1Who this policy is about
biometricQ is a face enrolment and sign-in console operated by [LEGAL ENTITY NAME] (ABN [ABN]), of [POSTAL ADDRESS], referred to in this policy as "we", "us" and "our". This policy covers biometricq.com, dashboard.biometricq.com and api.biometricq.com.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Two different groups of people appear in this policy, and it matters which one you are:
- Administrators. You signed up for a biometricQ console and you sign in to it. Your relationship is with us directly.
- Enrolled people. An organisation using biometricQ enrolled you, or invited you to enrol. That organisation decides why you were enrolled and how long your record is kept. We hold the record on their behalf. If you want your record changed or removed, ask them first, and see section 10 if you cannot reach them.
2Faces, and what actually happens to the photo
What is stored is a face token: a fixed string produced from the face together with the settings chosen at the time. The same person presenting the same face under the same settings produces the same token, which is what makes a later sign-in possible. A different person produces a different token.
A token is one way. It holds no picture and no set of measurements that can be rendered back into a face, and it cannot be fed to another system to find you. If our database were copied tomorrow, nobody would obtain a face from it.
Under Australian privacy law a face token is still sensitive information, because it is biometric information used for identification. We treat it that way. It is collected only with consent, used only for the purpose it was collected for, and deleted on request.
3What we hold about administrators
| Information | Why we hold it |
|---|---|
| Email address and phone number | To identify your account and to send you sign-in codes. Both are required, because sign-in checks both. |
| Name, company and plan | To label the account and to bill it where a paid plan applies. |
| Password | Held only as a one way hash. We never see, store or can recover the password itself. |
| Face token | Only if you chose to add face sign-in. See section 2. |
| API token and client identifier | To let your console talk to the biometric service on your behalf. |
| Sign-in and activity events | Date, time, IP address, browser user agent, what was attempted and whether it succeeded. This is our security record. It is how an intrusion is spotted and how a dispute is settled. |
| Usage counters | Daily totals of verifications, enrolments, emails and texts, for capacity and billing. |
4What we hold about people an organisation enrols
If an organisation invited you to enrol, we hold what they gave us and what you supplied at enrolment:
- Your name, and whichever of your email address and phone number the organisation used to reach you.
- Any group or reference the organisation attached to your record.
- Your face token, if you completed enrolment. Again, no image.
- A record of the consent you gave: what you agreed to, and when.
- Events showing when your record was created, verified, changed or removed.
The organisation that enrolled you is responsible for having a lawful reason to do so, for telling you about it, and for obtaining your consent before your face is captured. We provide the tools to record that consent. We do not decide on their behalf whether the enrolment was appropriate.
5What we use it for
- Creating accounts, and signing administrators in.
- Sending enrolment invitations and sign-in codes.
- Producing and comparing face tokens when you or an enrolled person asks us to.
- Keeping the security and audit record described in section 3.
- Counting usage for capacity planning and billing.
- Answering support requests, and telling you about changes that affect your account or this policy.
We do not use any of it for advertising, for profiling, for training models, or for building any general database of faces or people. We do not use it to identify anyone outside the organisation that enrolled them.
6Who else sees it
We do not sell, rent, trade or otherwise disclose personal information for anyone else's commercial purposes, and we run no third party advertising or analytics on our pages. There is no tracking pixel, no ad network and no behavioural profile.
A short list of service providers necessarily handle information in order to do their job:
| Provider | What reaches them |
|---|---|
| Our email delivery service | Your email address and the content of the message, so that a code or an invitation arrives. |
| Our SMS delivery service | Your phone number and the text of the message, for the numbers we can text. |
| The biometric token service behind biometricQ | The face photo, for the moment it takes to return a token, and the email address and phone number used to register the account. The photo is not retained there either. |
| Our hosting provider | Operates the servers the console and database run on. |
Beyond that, we disclose personal information only where the law requires it, for example a court order or a lawful request from a regulator, or where it is necessary to protect someone from serious harm.
7Where it is held
The biometricQ portal database and the console are hosted in [HOSTING LOCATION, for example Australia]. Some of the delivery providers in section 6 operate overseas, which means an email address or a phone number may be handled outside Australia purely in order to deliver a message to you. We take reasonable steps to ensure any such provider handles the information consistently with the Australian Privacy Principles.
8How long we keep it
- Face photos: not kept at all, not even briefly. See section 2.
- Administrator accounts: for as long as the account is open, and for a reasonable period afterwards where we are required to keep business records.
- Enrolled people: for as long as the organisation that enrolled you keeps your record. They can delete it, and a deletion removes the face token with it.
- Sign-in codes and invitations: minutes and days respectively, after which they expire and are useless.
- Security and audit events: kept long enough to be useful for investigating a security incident, then removed.
9Cookies, and what the console keeps in your browser
biometricQ sets no advertising or tracking cookies. The console keeps a small amount of data in your own browser, which never leaves your device except where noted:
| What | Where and why |
|---|---|
| Your session token | Browser session storage. It is what keeps you signed in, and it disappears when you close the tab. |
| Your theme choice | Local storage, so the console looks the same next time. |
| Your acceptance of this policy and the terms | Local storage, so you are not asked to read them again on this browser. |
Clearing your browser data removes all three. Nothing breaks: you sign in again and read the consent window once more.
10Your rights
You can ask us to:
- Tell you what we hold about you, and where it came from.
- Correct it, if it is wrong or out of date.
- Delete it. Deleting an enrolment removes the face token, and after that the person can no longer be recognised by the system.
- Withdraw consent to face enrolment at any time, which has the same effect as deletion.
Write to privacy@biometricq.com. We will ask a couple of questions to confirm who you are, so that we are not handing someone else's record to a stranger, and we aim to answer within 30 days.
If you were enrolled by an organisation, ask that organisation first. They control your record and can act on it immediately. If they cannot be reached, or you are not satisfied, write to us and we will help.
If you are unhappy with how we handled a privacy matter, tell us first so we can put it right. If you are still unhappy, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
11Security
Sign-in requires an emailed code, and a password, and where enabled a live face. Console sessions are short lived and signed. Passwords are stored only as one way hashes. Traffic runs over HTTPS. Repeated failed attempts are rate limited, and an image challenge sits in front of sign-in so that automated guessing costs the attacker something.
No system is perfectly secure. What we can say is that the thing people most fear losing in a biometric breach, the face itself, is not in our database to lose.
12Children
The biometricQ console is a business tool and is not directed at children. We do not knowingly create administrator accounts for anyone under 18. Where an organisation enrols a person under 18, that organisation is responsible for obtaining consent from a parent or guardian where the law requires it.
13Changes to this policy
If we change this policy we will update the version and date at the top of the page. Where a change materially affects how we handle your information, we will tell administrators by email and ask you to read the consent window again the next time you sign in.
14Contact us
Privacy questions, access requests and complaints: privacy@biometricq.com.
Anything else: support@biometricq.com.
biometricQ
Back to console