Affirmed Identity Authenticator and Identity Service
Privacy Policy
This privacy notice for Affirmed Identity LLC ("we," "us," or "our")
and AffirmedId Authenticator Application (“app”) and related Identity
Service (“service”), describes how and why we might collect, (“process” and “discard”) or capture (“process”,
“store” and “use”) your information when you use our app or our service,
such as when you:
·
Download, install, register, and use the app.
·
When you use the app to take part in an authentication
session initiated by a third party (“service
provider”) via our identity service.
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our app or services. If you still have any questions or concerns, please open a Support Ticket or
email us at Support@ProteqsIT.com.
What personal information do we process or store? When you use our app or when you visit, use, or navigate our services, we may collect or capture
personal information resulting from how you use or interact with our app and the services, the choices you make, and the features you use. Learn more about personal information you disclose
to us.
Do we collect or capture any personal identification information
(PII)? Yes, we do PII information
that is stored both locally on your cell phone and
remotely in our cloud service.
Do we collect sensitive personal information (SPI)? Yes, we do collect, process
and discard SPI information.
Do we capture and store sensitive personal information (SPI)? We do not capture or
store SPI information.
Do we receive any sensitive or personal information from third parties? We do not ask for or knowingly receive your sensitive or personal information from third parties.
How do we process your collected information? Within the app we process collected SPI for the purpose of
recognizing and verifying the identity of the person using the app. Should it
be you using the app, then it is your SPI the app is processing. The inference
processing of SPI information produces two values, a Boolean and a decimal
between 0 and 1, These are used to recognize and verify
your identity and to recognize when it is not you who is using your app. Within
seconds of collection the SPI is discarded and never
stored. You by installing and registering the app grant your permission for the
app to undertake SPI collection, processing, and discarding on your behalf.
During installation you are provided the opportunity
to decline collection of certain types of SPI information and the app will
respect your choices made.
How do we process your captured information? Within the app we collect and process PII information you provide and
export that to our service. Both our app and our service store that PII in an
internal record it creates on your behalf. You can choose not to provide the PII and you have the right and opportunity to at any time to
have the internally stored user record discarded. However, either option prevents both the app and service from performing
their respective tasks on your behalf.
In what situations and with which parties do we share sensitive or personal information? We do not share your information in any situations with any third
parties under any circumstance. We do share identity conclusions drawn
from processing the SPI information with those you have granted permission to
reference your personal record and the PII it contains.
How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information.
How do you exercise your rights? The easiest way to exercise your rights is by either support ticket submission using the app’s form
for doing so or by email to Support@ProteqsIT.com, or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws. Want
to learn more about what we do with any information we collect? Review
the privacy notice
in full.
·
WHAT INFORMATION DO WE COLLECT?
·
HOW DO WE PROCESS YOUR INFORMATION?
·
WHAT LEGAL BASIS DO WE RELY ON TO PROCESS
YOUR PERSONAL INFORMATION?
·
WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
·
HOW LONG DO WE KEEP YOUR INFORMATION?
·
HOW DO WE KEEP YOUR INFORMATION SAFE?
·
DO WE COLLECT
INFORMATION FROM MINORS?
·
WHAT ARE YOUR PRIVACY RIGHTS?
·
CONTROLS FOR DO-NOT-TRACK FEATURES
·
DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
·
DO OTHER REGIONS HAVE SPECIFIC
PRIVACY RIGHTS?
·
DO WE MAKE UPDATES TO THIS NOTICE?
·
HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
·
HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
We collect personal information that you voluntarily provide to us when you install and register the app or access our
services, express an interest in obtaining information about us or our products and services, when you participate in activities on the services, or otherwise when you contact us.
Personal Identification Information Provided by You. The PII that is captured by our app and
service is strictly limited to:
·
Verifiable email address: that is stored both locally by the app and remotely by the
service.
·
Optional phone number: if provided, is
stored both locally by the app and remotely by the service.
·
Personal
Identification Number (PIN): we
collect, process, and store the biometrics of PIN code entry. The PIN code
number itself is not collected or stored and remains
known only to you.
Sensitive Personal Information. We collect, process, and discard the following SPI. In some
cases you have the option to withhold granting
permission to use certain SPI either during installation of the app or by
visiting your device settings; we respect and honor those selections. Types of
SPI collected include:
·
Geolocation Information. We monitor
your geographic location for the purpose of verifying your identity. In doing
so we collect, process, and then discard the geolocation information and retain only the results of processing.
·
Proximity Information: We monitor
your proximity to nearby electronic devices for the purpose of verifying your
identity. In doing so we
collect, process, and then discard the original information retaining
only the results of processing.
·
Sensor information: We monitor and collect, process, and discard sensor information including
from accelerometer, magnetometer, gyrocompas, orientation, and other like
sensors of your cell phone.
·
Microphone and
camera information: We may request permission
to use either your microphone and/or camera sensor information and if granted
we may collect, process, and discard and never stored.
This information we collect, process, and discard
and retain only data produced by processing the
information as biometric data indicative of how, where, and when you use the
app.
·
Your email address is
applied as your username for the purpose of authentication. It may also
be used from time to time to inform you of important
information pertaining to the app or service.
·
Your cell phone number, if provided, for
the purpose of providing support and product information.
·
Your PIN code to provide the third leg of the three
factor authentication stool on which service providers and other may
rely.
·
Your SPI
information of verifying it is you who is using the app and to recognize when
it is an unidentified third party attempting to use
the app.
In Short: We must and do comply with
regional and local laws pertaining to protection of your PII and SPI
information in all regions and locals where we authorize the use of our app and
service. Unless otherwise stipulated, installing and
registering our app indicates your consent to process your PII and SPI.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal basis we rely on in order to process your personal information. As such, we may rely on the following legal basis to process your personal information:
Consent. We may process your information if you have given us permission (i.e., consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we
are involved.
Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can withdraw your consent at any time.
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:
·
If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way.
·
For investigations and fraud detection and prevention.
·
For business transactions provided certain conditions are met.
·
If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim.
·
For identifying injured, ill, or deceased persons and communicating with next of kin.
·
If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse.
·
.
·
If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province.
·
If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records.
·
If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced.
·
If the collection is solely for journalistic, artistic, or literary purposes.
·
If the information is publicly available and is specified by the regulations.
We do not share your personal information
with any third-party except in the following situations:
Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
We keep a user account record on your behalf
until such time as you direct us to delete it. It
holds the only personal information we store, your email address and phone
number if provided at the time of registration.
Our practice for storing all app and
service information is to do so only when encrypted. Additionally, all
information exchanged between our app and our service, between our service and
authorized service provider, or between our service and an authorized
person-to-person query are point-to-point encrypted in addition to using secure
protocols such as HTTPS. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and in so doing improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our services is at your own risk. You should only access the Services within a secure environment.
We do not knowingly solicit data from or market to children under 18 years of age. By using our app and
service, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the app and service. If we learn that personal information from users less than 18 years of age has been collected without
parental or guardian permission, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please
contact us at Support
@ProteqsIT.com.
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request
by contacting us by using the contact
details provided in the section
"HOW CAN YOU CONTACT US ABOUT THIS NOTICE?"
below.
We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority. If you are located in Switzerland, you may contact
the Federal Data Protection and Information Commissioner.
Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us by using the contact details provided in the section "HOW CAN YOU CONTACT US
ABOUT THIS NOTICE?" below or updating your preferences.
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
If you would at any time like to review or change the information in your account or terminate your account, you can:
·
Contact us by email at
Support@ProteqsIT.com.
·
Open a support ticket under app Options +
Support.
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable
legal requirements.
Do-Not-Track ("DNT") feature is implicit in our
app and service. We do not track nor do we capture any
information that could enable tracking.
In Short: If you are a resident of California, Colorado, Connecticut, Utah or Virginia, you are granted specific rights regarding access to your personal information.
As of the last update to this policy the
following categories of personal information were in effect. CAPTURED means captured,
processed, and stored by both app and service. COLLECTED means collected,
processed, and discarded by the app. The categories are:
Category |
Example |
Action |
A. Identifiers |
Email address and mobile phone number |
CAPTURED |
B. Personal information as defined in the California Customer Records statute |
Name, contact information, education, employment, employment history, and financial information |
NO |
C. Protected classification characteristics under state or federal law |
Gender and date of birth |
NO |
D. Commercial information |
Transaction information, purchase history, financial details, and payment information |
NO |
E.
Biometric information |
Inferred
by information collected from device sensors |
COLLECTED |
F. Biometric information |
Fingerprints and voiceprints |
NO |
G. Internet or other similar network activity |
Browsing history, search history, online behavior,
interest data, and interactions with our and other
websites, applications, systems,
and advertisements |
NO |
H. Geolocation data |
Device location |
COLLECTED |
I. Audio, electronic, visual, thermal, olfactory, or similar information |
Images and audio, video or call recordings created in connection with our business activities |
NO |
J. Professional or employment-related information |
Business
contact details
in order
to provide
you our
Services at
a business
level or
job title,
work history,
and professional
qualifications if
you
apply for a job with us |
NO |
K. Education Information |
Student records and directory information |
NO |
L. Inferences drawn from collected personal information |
Inferences drawn from
any of the collected personal information listed above
to create a profile or
summary about, for example, an individual’s preferences and characteristics |
NO |
M. Sensitive personal Information |
Inferred by SPI
collected from device sensors |
COLLECTED |
We will use and retain the PII and SPI as needed to provide the services or for:
·
Categories A -
As
long as you have an account with us and the app
remains installed on your cell phone.
·
Categories E, H, M - As long as the app remains installed on your cell phone.
We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:
·
Receiving help through our customer support channels;
·
Participation in customer surveys or contests; and
·
Facilitation in the delivery of our Services and to respond to your inquiries.
Learn about how we use your personal information in the section, "HOW DO WE PROCESS YOUR INFORMATION?"
We do not share your personal information
with anyone except as noted under, "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?"
California Civil Code Section 1798.83, also known as the "Shine The Light" law permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact
information provided below.
If you are under 18 years of age, reside in California, and have a registered account with the Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems
(e.g., backups, etc.).
CCPA Privacy Notice
This section applies only to California residents. Under the California Consumer Privacy Act (CCPA), you have the rights listed below. The California Code of Regulations defines
a "residents" as: every individual who is in the State of California for other than a temporary or transitory purpose and every individual
who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose All other individuals are defined as
"non-residents."If this definition of "resident" applies to you, we must adhere to certain rights and obligations regarding your personal information.
Right to request deletion of the data — Request to delete
You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities.
Right to be informed — Request to know
Depending on the circumstances, you have a right to know: whether we collect and use your personal information; the categories of personal information that we collect; the purposes for which the collected personal information is used; whether we sell or share personal information to third parties; the categories of personal information that we sold, shared, or disclosed for a business purpose; the categories of third parties to whom the personal information was sold, shared, or disclosed for a business purpose; the business or commercial purpose for collecting, selling, or sharing personal information; and the specific pieces of personal information we collected about you.
In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.
Right to Non-Discrimination
for the
Exercise of a Consumer’s Privacy Rights
We will not discriminate against
you if you exercise your privacy rights.
Right to Limit
Use and
Disclosure of Sensitive Personal Information
We do not process consumer's sensitive personal information.
Verification process
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. For instance, depending on the type of request you submit, we may ask you to provide certain information so that we can match the information you provide with the information we already have on file, or we may contact you through a communication method (e.g., phone
or email) that you have previously provided
to us. We may also use other verification methods
as the circumstances dictate.
We will only use personal information provided in your request to verify your identity or authority to make the request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.
Other privacy rights
You may object to the processing of your personal information.
You may request correction of your personal data if it is incorrect or no longer relevant or ask to restrict the processing of the information.
You can designate an authorized agent to make a request under the CCPA on your behalf. We may deny a request from an authorized agent that does not submit proof that they have been validly authorized
to act on your behalf in accordance with the CCPA.
You may request to opt out from future selling or sharing of your personal information to third parties. Upon receiving an opt-out request, we will act upon the request as soon as feasibly possible, but no later than fifteen (15) days from the date of the request submission.
To exercise these rights, you can contact us by visiting Support@ProteqsIT.com, by email at Support@ProteqsIT.com, by calling toll-free at 1-239-841-7585, Open a support ticket using in-app facilities., or by referring to the contact details at the bottom of this document. If you have a complaint
about how we handle your data, we would like to hear from you.
This section applies only to Colorado residents. Under the Colorado Privacy Act (CPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
·
Right to be informed whether or not we are processing your personal data
·
Right to access your personal data
·
Right to correct inaccuracies in your personal data
·
Right to request deletion of your personal data
·
Right to obtain a copy of the personal data you previously shared with us
·
Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling") To submit a request to exercise
these rights described above, please
email Support@ProteqsIT.com or
visit Support@ProteqsIT.com.
If we decline to take action regarding your request and you wish to appeal our decision, please email us at Support@ProteqsIT.com. Within forty-five (45) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the
reasons for the decisions.
This section applies only to Connecticut residents. Under the Connecticut Data Privacy Act (CTDPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
·
Right to be informed whether or not we are processing your personal data
·
Right to access your personal data
·
Right to correct inaccuracies in your personal data
·
Right to request deletion of your personal data
·
Right to obtain a copy of the personal data you previously shared with us
·
Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling") To submit a request to exercise
these rights described above, please
email Support@ProteqsIT.com or
visit Support@ProteqsIT.com.
If we decline to take action regarding your request and you wish to appeal our decision, please email us at Support@ProteqsIT.com. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written
explanation of the reasons for the decisions.
This section applies only to Utah residents. Under the Utah Consumer Privacy Act (UCPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
·
Right to be informed whether or not we are processing your personal data
·
Right to access your personal data
·
Right to request deletion of your personal data
·
Right to obtain a copy of the personal data you previously shared with us
·
Right to opt out of the processing of your personal data if it is used for targeted advertising or the sale of personal data
To submit a request to exercise these rights described above, please email Support@ProteqsIT.com or visit Support@ProteqsIT.com.
Under the Virginia Consumer Data Protection Act (VCDPA):
"Consumer" means a natural person who is a resident of the Commonwealth acting only in an individual or household context. It does not include a natural person acting in a commercial or employment context. "Personal data" means any information that is linked or reasonably linkable to an identified or identifiable natural person. "Personal data" does not include de-identified data or publicly available information. "Sale of personal data" means the exchange
of personal data for monetary
consideration.
If this
definition of "consumer" applies to you, we must adhere to certain
rights and obligations regarding your personal data.
Your rights with respect to your personal data
·
Right to be informed whether or not we are processing your personal data
·
Right to access your personal data
·
Right to correct inaccuracies in your personal data
·
Right to request deletion of your personal data
·
Right to obtain a copy of the personal data you previously shared with us
·
Right to opt out of the processing of your personal data if it is used for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
Exercise your rights provided under the Virginia VCDPA
You may contact us by email at Support@ProteqsIT.com or on the app by submitting a support ticket Options + Support.
If you are using an authorized agent to exercise your rights, we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.
Verification process
We may request that you provide additional information reasonably necessary to verify you and your consumer's request. If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request.
Upon receiving your request, we will respond without undue delay, but in all cases, within forty-five (45) days of receipt. The response period may be extended once by forty-five (45) additional days when reasonably necessary. We will inform you of any such extension within
the initial 45-day response period,
together with the reason for the extension.
Right to appeal
If we decline to take action regarding your request, we will inform you of our decision and reasoning behind it. If you wish to appeal our decision, please email us at Support@ProteqsIT.com. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may contact the Attorney General to submit a complaint.
In Short: You may have additional rights based on the country you reside in.
We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020 (Privacy Act).
This privacy notice satisfies the notice requirements defined in both Privacy Acts, in particular: what personal information we collect from you, from which sources, for which purposes, and other recipients of your personal information. If you do not wish to provide
the personal information necessary to fulfill
their applicable purpose,
it may affect our ability
to provide our services, in particular:
·
offer you the products
or services that you want
·
respond to or help with
your requests
·
manage your account
with us
·
confirm your identity
and protect your account
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU REVIEW, UPDATE, OR DELETE
THE
DATA WE COLLECT FROM
YOU?"
If you believe we are unlawfully processing your personal information, you have the right to submit a complaint about a breach of the Australian Privacy Principles to the Office of the Australian Information Commissioner and a breach of New Zealand's Privacy Principles to the Office of New Zealand Privacy Commissioner.
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
If you have questions or comments about this notice, you may contact our Data Protection Officer (DPO), Richard to attention of DPO by email at Support@ProteqsIT.com, by phone at 2398417585, or contact us by post at:
Affirmed Identity LLC
200 Vintage Circle, PO Box 104
Naples,
FL 34119 United
States
If you have any further questions or comments, you may also contact us by post at the following corporate address:
Affirmed Identity LLC
200 Vintage Circle, PO Box 104
Naples, FL 34119 United
States Phone: 2398417585
You
have the right to request access to the personal information we collect from
you, change that information, or delete it. To request
to review, update, or delete your personal information, please open a Support
Ticket or email us at Support@ProteqsIT.com.