1. Who We Are

AuthentiKate, Inc. ("AuthentiKate," "we," "us," or "our") is a Delaware C-corporation. We operate an anti-impersonation verification platform built on CKY (Customer Knows You): a system that allows people to confirm whether someone contacting them is genuinely who they claim to be, using a short-lived code only a verified figure can produce.

We operate two apps:

This policy also covers our website at authentikate.com. Business and enterprise use is governed by separate agreements.

Data Controller contact: privacy@authentikate.com

2. The Two Apps Have Very Different Data Profiles

2.1 AuthentiKate — Consumer App

When you use the consumer app:

In practical terms: we do not know who you are, and we have no way to find out from the data we hold.

2.2 AuthentiKate Verified — Figure App

This is where our substantive data-controller obligations arise. To become a verified figure, you must provide:

2.3 Website

When you visit authentikate.com, our hosting infrastructure (Google Cloud Platform via Cloud Run) receives standard server logs including IP address, browser type, and pages accessed. Cloudflare acts as our DNS and CDN provider and processes request metadata for security and performance purposes. We use PostHog for product analytics on the website and Verified app; PostHog is configured to collect aggregate usage data only — we do not use it to build profiles of individual users on the consumer surface, and the consumer app does not include PostHog or any analytics SDK.

3. How We Use Your Information

3.1 AuthentiKate Verified — Figures

3.2 Website Visitors

We do not send unsolicited marketing emails. We do not run advertising on or around our services. We do not use your data to build advertising profiles or sell data to third parties.

4. Legal Bases for Processing (GDPR)

For users in the European Economic Area (EEA), we rely on the following legal bases under GDPR Article 6:

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights — particularly because we collect the minimum data necessary for each purpose and implement strong privacy protections by design.

5. KYC and Identity Verification Data

Identity verification for AuthentiKate Verified is performed by Veriff, our third-party KYC provider. When you undergo verification:

Liveness checks are triggered by Veriff only at specific security-event moments (initial verification, account recovery, biometric configuration change on a device). They are not performed routinely.

6. Data Retention

We retain data only as long as necessary for the purpose for which it was collected, or as required by law. Key retention periods:

Where an account is deleted, we redact personally identifiable information (name, email, and other PII are replaced with an anonymized tombstone record). Audit log rows remain to preserve the integrity of the event record but no longer resolve to identifiable individuals. This approach satisfies GDPR Article 17 and is consistent with the legitimate-interest exception under Article 17(3)(b) for fraud detection and legal defence.

7. How We Share Your Information

We share information only in these limited circumstances:

7.1 Subprocessors

We engage third-party service providers who process data on our behalf and are contractually bound to use it only for the purposes we specify. Our current subprocessors are:

7.2 Business Transfers

If AuthentiKate is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will provide reasonable notice before your information is transferred and becomes subject to a different privacy policy.

7.3 Legal Requirements

We may disclose information if required to do so by applicable law, court order, or valid governmental request. Where legally permitted, we will notify you before disclosing.

7.4 Protection of Rights

We may disclose information when reasonably necessary to prevent fraud, enforce our Terms of Service, or protect the safety of users or the public.

8. International Data Transfers

AuthentiKate, Inc. is based in the United States. Our primary infrastructure operates on Google Cloud Platform in the US. If you are in the European Economic Area (EEA) and use AuthentiKate Verified, your personal data is transferred to the United States for processing.

We rely on the following transfer mechanisms for EEA-to-US transfers:

You may request a copy of the relevant safeguards by contacting us at privacy@authentikate.com.

9. Your Privacy Rights

Your rights depend on where you are located. We honor all of the following regardless of which legal regime applies to you.

9.1 Rights Available to All Users

9.2 Additional Rights Under GDPR (EEA Users)

9.3 California Residents (CCPA/CPRA)

California residents have the following rights under CCPA/CPRA:

California residents may also designate an authorized agent to make requests on their behalf.

9.4 Other US States

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), and other states with comprehensive privacy laws have similar rights to access, correction, deletion, portability, and opt-out of sale. Contact us to exercise these rights.

9.5 A Note for Consumer App Users

Because the consumer app does not collect personal information about you, there is generally no personal data for us to access, correct, or delete on your behalf. Your on-device verification history is controlled entirely by you through your device's app settings.

9.6 Exercising Your Rights

To exercise any of the above rights, contact us at privacy@authentikate.com. We will respond within 30 days (45 days with notice if additional time is required).

10. Data Security

We take security seriously, and the architecture of our platform reflects that:

No system is completely secure. In the event of a data breach that affects your rights and freedoms, we will notify affected users and relevant authorities as required by applicable law.

11. Children's Privacy

Our services are not directed to children. We do not knowingly collect personal information from:

If you believe we have inadvertently collected information from a child under the applicable age threshold, please contact us at privacy@authentikate.com and we will delete that information promptly.

The AuthentiKate Verified app requires identity verification through Veriff, which includes age verification. It is not accessible to minors.

12. Do Not Track

There is no widely accepted technical standard for "Do Not Track" browser signals. We do not respond to DNT signals. However, we do not engage in cross-site tracking of any kind, and the consumer app contains no tracking technology whatsoever.

13. Links to Third-Party Services

Our website and apps may contain links to third-party services (for example, social platforms associated with verified figures). This Privacy Policy does not apply to those services. We encourage you to review the privacy policies of any third-party services you use.

14. Enterprise and Business Use

Use of AuthentiKate by businesses, talent agencies, industry bodies, and enterprise customers is governed by separate agreements, which include applicable data processing addenda. If you are an enterprise customer or prospective partner, contact sales@authentikate.com.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

We encourage you to review this policy periodically. Continued use of our services after changes are posted constitutes acceptance of the revised policy, to the extent permitted by law.

16. Contact

For users in the EEA, if you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with your national supervisory authority. You may also contact us first so we have the opportunity to resolve the matter directly.