04 Biometric Verification and Liveness Detection Authorization
1. Separate Authorization Notice
Facial images, liveness detection results, biometric templates, similarity scores or risk results generated from them may constitute sensitive or high-risk personal data. The Platform treats this as a separate authorization item. Before checking this authorization, the user should carefully read and confirm understanding of the processing purposes, data categories, third-party providers, retention period, withdrawal mechanism and dispute resolution rules.
2. Purposes of Processing
Confirm whether the person submitting the document is the current operating user;
Prevent impersonation, identity theft, bot attacks, deepfakes, duplicate accounts and fraud;
Satisfy compliance, AML/CFT, sanctions compliance and risk control requirements;
Support backend manual review, Additional Verification, regulatory inspection, dispute resolution and audit.
3. Data Categories
Facial images, selfie videos, action detection results or screenshots submitted through camera or third-party SDK;
Biometric features, similarity scores, liveness detection results, risk flags and provider responses generated from facial images;
Comparison results between document portrait and live face, failure reasons, retry counts and manual review results;
Device, browser, IP address, timestamp and verification process logs.
4. Third-Party Providers and Security Measures
The Platform may complete liveness detection, face comparison and anti-fraud verification through entrusted third-party providers. The Platform should require providers to adopt reasonable security measures and process relevant data only for the purpose of this authorization.
Backend systems should not provide download functions for original biometric materials, and access should be controlled under permissions, the principle of least necessity and audit logs.
5. Failure and Manual Review
If liveness detection or face comparison fails, the Platform may allow a limited number of retries. If the failure reaches the threshold set by the Platform, the application may be routed to manual review and generate risk tags.
Facial verification or liveness detection failure does not automatically constitute rejection. The Platform may decide whether to reject, request Additional Verification or apply manual override approval based on retry counts, failure reasons, provider responses, document materials, risk tags and manual review results. Where a backend reviewer manually approves after face verification failure, the Platform should record the operator, time, reason, note and risk tag.
6. Withdrawal of Authorization
The user may request withdrawal of this authorization to the extent permitted by applicable law. Withdrawal may prevent the Platform from continuing to provide services that require biometric verification. Withdrawal does not affect lawful processing completed before withdrawal and does not prevent the Platform from retaining necessary records for legal, regulatory, AML/CFT, dispute or audit obligations.
7. Governing Law, Jurisdiction and Dispute Resolution
Unless otherwise required by mandatory applicable law, this authorization and any matters arising from biometric verification, liveness detection, face comparison, manual review, Additional Verification, account restrictions or related disputes shall, in principle, be governed by the laws of the Republic of El Salvador.
The user may first submit objections through the Platform’s customer support, privacy or compliance channels. If the dispute cannot be resolved through consultation, it may be submitted to the competent courts or competent authorities of the Republic of El Salvador. Before production launch, El Salvador counsel should confirm whether biometric data constitutes sensitive data, whether additional consent is required, the retention period, cross-border transfer arrangements and the user withdrawal process.