Privacy Policy

Last updated: 4 August 2026

1. Introduction

FacePlugin respects your privacy and is committed to protecting your personal information.

This Privacy Policy explains how FacePlugin collects, uses, stores, shares, and protects personal information when you:

  • visit our website;
  • contact us by email, WhatsApp, or a website form;
  • request product information, a demonstration, technical support, or licensing information;
  • become a customer, partner, supplier, or business contact; or
  • otherwise interact with our products and services.

This Privacy Policy applies to information processed by FacePlugin through this website and our direct business relationships.

Customers who deploy FacePlugin SDKs within their own servers, private cloud, air-gapped environments, or mobile devices are generally responsible for providing their own privacy notices to their end users.

2. Who We Are

For the purposes of applicable data-protection law, FacePlugin is responsible for the personal information described in this Privacy Policy unless another organisation is identified as the data controller.

FacePlugin

323 High Road
Chadwell Heath
Romford, Essex
United Kingdom

Email: info@faceplugin.com
WhatsApp: +1 (469) 278-4822

For privacy questions, rights requests, or complaints, please contact us using the details above.

3. Information We Collect

The information we collect depends on how you interact with us.

3.1 Information You Provide to Us

You may provide information including:

  • your name;
  • business email address;
  • telephone or WhatsApp number;
  • company name and job title;
  • country or business location;
  • details contained in your enquiry;
  • product and licensing requirements;
  • technical-support communications;
  • information submitted through forms;
  • correspondence and feedback;
  • billing, invoicing, and transaction information where applicable; and
  • files or technical materials voluntarily provided for evaluation or support.

Please do not send facial images, identity documents, biometric templates, or other sensitive information through general contact channels unless FacePlugin has specifically requested the information and agreed on an appropriate secure transfer method.

3.2 Information Collected Automatically

When you visit our website, certain technical information may be collected automatically, including:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • approximate geographic region;
  • referring website;
  • pages viewed;
  • date and time of access;
  • website interactions;
  • error and security logs; and
  • cookie or similar technology identifiers.

We use this information to operate, secure, maintain, and improve the website.

3.3 Customer and Licensing Information

When you request, purchase, activate, or receive support for a FacePlugin product, we may process:

  • customer and organisation details;
  • authorised-user information;
  • SDK and licence information;
  • deployment environment details;
  • product activation records;
  • device or server identifiers needed for licensing;
  • support tickets;
  • diagnostic information;
  • product version information; and
  • records relating to contracts, invoices, and payments.

4. Biometric and Identity Information

FacePlugin provides face recognition, face-liveness detection, deepfake detection, document recognition, document-liveness detection, and identity-verification SDKs.

4.1 Customer-Controlled Deployments

FacePlugin products are designed primarily for deployment within infrastructure controlled by the customer, including:

  • on-premises servers;
  • private cloud or VPC environments;
  • air-gapped environments; and
  • mobile or edge devices.

When an SDK is deployed in this way and configured according to the applicable documentation and agreement, facial images, biometric templates, identity documents, extracted document information, liveness results, matching scores, and verification decisions are processed within the customer-controlled environment.

FacePlugin does not ordinarily receive or store end-user biometric or identity information from a standard customer-controlled deployment.

4.2 Customer Responsibilities

Customers using FacePlugin products generally determine:

  • why end-user information is processed;
  • which information is collected;
  • the legal basis for processing;
  • how long the information is retained;
  • who may access it; and
  • how verification results are used.

In these circumstances, the customer will normally act as the data controller and is responsible for:

  • providing an appropriate privacy notice;
  • identifying a lawful basis for processing;
  • identifying an applicable condition for special-category biometric data;
  • obtaining consent where required;
  • completing any required data-protection impact assessment;
  • configuring suitable retention periods;
  • protecting user information; and
  • responding to end-user rights requests.

4.3 Support, Testing, and Evaluation Data

A customer may sometimes choose to provide sample images, videos, documents, logs, or other information for technical support, testing, evaluation, or troubleshooting.

Where this happens, FacePlugin will process the information only for the agreed purpose, subject to applicable instructions, confidentiality obligations, security controls, and contractual terms.

Customers must not provide real end-user biometric or identity information unless:

  • it is necessary for the agreed purpose;
  • they have authority to provide it;
  • appropriate notices and legal grounds are in place; and
  • FacePlugin has approved a secure method of transfer.

5. How We Use Personal Information

We may use personal information to:

  • respond to enquiries;
  • arrange demonstrations and meetings;
  • provide product and licensing information;
  • prepare proposals and quotations;
  • enter into and administer contracts;
  • provide SDK licences and activation services;
  • deliver technical support;
  • manage customer and partner relationships;
  • process invoices and business transactions;
  • maintain website functionality;
  • protect our systems and prevent fraud or misuse;
  • investigate technical and security incidents;
  • improve our website, SDKs, documentation, and services;
  • understand interest in our products;
  • send requested communications;
  • send relevant business communications where permitted;
  • establish, exercise, or defend legal claims; and
  • comply with legal, regulatory, tax, accounting, and contractual obligations.

We do not sell personal information.

6. Legal Bases for Processing

Depending on the circumstances, we may process personal information on one or more of the following grounds:

Contract

Processing may be necessary to enter into or perform a contract with you or your organisation, including providing licences, products, support, and related services.

Legitimate Interests

We may process information where necessary for legitimate business interests, including:

  • responding to business enquiries;
  • developing customer relationships;
  • improving our products and website;
  • maintaining network and information security;
  • preventing misuse;
  • administering our business; and
  • communicating with existing or prospective business customers.

We consider the nature of the information, the purpose of processing, and the potential effect on individuals before relying on legitimate interests.

Consent

We may rely on consent for optional cookies, certain marketing communications, demonstrations involving voluntarily supplied information, or another activity where consent is appropriate.

You may withdraw consent at any time. Withdrawal does not affect processing that took place before consent was withdrawn.

Legal Obligation

We may process information where necessary to comply with legal, regulatory, tax, accounting, or other obligations.

Legal Claims

We may process information where necessary to establish, exercise, or defend legal claims.

Where FacePlugin itself processes special-category biometric information, we will identify both an appropriate lawful basis and a valid special-category condition before processing begins.

7. Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

  • provide essential website functionality;
  • remember user preferences;
  • protect forms and prevent misuse;
  • maintain security;
  • understand website performance; and
  • measure how visitors use the website.

Strictly necessary technologies may operate without optional consent where permitted by law.

Analytics, advertising, or other non-essential technologies will only be used in accordance with applicable consent requirements. Where a cookie preference tool is available, you can use it to accept, reject, or manage optional technologies.

You can also control cookies through your browser settings. Disabling certain cookies may affect website functionality.

UK rules concerning cookies and similar storage or access technologies are principally governed by PECR, as amended. ICO guidance confirms that these rules can cover cookies, tracking pixels, web storage, device fingerprinting, scripts, tags, and similar technologies.

8. Communications and Marketing

We may send you communications that you request or that relate to an existing business relationship.

Where permitted, we may also send relevant information about FacePlugin products, SDK updates, services, events, or licensing opportunities.

You can unsubscribe from marketing communications at any time by:

  • using the unsubscribe option provided in the communication; or
  • contacting info@faceplugin.com.

We may retain limited information on a suppression list to ensure that we respect an unsubscribe request.

Service, security, contractual, licensing, or support messages are not marketing communications and may still be sent where necessary.

9. How We Share Information

We may share limited personal information with trusted third parties where necessary, including:

  • website-hosting providers;
  • cloud and IT-service providers;
  • email and communication providers;
  • customer-support systems;
  • cybersecurity providers;
  • analytics providers where enabled;
  • payment, banking, or accounting providers;
  • legal, financial, insurance, and professional advisers;
  • contractors supporting our business;
  • regulators, courts, law-enforcement bodies, or public authorities where legally required; and
  • parties involved in a merger, acquisition, financing, restructuring, or sale of business assets.

Service providers are permitted to process information only for the relevant service and subject to appropriate contractual and security obligations.

We may also share information where:

  • you have authorised us to do so;
  • it is required to perform a contract;
  • it is necessary to protect rights, property, systems, or safety; or
  • disclosure is required or permitted by law.

10. International Data Transfers

Some service providers or business recipients may process information outside the United Kingdom.

Where a restricted international transfer takes place, we will use an appropriate transfer mechanism where required, such as:

  • UK adequacy regulations;
  • the UK International Data Transfer Agreement;
  • the UK Addendum to approved standard contractual clauses;
  • another approved contractual safeguard; or
  • an applicable legal exception.

We will also consider whether supplementary contractual, organisational, or technical protections are appropriate.

Current ICO guidance identifies adequacy regulations and Article 46 safeguards, including the UK IDTA and Addendum, as mechanisms that may support restricted international transfers.

11. Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected.

Retention periods may depend on:

  • the nature of the information;
  • the purpose for which it is used;
  • the duration of a customer or business relationship;
  • contractual requirements;
  • licensing and support needs;
  • security and fraud-prevention requirements;
  • legal limitation periods;
  • tax and accounting obligations;
  • regulatory requirements;
  • actual or potential disputes; and
  • whether an individual has requested deletion or objected to processing.

In general:

  • enquiry information is retained while we respond and for a reasonable follow-up period;
  • customer, contract, licensing, and invoice records may be retained for the duration of the relationship and any legally required period afterwards;
  • support records are retained for as long as needed to provide support, maintain service history, and resolve disputes;
  • security and technical logs are retained for a limited period appropriate to their purpose;
  • marketing information is retained until you unsubscribe, withdraw consent, or the information is no longer required; and
  • information provided for testing or troubleshooting is deleted, returned, anonymised, or retained according to the relevant agreement and purpose.

When personal information is no longer required, we will delete it, anonymise it, or securely place it beyond normal use, subject to applicable legal and technical requirements.

UK data-protection rules do not prescribe one universal retention period; organisations must determine and justify appropriate periods based on their processing purposes and should erase or anonymise information when it is no longer needed.

12. Information Security

We use appropriate technical and organisational measures designed to protect personal information against:

  • unauthorised access;
  • unlawful use;
  • accidental loss;
  • destruction;
  • alteration;
  • unauthorised disclosure; and
  • other inappropriate processing.

Measures may include, where appropriate:

  • access controls;
  • authentication;
  • encryption;
  • network protection;
  • secure development practices;
  • logging and monitoring;
  • staff and contractor confidentiality requirements;
  • backups;
  • incident-response procedures; and
  • regular review of security controls.

No internet transmission, electronic storage system, or security measure can guarantee absolute security. You should use an approved secure channel before sending confidential, biometric, identity-document, or other sensitive information.

13. Automated Decisions

FacePlugin does not ordinarily use personal information collected through this website to make solely automated decisions that produce legal or similarly significant effects on website visitors.

FacePlugin SDKs may generate match scores, liveness results, fraud indicators, document-reading results, or other technical outputs. Customers determine how those outputs are used within their own systems and decision-making processes.

Customers are responsible for implementing appropriate human review, thresholds, notices, safeguards, and appeal mechanisms where required.

14. Your Data-Protection Rights

Depending on applicable law and the circumstances, you may have the right to:

  • be informed about how your information is used;
  • request access to your personal information;
  • request correction of inaccurate or incomplete information;
  • request deletion of your information;
  • request restriction of processing;
  • object to certain processing;
  • request data portability where applicable;
  • withdraw consent where processing is based on consent; and
  • raise a complaint about how your information has been handled.

These rights are not absolute and may be subject to legal exemptions.

To exercise a right, contact:

Email: info@faceplugin.com

We may request reasonable information to verify your identity and locate the relevant records.

You will not normally be charged for exercising your rights. We aim to respond within the period required by applicable data-protection law.

The ICO identifies access, rectification, erasure, restriction, objection, portability, and withdrawal of consent among the rights available under UK data-protection law.

15. Data-Protection Complaints

You may submit a complaint if you are concerned about:

  • how we collected or used your information;
  • the accuracy of information we hold;
  • how long information has been retained;
  • the security of your information;
  • our response to a rights request;
  • marketing communications; or
  • another privacy or data-protection matter.

Complaints may be submitted to:

Email: info@faceplugin.com
WhatsApp: +1 (469) 278-4822
Address: 323 High Road, Chadwell Heath, Romford, Essex, United Kingdom

We will:

  • provide an accessible method for submitting complaints;
  • acknowledge a data-protection complaint within 30 days;
  • investigate the complaint appropriately;
  • keep you informed where necessary; and
  • communicate the outcome of our investigation.

You also have the right to raise a concern with the UK Information Commissioner’s Office. We encourage you to contact FacePlugin first so that we have an opportunity to investigate and resolve your concern.

16. Children’s Privacy

Our website and products are intended for organisations, developers, professional users, and enterprise customers.

They are not directed at children, and we do not knowingly collect personal information directly from children through this website.

Customers using FacePlugin products in services involving children or age-restricted users are responsible for implementing appropriate notices, legal grounds, consent mechanisms, safeguards, and age-appropriate design measures.

17. Third-Party Websites and Services

Our website may contain links to third-party websites or communication platforms.

When you follow a third-party link or contact us through an external platform such as WhatsApp, the third party may process information under its own terms and privacy policy.

FacePlugin is not responsible for the privacy practices, security, or content of third-party services. You should review the relevant third-party privacy information before providing personal information.

18. Changes to This Privacy Policy

We may update this Privacy Policy when:

  • our website, products, or services change;
  • our processing activities change;
  • new service providers are introduced;
  • legal or regulatory requirements change; or
  • we improve our privacy practices.

The updated version will be published on this page, and the “Last updated” date will be revised.

Where a change materially affects how we use personal information, we may provide an additional notice where appropriate.

19. Contact Us

For privacy questions, rights requests, or complaints, contact:

FacePlugin
323 High Road
Chadwell Heath
Romford, Essex
United Kingdom

Email: info@faceplugin.com
WhatsApp: +1 (469) 278-4822

Scroll to Top