Privacy Policy
This Policy explains how Third Factor Authentication Inc. (“Autenti.ca”, “we”) — a Canadian corporation with its head office at 306 East 26th Street, Hamilton, Ontario, L8V 3E1, Canada — handles personal data on the autenti.ca website and in the Autenti.ca platform used by schools. It is written to meet Brazil's Lei Geral de Proteção de Dados (LGPD, Lei nº 13.709/2018) and Canada's federal privacy law (PIPEDA).
1. Roles: who answers for what
- School community data (students, guardians, staff) processed in the platform: the School is the controller and we are the processor/operator, handling data on the School's instructions under the Data Processing Addendum in the Terms of Service. Requests about this data should go first to the School — and we help it respond.
- We are the controller for: data about visitors to this website; contact and billing data of School administrators; and training images retained with specific consent (section 5).
- Stripe (our payment processor at checkout) is an independent controller of payment data — section 6.
2. What data we process
- Palm biometric templates — protected, irreversible mathematical representations of the palm (vein pattern and palmprint). We do not store an image of the hand for recognition: the protected template cannot be used to reconstruct it and can be revoked and replaced at any time.
- Encrypted palm images — only with the specific, separate consent described in section 5.
- School identification data — student name, class and identifier, provided by the School.
- Attendance events — date and time of recognitions, terminal used and outcome.
- Guardian contact details — WhatsApp number for arrival notifications and the consent flow.
- Administrative data — name, email and credentials of School administrators; billing data.
- Technical records — application access logs (Marco Civil da Internet, art. 15) and error diagnostics without personal identifiers.
- Website cookies — analytics only, with consent (section 12).
3. Children and adolescents
Biometric data is sensitive personal data (LGPD, art. 5(II)) and most data subjects in the platform are children and adolescents — so the processing is designed around the best interest of the minor (LGPD, art. 14; ECA):
- Biometric enrollment happens only with the specific, highlighted consent of at least one parent or legal guardian (arts. 11(I) and 14 §1), collected by the School — for example via the platform's WhatsApp flow, which records the response.
- Consent is free: using biometrics is never a condition of enrollment or of taking part in school life. Students without consent — or who choose to stop — have their attendance recorded manually by the teacher, a feature included in the platform, with no detriment.
- Withdrawing is as easy as granting: just reply on the same WhatsApp. Once consent is withdrawn, the biometric template is deleted (timelines in section 8).
- We do not use student data for advertising or commercial profiling, consistent with the LGPD and with Lei nº 15.211/2025 (Brazil's Digital ECA).
For you, the student: the reader at school recognizes the pattern of veins in your hand to record that you arrived. We keep only a scrambled code — not a photo of your hand — and nobody can turn that code back into a picture. Using your palm is your and your family's choice: you can stop whenever you want by messaging the school's WhatsApp, and your teacher will mark your attendance the regular way.
4. Purposes and legal bases
- Recognition and attendance — consent of parents or guardians (LGPD, arts. 11(I) and 14 §1).
- WhatsApp notifications to families — the same consent, explained when it is given.
- Gamification and engagement — class points and achievements derived from attendance events, in the student's interest and under the same consent; no rankings that expose individual absences.
- Administrator accounts and billing — performance of a contract (LGPD, art. 7(V)) and legal obligations.
- Security, logs and abuse prevention — legal obligation (Marco Civil, art. 15) and legitimate interest for non-sensitive data.
- Model improvement — specific, separate consent (section 5).
5. Images for model improvement (optional)
With the additional, separate, revocable consent of parents or guardians, we retain encrypted palm images to train and improve our recognition models. For that processing, Autenti.ca is the controller. The rules:
- it is an opt-in per student — without this consent no images are retained and the platform works normally;
- the images are encrypted with segregated keys and are never used for advertising or shared with third parties;
- for training, the images are transferred to Canada and processed there by Autenti.ca — an international transfer disclosed before consent is given and covered by it (LGPD, art. 33(VIII)), under the same encryption and retention limits;
- maximum retention of 3 years from capture — or less, if the student leaves the school or consent is withdrawn;
- withdrawal (via WhatsApp or through the School) deletes the student's images, including from backups, within the timelines in section 8.
6. Sharing and sub-processors
We do not sell personal data. We share only with:
- Google Cloud — platform hosting in the São Paulo (Brazil) region; website infrastructure.
- Meta (WhatsApp) — delivery of notifications and the consent flow; Meta receives the phone numbers and message content needed for that delivery.
- Stripe — checkout payment processor, as an independent controller: it receives name, email, billing address, payment details and CPF/CNPJ (required for Pix). See Stripe's Privacy Policy.
- TRST Tecnologia Ltda (CNPJ 64.966.968/0001-50, Brasília – DF) — responsible for sales and billing in Brazil: it receives Brazilian Schools' contact and billing data for invoicing and Brazilian tax documents.
- Sentry — software error diagnostics, receiving technical data only; our systems strip personal identifiers before sending, and biometric data is never sent.
- Authorities — where required by law or court order, to the extent required.
7. International data transfers
Public international-transfer notice (Resolução CD/ANPD nº 19/2024): the platform's personal data is stored in Brazil (Google Cloud, São Paulo region). Our support and engineering team, located in Canada, may access data remotely to operate and support the platform. Canada does not have an ANPD adequacy decision; this transfer is covered by the ANPD standard contractual clauses, incorporated into our contract with each School. The full text of the clauses is available to any data subject on request from ola@autenti.ca. Training images (section 5) are transferred to Canada on the basis of the parents' or guardians' specific, highlighted consent, given after prior notice of the international character of the operation (LGPD, art. 33(VIII)).
Transparency required by Canadian law: data accessed from Canada may be subject to lawful requests from Canadian authorities. Payment data is handled by Stripe under its own policy; Sentry's technical diagnostics (without personal identifiers) are processed in the United States.
8. How long we keep data
- Biometric templates — deleted within 30 days of consent withdrawal, the student leaving, or the School's instruction; recognition stops immediately.
- Training images (opt-in) — maximum 3 years from capture; deleted earlier on withdrawal or when the student leaves.
- Backups — copies expire within 35 days of deletion of the primary data.
- Attendance events and school records — kept for the duration of the contract, under the School's control; returned or deleted within 60 days after it ends.
- Application access logs — 6 months (Marco Civil, art. 15).
- Security and audit logs — 12 months.
- Consent records — for as long as the processing lasts and for 5 years after, as evidence of compliance.
- Billing data — 7 years (Canadian tax obligations).
- Error diagnostics — 90 days.
9. Security
Measures aligned with LGPD art. 46: biometric template protection (protected, revocable, irreversible templates), encryption at rest and in transit, segregated keys for training images, role-based access control, per-institution segregation, and audit logging of administrative operations.
10. Security incidents
Incidents that may create relevant risk or harm are reported to the School within 3 business days of our becoming aware, with the information needed for notifications to the ANPD and to data subjects (Resolução CD/ANPD nº 15/2024). Where we act as controller, we make those notifications ourselves.
11. Your rights
Every data subject (or their legal guardian) can exercise the rights in LGPD art. 18:
- confirmation that processing exists, and access to the data;
- correction of incomplete, inaccurate or outdated data;
- anonymization, blocking or deletion of unnecessary or excessive data;
- portability, as regulated;
- deletion of data processed on the basis of consent;
- information about sharing and about the option not to consent;
- withdrawal of consent, at any time and free of charge.
For school community data, direct your request first to your School (the controller) — and count on us too: we also receive requests at ola@autenti.ca and forward them. You may also petition the ANPD (gov.br/anpd). In Canada, PIPEDA's access and complaint rights apply, before the Office of the Privacy Commissioner of Canada (priv.gc.ca).
12. Cookies on this website
We use only Google Analytics 4 analytics cookies
(_ga, _ga_CF3TPCTM9V), which collect
aggregated browsing data without identifying individuals.
No advertising or cross-site tracking cookies are used.
We implement Google Consent Mode v2 defaulting to denied: on your first visit Google Analytics runs cookieless; analytics cookies are only set if you click Accept on the cookie notice. You can change your choice at any time:
13. Communications and marketing
Operational messages (arrival notifications, consent, billing) are part of the Service. We may send informational or marketing communications to School contacts; every message identifies the sender and includes an immediate unsubscribe option, honoured within 10 days (LGPD and Canada's anti-spam law — CASL).
14. Data Protection Officer and contact
Our data protection officer (LGPD, art. 41 encarregado) and Privacy Officer (PIPEDA) is Carlos José Gonçalves Vidal — ola@autenti.ca · Third Factor Authentication Inc., 306 East 26th Street, Hamilton, Ontario, L8V 3E1, Canada. He responds in Portuguese and English.
15. Changes to this Policy
Material changes are announced on this page at least 30 days in advance, and where the legal basis is consent we offer a fresh opportunity to decide. The date of the last update appears at the top.