Biometric Data Notice & Consent
This notice explains, in plain terms, the face data Identrifi collects to verify you, why it is needed, who it is and isn't shared with, how long it is kept, and the risks — so your consent is informed. Please read it before you consent on the verification screen.
Who is collecting this
Identrifi, operated by Vylaline Inc. (Alberta, Canada), is the organization collecting and processing your biometric data, acting as an independent data controller. Contact: office@vylaline.com.
The biometric data we collect
- A face reference derived from the portrait on your government ID.
- Face vectors (a mathematical representation of your facial features) computed from the short video you record.
These are used to confirm the live person in the video is the same person as the ID portrait, and that it is a real, present person — not a photo, mask, or synthetic fake.
Why we collect it, and that it is one-to-one
The sole purpose is identity verification — matching your face to your own ID. This is one-to-one verification, not one-to-many identification: your face is compared only against your own document, never searched against any database of other people. We use the minimum biometric data needed for that match.
This is integral to the service
The face match is integral to what Identrifi does — without it, identity cannot be verified — so it is required to complete a verification. If you do not consent, verification cannot proceed, and the platform that sent you here will not receive a pass. You are free to decline and not use the service.
What we do not do
- We do not share your face data, ID, video, or date of birth with the platform you're joining — it receives only a signed pass/fail.
- We do not sell biometric data or share it for advertising.
- We do not analyze your biometric data to infer secondary characteristics such as health, ethnicity, emotion, or biological relationships.
- We do not use your face data to identify you elsewhere or to train unrelated systems.
How long we keep it, and destruction
Biometric data (the face reference and face vectors) and the verification video are kept only as long as the verification requires and are permanently destroyed within 30 days of the verification completing — deleted from all locations, including backups. Non-biometric audit records (result, timestamps, token metadata) are kept for a longer defined period for security and compliance, then destroyed.
How we protect it
Biometric data is encrypted in transit and at rest, access is tightly restricted, and the verification environment is kept separate from the platforms that call Identrifi.
Risks
No system is risk-free. Biometric data is sensitive; in the event of unauthorized access it cannot be "reset" like a password. We limit that risk by minimizing what we collect, matching one-to-one, isolating the data, and destroying it quickly. We tell you this so your consent accounts for it.
Your choices and rights
Your consent is express and voluntary, given on its own screen before any face data is captured. You may withdraw consent at any time by contacting office@vylaline.com; withdrawal stops further processing and triggers deletion of your biometric data, subject to any short retention needed to resolve the verification you started. You may also request access to, or deletion of, your data. These rights are provided under Alberta's PIPA and Canada's PIPEDA; where a stricter regional law applies to your verification, we apply the stricter standard.
Contact
Vylaline Inc. (operating Identrifi), Alberta, Canada — office@vylaline.com. For how your data is handled generally, see the Privacy Policy.