Demo App – Privacy Notice
Effective date: 4 November 2025
1. Introduction
At iProov Limited (“iProov”, “we”, “us”, or “our”), we are committed to protecting your privacy and ensuring that your personal data is handled in a lawful, fair, and transparent manner. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our demonstration application (“the Demo App”).
The purpose of the Demo App is to allow approved users to experience and evaluate iProov’s biometric technology and authentication services. By participating, you help us demonstrate and refine our capabilities so that we can showcase the accuracy, reliability, and effectiveness of our services to our customers and partners.
2. Scope and Our Relationship with You
When you use the Application, we act as the Data Controller for the personal data collected and processed. This means that we determine how and why your personal information is used within the Application.
The Application is provided solely for demonstration purposes. By using the Demo App, you acknowledge that it is intended to allow iProov to showcase its biometric technology and authentication services in a controlled environment. iProov collects only the personal data necessary to operate the Application and to achieve the objectives of the demonstration.
This Policy does not apply to:
- the use of iProov’s commercial authentication services provided to customers under separate contractual arrangements;
- personal data collected through other iProov websites, products, or services governed by distinct privacy notices; or
- processing carried out by third parties that integrate iProov technology under their own data protection responsibilities.
3. Categories of Data Collected
When you use the Demo App, we collect certain types of information about you to enable the demonstration to function as intended and to showcase the biometric technology.
A. Identification Data
- Email address (used to identify you as an iProov Application participant).
- Unique user identifier generated by the iProov Application.
- Information derived from an identity document (e.g. passport or driving licence) processed by a third party on iProov’s behalf to verify identity during demonstrations or trials.
B. Biometric Data
- Facial imagery collected via live image streaming (“User Image”).
- Frames of your facial image used to generate and compare biometric templates for authentication.
- Fingerprint imagery and associated biometric template.
C. Device and Technical Data
- Internet Protocol (IP) address.
- Mobile device information (type, model, identifier).
- Camera attributes (such as f-number, ISO, aperture value, brightness value, focal length, and pixel dimensions).
- Data from gyroscopes and accelerometers.
- Timestamp and session data associated with authentication attempts.
D. Behavioural and Motion Data
- Motion data reflecting how you hold and use your device during authentication attempts.
- Details of whether you are right- or left-handed.
E. Location Data
- Location information, to verify usage within a defined region.
De-identified Data
For algorithm training and product improvement purposes, iProov may de-identify personal data so that it can no longer be linked to an identifiable individual.
Other (Non-Personal) Data Collected
In addition to the personal data described above, iProov also collects other data when you use the iProov Application. This data is not considered personal data under data protection law but is included here for transparency:
- Data from the gyroscopes and accelerometers of your device.
- Mobile device type, model and identifier.
Aggregated data for statistical analysis purposes. - Camera attributes such as f-number, ISO, aperture value, brightness value, focal length, and pixel x and y dimensions.
- Timestamp associated with authentication attempts.
- Survey data to assess your experience of the iProov Application and any suggested improvements.
4. Purpose of Data Collection
iProov collects and processes personal data when you use the iProov Application for the following purposes:
- Demonstration and Product Evaluation
To enable you to participate in demonstrations or trials of iProov’s products and services and to showcase the capabilities of iProov’s technology to customers and partners. - Genuine Presence and Liveness Assurance
To verify that the individual interacting with the iProov Application is a living person and not an impersonation or spoof attempt. This involves processing facial or fingerprint imagery through automated biometric matching and imagery analysis. - Biometric Enrolment and Authentication
To enrol users for biometric verification and to perform subsequent authentication attempts by comparing biometric templates generated from live imagery. - Anti-Spoofing and Fraud Detection
To detect and prevent fraudulent or fake imagery submissions during authentication attempts, using machine-learning algorithms that combine data from imagery and device sensors. - Algorithm Training and Product Improvement
To train, update, and improve the accuracy and efficacy of iProov’s biometric systems and algorithms. Where data is used for algorithm training, it is de-identified so that it cannot be traced back to an identifiable individual. - Service Analysis and Statistical Reporting
To analyse the performance of the iProov Application, generate aggregated statistics, and support ongoing product improvement. - Technical Support and Security
To maintain the security and integrity of the iProov Application, detect and prevent technical issues, and ensure reliable operation. - User Experience and Feedback
To collect survey or feedback data to assess user experience and identify opportunities for improvement in iProov’s products and services.
5. Lawful Basis for Processing
iProov processes your personal data collected through the iProov Application on the following lawful bases:
1. Consent (Article 6(1)(a) and Article 9(2)(a) UK GDPR)
- iProov relies on your explicit consent to collect and process biometric data, including your facial imagery or fingerprint print data, when you use the iProov Application.
- You provide consent before data collection begins and may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
2. Legitimate Interests (Article 6(1)(f) UK GDPR)
iProov processes certain personal data where it is necessary for its legitimate business interests, provided that those interests are not overridden by your rights and freedoms. These legitimate interests include:
- Analysing and improving the performance and accuracy of iProov’s products and services.
- Detecting and preventing fraud, spoofing, and other misuse of biometric technologies.
- Training and enhancing iProov’s algorithms to improve accuracy and efficacy.
3. Compliance with Legal Obligations (Article 6(1)(c) UK GDPR)
Where required, iProov will process data to comply with its obligations under applicable laws, including maintaining appropriate records of consent and responding to requests from data subjects.
6. Data Retention
iProov retains personal data collected through the iProov Application only for as long as necessary to fulfil the purposes set out in this Privacy Notice.
- Personal data is retained for a maximum of thirty (30) days after your last use of the iProov Application.
- After this period, your data is permanently anonymised so that it can no longer be used to identify you.
- Anonymised and aggregated data may be retained for longer periods for research, statistical, and product improvement purposes, provided that it does not identify any individual.
7. Data Sharing and Disclosures
iProov does not sell or commercially exploit your personal data.
Access to data collected through the Platform is strictly limited to authorised personnel within iProov who require access for technical, research, or operational purposes. This may include members of the product, and engineering teams.
In certain circumstances, data may be hosted or processed on third-party infrastructure, such as Firebase by Google. Where this is the case, all vendors are contractually bound by appropriate data processing agreements and are subject to technical and organisational safeguards.
Data may also be disclosed where required by law or in response to valid legal process.
8. Data Security
We implement and maintain appropriate technical and organisational security measures to ensure a level of security appropriate to the risk presented by the processing of personal data through the Demo App. These measures are designed in alignment with recognised industry standards, including the principles of ISO/IEC 27001:2022, the international standard for information security management.
Key safeguards include:
- Encryption of data in transit and at rest;
- Role-based access controls to restrict access to personal data to authorised personnel only;
- Segregated demo environments hosted in secure, access-controlled infrastructure managed by iProov;
- Automated deletion mechanisms to ensure that personal data is erased within 30 days of the demonstration;
- Hardened configuration of all supporting systems, including video processing and storage infrastructure;
- Regular monitoring and review of access logs and system alerts to detect unauthorised activity.
iProov actively maintains its security posture in accordance with best practices and continuously improves its controls to mitigate emerging threats.
9. International Transfers
Your data will not be stored or processed in jurisdictions outside the United Kingdom or the European Economic Area (EEA).
If the hosting location changes and a transfer outside the UK or EU becomes necessary, iProov will implement appropriate safeguards in line with the UK GDPR and EU GDPR, such as the UK Addendum to the EU Standard Contractual Clauses or other approved transfer mechanisms. You may request a copy of these safeguards by contacting us.
10. Your Rights
Under applicable data protection law, you may have the right to:
- Request access to your personal data and obtain a copy of it.
- Request rectification of inaccurate or incomplete data.
- Request erasure of your data where it is no longer needed, or where consent has been withdrawn.
- Object to or request restriction of processing, particularly where based on legitimate interests.
- Lodge a complaint with the UK Information Commissioner’s Office (ICO) or another competent supervisory authority.
Please note that in cases where your data has been pseudonymised or delinked, these rights may no longer be exercisable unless you are able to re-establish your identity through your user identifier. iProov may not be able to accommodate deletion or access requests if it no longer has the ability to re-identify the relevant records.
To exercise your rights, please contact the iProov Privacy Team at dpo@iproov.com.
11. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect operational changes, legal developments, or refinements to how the Demo App is delivered. Where material changes are made, we will provide appropriate notice. This may include messaging at the start of the demo or updates to publicly available documentation.
You are responsible for reviewing any changes. Participation in a demo session after an updated Privacy Policy is made available constitutes your acknowledgement of the updated terms.
12. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact:
Email: dpo@iproov.com
ICO Registration Number: ZA859100
Company Name: iProov Limited
Registered Address: 14, Bank Chambers, 25 Jermyn Street, London, England, SW1Y 6HR
Supervisory Authority: UK Information Commissioner’s Office (www.ico.org.uk)
iProov Demo App – Acceptable Use Policy
1. Introduction
This Acceptable Use Policy (“Policy”) governs your use of the iProov Demo App (the “App”), provided by iProov Limited (“iProov”, “we”, “us”, or “our”).
By using the App, you confirm that you have read, understood, and agree to comply with this Policy. The App is provided solely for demonstration and evaluation purposes, to allow approved users to experience and assess iProov’s biometric technology in a controlled environment.
If you do not agree to this Policy, you must not access or use the App.
2. General Responsibilities
You agree to use the App:
- For lawful purposes only;
- In accordance with this Policy and all applicable laws and regulations; and
- In a manner that does not impair, disrupt, or negatively affect the operation or integrity of the App or iProov’s systems.
You must be at least 18 years old to use the Demo App.
3. Prohibited Conduct
You must not use the Demo App to:
(a) Engage in unlawful or harmful behaviour
- Upload, transmit, or display any content that is illegal, defamatory, obscene, discriminatory, or otherwise objectionable.
- Promote violence, hatred, harassment, or discrimination based on race, gender, colour, religion, sexual orientation, disability, or any other protected characteristic.
- Impersonate another individual or misrepresent your identity.
(b) Interfere with or damage the App or its security
- Introduce or attempt to introduce malware, viruses, bots, or other harmful code.
- Bypass, disable, or exploit any access control, security feature, or session restriction.
- Conduct unauthorised testing, probing, or vulnerability scanning.
- Overload, disrupt, or degrade the performance or availability of the App or its infrastructure.
(c) Misuse the demonstration environment
- Attempt to spoof, falsify, or manipulate biometric data, imagery, or sensor input.
- Use synthetic, recorded, or manipulated imagery to simulate genuine presence.
- Capture, record, reproduce, or share any part of the App (including screenshots, interfaces, or results) without iProov’s prior written consent.
Publish or distribute material designed to expose or exploit actual or perceived vulnerabilities in iProov’s technology.
(d) Misrepresent your relationship with iProov
- Suggest or imply that the App is your own product or that it operates independently of iProov.
- Attempt to sell, sublicense, or otherwise distribute access to the App or its outputs.
4. Integrity of the Demo Environment
You must not:
- Attempt unauthorised access to iProov’s systems, APIs, storage, or configuration;
- Interfere with biometric enrolment, authentication, or data collection processes;
- Compromise or attempt to compromise the confidentiality, integrity, or availability of the App or related systems;
- Use automated scripts, bots, or scraping tools to interact with or extract data from the App.
5. Integrity of the Demo Environment
Breach of this Policy may result in suspension or termination of your access to the App, removal of offending content, and any other action that iProov considers necessary to protect its systems and legal rights.
iProov may also:
- Report unlawful activity to the appropriate authorities;
- Cooperate with investigations or requests from law enforcement; and
- Take legal action where appropriate to prevent or remedy misuse.