Meta Privacy Notice 

Effective Date: 2nd June, 2025

Introduction

This notice describes the personal data iProov (“we”, “our”, “us”) processes specifically when using iProov’s biometric authentication technology solely for liveness detection purposes. This policy applies to the Meta App ID developed and managed by Meta and relates explicitly to the ‘Login dialog and app details’ provided through our integration with Meta’s developer platform. The iProov service will support Meta in account recovery, where remote liveness detection technology will be used by scanning the user’s face.

Our relationship with you 

In order to support the reactivation of your Facebook account,  the iProov solution checks that you are a real person (also known as a ‘liveness’ check). To conduct these checks, we process your facial imagery such as pictures and a short video stream of you based on the instructions provided by Meta, this is as part of our integration with Meta. 

Scope and Purpose of Processing

We use iProov technology to confirm that a real, live person is attempting to reactivate a Meta account. This process does not involve facial matching, and we do not keep any biometric identifiers after the verification session ends. During the session, images or videos are temporarily processed and then deleted unless fraud is suspected. In such cases, limited data is retained for a set period to help detect and prevent future fraud.

Users complete the liveness check using either a mobile device or a desktop browser. No biometric data is stored on the user’s device. All data is processed through Meta’s systems for account reactivation purposes.

Only data related to suspected fraudulent activity (known as “attack data”) along with pseudonymised user IDs are stored by iProov. This data is kept only for the duration agreed in our Data Processing Agreement with Meta and is used solely for fraud prevention and improving system performance. Meta integrates and controls the use of iProov’s technology and retains responsibility for all client data collected.

Personal Data We May Collect

We may collect the following categories of data:

  • Pseudonym: such as unique identifier assigned to a biometric template to protect your identity 
  • Facial imagery: for the explicit purpose of determining liveness only
  • Technical data (such as IP address, device information) necessary for the secure functioning of the verification process

Legal Basis for Processing

We process your personal data:

  • Performance of a Contract – Your personal data is processed as part of the authentication and account recovery services integrated with Meta. Thus processing is necessary to fulfill the service requested by Meta under a contract with iProov. 
  • Legitimate Interest – iProov and its customers have a legitimate interest in preventing fraud and maintaining the security of our biometric authentication system and the systems of our customers. If a fraud attempt is reasonably suspected, we may retain and use your personal data for up to a period agreed in the Data Processing Agreement with Meta.
  • Explicit Consent – Your data will be processed based on your explicit consent provided to Meta at the time of your imagery capture. As this data is used to identify you, it is biometric data and in certain countries requires special handling.
  • Compliance with a legal obligation – Where fraud or other unlawful activities are detected, we reserve the right to involve law enforcement, to retain information for use as evidence or for the defense of a legal claim.

Data Retention

At iProov, we process your facial imagery in line with Meta’s instructions and ensure data minimisation throughout the process: 

  • Disposal of Facial Imagery:

Facial images captured during the iProov liveness verification process are processed and deleted immediately following the completion of the verification session. iProov does not retain facial images beyond this immediate verification period, except in cases of suspected fraud.

  • Fraud Prevention and System Enhancement:

In instances where our technical controls indicate a reasonable suspicion of fraudulent activity, iProov may retain the relevant facial imagery for a period of up to one year. This retention is solely for the purpose of enhancing our fraud prevention systems and improving the accuracy of our liveness detection technology.

  • Data Retention and Meta Integration:

iProov does not retain biometric templates as part of this integration with Meta. Meta’s use case does not require facial matching, and therefore iProov’s proprietary biometric templates are not shared or stored.

Retention periods for data processed through Meta’s integrated services may differ from iProov’s standard practices. We strongly recommend that you consult Meta’s privacy notice and terms of use to understand how they handle and store your data, as their policies and retention periods may vary

Data Sharing and Transfers

We do not share or transfer image or biometric data with other third parties beyond our approved subprocessors and business partners solely for the facilitation of the purposes defined above. Any transfers of data internationally comply with applicable data protection law requirements, including appropriate safeguards such as ensuring that there is a contract in place with the supplier, that they are obligated to ensure confidentiality and that security measures are in place. iProov only shares data with third parties other than suppliers or business partners when legally required, such as in response to law enforcement requests, for fraud prevention, or to address legal claims.

Security Measures

We implement robust technical and organisational security measures compliant with relevant global data protection legislation requirements to protect personal data, including encryption, secure data transmission protocols, and access control.
iProov adheres to GDPR, the UK Data Protection Act 2018, and other relevant international data protection and cybersecurity laws through robust security and privacy policies, controls, and measures. These include regular security testing and independent assessments leading to certifications against international information security standards that meet data protection requirements. We continuously test our security to ensure your data remains protected.

Your Rights to Your Data

Your rights to your data vary from country to country and some of the rights given below may not be available to you. We recommend that you contact the data protection supervisor in the country where you live to understand what rights you may have.

Under European and UK data protection legislation, you have the right to:

  • Access personal data processed by us.
  • Rectification of inaccurate personal data where we use legitimate interest as the lawful basis for processing.
  • Erasure of personal data.
  • Restriction of processing.
  • Portability of personal data.
  • Objection to processing.

When you would like to exercise any of the rights above you must contact Meta in the first instance because iProov, acting alone, cannot identify you due to our pseudonymisation process that is used to protect your identity. We act under the instructions of Meta and they are able to identify you.

  • The Data processed by iProov is pseudonymised, meaning it is separated from direct identifiers and linked via only pseudonyms (a string of characters ) held and known by Meta. iProov does not hold information about you that could identify you directly. 
  • iProov cannot fulfill any data subject requests without Meta providing the pseudonym reference.
  • In the event that we receive a data subject request from you, we will refer you to Meta who can identify you directly and control your data. They are able to provide the necessary information.
  • We will take reasonable steps to assist Meta in responding to your request and we are contractually obligated to do so.
  • iProov only uses your data to verify that you are a living person. We do not sell your data and only share data where we have a contract in place with a supplier who provides their products or services as a part of the contract the iProov has in place with Meta.

Our privacy practices comply with applicable laws in the regions where we operate. The legal requirements, allowances and restrictions related to data processing vary globally. As a result, if you attempt to reactivate your Facebook account in a different jurisdiction; whether national, state or geographic borders beyond the UK or EU, the data processing practices described in this notice including iProov, may differ. We recommend that you contact Meta in the first instance and your local data protection supervisor where you need further information. 

Complaints

For questions related to this policy, please contact our Data Protection Officer at DPO@iproov.com

If you believe your data protection rights have been violated, you may lodge a complaint with the supervisory authority in your jurisdiction.

Changes to this Privacy Notice

We reserve the right to update this Privacy Notice periodically. Users will be informed via this Privacy Notice page.