Privacy Policy
How Payface collects, uses, and protects your personal and biometric data on the Payface and Fortface platforms.
Payface (Payface Instituição de Pagamento S.A. and its affiliates, collectively "Payface," "we," "us," or "our") is committed to protecting your privacy and your personal data. This Privacy Policy describes how your personal data may be used on the Payface and Fortface platforms.
1. What is the Payface Platform?
The Payface and Fortface platforms are a suite of technologies and services that enable biometric facial authentication for payments and identity verification, including but not limited to: liveness detection (verifying that a real person is present in front of the camera, not a photo or video), 1:1 facial validation (comparing the captured face against a single reference image), 1:N identification (comparing the captured face against a database of images), anti-injection technologies, and image-capture SDKs.
When you transact with a retailer or business that uses our services, Payface generally acts as a data processor on behalf of that business. In those cases, the business's own privacy policy governs how your data is handled. In some scenarios — such as when you access our pages or use the platform in demo or test mode — Payface may act as a data controller, as described in this policy.
2. What personal data do we collect and how?
Depending on the context, we may collect the following categories of personal data:
- Usage data, collected automatically: IP address, date, time, content accessed, and duration of access on our pages or platform.
- Device data, collected automatically: operating system, hardware model, geolocation, gyroscope, VPN usage, and battery level.
- Identification data, provided by you or by the business using the platform: full name, government-issued ID numbers, and similar identifiers.
- Biometric data, provided by you or by the business using the platform: facial photographs and biometric templates.
- Identity document copies, such as a driver's license or passport, provided by you or the business using the platform.
We recognize that biometric data requires heightened care given its sensitivity. We apply enhanced security measures for this data, including encryption in transit and stricter access controls.
3. Do we process data of minors?
Payface may process personal data of minors when the business using the Fortface platform requires identification or authentication in the context of its own products or services. Such processing is always carried out in the best interest of the minor, and parents or legal guardians may exercise the rights described in Section 8 on behalf of the child or adolescent.
4. For what purposes do we use personal data?
| Purpose | Data categories used |
|---|---|
| Access and usage records. Some data is collected when you access and use our pages or platform. These records support compliance with legal and regulatory obligations. | Usage data; Device data |
| Biometric identification and authentication. Your data may be used to identify you in a database and to authenticate your access to a service or function, ensuring security and preventing fraud. | Identity document copies; Identification data; Biometric data; Device data |
| Algorithm training. We may use certain information to train our facial recognition algorithms and technologies, improving platform accuracy and reliability. | Identity document copies; Identification data; Device data; Biometric data |
| Audit and fraud prevention. We store records of each authentication session to support internal or external audits, correct operational issues, and prevent fraud attempts. | Usage data; Device data; Identity document copies; Identification data; Biometric data |
| Business intelligence. Your data may be used in aggregated form to improve or develop our services. Where possible, this data is anonymized so that you are no longer identifiable. | Usage data; Device data; Identity document copies; Identification data; Biometric data |
5. Do we use cookies or other tracking technologies?
Cookies are small text files stored on your browser or device. They allow us to recognize your preferences and adapt our pages to your needs. Some information is saved in these files so that, when you revisit our pages, your browser is recognized and configured according to your previous preferences.
We may use the following types of cookies:
- Strictly necessary cookies, required for our pages to function correctly (such as authenticating logins). These cannot be refused if you intend to continue using our pages.
- Analytics cookies, to understand how our pages are used and improve content and user experience.
- Functionality cookies, to remember previously provided information (such as language preferences) and improve navigation.
You can manage or remove cookies through your browser settings. For instructions, refer to the documentation for your browser (e.g., Firefox, Chrome, Safari, Microsoft Edge).
We are not responsible for the use of cookies by third parties. Third-party cookies may continue to monitor your online activity; we recommend regularly managing the cookies installed in your browser.
6. With whom may your personal data be shared?
To provide our services, your personal data may be shared with third parties, including:
- Service providers. We work with vendors who support our operations (such as legal firms, software providers, and solution developers). We share data only as necessary for their services and require them to comply with data security and privacy obligations.
- Retailers and resellers. To deliver the Payface platform to you, we work with retailers and channel partners. Proper biometric identification and authentication requires sharing data with these parties.
- Public authorities. We comply with applicable legal requirements. If required by law, court order, or legitimate regulatory authority, we may share personal data accordingly.
- Affiliates and subsidiaries. Payface may transfer personal data among companies within its group for corporate operations, product or service development, and compliance with legal or regulatory obligations.
- Data analysis and verification partners. We may transfer personal data, including sensitive personal data, to partners who provide authentication scoring and fraud prevention services. We carefully evaluate these partners' compliance with applicable law and require contractual data protection obligations.
7. Is your data transferred internationally?
Information used by Payface may be stored and processed on servers located in Brazil and the United States, including for hosting, production processing, security, support, optimization, operational efficiency, and backup. Depending on vendors and technical architecture, processing may also involve other locations, always subject to applicable legal safeguards.
When personal data is transferred to companies in other countries, we take appropriate steps to ensure those companies protect your data in accordance with this Privacy Policy and applicable data protection laws, such as the execution of standard contractual clauses. Your personal data will be stored only for as long as necessary to fulfill the purpose of the transfer.
8. Your privacy rights
Depending on where you are located, you may have specific rights regarding your personal data. In general, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Correct inaccurate or incomplete personal data.
- Delete your personal data in certain circumstances.
- Restrict or object to certain processing activities.
- Withdraw consent at any time where processing is based on consent (without affecting the lawfulness of prior processing).
- Data portability: receive your data in a structured, machine-readable format for transfer to another controller, where technically feasible.
- Review automated decisions that affect your interests.
California residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete personal information, the right to correct inaccurate personal information, the right to opt out of the sale or sharing of personal information, and the right to limit use of sensitive personal information (which includes biometric data). We do not sell personal information. To exercise your rights, contact us at the address in Section 11.
Residents of states with biometric privacy laws
If you are a resident of a state with specific biometric privacy legislation (such as the Illinois Biometric Information Privacy Act, BIPA), you may have additional rights, including prior written notice and consent before collection of biometric identifiers, the right to request destruction of biometric data, and limits on disclosure to third parties. Payface's enrollment flows are designed to obtain affirmative opt-in consent before collecting biometric data. Contact us to exercise any additional rights applicable to you.
To exercise any of these rights, contact us using the information in Section 11. For requests related to data processed on behalf of a retailer or business, we recommend contacting that business directly for faster resolution. To verify your identity before fulfilling requests, we may ask for additional information — this protects against disclosure to unauthorized parties. Certain requests may not be fully accommodated where technically impossible, where fulfillment would violate our intellectual property or trade secrets, or where it would risk harm to third parties.
9. How long do we keep your personal data?
Payface retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable legal, regulatory, or contractual obligations. You may request deletion of your personal data at any time, subject to any overriding legal requirements, as described in Section 8.
10. How do we protect your personal data?
We implement technical and organizational security measures appropriate to our activities and proportionate to the risks of processing, including encryption, pseudonymization, access controls, logical segregation, audit logs, monitoring, vulnerability management, and internal information security policies.
No system is perfectly secure. Hardware or software failures outside our control and other external factors may compromise data security. If you identify or become aware of anything that compromises the security of your data, please contact us using the information below.
11. How to contact us
If you believe your personal data has been processed in a manner inconsistent with this Policy, or if you have questions, comments, or suggestions, please contact our Privacy team:
Privacy Officer: Baptista Luz Advogados
Contact: privacy@payface.com.br
12. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect improvements or changes to the Payface and Fortface platforms. We recommend checking this page periodically to stay informed of any updates.