🎉 @facesmash/sdk v0.1.0 is now available on npm — Read the docs →
FaceSmash Docs
Security & Privacy

Compliance

GDPR, BIPA, and CCPA compliance for biometric data

Regulatory Framework

FaceSmash processes biometric data (face descriptors) which is subject to special regulation in many jurisdictions. This page outlines how FaceSmash complies with major privacy regulations.

BIPA (Illinois Biometric Information Privacy Act)

BIPA is the strictest U.S. biometric privacy law. FaceSmash complies by:

RequirementHow FaceSmash Complies
Written consent before collectionUsers explicitly consent during registration
Purpose disclosureClear explanation of how biometric data is used
Retention scheduleData retained only while account is active
Destruction upon purpose fulfillmentImmediate deletion when user deletes account
No sale or profit from biometric dataBiometric data is never sold or shared
Reasonable security measuresTLS encryption, access controls, audit logging

GDPR (EU General Data Protection Regulation)

Face descriptors qualify as "biometric data" under GDPR Article 9 (special category data).

FaceSmash processes biometric data under explicit consent (Article 9(2)(a)):

  • Users provide explicit consent during registration
  • Consent is specific, informed, and freely given
  • Users can withdraw consent at any time by deleting their account

Data Subject Rights

RightImplementation
Right of accessUsers can view all stored data via dashboard
Right to erasureOne-click account deletion removes all biometric data
Right to portabilityData export in machine-readable JSON format
Right to restrictionUsers can disable face login without deleting data
Right to objectUsers can delete their account at any time

Data Protection Principles

PrincipleImplementation
LawfulnessExplicit consent obtained
Purpose limitationData used only for authentication
Data minimizationOnly 128-d descriptors stored, not images
AccuracyMulti-template learning improves over time
Storage limitationData deleted when account is deleted
IntegrityTLS encryption, access controls

CCPA (California Consumer Privacy Act)

Consumer Rights

RightImplementation
Right to knowPrivacy policy discloses all data collection
Right to deleteAccount deletion removes all data
Right to opt-outNo sale of biometric data
Right to non-discriminationNo service difference based on privacy choices

Data Processing Agreement

For enterprise customers, FaceSmash provides a Data Processing Agreement (DPA) that covers:

  • Sub-processor disclosure
  • Data breach notification (within 72 hours)
  • Data transfer mechanisms
  • Technical and organizational security measures
  • Audit rights

Contact legal@everjust.co for DPA requests.

Security Certifications

CertificationStatus
SOC 2 Type IIPlanned
ISO 27001Planned
GDPR compliance auditIn progress
BIPA compliance reviewComplete

Contact

For privacy-related inquiries:

On this page