Skip to content
Publisher
WiseWave Limited
Category
Verification & Biometrics
Effective date
Effective 2026-07-01
Last updated
Updated 2026-07-17

Biometric Information Policy

Reading note. This Policy explains exactly how biometric information is processed on Tirvea. The biometric template used for matching is generated and held by AWS in an EU face collection; in our own systems we hold only an opaque reference to it. Processing happens only with your explicit consent, which you can withdraw.

1. Purpose

Purpose. To govern every collection, processing, storage, matching, verification, retention, deletion, and protection of biometric information on Tirvea. Biometric information is used for one purpose only: photo verification, which confirms that the person using an account matches its profile photographs.

2. Scope

Purpose. To state what this Policy covers. It covers the biometric processing carried out for photo verification (§10-§12). It does not cover identity verification through documents (Identity Verification Policy, /legal/identity-verification) or how non-biometric data is processed (Privacy Policy, /legal/privacy).

3. Definitions

Purpose. To define biometric terms. Data-protection terms are defined in the Privacy Policy (/legal/privacy).

  • "Biometric information" / "biometric data" - personal data resulting from specific technical processing relating to facial characteristics that allows or confirms unique identification (GDPR Article 9). On Tirvea this is the facial template used for photo verification.
  • "Template" / "faceprint" - the mathematical representation of a face used for matching, generated and held by our provider.
  • "FaceId" - an opaque reference to a face in the provider's collection; in our systems it is treated as a reference handle, not as biometric content.
  • "Liveness" - the check that a real, live person is present.

4. What Biometric Information We Process

Purpose. To identify the biometric data. During photo verification, a facial template is generated from your face and used to confirm that you are the same person shown in your profile photographs. This template is biometric data and a special category of personal data under GDPR Article 9. It is the only biometric data we process.

5. Purpose Limitation

Purpose. To limit the use of biometric data. We use biometric data solely to perform photo verification - to confirm you are a live person and that you match your profile photographs. We do not use it for advertising, profiling, tracking, or any purpose other than verification, and we do not sell it.

6. Legal Basis (GDPR Article 9)

Purpose. To state the legal basis. Biometric data is a special category of personal data. We process it on the basis of your explicit consent under Article 9(2)(a) of the GDPR. Without that consent, we do not carry out biometric processing. [Legal review required before publication - confirm Article 9(2)(a) explicit consent as the lawful basis and the accompanying Article 6 basis.]

Purpose. To explain consent. Before any biometric processing, we obtain your explicit, specific, informed, and freely given consent. The liveness and comparison steps do not run unless we have a record of your active consent. Consent is separate from your acceptance of the Terms and is requested specifically for biometric processing.

Purpose. To explain versioned consent. Your biometric consent is versioned (the current version is 2026-07-bio-v1) and recorded with a timestamp and the version accepted. If we materially change how we process biometric data, we may require renewed consent to the new version before processing continues. Consent is only "active" when it matches the current version.

Purpose. To explain how to withdraw. You can withdraw your biometric consent at any time, from privacy settings, which clears your consent record and stops further biometric processing, and leads to deletion of your biometric reference (§17). Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Withdrawing may mean you can no longer use features that depend on photo verification.

10. AWS Face Liveness

Purpose. To describe the liveness step. Photo verification begins with an AWS Face Liveness session that confirms a real, live person is present, to prevent spoofing with a photo, mask, or screen. Short capture media exists only transiently in the provider's environment during the check; we do not retain it. This step requires active consent (§7).

11. Facial Comparison

Purpose. To describe the comparison step. AWS Rekognition compares your live capture against a reference face to confirm a match, using a face collection (§12). We receive only the match outcome and a confidence indication; the images and similarity scores are not stored in our systems or logs.

12. Face Collections and Templates

Purpose. To explain where the template lives. Your reference face is indexed into an AWS Rekognition face collection, which generates a biometric template (faceprint) and returns a FaceId. Matching is performed by searching the collection with a new capture. The template is generated and held by AWS in the collection, in the EU (§14); in our systems we hold only the opaque FaceId reference (§13).

13. What We Store (Data Minimisation)

Purpose. To state what we hold, minimally. In Tirvea's own systems we store only: an opaque FaceId reference, and a reference record that is a keyed hash of environment, user, and reference version (under a secret key) used to track and delete the reference. The label attached to the face at AWS is that same opaque hash. We do not store face images, face geometry, raw templates, or similarity scores in our systems or logs. This is the least data necessary to operate and to guarantee deletion.

14. Storage Location and International Transfers

Purpose. To state where processing happens. Biometric processing is configured to take place in an EU region (eu-west-1, Ireland) and is region-guarded so it cannot run outside the allowed region. Because processing is in the EU, there is no transfer of biometric data outside the EEA for this purpose. [Legal review required before publication - confirm the EU processing location and that no biometric transfer outside the EEA occurs.]

15. Retention (Storage Limitation)

Purpose. To state how long we keep biometric data. Your biometric reference is kept only while your photo verification is valid, and is destroyed on withdrawal of consent or account deletion (§17). The exact retention and rotation periods are configuration-driven and set by the Data Protection Impact Assessment; they are governed by the Data Retention Policy (/legal/data-retention), which this Policy does not override on the numeric periods. [Legal review required before publication - fix the exact biometric retention and rotation periods after the DPIA.]

16. Rotation

Purpose. To explain rotation. The biometric reference is versioned and rotated periodically: a new reference version supersedes and replaces the prior one, and the superseded reference is deleted (§17). Rotation limits how long any single reference exists. The rotation interval is set by the DPIA (§15).

17. Deletion

Purpose. To explain deletion. When your verification is no longer valid, you withdraw consent, or you delete your account, your biometric reference is deleted from the provider's collection (DeleteFaces). A reference registry tracks every FaceId ever created for you so that deletion can be confirmed complete - all references removed, not just the latest. Deletion is irreversible; you can re-verify later with fresh consent. See the Data Retention Policy (/legal/data-retention).

18. Human Review

Purpose. To explain human oversight. The identity-to-liveness binding is subject to a human review process, so that a person can confirm or reconsider a binding where required. Human review does not expose face images or templates to reviewers beyond what is necessary; reviewers act on outcomes and references. See the Trust & Safety Policy (/legal/trust-safety).

19. Verification Outcome and Badge

Purpose. To explain the outcome. A successful photo verification results in a verified status (a photo-verified badge) that other members can see. The badge reflects only current, valid verification and is issued from the verification outcome, not from any stored biometric content.

20. Verification Revocation

Purpose. To explain revocation. Where a verification is invalidated, found to be wrongful on review, or consent is withdrawn, the verified status is revoked and cleared so it no longer displays or confers benefits, the badge is removed, and the associated biometric reference is deleted (§17). See the Account Suspension Policy (/legal/account-suspension).

21. Security

Purpose. To explain protection. Biometric processing is protected by access controls, keyed and hashed references, EU-region processing, and the safeguards in the Security Policy (/legal/security). Because we do not store images, geometry, or raw templates, a compromise of our systems does not expose biometric content. Provider credentials and configuration are access-controlled.

22. Children

Purpose. To confirm the adults-only position. Tirvea is strictly for adults (18+). We do not knowingly process the biometric data of a minor. Child-safety matters are governed by the Child Safety Policy (/legal/child-safety).

23. Appeals

Purpose. To explain challenge routes. If your verification fails or is revoked and you believe that is wrong, you can re-attempt verification and, where a decision affects your account, appeal under the Appeals Policy (/legal/appeals). An appeal against an automated outcome is reviewed by a person.

24. Your Rights

Purpose. To connect to your data rights. Your biometric data is subject to your GDPR rights, exercised as described in GDPR & Your Rights (/legal/gdpr), including withdrawal of consent (§9). Because the reference we hold is an opaque provider handle rather than portable profile data, it is not included in the self-service data export; you can, however, have it deleted by withdrawing consent or deleting your account.

25. Updates

Purpose. To explain changes. We update this Policy to reflect changes in our biometric processing or the law, including when the DPIA fixes the retention and rotation periods. Material changes to biometric processing may require renewed consent (§8). We update the "Last Updated" date and take reasonable steps to communicate material changes.

26. Contact

Purpose. To tell you how to reach us about biometric data.

  • Data Controller: WiseWave Limited (Company Number 762171)
  • Registered office: 39 Cooley Park, Dundalk, Co. Louth, A91 AP2V, Ireland
  • Email: info@tirvea.com

For how photo verification works, see the Photo Verification Policy (/legal/photo-verification); for your rights, GDPR & Your Rights (/legal/gdpr); for retention, the Data Retention Policy (/legal/data-retention).


Version history

  • v1.02026-07-17Initial master draft.