Privacy Policy
Last updated: October 7, 2026
Issued by IT Brains SASU (a company registered in France), operating under the brand ProofAge — privacy@proofage.net
IT Brains SASU is a French SASU (a simplified joint-stock company with a single shareholder), registered under SIREN 991 773 300 (RCS Paris), with its registered office at 61 rue de Lyon, 75012 Paris, France and a share capital of €30,000. VAT number: FR15991773300.
This policy is written in English. Translations are provided for convenience only; if a translation differs from the English version, the English version prevails.
1. About This Policy and Our Role
This Privacy Policy describes how IT Brains SASU (a company registered in France, operating under the brand "ProofAge", "we", "us") processes personal data in connection with our age verification and identity verification (KYC) services.
ProofAge provides its services to businesses ("Service Providers") who integrate our API into their own platforms. When end users complete a verification, they interact with ProofAge's technology on behalf of that Service Provider.
Our Role Under GDPR
- Data Controller
- The Service Provider — the company whose platform directs you to a ProofAge verification. They decide why your data is processed and are responsible for their own privacy practices.
- Data Processor
- ProofAge (IT Brains SASU) — we process personal data exclusively on documented instructions from the Service Provider and for no other purpose, except as required by applicable law.
This policy covers two groups of people whose data ProofAge processes:
- Business customers who integrate the ProofAge API
- End users who complete a verification through a Service Provider's platform
This policy is governed by Regulation (EU) 2016/679 (GDPR) and the French Data Protection Act (Loi n° 78-17 du 6 janvier 1978 modifiée, "Loi Informatique et Libertés").
2. Business Customers (Data Controllers)
When you register for and use the ProofAge API as a business, we process the following data for which ProofAge acts as a Data Controller in its own right:
Data collected
- Company name, registered address, and business contact details
- Account credentials (email, hashed password)
- API keys and workspace configuration
- Billing and payment information (processed by our payment processor, Stripe)
- API usage data and request logs
- Support communications
Legal basis and purpose
- Contract performance (GDPR Art. 6(1)(b)) — to provide the ProofAge service, manage your account, and process billing
- Legal obligation (GDPR Art. 6(1)(c)) — to comply with tax, financial, and regulatory obligations
- Legitimate interest (GDPR Art. 6(1)(f)) — to maintain API security, prevent abuse, and improve our service
Retention
Account data is retained while your account is active and for up to 5 years after closure to satisfy legal and contractual obligations. API logs are retained for 12 months.
Providers for account data
We use Stripe to take payments and Brevo to send account and service email. Each receives only the account, billing and contact data it needs for that task. They do not receive any end-user verification data, and they are not sub-processors under our Data Processing Agreement.
3. End Users — Age Verification
When you complete an age verification through a Service Provider's platform (a Facial age estimation, or an Age verification by ID), ProofAge acts as a Data Processor on behalf of that Service Provider.
Private and Protected modes
The Service Provider runs each verification in one of two modes, which decides what ProofAge keeps:
- Private (nothing remembered): photos, video and document images are deleted immediately after the decision. No face template is kept and no device fingerprint is collected.
- Protected (remembers, to protect): ProofAge keeps a face template and a device fingerprint hash so that it can run the face blocklist, the device blocklist and duplicate detection for the Service Provider.
Data collected
- A live facial photograph or short video captured via your device camera
- Where an ID document is used (an Age verification by ID, or a Facial age estimation that falls back to an ID document): images of the document and the first name, last name and date of birth read from it
- Protected mode only: a face template (face embedding), a mathematical vector representing your facial geometry (see Section 5)
- Age verification result: whether the Service Provider's configured age threshold is met
- IP address and approximate geolocation (country / city)
- User-Agent string (browser and device information)
- Protected mode only: device fingerprint hash (a pseudonymous identifier for fraud prevention)
- Timestamps of session events
- Consent record: version accepted, date, and time
Purpose and legal basis
| Purpose | Legal basis |
|---|---|
| Estimating whether you meet the age threshold configured by the Service Provider | GDPR Art. 9(2)(a) — Explicit consent |
| Deriving and retaining a face template for fraud prevention (Protected mode) | GDPR Art. 9(2)(a) — Explicit consent |
| IP geolocation for fraud prevention | GDPR Art. 9(2)(a) — Explicit consent |
| Device fingerprinting for fraud prevention (Protected mode) | GDPR Art. 9(2)(a) — Explicit consent |
Retention
| Data | Retention | Reason |
|---|---|---|
| Private mode | ||
| Photos, video and document images | Deleted immediately after the decision | Used only to reach the decision |
| Face template and device fingerprint | Not kept | Not used in Private mode |
| Protected mode | ||
| Facial photograph or video, and document images | 30 days | Dispute resolution, technical audit |
| Verification data: result, date of birth read from a document, IP address and geolocation | 30 days | Fraud prevention, dispute resolution |
| Face template (face embedding) | 12 months | Fraud prevention |
| Device fingerprint hash | 12 months | Fraud prevention |
| Consent record | As long as the law requires | Compliance audit |
After each retention period, data is permanently and irreversibly deleted. The Service Provider's own retention practices are governed by their privacy policy.
4. End Users — Identity Verification (KYC)
KYC verification is either initiated directly by the Service Provider or triggered as an escalation from face-based age verification when confidence is insufficient. It requires a separate explicit consent, additional to any age verification consent.
Identity verification (KYC) always runs in Protected mode, so the retention periods below apply to every KYC verification.
Data collected
Images:
- Live selfie photograph
- Identity document — front image (all document types)
- Identity document — back image (ID cards and driver's licences)
Biometric data (special category, GDPR Art. 9):
- Face embedding from selfie (see Section 5)
- Face embedding from document photo
- Face matching result: similarity score, threshold, decision (matched / not matched)
Identity document data extracted automatically:
- Full legal name, date of birth, nationality, gender
- Document type, number, issuing country, issue and expiry dates
- Address (when present on the document)
- Machine Readable Zone (MRZ) data
Document validation and technical data:
- MRZ checksum, field format and consistency validation, expiry status
- IP address, geolocation, User-Agent, device fingerprint hash, timestamps
- Consent record: version, date, time
Retention
| Data | Retention | Reason |
|---|---|---|
| Selfie photograph or video | 30 days | Dispute resolution, technical audit |
| Document images (front + back) | 30 days | Dispute resolution, document authenticity audit |
| Face template — selfie | 12 months | Fraud prevention |
| Face template — document photo | 12 months | Fraud prevention |
| Extracted document fields (name, DOB, etc.) | 30 days | Dispute resolution |
| Face matching result | 30 days | Technical audit |
| IP address + geolocation | 30 days | Fraud prevention, dispute resolution |
| Device fingerprint hash | 12 months | Fraud prevention |
| Consent record | As long as the law requires | Compliance audit |
5. Fraud Prevention and Face Embeddings
A face template (also called a face embedding) is a mathematical vector derived from a facial image. It represents the relative distances between facial landmarks as a series of numbers. A face template cannot be used to reconstruct or display a photograph.
Face templates and device fingerprint hashes are kept only for verifications in Protected mode. In Private mode, neither is kept.
In Protected mode, ProofAge keeps face templates for 12 months after each verification for the following fraud prevention purposes:
- Comparing a new verification attempt against a list of previously blocked profiles
- Detecting repeated attempts by the same person under different identities
- Protecting Service Providers and their users from identity fraud
Face templates are stored encrypted, in the region where the Service Provider's verification data is kept (Google Cloud EU regions by default). They are not shared with Service Providers or any third party. After 12 months they are permanently and irreversibly deleted.
The retention of face templates is covered by the explicit consent you provide before each verification. If you withdraw consent, your face template will be deleted within 30 days of your request.
6. International Data Transfers
By default, verification data — photographs, face embeddings, identity document data, and session metadata — is stored within the European Economic Area (EEA), on Google Cloud Platform infrastructure in EU regions. The primary processing, including the AI models that analyse images and documents, also runs there. Certified liveness, where the Service Provider uses it, runs on Amazon Web Services in an EU region.
A Service Provider may instead ask ProofAge to keep its verification data in another region, such as the United States. In that case your data is stored and processed in that region, and transfers from the EEA are covered by the safeguards described below.
In the limited cases below, some data may be sent to service providers located outside the EEA, including the United States. Each receives only the data it needs for that task.
Transfers outside the EEA
- IP geolocation — to find the approximate location of an IP address for fraud prevention. Only the IP address is sent; no photographs, embeddings, or document data.
- Backup AI model providers (Anthropic and OpenAI, United States) — used only if the primary EU-hosted models are unavailable or cannot complete an analysis, or if a verification needs a second model's review. In that case the selfie and document images and related verification signals for that verification may be sent to a backup provider, for anti-spoofing checks and fraud review. Their API terms do not allow them to use the data to train their models.
- Device intelligence — runs only in Protected mode, where this optional fraud check is enabled: browser and device attributes and the IP address may be sent to a device intelligence provider.
These transfers are governed by the EU Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Decision 2021/914), with the UK Addendum for transfers subject to UK law. The providers, and exactly what each receives, are named in Annex III of our Data Processing Agreement.
7. No Sale, Advertising, or AI Training
ProofAge uses verification data only to carry out the verification requested by the Service Provider, to prevent fraud as described in Section 5, and to meet its legal obligations. In particular, ProofAge does not:
- Sell or rent personal data — to anyone, for money or any other consideration. This applies to end-user verification data and to business customer account data.
- Use personal data for advertising or marketing — including targeted, behavioural, or cross-context advertising — or to build profiles of you beyond the verification itself.
- Train AI models on your data — photographs, face embeddings, identity documents, and extracted document data are not used to train, fine-tune, or otherwise develop machine-learning models, whether ProofAge's own or anyone else's.
- Allow sub-processors to use it for their own purposes — sub-processors, including providers of AI models used in the verification process, act only on ProofAge's instructions under data processing agreements and may not use the data to train their models.
Reviewing an individual verification — for example, to confirm that a decision was correct or to investigate suspected fraud or a technical fault — is part of providing the service and is not model training.
8. Data Security
ProofAge implements appropriate technical and organisational measures (TOMs) to protect personal data against unauthorised access, accidental loss, destruction, or alteration. Measures include, but are not limited to:
- Data encrypted in transit and at rest: TLS 1.2+ in transit, AES-256 at rest
- Least-privilege, role-based access for staff; two-factor authentication and passkeys for dashboard accounts
- Daily encrypted backups, kept for 7 days
- Notice to the Service Provider of a personal data breach within 48 hours
- Data minimisation — only data necessary for each purpose is collected
- Sub-processors operating under binding data processing agreements
Our Security page describes these measures in full.
As set out in Section 7, ProofAge does not sell personal data. Data is disclosed only to:
- The Service Provider (Data Controller) — verification result only (approved / declined)
- Sub-processors — mainly cloud infrastructure in Google Cloud EU regions, and the providers described in Section 6, all under data processing agreements and listed in our Data Processing Agreement
- Competent authorities or courts — when required by applicable law
9. Your Rights Under GDPR
If you have undergone a verification through a Service Provider's platform, you have the following rights with respect to data processed by ProofAge:
- Right of Access (Art. 15)
- Obtain a copy of your personal data held by ProofAge.
- Right to Rectification (Art. 16)
- Request correction of inaccurate data.
- Right to Erasure (Art. 17)
- Request deletion of your personal data ("right to be forgotten").
- Right to Restriction (Art. 18)
- Request that we limit how we use your data.
- Right to Portability (Art. 20)
- Receive your data in a structured, machine-readable format.
- Right to Withdraw Consent (Art. 7(3))
- Withdraw your consent at any time without affecting prior processing.
- Right re. Automated Decisions (Art. 22)
- Request human review of an automated verification decision through the Service Provider.
How to exercise your rights
Email privacy@proofage.net and include your verification session URL or token. This allows us to locate your data without requiring you to provide additional identity documents.
If you no longer have your session token, provide the approximate date and time of your verification and the name of the Service Provider. ProofAge will respond within 30 days.
For data held by the Service Provider, contact them directly using the details in their own privacy policy.
10. Automated Decision-Making
ProofAge verification processes involve fully automated decision-making as defined by GDPR Article 22. No human routinely reviews your photograph, face embedding, or identity document.
The automated system produces a binary outcome (approved / declined) which is communicated to the Service Provider. The Service Provider then determines whether to grant you access to their service.
In accordance with Art. 22 GDPR, you have the right to:
- Request human review of the decision by contacting the Service Provider
- Express your point of view
- Contest the decision
You also have the right to contact ProofAge at privacy@proofage.net if you believe the automated result was technically incorrect.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. When we do, we will update the "Last updated" date at the top of this page.
Material changes that affect end users will be reflected in an updated consent version presented at the next verification. Business customers will be notified by email.
12. Contact and Supervisory Authority
Data Protection Contact
IT Brains SASU
operating under the brand ProofAge
61 rue de Lyon, 75012 Paris, France
Email: privacy@proofage.net
We respond to all data subject requests within 30 days.
Supervisory Authority
Commission Nationale de l'Informatique
et des Libertés (CNIL)
3 Place de Fontenoy, 75007 Paris, France
Website: www.cnil.fr
Tel: +33 (0)1 53 73 22 22
You have the right to lodge a complaint with the CNIL if you believe your personal data has been processed in violation of the GDPR.