Legal

Biometric Consent Notice

This notice describes how TRUSTTICA collects, processes, stores, and deletes biometric data during identity verification, and the rights you have over that data.

Effective: July 30, 2026 · Operated by ELONZYA INC., Austin TX

What Biometric Data We Collect

During identity verification (KYC), TRUSTTICA captures the following biometric data from your device's camera:

  • Facial image — a photograph of your face captured via selfie for face-matching
  • Facial geometry — biometric measurements derived from the facial image used to compare against your government-issued ID photo

Note:Face ID or fingerprint authentication used to unlock the app is processed entirely by your device's own secure hardware and is never accessed by TRUSTTICA. Only the identity-verification selfie described above involves TRUSTTICA's biometric processing.

Purpose of Collection

Biometric data is collected solely for the purpose of verifying that you are the same person depicted in your government-issued identity document. This is required to issue a Stage 1 Identity Trust Token and to comply with identity verification requirements within the TRUSTTICA platform. We do not use your biometric data for marketing, profiling, or any purpose beyond identity verification.

How We Process Your Biometric Data

Your facial image and derived biometric data are processed as follows:

  1. The app captures your selfie image and transmits it over a TLS-encrypted connection to TRUSTTICA's backend servers, hosted on Microsoft Azure in the United States.
  2. The image is forwarded to Verisefy (operated by iDBIMA) — our third-party identity verification provider — for face-to-document matching.
  3. Verisefy returns a match confidence score. The raw facial image is not retained by Verisefy beyond the comparison transaction.
  4. TRUSTTICA records the outcome (match confidence, decision) in your verification record. The full biometric retention schedule is described at /privacy/retention.

Who Has Access to Your Biometric Data

  • ELONZYA INC. (TRUSTTICA) — processes the verification outcome and stores the confidence record
  • Verisefy / iDBIMA — receives the facial image for face-to-document matching only; does not retain data beyond the transaction
  • Microsoft Azure — provides the encrypted cloud infrastructure on which biometric data transits and is temporarily stored

We do not sell, lease, or trade your biometric data to any third party. No biometric data is shared for marketing, advertising, or analytics purposes.

Consent and Withdrawal

Before capturing any biometric data, TRUSTTICA presents an explicit consent screen describing:

  • What biometric data will be captured
  • The specific purpose (identity verification only)
  • How long the data will be retained
  • Your right to refuse and the consequences (verification will not be completed)

You may withdraw consent at any time by submitting an account deletion request via the Delete Your Account page or by contacting us at support@trusttica.com. Upon withdrawal, all raw biometric images associated with your account will be deleted within 30 days. Derived confidence scores retained for compliance purposes will be anonymized.

Illinois BIPA Disclosure

If you are a resident of Illinois, your biometric data is subject to the Illinois Biometric Information Privacy Act (BIPA). In compliance with BIPA: (a) we have a publicly available written policy (this notice, together with our Data Retention & Destruction Policy) governing biometric data retention and destruction; (b) we obtain your written consent prior to collecting biometric data; (c) your biometric data will be permanently destroyed within 3 years of your last interaction with the platform or within 3 years of this disclosure, whichever comes first; (d) we will not sell, lease, trade, or otherwise profit from your biometric data.

Contact

For questions about biometric data processing, contact us at support@trusttica.com. ELONZYA INC., Austin, TX, United States.