App Privacy Policy
Nextarp Liveness Verification mobile app
This Privacy Policy explains how Nextarp B.V. (“Nextarp”, “we”, “us”, “our”) collects, uses, protects and shares personal data when you use the Nextarp Liveness Verification mobile application (the “App”). It is written to comply with the EU General Data Protection Regulation (“GDPR”), known in the Netherlands as the Algemene Verordening Gegevensbescherming (“AVG”).
This policy applies only to the App. Because the App performs facial liveness detection and face verification, it processes facial and biometric data, which is special-category personal data under Article 9 of the GDPR. Our website privacy policy continues to govern your use of the nextarp.com website and does not describe the biometric processing set out here.
1. Who is responsible for your data (Controller)
The data controller for personal data processed through the App is:
- Nextarp B.V.
- Wilhelminaplein 1, 3072 DE Rotterdam, The Netherlands
- Email: info@nextarp.com
- Telephone: +31 10 257 99 99
- Website: www.nextarp.com
Where the App is provided to you through an organisation that asked you to verify your identity (a “relying party”), that organisation may be a separate or joint controller for its own purposes. This policy describes Nextarp’s processing as the operator of the App.
2. Summary at a glance
We keep this consistent with the App’s Google Play Data Safety declaration:
- The App collects facial/biometric data to check that a real, live person is present and, where requested, to verify that person against a reference image.
- Biometric data is processed only with your explicit consent, which you can withdraw at any time.
- Data is encrypted in transit and at rest and hosted in the European Union.
- We do not sell your data, do not use it for advertising, and use no third-party biometric processors.
- You can request deletion of your data, including your biometric data, at any time.
- Optional, separate consents let you (a) share demographic data, (b) provide date of birth for age estimation, and (c) allow your captures to be used to train and improve our models. These are off unless you turn them on.
3. What data we collect
Depending on the features you use and the consents you give, the App may collect:
Biometric and session capture (core function)
- Facial images and/or short video frames captured during a liveness or verification session.
- TrueDepth depth data on supported iOS devices (a depth map of your face used to help confirm a live, three-dimensional person).
Device and session metadata
- Device model and operating-system information.
- Timestamps of the session.
- Motion and orientation (IMU) sensor readings during capture.
- Ambient-lighting and environment labels (for example, an indication that the scene was dark or backlit).
- A device correlation identifier used to link the events of a single session and device.
- A device-integrity attestation signal from Google Play Integrity (Android) or Apple App Attest (iOS), used to confirm the App is genuine and running on a genuine device and to detect tampering or emulators.
Optional data — only if you separately opt in
- Demographic data: skin tone recorded on the Monk Skin Tone scale.
- Date of birth / age: provided by you for age estimation features.
We do not knowingly collect more data than is needed for the purpose you have chosen.
4. Special-category (biometric) data
Facial and biometric data reveal information about you and are treated as special-category personal data under Article 9 of the GDPR. We process this data only on the basis of your explicit consent, in accordance with Article 9(2)(a) GDPR. If you do not give consent, the App cannot perform liveness detection or face verification.
5. Why we process your data (purposes)
- Liveness detection. To confirm that a real, live person is present in front of the camera and to detect presentation attacks (for example a photo, mask, replayed video or deepfake).
- 1:1 face verification. Where requested, to compare your face against a single reference image that you or the relying party provide, in order to confirm that the two are the same person. We do not perform 1:N identification, we do not run your face against any watchlist or database, and we do not use the App for surveillance.
- Model improvement (optional, separate consent only). If, and only if, you opt in, we may use your captures to train and improve our anti-spoofing models and, optionally, our age-estimation models, so that the technology becomes more accurate and more robust across different people and conditions.
6. Legal basis and your consent choices
Our legal basis for all processing described here is your explicit consent (Article 6(1)(a) and, for biometric data, Article 9(2)(a) GDPR). We ask for consent in separate, independent opt-ins, so you stay in control of each type of processing:
- (a) liveness detection and 1:1 verification;
- (b) demographic data (Monk skin-tone scale);
- (c) age estimation / date of birth;
- (d) use of your captures to train and improve our models.
Each opt-in is optional and can be refused or withdrawn independently at any time, without affecting the others. You can withdraw consent in the App or by contacting us at info@nextarp.com. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, but we will stop the relevant processing and, on request, delete the associated data.
7. Children and minors
Where a user is a minor, processing requires verifiable parental or guardian consent. The App enforces a guardian-consent gate before a minor’s data is processed. If you believe a minor has used the App without the required consent, please contact us at info@nextarp.com and we will take appropriate action, including deletion where required.
8. Automated decision-making
The liveness and verification result (for example, “live person confirmed” or “faces match”) is produced automatically by our software, without human intervention at the moment of the check. This automated result may be used by you or by the relying party to make a decision (for example, to allow or refuse access to a service).
Where such a decision produces legal effects concerning you or similarly significantly affects you, you have the right not to be subject to a decision based solely on automated processing. You may request human review of, express your point of view on, and contest an automated outcome, where this right applies. To do so, contact us at info@nextarp.com; where the decision was taken by a relying party using our result, we will help direct your request appropriately.
9. How long we keep your data (retention)
- Raw captures (facial images, video frames and depth data) are retained for a maximum of 360 days and are then automatically deleted.
- Data you have allowed us to use for model training is kept only for as long as necessary for that stated purpose, and no longer.
- Where you provide a date of birth, your actual date of birth is held only in a secured consent registry (see “How we protect your data”) and is never placed in the training dataset; only a derived age is retained where needed.
If you withdraw consent or request erasure earlier, we delete the relevant data sooner, as described in “Your rights”.
10. How we store and protect your data (security)
- Data is encrypted in transit using TLS and encrypted at rest using AES-256.
- Data is hosted in the European Union, on Google Cloud infrastructure in the Netherlands region.
- Access to data is restricted to authorised personnel on a need-to-know basis.
- Identifiers used in our systems are pseudonymous. Where you provide a date of birth, it is held only in a secured consent registry, separated from the biometric and training data, and never included in any training dataset (only a derived age is kept where needed).
No method of transmission or storage is completely secure, but we take appropriate technical and organisational measures to protect your data against misuse, loss, unauthorised access, unwanted disclosure and unauthorised modification.
11. Who we share your data with (sub-processors)
We do not sell your data, do not use it for advertising, and use no third-party biometric processors. Your biometric data is processed by Nextarp’s own systems.
Google Cloud acts solely as a hosting sub-processor under a Data Processing Agreement, providing the EU-based infrastructure on which the service runs. Data remains in the EU. Google Cloud processes the data only on our instructions and for hosting purposes, not for its own purposes.
The device-integrity attestation features (Google Play Integrity, Apple App Attest) are provided by Google and Apple respectively as part of the mobile platform; they return an integrity signal to us and are not used to identify you.
We may also disclose data where we are legally required to do so, for example to comply with a valid legal obligation or lawful request from a competent authority.
12. International transfers
For this App, there are no transfers of your personal data outside the European Union. Storage and processing take place within the EU.
13. Your rights
Under the GDPR you have the right to:
- Access your personal data;
- Rectify inaccurate or incomplete data;
- Erasure (“the right to be forgotten”), including deletion of your biometric data on request. Deletion can be carried out using your consent reference, which lets us locate and remove the data associated with your sessions;
- Restrict processing;
- Data portability, to receive certain data in a structured, commonly used, machine-readable format;
- Object to processing;
- Withdraw consent at any time, separately for each opt-in, without affecting processing carried out before withdrawal.
14. How to exercise your rights, and how to complain
To exercise any of these rights, contact us at info@nextarp.com. To help us protect your privacy and confirm your identity, please include enough information for us to locate your data (for example, your consent reference). We will respond to your request as soon as possible, and in any event within four weeks.
You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), via autoriteitpersoonsgegevens.nl.
15. Changes to this policy
We may update this policy from time to time, for example when the App changes or the law changes. When we do, we will update the “Effective date / last updated” shown at the top of this page and, where appropriate, notify you in the App. The current version is always available at this URL.
16. Contact
Questions about this policy or about how we handle your data can be sent to info@nextarp.com, or by post to Nextarp B.V., Wilhelminaplein 1, 3072 DE Rotterdam, The Netherlands.
