Privacy Policy
This Privacy Policy describes how Idvizer SASU (“Idvizer”, “we”, “us”, “our”), a company registered in France, processes personal data in connection with the operation of the Idvizer.com B2B AI face verification API (the “API”, “Service”).
This Policy is directed at our business clients (“Clients”) and their representatives. It does not govern the processing of End-User biometric data submitted to the API — that processing is the sole responsibility of the Client as Data Controller. This distinction is fundamental to understanding Idvizer's role and is explained in detail in Section 3 below.
Idvizer processes personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the French Loi Informatique et Libertés (Law No. 78-17 of 6 January 1978, as amended), and all applicable EU and French data protection legislation. Idvizer is subject to the oversight of the Commission Nationale de l'Informatique et des Libertés (“CNIL”) as lead supervisory authority.
1. Identity of the Data Controller
Idvizer SASU
Legal form: Société par Actions Simplifiée Unipersonnelle (SASU), registered in France
Website: https://www.idvizer.com
Data Protection Officer (DPO): dpo@idvizer.com
Legal & Privacy: legal@idvizer.com
General contact: support@idvizer.com
2. Scope of This Policy
This Policy covers the personal data Idvizer processes as Data Controller in connection with:
- Entering into and managing commercial relationships with Clients (account contacts, billing representatives, legal signatories);
- Providing technical support and communications to Client personnel;
- Operating and securing the API infrastructure (non-biometric technical logs only);
- Complying with applicable legal and regulatory obligations.
This Policy does NOT cover the processing of End-User biometric data submitted to the API. See Section 3 for a full explanation of Idvizer's role with respect to such data.
3. The Critical Distinction: Idvizer's Role Regarding Biometric Data
3.1 Idvizer Does Not Store or Retain Biometric Data
The Idvizer API is built on a Zero-Retention Architecture. When a Client submits a face verification request:
- Facial image data and all biometric payload are processed exclusively in volatile memory (RAM) for the duration of that single API call;
- No biometric data, facial images, biometric templates, or derived identifiers are written to disk, stored in any database, or persisted on any Idvizer infrastructure;
- No biometric payload is recorded in server-side logs;
- All in-memory data is automatically and irrecoverably purged upon the return of the API response.
This is a deliberate Privacy by Design measure implemented pursuant to Article 25 GDPR, and constitutes a core architectural principle of the Service, not merely a policy commitment.
3.2 Client as Data Controller for End-User Biometric Data
The Client determines the purposes and means of processing End-User biometric data and is therefore the Data Controller under Article 4(7) GDPR for that processing. Idvizer acts as Data Processor under Article 4(8) GDPR solely for the ephemeral duration of each API call, processing only on the Client's documented instructions.
Because no End-User biometric data is retained by Idvizer after the API response is returned, Idvizer does not hold a persistent dataset of biometric data subject to standard data subject rights obligations on Idvizer's part. All data subject rights requests from End-Users (access, erasure, rectification, portability, objection) must be directed to and handled by the Client as Data Controller.
3.3 Biometric Data as Special Category Data
Face verification data constitutes Biometric Data as defined in Article 4(14) GDPR and is a special category of personal data under Article 9 GDPR, subject to the highest level of legal protection. The processing of such data by the Client requires an explicit legal basis under Article 9(2) GDPR (most commonly, the explicit consent of the End-User under Article 9(2)(a)), in addition to a general legal basis under Article 6 GDPR. Ensuring compliance with Article 9 is the sole and non-delegable responsibility of the Client.
3.4 What Idvizer Does Retain
The only data Idvizer retains in connection with API calls is non-biometric transactional metadata strictly necessary for billing and operational security:
- API call timestamp;
- Client API key identifier (hashed);
- API endpoint called;
- HTTP response code;
- Response latency (milliseconds);
- Approximate data volume (bytes transferred, not content).
No facial images, biometric vectors, match scores tied to individual End-Users, or any other biometric-derived data are included in this metadata.
4. Personal Data We Process About Client Representatives
The table below describes the personal data Idvizer processes as Data Controller in respect of Client personnel (account managers, technical contacts, billing contacts, legal signatories).
| Category of Data | Purpose | Legal Basis (GDPR) | Retention |
|---|---|---|---|
| Client contact & account data (name, email, company, role) | Contract management, account access, invoicing | Art. 6(1)(b) — Contract performance | Duration of contract + 3 years |
| Billing & payment data (payment method, invoice records, VAT) | Fee processing, accounting, tax compliance | Art. 6(1)(b) & Art. 6(1)(c) — Legal obligation | 10 years (French accounting law) |
| API transactional metadata (timestamp, Client ID, endpoint, response code, latency — NO biometric payload) | Billing reconciliation, uptime monitoring, security auditing | Art. 6(1)(b) & Art. 6(1)(f) — Legitimate interest | 12 months rolling |
| Support communications (email content, ticket history) | Customer support and dispute resolution | Art. 6(1)(b) — Contract performance | 3 years after last interaction |
| Security and access logs (IP address, API key hash, authentication events — NO biometric data) | Security monitoring, fraud prevention, abuse detection | Art. 6(1)(f) — Legitimate interest | 12 months rolling |
| Contractual and legal documents | Compliance with legal obligations, litigation | Art. 6(1)(c) — Legal obligation | As required by applicable law |
Where processing is based on legitimate interests (Article 6(1)(f) GDPR), Idvizer has conducted a balancing test confirming that such interests are not overridden by the rights and freedoms of data subjects. Details are available upon request from dpo@idvizer.com.
5. How We Use Personal Data
Idvizer uses Client representative personal data exclusively for:
- Executing and managing the contractual relationship, including API access provisioning, invoicing, and account administration;
- Providing technical support, responding to queries, and communicating service updates;
- Monitoring and securing the API infrastructure against misuse, fraud, and security incidents;
- Fulfilling legal, accounting, and regulatory obligations under French and EU law;
- Defending Idvizer's legal rights in the event of a dispute.
Idvizer does not use Client representative personal data for marketing purposes without prior consent, and does not engage in profiling or automated decision-making with respect to Client representatives.
6. Sharing and Disclosure
6.1 Sub-processors
Idvizer engages a limited number of sub-processors who process Client representative personal data on Idvizer's behalf under Article 28 GDPR Data Processing Agreements. These are limited to:
- Cloud infrastructure provider(s) for API hosting and non-biometric log storage (EEA-hosted);
- Invoicing and accounting software provider;
- Email and communications platform for support interactions.
Idvizer does not engage sub-processors with access to biometric API payload data. A current list of sub-processors is available upon request at dpo@idvizer.com. Idvizer will provide at least 30 days' advance notice of changes to sub-processor arrangements.
6.2 Legal Disclosures
Idvizer may disclose personal data to French or EU public authorities, law enforcement, or courts where required by applicable law or a binding legal order. Idvizer will notify the Client of such disclosures where legally permitted.
6.3 No Sale of Data
Idvizer does not sell, rent, or trade personal data of any kind to third parties for commercial purposes.
7. International Data Transfers
Idvizer processes and stores Client representative personal data within the European Economic Area (“EEA”). Where any sub-processor operates outside the EEA, Idvizer ensures appropriate safeguards are in place pursuant to Chapter V GDPR, including:
- Standard Contractual Clauses (Decision 2021/914/EU) supplemented by transfer impact assessments where required;
- Transfers covered by a European Commission adequacy decision.
Given the Zero-Retention Architecture, biometric data submitted via the API is never transferred internationally — it does not leave the EEA-hosted processing environment and is not persisted in any form.
8. Data Security
Idvizer implements technical and organisational measures proportionate to the risk, in accordance with Article 32 GDPR and Article 9 of the French Loi Informatique et Libertés. Measures include:
- TLS 1.2 or higher encryption for all data in transit;
- Encryption at rest for all persistent data stores containing Client representative data;
- Strict isolation of API processing infrastructure to prevent any biometric data from touching persistent storage layers;
- Role-based access controls limiting personal data access to authorised personnel on a need-to-know basis;
- Regular penetration testing, vulnerability assessments, and code security reviews;
- Incident response procedures aligned with the 72-hour CNIL notification requirement under Article 33 GDPR;
- Regular staff training on data protection and information security.
In the event of a personal data breach affecting Client representative data that is likely to result in a risk to rights and freedoms, Idvizer will notify the CNIL within 72 hours and inform affected data subjects without undue delay as required by Articles 33 and 34 GDPR. Given the Zero-Retention Architecture, a breach of Idvizer's systems cannot expose End-User biometric data, as no such data is present on Idvizer infrastructure.
9. Your Rights as a Data Subject
Client representatives whose personal data is processed by Idvizer as Data Controller have the following rights under Chapter III GDPR and the French Loi Informatique et Libertés:
- Right of Access (Article 15 GDPR): To obtain a copy of personal data held about you and information about how it is processed.
- Right to Rectification (Article 16 GDPR): To request correction of inaccurate or incomplete personal data.
- Right to Erasure (Article 17 GDPR): To request deletion of personal data where it is no longer necessary, where consent is withdrawn, or where processing is unlawful, subject to Idvizer's legal retention obligations.
- Right to Restriction (Article 18 GDPR): To request that processing be restricted in certain circumstances.
- Right to Data Portability (Article 20 GDPR): To receive personal data in a structured, machine-readable format where processing is based on contract or consent and carried out by automated means.
- Right to Object (Article 21 GDPR): To object to processing based on legitimate interests. Idvizer will cease such processing unless it can demonstrate compelling legitimate grounds.
- Right to Lodge a Complaint: To lodge a complaint with the CNIL (www.cnil.fr) or the supervisory authority of your EU Member State of residence.
To exercise any of these rights, contact our DPO at dpo@idvizer.com. We will respond within one month (extendable by two months for complex requests, with notice). Requests are free of charge unless manifestly unfounded or excessive. Identity verification may be required.
Note: These rights apply only to personal data processed by Idvizer as Data Controller (i.e. Client representative data). Rights requests relating to End-User biometric data must be directed to the Client as Data Controller, not to Idvizer.
10. Cookies and the Idvizer Website
The Idvizer.com website uses strictly necessary cookies for session management and security. No third-party advertising or behavioural tracking cookies are deployed. The API itself does not use cookies. Analytics, if any, are conducted using privacy-preserving, cookieless tools. Full details are available in the Cookie Notice at https://www.idvizer.com/cookies.
11. Data Processing Agreement for Clients
As Idvizer processes End-User biometric data as a Data Processor on behalf of Clients, a Data Processing Agreement (“DPA”) compliant with Article 28 GDPR is required between Idvizer and each Client. The Idvizer standard DPA is available at https://www.idvizer.com/dpa or upon request at legal@idvizer.com.
The DPA documents the limited, ephemeral nature of biometric data processing by Idvizer, Idvizer's sub-processor arrangements, security measures, and the respective obligations of the parties. Clients must ensure the DPA is in place before commencing live processing of End-User biometric data through the API.
12. AI Act and Biometric Data — Client Responsibilities
As Deployer of a High-Risk AI System under Annex III of the EU AI Act (Regulation (EU) 2024/1689), Clients bear specific obligations which intersect with data protection law:
- Conducting a Fundamental Rights Impact Assessment (FRIA) before deploying the Service in contexts affecting natural persons (Article 27 EU AI Act);
- Ensuring meaningful human oversight of verification decisions that may produce legal or significant effects on End-Users (Article 26(2) EU AI Act);
- Maintaining records of use of the High-Risk AI System for the period required by Article 26(6) EU AI Act;
- Ensuring End-Users are informed that they are subject to an automated face verification process, in accordance with Article 50 EU AI Act and Article 13 GDPR;
- Conducting and maintaining a DPIA as required by Article 35 GDPR prior to deployment.
Idvizer, as Provider, maintains the required technical documentation and conformity assessment for the AI system and will provide Clients with the information necessary to discharge their obligations as Deployers.
13. Changes to This Policy
Idvizer may update this Policy to reflect changes in applicable law (including EU AI Act implementing acts and CNIL guidelines), Idvizer's architecture, or sub-processor arrangements. Material changes will be communicated to Client contacts by email at least 30 days before taking effect. The current version is always available at https://www.idvizer.com/privacy-policy.
14. Supervisory Authority
Commission Nationale de l'Informatique et des Libertés (CNIL)
3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07, France
Tel: +33 (0)1 53 73 22 22 | Website: https://www.cnil.fr
EU supervisory authorities directory: https://edpb.europa.eu
15. Contact
Idvizer SASU | Registered in France
Data Protection Officer: dpo@idvizer.com
Legal & Compliance: legal@idvizer.com
General Support: support@idvizer.com
DPA requests: legal@idvizer.com
Website: https://www.idvizer.com
Idvizer SASU is committed to Privacy by Design. No End-User biometric data is ever stored on our infrastructure.