This Privacy Policy explains how Alpaka Ltd, a company incorporated in England and Wales under company number 10461680 whose registered office is at 6 The Leys, Northampton, NN2 6QZ ("Alpaka", "we", "us" or "our"), handles personal data in connection with the Presence Tools platform.
Presence Tools is designed with separation of data as a core architectural principle. This policy explains what that means in practice and how it affects the privacy of the different people whose data flows through the platform.
There are three distinct groups of people whose data we process, in different ways and for different purposes:
This policy covers all three groups. Where Alpaka processes End User data on behalf of a customer, Alpaka acts as processor and the customer acts as controller. End Users with questions about their data should contact the organisation that ran their presence verification session in the first instance.
For any questions about this policy or how we handle personal data:
Alpaka Ltd
6 The Leys, Northampton, NN2 6QZ
Email: hello@presence.tools
When you sign up for a Presence Tools account, we collect:
Minimal account data by design. We do not require you to provide a phone number, postal address, or any information beyond what is needed to operate your account and process payment. Authentication is handled by Clerk, which means we do not store your password.
| Purpose | Lawful basis |
|---|---|
| Account creation, authentication and management | Performance of a contract |
| Billing, invoicing and payment processing | Performance of a contract; legal obligation |
| API usage monitoring, quota enforcement, rate limiting | Performance of a contract; legitimate interests |
| Security monitoring and incident response | Legitimate interests; legal obligation |
| Product communications and service notices | Performance of a contract; legitimate interests |
| Improving the platform | Legitimate interests |
We retain account data for the duration of your account and for a reasonable period thereafter for legal, accounting and support purposes. API logs are retained for up to 90 days for security and debugging purposes.
End Users are the people whose physical presence is verified through the Presence Tools API. Their data is submitted by customers - the businesses and developers who build on our platform. Alpaka processes this data as a processor, under the customer's instructions.
Identity and biometrics are architecturally separated. An identity record in Presence Tools contains only what the customer chooses to include - typically a name, an email address, and optionally a reference to an enrolled photo. The photo itself is stored in isolated object storage (AWS S3) and is referenced only by a key. At no point does a session response contain raw biometric data - it contains a confidence score and a storage key. The two can only be linked by the customer who created them.
An identity record may contain:
A completed session record contains:
Face match processing uses computer vision to compare a live capture against an enrolled reference photo. This processing is transient - it occurs at the point of challenge completion and the result is a numerical confidence score. Alpaka does not retain biometric template data derived from face images. Captured photos are stored at the S3 key returned in the session result and are subject to the data retention period configured by the customer for that project.
Customers configure data retention on a per-project basis in the Console. When the retention period expires, identity records and associated session data are deleted. Customers can also delete individual identity records or sessions via the API at any time.
For End User data, Alpaka is a processor. We do not use End User data for our own purposes, do not sell it, do not analyse it for advertising, and do not share it with third parties except as necessary to operate the infrastructure (AWS) or comply with a legal obligation.
The customer who created the identity and the event is the data controller for End User data. End Users who wish to exercise their rights - access, erasure, rectification, restriction - should contact the organisation that ran their session.
When you visit presence.tools without signing up, we collect standard server log data (IP address, browser type, pages visited, referrer) for security and operational purposes. We do not use third-party analytics trackers or advertising cookies on the marketing site.
We use the following categories of subprocessors:
We do not sell personal data. We do not share Customer Data or End User data with advertising networks or data brokers.
Presence Tools is built on AWS and uses standard cloud security practices including encryption at rest and in transit, IAM-based access controls, and isolated storage per project. API access requires both a project JWT and an API key. Developer console access is authenticated via Clerk.
No internet service can be guaranteed completely secure. You are responsible for the security of your API keys and project credentials.
If you are a developer or customer, you have the following rights under UK GDPR in respect of the personal data we hold about you as controller:
To exercise any of these rights, contact us at hello@presence.tools.
If you are an End User whose presence was verified through the platform, your rights should be exercised with the organisation that ran your session. Alpaka can direct requests to the relevant customer where necessary.
We may update this Privacy Policy from time to time. The latest version will always be available at presence.tools/privacy.html with its effective date. Continued use of the Services after a material change constitutes acceptance of the updated policy.