Biometric Data Notice

Last updated: 2026-06-18

Draft template, pending legal review. This is not legal advice.

This notice explains how we process your biometric data (facial images and features) for identity verification. Biometric data is a special category of data and is processed only on the basis of your explicit consent.

What biometric data we collect

  • Facial images captured during identity verification (KYC) and during the "liveness" check (proof that you are a real, present person).
  • Derived facial features, used to compare your face against the reference photo.

Why

  • To confirm you are the enrolled person (anti-fraud).
  • To keep participation and the learning-time records required by your employer trustworthy.

Legal basis

Explicit consent under Art. 9(2)(a) GDPR. Processing does not start without your agreement, given separately from the other terms.

Who processes the data

Face verification is performed by Amazon Web Services (Rekognition) in an EU region, and document verification by Didit, both acting as processors under our instructions. Images are stored securely (encrypted).

How long we keep it

The reference image and captures are kept only as long as needed for verification and for the compliance evidence required by your employer: [BIOMETRIC RETENTION PERIOD]. After expiry they are deleted or anonymised.

Withdrawing consent

You can withdraw consent at any time by writing to [EMAIL CONTACT / CONTACT EMAIL]. Note that, without biometric verification, you will not be able to access features that require a verified identity; your employer may require an alternative method.

No other uses

We do not use your biometric data for other purposes (e.g. surveillance, advertising) and we do not sell it.