Because biometric data is treated as a special, higher-risk category of personal data under UK GDPR, EU GDPR, and biometric privacy laws in certain other jurisdictions (including parts of the United States), we apply the following additional protections.
5.1 What counts as biometric data
For the purposes of this Policy, "Biometric Data" means:
- The Selfie image or video you provide
- The photograph and any facial image stored on your identity document
- Any facial geometry scan, facial template, or similar mathematical representation generated by comparing the two
- Any data read from the NFC chip embedded in your passport that is used to verify the document's authenticity
5.2 Standalone consent
Before we collect or process any Biometric Data, you will be shown a dedicated consent screen, separate from your general acceptance of these Terms and this Policy. We will not proceed with biometric verification unless you actively confirm your consent on that screen. You may decline, in which case alternative verification methods may be offered where available, or you may be unable to complete verification.
5.3 How Biometric Data is used
Biometric Data is used exclusively to: compare your Selfie against your identity document to confirm they depict the same individual; confirm the authenticity of your identity document via NFC chip verification; and detect signs of document tampering, forgery, or impersonation.
We do not use Biometric Data for any other purpose, including marketing, profiling, or advertising. We do not sell, lease, trade, license, or otherwise profit from your Biometric Data.
5.4 Retention and deletion of Biometric Data
The facial geometry scan generated for comparison purposes is deleted automatically within 72 hours of a successful or unsuccessful verification attempt, once the comparison has been completed.
Your Selfie image and the image of your identity document are retained for as long as your TrvlEz account remains active, and for 12 months after account closure or your last platform activity, whichever is later, unless a longer period is required to comply with a legal obligation, resolve a dispute, or investigate suspected fraud.
NFC chip verification data confirming document authenticity is retained for the same period as the document image above. The raw chip data itself is not retained beyond the verification session; only the verification result (pass or fail) is stored.
You may request earlier deletion of your Biometric Data at any time, as described in Section 5.5, save where we are required to retain it by law or where retention is necessary to defend against a legal claim.
5.5 Withdrawing consent and requesting deletion
You may withdraw your consent to biometric processing, and request deletion of your Biometric Data, at any time by using the "Delete my identity data" function within the app, or contacting privacy@trvlez.io.
We will process your request within 30 days. Please note that withdrawing consent or deleting your Biometric Data will mean you can no longer use TrvlEz's verification-based check-in features, and any previously verified status will be revoked.
5.6 No automated biometric decision-making without review
Where a facial comparison results in a failed match, you will always be offered the option of manual review by a human member of our verification team before any final decision is made about your account or access to the Platform.