1. Who We Are

AuthentiKate, Inc. ("AuthentiKate," "we," "us," or "our") is a Delaware C-corporation. We operate an anti-impersonation verification platform built on CKY (Customer Knows You): a system that allows people to confirm whether someone contacting them is genuinely who they claim to be, using a short-lived code only a verified figure can produce.

We operate two apps:

This policy also covers our website at authentikate.com. Business and enterprise use is governed by separate agreements.

Data Controller contact: privacy@authentikate.com

2. The Two Apps Have Very Different Data Profiles

2.1 AuthentiKate — Consumer App

When you use the consumer app:

In practical terms: we do not know who you are, and we have no way to find out from the data we hold.

2.2 AuthentiKate Verified — Figure App

This is where our substantive data-controller obligations arise. To become a verified figure, you must provide:

2.3 Website

Our website (authentikate.com) is served from Cloudflare Pages, not our Cloud Run backend. Cloudflare keeps standard access logs for the site — IP address, browser type, and pages accessed — retained for 30 days, and separately acts as our DNS and CDN provider, processing request metadata for security and performance purposes.

The Contact and Claim Your Name forms on this website collect the name and email address you provide, plus (Contact) your company and how we can help, or (Claim Your Name) the public name you're claiming and your relationship to it, along with any free-text message you add. Submissions are relayed as a single email to our team via the Resend API — they are not written to a database.

3. How We Use Your Information

3.1 AuthentiKate Verified — Figures

3.2 Website Visitors

We do not send unsolicited marketing emails. We do not run advertising on or around our services. We do not use your data to build advertising profiles or sell data to third parties.

4. Legal Bases for Processing (GDPR)

For users in the European Economic Area (EEA), we rely on the following legal bases under GDPR Article 6:

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights — particularly because we collect the minimum data necessary for each purpose and implement strong privacy protections by design.

5. KYC and Identity Verification Data

Identity verification for AuthentiKate Verified is performed by Veriff, our third-party KYC provider. When you undergo verification:

Liveness checks are triggered by Veriff only at specific security-event moments (initial verification and account recovery). They are not performed routinely.

6. Data Retention

We retain data only as long as necessary for the purpose for which it was collected, or as required by law. Key retention periods:

Where an account is deleted, we redact personally identifiable information (name, email, and other PII are replaced with an anonymized tombstone record). Audit log rows remain to preserve the integrity of the event record but no longer resolve to identifiable individuals. This approach satisfies GDPR Article 17 and is consistent with the legitimate-interest exception under Article 17(3)(b) for fraud detection and legal defence. The retention periods above describe our live database; data removed from it can also persist for up to 7 days in encrypted database backups taken for disaster-recovery purposes, until that backup is rotated out.

7. How We Share Your Information

We share information only in these limited circumstances:

7.1 Subprocessors

We engage third-party service providers who process data on our behalf and are contractually bound to use it only for the purposes we specify. Our current subprocessors are:

7.2 Business Transfers

If AuthentiKate is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will provide reasonable notice before your information is transferred and becomes subject to a different privacy policy.

7.3 Legal Requirements

We may disclose information if required to do so by applicable law, court order, or valid governmental request. Where legally permitted, we will notify you before disclosing.

7.4 Protection of Rights

We may disclose information when reasonably necessary to prevent fraud, enforce our Terms of Service, or protect the safety of users or the public.

8. International Data Transfers

AuthentiKate, Inc. is based in the United States. Our primary infrastructure operates on Google Cloud Platform in the US. If you are in the European Economic Area (EEA) and use AuthentiKate Verified, your personal data is transferred to the United States for processing.

We rely on the following transfer mechanisms for EEA-to-US transfers:

You may request a copy of the relevant safeguards by contacting us at privacy@authentikate.com.

9. Your Privacy Rights

Your rights depend on where you are located. We honor all of the following regardless of which legal regime applies to you.

9.1 Rights Available to All Users

A note on verified figures and on-device history: Your on-device verification history is a personal record of your own past interactions — it is not a live connection to a figure's current profile. If a figure updates their profile, is suspended, or has their account deleted, entries already stored on your device are not updated or removed to reflect that change; they remain a snapshot of the figure's status at the moment you verified them, similar to a dated receipt. Because this history lives solely on your device and we never receive it, we have no way to reach, alter, or delete it as part of a figure's data request.

9.2 Additional Rights Under GDPR (EEA Users)

9.3 California Residents (CCPA/CPRA)

California residents have the following rights under CCPA/CPRA:

California residents may also designate an authorized agent to make requests on their behalf.

9.4 Other US States

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws have similar rights to access, correction, deletion, portability, and opt-out of sale. Contact us to exercise these rights.

9.5 A Note for Consumer App Users

Because the consumer app does not collect personal information about you, there is generally no personal data for us to access, correct, or delete on your behalf. You control your on-device verification history directly in the app: the History screen lets you delete a single entry or clear all history at once, on both iOS and Android. Uninstalling the app also removes it. Clearing history in the app stops it from being included in any future device backup, but does not reach a copy already captured in a backup taken before you cleared it.

9.6 Exercising Your Rights

To exercise any of the above rights, contact us at privacy@authentikate.com. We will respond within 30 days (45 days with notice if additional time is required).

10. Data Security

We take security seriously, and the architecture of our platform reflects that:

No system is completely secure. In the event of a data breach that affects your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.

11. Children's Privacy

Our services are not directed to children. We do not knowingly collect personal information from:

If you believe we have inadvertently collected information from a child under the applicable age threshold, please contact us at privacy@authentikate.com and we will delete that information promptly.

The AuthentiKate Verified app requires identity verification through Veriff, which includes age verification. It is not accessible to minors.

12. Do Not Track

There is no widely accepted technical standard for "Do Not Track" browser signals. We do not respond to DNT signals. However, we do not engage in cross-site tracking of any kind, and the consumer app contains no tracking technology whatsoever.

13. Links to Third-Party Services

Our website and apps may contain links to third-party services (for example, social platforms associated with verified figures). This Privacy Policy does not apply to those services. We encourage you to review the privacy policies of any third-party services you use.

14. Enterprise and Business Use

Use of AuthentiKate by businesses, talent agencies, industry bodies, and enterprise customers is governed by separate agreements, which include applicable data processing addenda. If you are an enterprise customer or prospective partner, contact sales@authentikate.com.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

We encourage you to review this policy periodically. Continued use of our services after changes are posted constitutes acceptance of the revised policy, to the extent permitted by law.

16. Contact