Skip to content

Biometric Data Policy

Version 0.0.1 · effective 24 August 2026

All documents

1 · On one screen (the human summary)

When you verify your identity in Datta:

  1. You scan your ID document with the camera. Reading (OCR/MRZ) and authenticity checks run on your phone.
  2. You hold the document against your phone (NFC) if it has a chip. The phone reads the chip's signed contents: your identity data (MRZ) and the document's official photo.
  3. You take a selfie. Your phone compares the selfie against the document photo and runs the liveness check. Neither the selfie nor any camera image leaves the device.
  4. What travels to your vault: the text data extracted from the document (name, number, dates) and, in the chip flow, the chip's signed contents including the official photo: stored as a document of yours, in your vault, under your access and deletion rules (retention).
  5. We never build a face database: no facial templates server-side, no search-by-face (1:1 "is this you?" only, never 1:N), and we never sell or share biometric data.

If you don't want biometric verification, you can use Datta without it: your account works at a lower verification level and features that require verified identity stay off and you can use Datta without verifying, with the features that do not require verified identity.

2 · What is processed, where, and for how long

DataProcessed whereLeaves the device?Lifetime
Camera images of the documentOn deviceNoEphemeral: discarded when the scan session ends
Selfie / face captureOn deviceNo: verified: the face services contain no network callEphemeral
Facial template/embedding used for matchingOn deviceNoEphemeral: never persisted
Match result (similarity, liveness)Computed on deviceOnly the result (verified yes/no, level)For the life of the account
Document text data (name, number, dates)Extracted on deviceYes: to your vaultAs vault content: until you delete it
NFC chip contents: MRZ (DG1) + official photo (DG2) + security object (SOD)Read on deviceYes: POST /v1/me/identity/chip to your vaultAs vault content: until you delete it
Unlock biometrics (OS fingerprint/Face ID)100% the operating systemNo: Datta only receives "authenticated yes/no"Managed by your OS

Honest technical note: the verification SDK downloads its recognition database from the vendor's infrastructure at initialization; no personal data of yours travels in that download.

3 · Purpose and lawful basis

  • Single purpose: confirming that the person creating or upgrading an account is who they say they are (1:1 verification), and sealing the result into your vault as an attribute of yours. Datta's network trust is built on verified identities, that is the product's purpose.
  • What is NOT a purpose: 1:N identification ("whose face is this?"), surveillance, trait classification, advertising, third-party scoring, model training.
  • Legal basis (EEA/UK): your explicit consent (GDPR art. 9(2)(a)), requested on its own screen before the camera turns on, revocable at any time without affecting what was lawfully verified. For the rest of the document data: performance of the contract plus a documented anti-fraud legitimate interest.
  • Colombia: sensitive data (Ley 1581, arts. 5–6): explicit authorization, and no essential service is conditioned on providing it, verification is optional.
  • Mexico: sensitive data under the current LFPDPPP: express consent (in writing where applicable, counsel to validate the e-signed checkbox).
  • United States: see annex (BIPA/CUBI/MHMD).

4 · Verifiable commitments (BIPA style)

  1. Publication: this policy is public and stable (this URL).
  2. Destruction schedule: session biometric images and templates are destroyed on device when the comparison ends; chip contents stored in your vault are destroyed when you delete them or when your account closes, per the retention policy, and no later than 3 years from your last interaction with Datta.
  3. Zero profit from biometrics: Datta does not sell, lease, trade, or otherwise profit from biometric data (BIPA (c)).
  4. Zero disclosure: no biometric data is shared with third parties; there are no "data partners." SDK vendors process on device and receive no data.
  5. Security: chip contents travel encrypted in transit (TLS) with a session token and are stored under the vault regime.

5 · Your biometric-specific rights

  • Withdraw consent: in settings or by writing to datta.global/contact; stops all future biometric processing.
  • Delete: remove the document and its chip data from your vault; the retention policy applies (including the anti-resurrection journal).
  • Re-verify: you can repeat verification with a new document; the previous one is replaced the previous one.
  • Automated decisions: the match result is produced by an algorithm. If a failure blocks you, you have the right to human review: channel: datta.global/contact.

Version 0.0.1 · Last updated: 24 August 2026 · Controller: DATTTA LLC (trading as «Datta») · Contact: datta.global/contact

Back to home

DATTA / Your data. Your terms.

Talk with Datta

We’re exploring: Your data. Your terms..