controller for End User data. End Users who wish to exercise their rights - access, erasure, rectification, restriction - should contact the organisation that ran their session.

5. Website visitors

When you visit presence.tools without signing up, we collect standard server log data (IP address, browser type, pages visited, referrer) for security and operational purposes. We do not use third-party analytics trackers or advertising cookies on the marketing site.

6. Subprocessors and hosting

We use the following categories of subprocessors:

  • AWS (eu-west-1, Dublin) - all Customer Data, including identity records, session data, and captured photos, is hosted in AWS eu-west-1. No Customer Data is transferred outside the EU/EEA for storage purposes.
  • Clerk - developer account authentication. Clerk processes your email address and authentication state on our behalf.
  • Stripe - payment processing for paid plans. Stripe processes billing and card data on our behalf.

We do not sell personal data. We do not share Customer Data or End User data with advertising networks or data brokers.

7. Security

Presence Tools is built on AWS and uses standard cloud security practices including encryption at rest and in transit, IAM-based access controls, and isolated storage per project. API access requires both a project JWT and an API key. Developer console access is authenticated via Clerk.

No internet service can be guaranteed completely secure. You are responsible for the security of your API keys and project credentials.

8. Your rights

If you are a developer or customer, you have the following rights under UK GDPR in respect of the personal data we hold about you as controller:

  • the right to access your personal data;
  • the right to correct inaccurate data;
  • the right to erasure (the "right to be forgotten");
  • the right to restrict processing;
  • the right to object to processing based on legitimate interests;
  • the right to data portability;
  • the right to lodge a complaint with the Information Commissioner's Office (ICO).

To exercise any of these rights, contact us at hello@presence.tools.

If you are an End User whose presence was verified through the platform, your rights should be exercised with the organisation that ran your session. Alpaka can direct requests to the relevant customer where necessary.

9. Changes to this policy

We may update this Privacy Policy from time to time. The latest version will always be available at presence.tools/privacy.html with its effective date. Continued use of the Services after a material change constitutes acceptance of the updated policy.

presence.tools
Powered by Alpaka
  • Console
  • About
  • Terms
  • Privacy
  • DPA
  • Biometric AUP
  • Contact