Introduction
This Privacy Policy describes how Innovantics LTD ("Innovantics," "we," "our," or "us") collects, uses, and protects personal data in connection with the Bifense biometric verification platform ("Platform") and our website at bifense.com.
Innovantics LTD is the data controller for personal data processed through our website and marketing activities. When processing biometric data on behalf of our customers, Innovantics LTD acts as a data processor under the terms of our Data Processing Agreement.
By using our Platform or website, you acknowledge that you have read and understood this Privacy Policy.
Data We Collect
Account information
When you create an account, we collect your name, email address, organisation name, and billing information. This data is necessary to provide our services and manage your account.
Usage data
We collect information about how you interact with our Platform, including API call logs, feature usage patterns, and performance metrics. This data helps us maintain and improve our services.
Technical data
We automatically collect technical information such as IP addresses, browser type, device information, and access timestamps for security and operational purposes.
Biometric data
When our customers use the Platform for biometric verification, we process facial images and biometric templates on their behalf. This data is processed strictly in accordance with our customer agreements and applicable law. See the dedicated Biometric Data section below.
How We Use Data
We process personal data for the following purposes:
- Providing, maintaining, and improving the Bifense platform
- Processing biometric verification requests on behalf of our customers
- Managing accounts, billing, and customer support
- Detecting and preventing fraud, abuse, and security incidents
- Complying with legal obligations and regulatory requirements
- Communicating service updates and relevant product information
Biometric Data
Biometric data is classified as a special category of personal data under GDPR and similar regulations. We apply heightened protections to this data:
- Biometric data is processed only as instructed by our customers (the data controllers) and only for the specific purposes defined in the service agreement
- Original biometric images are processed in memory and converted to mathematical templates; raw images are not persisted unless explicitly configured by the customer
- Biometric templates are encrypted using per-tenant encryption keys and stored in isolated, access-controlled environments
- No biometric data is shared across tenants, used for training purposes, or processed for any purpose beyond the scope of the customer agreement
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
- Account data: retained for the duration of the account relationship plus any legally required retention period
- Biometric data: retained according to the retention schedule configured by the customer, subject to regulatory minimums
- Audit logs: retained for a minimum of 12 months for security and compliance purposes
When data reaches the end of its retention period, it is securely deleted using cryptographic erasure or secure overwrite methods.
Your Rights
Under applicable data protection laws, including the GDPR, you may have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: request correction of inaccurate personal data
- Right to erasure: request deletion of your personal data, subject to legal retention obligations
- Right to restrict processing: request that we limit how we process your data
- Right to data portability: receive your data in a structured, machine-readable format
- Right to object: object to processing based on legitimate interests
To exercise any of these rights, contact us at privacy@innovantics.com. We will respond within 30 days.
If your biometric data was processed through a Bifense customer, please direct your request to that organisation as the data controller. We will assist them in fulfilling your request.
Third Parties
We may share personal data with the following categories of third parties, only to the extent necessary:
- Infrastructure providers: cloud hosting and infrastructure services that process data on our behalf under strict contractual obligations
- Payment processors: for billing and subscription management
- Legal and regulatory bodies: where required by law, court order, or regulatory request
We do not sell personal data. We do not share biometric data with third parties except as necessary to provide the Platform services to our customers.
Contact Information
For any questions about this Privacy Policy or our data practices, please contact us:
You also have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been infringed.