CONFRMO PRIVACY POLICY
Last Updated: 20 July 2026
1. INTRODUCTION
Confrmo Ltd (“Confrmo”, “we”, “our” or “us”) is committed to protecting your privacy and handling your personal information fairly, lawfully and transparently.
This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you use the Confrmo mobile application, website, APIs, SDKs and associated services (the “Service”).
By using Confrmo, you acknowledge that your personal information will be processed as described in this Privacy Policy.
2. DATA CONTROLLER
For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, the data controller is:
Confrmo Ltd
Company Number: 17203914
England and Wales
Email: privacy@confrmo.com
Website: https://www.confrmo.com/
3. INFORMATION WE COLLECT
The information we process depends on how you use the Service.
Identity Information
• Full name
• Date of birth
• Nationality
• Residential address
• Email address
• Telephone number
Identity Documents
Where required for verification, you may choose to add or present documents including:
• Passport
• Driving licence
• National identity card
• Residence permit
• Proof of address
• Bank statement
• Other verification documents requested by a participating organisation
Face and Biometric Information
Where you provide consent, Confrmo may process:
• Facial images
• Head-position and liveness signals
• A mathematical facial feature print used for matching
• Face-verification results
• Device-authentication results
The specific processing, storage, sharing, retention and deletion arrangements for face data and Apple TrueDepth information are explained in Section 8 below.
Technical Information
• Device model
• Operating system
• Browser type
• IP address
• Device identifiers
• App version
• Time zone
• Security and diagnostic logs
Usage Information
• Authentication history
• Login activity
• Verification attempts
• Transaction approvals
• Document-presentation history
• Security events
• Fraud-prevention signals
Communications
If you contact us, we may process:
• Support requests
• Emails and other correspondence
• Feedback
• Complaint information
4. HOW WE COLLECT INFORMATION
We may collect information:
• Directly from you
• From your device
• From participating organisations
• From identity-verification providers where applicable
• From fraud-prevention partners
• From publicly available sources where legally permitted
5. WHY WE PROCESS YOUR INFORMATION
We process personal information to:
• Verify identity
• Authenticate users
• Prevent fraud and impersonation
• Provide secure passwordless sign-in
• Present documents following the user’s explicit approval
• Facilitate secure approvals and ownership transfers
• Protect user accounts
• Investigate misuse
• Maintain and improve the Service
• Comply with legal obligations
• Respond to support requests
6. LAWFUL BASES FOR PROCESSING
Depending on the circumstances, we rely on one or more of the following lawful bases:
• Performance of a contract
• Compliance with a legal obligation
• Our legitimate interests or those of another party
• Your consent
• Protection of vital interests where applicable
Where processing face or biometric information requires consent under applicable law, Confrmo requests consent before that processing begins.
You may decline face enrolment where the app provides that option and may delete retained face data at any time.
7. HOW WE USE BIOMETRIC INFORMATION
Face-verification information is used only to:
• Verify that the person using the device is the enrolled account holder
• Confirm liveness
• Reduce impersonation
• Protect sensitive approvals and transfers
• Prevent account takeover
Confrmo does not sell face or biometric information.
Confrmo does not use face or biometric information for advertising, tracking, marketing or profiling.
8. FACE DATA AND TRUEDEPTH INFORMATION
Confrmo offers optional face verification to confirm that the person using your device is you.
What We Collect
During a face check, the front camera captures images of your face. On devices with a TrueDepth camera, Apple’s ARKit framework tracks your head position to confirm that you are a live person.
TrueDepth depth information and face geometry are processed temporarily in the device’s memory and are immediately discarded. They are not retained or transmitted.
From a captured face image, Apple’s Vision framework creates a mathematical representation called a feature print. The feature print and a small set of reference face images are retained for future on-device identity matching.
Confrmo does not access or collect the biometric information enrolled in Apple Face ID. Apple does not provide applications with access to a user’s Face ID data.
Purpose
Face data is used only to verify that the person using the device is the enrolled account holder before sensitive actions, including:
• Signing in
• Approving authentication requests
• Approving document-sharing requests
• Approving ownership transfers
• Deleting an account
• Other security-sensitive actions
Face data is also used to prevent spoofing and impersonation using photographs, videos or another person.
Where Face Data Is Stored
The retained feature print and reference images are stored only on the user’s device.
They are encrypted using AES-256-GCM. The encryption key is stored in the device Keychain and never leaves the device.
Face images, feature prints, face templates, TrueDepth information, depth maps and face geometry used by Confrmo’s face-verification feature are not uploaded to Confrmo’s servers.
Sharing
Confrmo does not share face data with anyone.
No third party or third-party software component receives face images, feature prints, templates, depth information or face geometry from Confrmo’s face-verification feature.
Face data is never sold and is never used for advertising, tracking, marketing or profiling.
Retention and Deletion
Retained face data remains on the user’s device until the user deletes it.
Users can delete their face data at any time in the Confrmo app by navigating to:
Profile → Privacy & Data → Face Data → Delete Face Data
Face data is also removed when the user:
• Deletes their Confrmo account through Profile → Privacy & Data → Delete Account; or
• Removes the Confrmo app from the device.
There is no server-side retention period for this face data because it is not uploaded to Confrmo’s servers.
9. IDENTITY DOCUMENTS AND DOCUMENT SHARING
Documents added to Confrmo are used to support identity verification and user-approved document presentation.
Documents are presented only after the user receives and explicitly approves a request.
Participating organisations cannot browse a user’s document wallet or view a document without approval.
The Confrmo “It’s You” service is designed to present an approved document temporarily during an active session. The user or verifier may end that session at any time.
Users should add documents only where they have the legal right to use and present them.
10. SHARING YOUR INFORMATION
Depending on the service being used, we may share non-face personal information with:
• Organisations you choose to interact with through Confrmo
• Identity-verification providers where required
• Cloud-hosting and infrastructure providers
• Fraud-prevention and security services
• Payment providers where applicable
• Professional advisers
• Regulators
• Law-enforcement agencies where disclosure is legally required
Information is shared only where necessary, legally permitted and subject to appropriate safeguards.
The restrictions in Section 8 apply specifically to face data and TrueDepth information. That information is not uploaded to Confrmo and is not shared with these organisations or providers.
We do not sell personal information or licence personal information to advertisers.
11. INTERNATIONAL TRANSFERS
Where information is transferred outside the United Kingdom, we implement appropriate safeguards, which may include:
• The UK International Data Transfer Agreement or UK Addendum
• Transfers to countries covered by UK adequacy regulations
• Approved contractual and organisational safeguards
12. DATA SECURITY
We use technical and organisational measures designed to protect personal information, including:
• Encryption in transit
• Encryption at rest where appropriate
• Secure authentication
• Access controls
• Audit logging
• Security monitoring
• Penetration testing
• Vulnerability management
Although we take reasonable measures to protect personal information, no online system can guarantee absolute security.
13. DATA RETENTION
Except for the on-device face data covered by Section 8, we retain information only for as long as reasonably necessary to:
• Provide the Service
• Satisfy legal and regulatory obligations
• Resolve disputes
• Prevent fraud
• Protect our legal rights
Retention periods vary depending on the type of information, applicable law, regulatory requirements and contractual obligations.
When information is no longer required, it will be securely deleted or anonymised.
Where a ledger record must be retained to preserve an ownership or transaction history, personal identity information may be removed or replaced with an anonymised deleted-account reference.
14. ACCOUNT DELETION
Users can request permanent account deletion directly within the Confrmo application by navigating to:
Profile → Privacy & Data → Delete Account
The account-deletion process explains what will be deleted and requires explicit confirmation and device authentication.
Account deletion removes or anonymises personal account information as appropriate, revokes active sessions and device tokens, deletes on-device face data and signs the user out.
Certain anonymised or legally required records may be retained where necessary to prevent fraud, comply with law or preserve the integrity of ownership and transaction records.
15. YOUR RIGHTS
Subject to applicable law, you may have the right to:
• Access your personal information
• Correct inaccurate information
• Request deletion
• Restrict processing
• Object to processing
• Request portability of your information
• Withdraw consent where processing is based on consent
• Complain to the Information Commissioner’s Office
Withdrawing consent does not affect processing that was lawful before consent was withdrawn.
Requests may be submitted to privacy@confrmo.com.
16. AUTOMATED DECISION MAKING
Confrmo may use automated systems to assist with:
• Fraud detection
• Identity verification
• Authentication risk scoring
• Suspicious-activity monitoring
Where a decision produces legal or similarly significant effects and applicable law requires it, you may request human review.
17. CHILDREN’S PRIVACY
Confrmo is not intended for children unless its use is specifically authorised under applicable law or through a service designed for minors with the required parental or guardian consent.
Confrmo does not currently provide an age-assurance mechanism or parental-control system within the application.
18. COOKIES AND SIMILAR TECHNOLOGIES
Our website may use cookies and similar technologies to:
• Remember user preferences
• Improve website performance
• Understand service usage
• Protect the website and Service
Additional information may be provided through our cookie notice or Cookie Policy.
19. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes to the Service, our processing activities or applicable law.
Material changes will be communicated through the Service or by other appropriate means.
The “Last Updated” date at the beginning of this policy identifies when it was most recently revised.
20. CONTACT US
If you have questions about this Privacy Policy or how Confrmo processes personal information, please contact:
Privacy Team
Confrmo Ltd
Email: privacy@confrmo.com
Website: https://www.confrmo.com/
21. COMPLAINTS
If you believe we have not handled your personal information correctly, please contact us using the details above so that we can investigate your concern.
You also have the right to complain to the Information Commissioner’s Office if you believe your personal information has been processed unlawfully.
Information about the Information Commissioner’s Office is available at:
https://ico.org.uk/