Legal
Privacy Policy
How the TrustVision eKYC/FA app collects, uses and retains the images, face vectors and device data it processes on behalf of our clients.
Effective 8 April 2020 — privacy practices specific to Service Data.
Overview
Our facial recognition service (the “Service”) allows our clients (“End Users”) to check image quality, check liveness, and match face images as part of their KYC process. Clients use the Service at the point of sale to onboard customers in highly regulated industries such as banking, financial services and telecommunications — matching faces between selfies and ID cards, checking liveness, and extracting ID details through OCR.
We require Partners to use the following approach when deploying the Service:
- It requires the customer’s explicit consent.
- To use the Service, the End User takes a photo of their customer.
- The Partner does not provide us with the individual’s name, contact information or username as part of this process.
- We scan the photo to create a vectorized customer image (Face Index) — a unique collection of measurements of the face, used to compare against faces in another photo or video.
- If photo quality is insufficient, the Service offers an opportunity to submit a better photo.
- All face images collected can be deleted in a period determined by the End User.
Types of Service Data
The Service handles the following types of data:
Captured from the customer
- Selfies submitted through the app.
- ID card images submitted through the app.
- Face vectors created from those photos.
- Matching scores.
- Information extracted from the ID card.
Device and app metadata
- Handphone type.
- Device ID.
- App ID.
Uses and disclosures of Service Data
Subject to our contractual obligations to Channel Partners and End Users, we use Service Data as follows:
- To provide the Service — face matching, face authentication, ID OCR and liveness checking for customer onboarding, KYC and underwriting.
- To improve the Service.
- To enforce the legal terms that govern the Service.
- For other purposes authorized by the client or their representative (usually a Channel Partner or Registration Provider).
We do not share data with third parties.
Personal data rights and choices
We allow clients to request deletion of all test face and ID data sent to us, on request or at a specified period from the point of testing. Contact your Account Manager to determine how long data should be stored for audit or testing purposes.
Security and data retention
To manage data security risks we maintain physical, organizational and technical safeguards, which are subject to periodic change. We hold information for as long as necessary to fulfil the purposes set out in this Privacy Policy, or as long as we are legally required or permitted to do so. Information may persist in copies made for backup and business continuity purposes for longer than the original data.
International data transfers
We are based in Singapore, and recipients of the data disclosures described in this Privacy Policy are located in Singapore and elsewhere in the world, including where privacy laws may not provide as much protection as the country in which you are located. Where applicable, we comply with legal requirements for cross-border data protection.
Notification of changes
Trusting Social may change this Privacy Policy to reflect changes in the law, our data handling practices, or the features of our business.
The current version of this policy is always posted at ekyc.trustingsocial.com/privacy-policy.