Privacy Policy

1. WHO WE ARE

PPAC Solutions LTD ("PPAC", "we", "us", "our") is a digital verification and identity UK company registered in England and Wales, registered number 10161579. This Privacy Notice explains the way in which PPAC handles your personal data whilst using its services and engaging with us. PPAC is committed to ensuring privacy and security are at the core of our product development and products. You can learn more about our values and approach on our website.

Our registered office is at 11 West Street, Epsom, England, KT18 7RL and is the address used for any formal contact. You can also contact us to enquire further about how your data is being used at dpo@ppac.co.uk or for complaints, disputes or any other communication please see the section on communications within this policy.

PPAC is registered with the ICO as a data controller and our registration number is ZA207961. PPAC may act as both the data controller and data processor. A full breakdown of responsibilities is covered in this Notice, however PPAC operates as the Data Controller with respect to the service and development of the product. PPAC Clients who initiate the request for you to share the data for are the Data Controllers for each check being requested.

PPAC commits to upholding GDPR Principles and we ensure to only collect the data required to provide the services to you and our clients and will not share or use your data for any reason other than to provide the services as detailed in this Notice.

2. HOW TO CONTACT OUR DATA PROTECTION OFFICER

We have appointed a Data Protection Officer (DPO) who oversees how we handle personal data. You can contact our DPO directly about anything in this notice, about any rights request, or about any concern or questions you might have:

DPO contact details:

Our standard commitment is to respond within 10 working days of your request to acknowledge your communication and resolution of your request within the statutory period defined under GDPR. In exceptional or complex cases, we may need up to the full statutory period permitted under UK GDPR (one calendar month, extendable by up to two further months) and we will notify you and explain why.

3. PPAC AS A DATA CONTROLLER

Data Subject/ActorData TypeDescriptionLawful Basis
PPAC ClientsName, role, work email address, work telephone number, and the organisation you work for, account credentials and activity.In order to provide our services to you as our clients, billing, communication and account management.We rely on performance of a contract (with your organisation, to which you are linked through your role) or legitimate interests when initially setting up our engagement.
Website visitors and mobile app userse-mail address, IP address, browser type and version, length of visit. Cookies (if accepted), contact information for communication and engagement if you complete our form.Data is captured to ensure accuracy of the website and product alongside statistical data. Website analytical data is retained for up to 14 months and security logs for up to 12 months.Legitimate Interest to improve the services and website and consent when visiting the website alongside communication and engagement with you if you fill out our contact us requests.
Website VisitorsName, E-mail, Account data if you set up an account with PPACTo ensure PPAC can maintain, secure and provide you with an account.Performance of a Contract and Legitimate Interest.
PPAC Clients and Potential ClientsContact details, transaction details and business needs. Payment details.Management and processing of business transactions relevant to the service and payment for services.Legitimate Interest to provide you with a contact and support for an enquiry or query regarding the service and through fulfilling our Contract for payment.
Job Applicants and employees of PPACSpecifically covered within applicant and employee privacy notice.Please refer to the applicant and employee privacy notice.Please refer to the applicant and employee privacy notice.
Data Subjects/PPAC ClientContact details, complaint, query or requestSpecifically to complete data subject and client support and help desk requests and to provide necessary actions for GDPR.Legitimate Interest to provide a service to you and to complete any GDPR requests or respond to complaints or disputes.

3.1 WHO HAS ACCESS TO YOUR INFORMATION?

PPAC ensures all data collected through the service is only used for the purposes defined within this Notice. PPAC uses a number of sub-processors to support our Service and to support the delivery of these Services. A full list of all sub-processors can be provided upon request, however a list of main sub-processors has been provided below in this Notice.

Specifically PPAC may disclose your personal data where the disclosure is required for compliance with a legal obligation of which PPAC is subject to. PPAC will never sell your personal data or information to third parties, use it for marketing purposes or for training any AI models.

PPAC commits to ensuring all Personal Data remains and is processed not only by PPAC but our sub-processors within the UK and EEA. No Personal Data is transferred outside the UK and EEA. Where this may occur in the future, PPAC will notify our Clients and ensure appropriate security and data transfer controls and agreements are in place prior to starting the data transfer.

3.2 HOW LONG IS DATA RETAINED

PPAC operates on the basis that any Personal Data is only kept for the length of time necessary to complete the purpose or purposes for which it was provided, or if required to comply with a legal obligation. If you have provided your information directly to PPAC either through the website or as a potential candidate for example, PPAC will have defined retention schedules for that data depending on how it was gathered and the use case. Where PPAC acts as a data processor, our clients as the data controllers set the retention period for your data which was provided as part of the service and you should contact them for any data access requests.

4. PPAC AS A DATA PROCESSOR

PPAC acts as a Data Processor on behalf of our Clients/Relying Parties where we process data under their instruction. It is our Clients responsibility to ensure an appropriate Lawful Basis has been determined and where required consent has been given.

Where you have been directed to use PPAC services, the Client who has engaged PPAC to conduct the service is the Data Controller of your personal data and has instructed PPAC to complete a specific service and process your data on their behalf. If you have any questions regarding the processing of this data and why beyond this Privacy Notice you should refer to their privacy notice or contact details.

PPAC Clients may instruct us to provide our services which requires us to use your personal data, acting under instruction from them as the data controller and in accordance with this Privacy Notice and applicable data protection legislation, to ensure PPAC can provide the services. Some of the types of personal data we may process when providing this service include:

  • Identification data – name, date of birth, address history, contact details, employment screening and background check data, ID Documents and their image capture.
  • Special Category Data – Specifically biometric data regarding your image on the ID Document and a capture of your face which constitutes biometric data and for use to verify your identity. Full details of our use of biometrics can be found in our Biometric Notice here.

PPAC offers a number of services to our Clients and depending on the check will require a combination of your personal data. The below details break down where each check is relevant and defined roles and requirements.

4.1 IF YOU ARE AN END USER OF OUR IDENTITY VERIFICATION SERVICE

This section applies to you if your identity is being verified through our service - for example, because a UK employer or another organisation has asked you to prove your identity or your right to work, and they use our service to do that.

4.1 What personal data we collect about you

CategoryExamples
Identity evidenceYour passport, ID or any other identity document (including the personal details printed on it, the document's machine-readable zone, and the photograph or face image)
Photographs and a short live capture (selfie / liveness video)An image of your face captured during the verification process; liveness detection used to confirm that the image is of a live person and not a printed photo or video replay
Biometric dataMathematical templates derived from your face image and used to compare the live capture to your identity document photograph. This is special category personal data under UK GDPR Art. 9 and we explain its handling carefully through our Biometric Notice provided during the check and capture explicit consent for process your biometric data.
Personal detailsName, date of birth, nationality, place of birth, contact details, address and other information that appears on your identity evidence or that you enter into the verification flow
Right to Work information (where applicable)Your nationality and immigration status as evidenced by your document, the share code or related information you provide, and any check we perform with the Home Office Employer Checking Service
Verification result and confidence levelsThe outcome of the checks we perform (pass / fail / refer) and the levels of confidence we associate with the identity (under GPG 45)
Activity and technical dataThe date and time of the verification, the device characteristics (browser, operating system), the IP address, error events, and audit records - used to detect fraud and to evidence the integrity of the verification

4.2 Why we use your personal data

  • To verify your identity to the level required by the organisation that asked us (for example, a UK employer for a right to work check);
  • To detect and prevent identity fraud;
  • To provide the organisation that asked us with a result they can rely on (a confidence score and the categories of evidence used), and where applicable right to work digital evidence;
  • To meet our legal and regulatory obligations including completing data subject access requests and responding to requests from public bodies or law enforcement such as the ICO;
  • To handle complaints and disputes;
  • To improve the security and accuracy of our service (this includes statistical performance measurement of the biometric component, on aggregated and deidentified data wherever practicable).

4.3 Our lawful basis

We rely on different lawful bases for different categories of data.

Data categoryUK GDPR lawful basisNotes
Ordinary personal data (name, DOB, address, document details, contact)Art. 6(1)(f) Legitimate Interests (to perform identity verification services under contract with the relying party)PPAC Clients as the Data Controller are required to identify their own lawful basis for initiating the check and handling your personal data.
Special category - biometric data used for identificationArt. 9(2)(a) explicit consent, which we ask for before your check begins (see section 3.5). Your explicit consent also provides the basis for the automated decision making described in section 3.5 (Art. 22(2)(c))Our use of biometric data is necessary, proportionate and is supported by a Data Protection Impact Assessment (Art. 35) and appropriate controls and measures.
Verification logs and fraud indicatorsArt. 6(1)(f) legitimate interests for prevention of fraud. Where these involve criminal conviction or fraud offence data, we also rely on Art. 10 with a condition in DPA 2018 Schedule 1 Part 2 paragraph 14 (preventing fraud).

4.4 What we do with your biometric data specifically

We handle biometric data carefully and with specific considerations because it is special category personal data under UK GDPR. Full details on the use of your biometric can be seen within our Biometric Notice which is given to data subjects prior to the capture of any biometric data.

4.5 Automated decision making

You have the right to contest a decision and obtain human intervention. If your verification fails, you can contest the result and obtain a review by a trained compliance reviewer who has authority to overturn the decision. You can do this through the dispute option shown at the point of failure, or through any of the contact channels in section 12; your request is handled under our Contested Result Review Procedure. A pass result is only ever issued after a compliance reviewer has confirmed it.

Parts of our verification service are automated. When you complete a check, our systems automatically examine your identity document, compare your facial biometrics with the photograph in the document, and confirm that a real person is present. If these automated checks identify a clear problem, for example a document that fails authenticity checks, your verification may be declined without a person being involved at that stage. Successful verifications are always confirmed by a trained member of our compliance team before the result is issued.

An automated decline is never the end of the process. If your verification is declined, you can:

  • correct and resubmit your check at the point of failure, for example where the problem was caused by a data entry issue or a poor quality image;
  • ask for your case to be reviewed by a trained human reviewer, who will examine the evidence and can confirm or overturn the automated outcome; and
  • share any information you think we should take into account, and contest the outcome, by contacting our DPO (section 2).

The result of your check is provided to the organisation that requested it, which makes its own decisions based on that result, for example in relation to your employment. Our verification service supports right to work checks and is intended for people of working age (16 or over); we do not knowingly carry out checks on, or process the personal data of, children below that age.

Because these checks rely in part on your biometric data, we only carry them out with your explicit consent, which we ask for before your check begins. The safeguards above reflect your rights under UK GDPR in relation to automated decision making (Article 22).

5. IF YOU HAVE APPLIED FOR A JOB WITH US

If you've applied for a role with PPAC, our handling of your application is covered in the Candidate Privacy Notice which sits inside our Recruitment Policy and which you receive at the point of application. Should you require a copy of this please let us know using the contact details within this Notice or on our website.

6. WHERE WE SEND YOUR DATA AND WHO WE SHARE IT WITH

6.1 Within PPAC

Within PPAC, your personal data is accessed only by the people whose role requires it and to ensure our service can be completed. We operate an information security management system certified to ISO/IEC 27001:2022 (certificate no. 240293) and our internal access controls are described in our policies.

6.2 With our processors and suppliers

We use carefully selected suppliers who process personal data on our behalf, under written contracts that include the data protection terms required by UK GDPR Art. 28. The main categories of supplier are:

Supplier roleWhat they doWhere they process data
Cloud hosting (AWS)Hosts the services on which our identity verification runs.Within the UK / EEA region(s)
Regula (biometric software licensor)Provides the Regula Document Reader SDK and Regula Face SDK that we run inside our own environment; PPAC (not Regula) operates the document recognition and biometric matching. Regula Forensics Inc receives only license-usage telemetry (a transaction counter) - no personal data.Regula SDKs run in PPAC's AWS region; license-usage telemetry only to Regula Forensics Inc in the United States - see section 5.4.
Productivity and collaboration (Microsoft 365, GitHub)Operates our internal email, collaboration and source code platforms. No data subject personal data is stored.Per the relevant supplier's processing locations
Fraud prevention (CIFAS)Uses information from our service to help prevent identity fraud in line with the CIFAS scheme of which we are a member; further details at www.cifas.org.uk/fpnWithin the UK
Professional services (legal, accounting, audit, screening providers)Provide professional services we need to operate compliantlyPrimarily the UK; we tell you if anything material changes

6.3 With regulators and law enforcement

  • We may share data with the UK Information Commissioner's Office (ICO), the Office for Digital Identities and Attributes (OfDIA), our Conformity Assessment Body (CAB), or other regulators and law enforcement bodies where we are required by law or where we lawfully decide to do so for the prevention or detection of fraud or other crime;
  • We may submit Suspicious Activity Reports to the National Crime Agency under the Proceeds of Crime Act 2002 where the law requires;
  • We do not share your personal data with marketing partners; we don't sell personal data or use beyond the requirement and processes defined in this privacy notice.

6.4 International transfers

PPAC does not transfer your data outside of the UK/EEA. Personal data remains strictly within the UK/EEA. Non-personal license telemetry is sent to Regula in the US as described in Section 6.2

7. HOW LONG WE KEEP YOUR DATA

We keep personal data only for as long as we need it, considering the purpose we collected it for and any legal obligation that applies to us. The high-level retention periods are below; we operate a full data retention and GDPR compliant data management process internally to ensure data minimisation and your rights are protected.

CategoryTypical retention
End-user identity verification records (excluding biometric templates and raw biometric media)Up to seven (7) years from the date of the verification, or longer if required by the contract with the organisation that engaged us or by law (e.g., Right to Work record keeping)
Biometric templates, reference vectors and raw biometric media used in the verificationMaximum of two (2) years following account inactivity, then securely deleted; retention justified in our biometric DPIA
Right to Work evidence (UK)Per UK Home Office guidance - typically duration of employment plus two (2) years; held by the employer who engaged us as the data controller who sets the retention period.
Customer / relying party contact recordsDuration of the relationship plus six (6) years
Suppliers contact recordsDuration of the engagement plus six (6) years
Website analyticsUp to 14 months
Website security logsUp to 12 months unless extended for security or legal reasons
Job applications (unsuccessful)Six (6) months after the role is filled (or two (2) years with your consent)
Personnel records (staff)Duration of employment plus six (6) years
Financial records (invoices, payments)Six (6) years from the end of the financial year to which they relate
Records required by the UK DVSTF certification / OfDIAPer the certification's record keeping requirements

8. YOUR RIGHTS

Under UK GDPR and the Data Protection Act 2018 you have rights over the personal data we hold about you. If we process your data in our capacity as Data Processor, we will meet our requirements under Data Protection Law to support the Data Controller and pass on your request to them as the Controller of your data. Where PPAC is the Data Controller of your personal data we will ensure your rights are completed. They are summarised below - you can find more on the ICO website (www.ico.org.uk).

To exercise any of these rights, contact our DPO (section 2). PPAC will aim to complete your request within the requirement of one month although complex or excessively large requests may be extended by two extra months and we will inform you if this is required. Exercising a right is free of charge unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request (we will tell you why).

RightWhat it means
Right to be informedYou have the right to ask us for information about how we use your personal data.
Right of accessYou can ask us to confirm whether we hold personal data about you, and to give you a copy along with information about what we use it for.
Right to rectificationYou can ask us to correct personal data that is inaccurate, or to complete personal data that is incomplete.
Right to erasure ("right to be forgotten")You can ask us to delete personal data in certain situations - for example, where we no longer need it for the purpose we collected it. In some cases, we may be required to retain certain information for regulatory purposes – in this case we will let you know as part of the response.
Right to restrictionYou can ask us to stop using personal data while we investigate a concern you have raised.
Right to objectYou have the right to object to your personal data being processed.
Right to data portabilityWhere we rely on contract or consent, you can ask us to provide personal data you have given us in a structured, commonly used and machine-readable format.
Right not to be subject to a decision based solely on automated processingYou have the right not to be subject to this type of processing.
Right to withdraw consentWhere we rely on your consent (for example, analytics, cookies or biometrics), you can withdraw it at any time.

9. HOW TO CONTACT US, AND HOW TO COMPLAIN

9.1 Contact us

In the first instance, please contact us - we'd rather hear from you directly on any matters so we can support and engage with you on your request.

9.2 Complain to the ICO

If you are not happy with how we've handled your personal data, you have the right to complain to the UK Information Commissioner's Office (ICO):

  • ICO website: www.ico.org.uk/make-a-complaint
  • ICO helpline: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

9.3 Complain to OfDIA

Where your concern is specifically about our operation under the UK Digital Identity and Attributes Trust Framework - for example, the verification outcome or the way our service operated - you can raise it with the Office for Digital Identities and Attributes (OfDIA) through their published contact channels, or with our Conformity Assessment Body. We'd appreciate the chance to resolve the matter with you first and complaints can be communicated to us at support@ppac.co.uk.

9.4 Data Protection Complaint

Under the Data Use and Access Act, individuals have a right to make a complaint to the controller if you consider your data processing has been incorrectly handled or infringes UK GDPR. Where PPAC acts as a controller you can submit any data protection complaint to us at dpo@ppac.co.uk. We have specific processes set up for this and will acknowledge your complaint within 30 days and take appropriate steps to ensure a full investigation is completed without undue delay. We will keep you informed regarding the investigation and outcome of the complaint and will inform you without undue delay. Should PPAC be unable to resolve your complaint or you are unhappy with the process, you have the right to complain to the ICO using the above contact details.

10. COOKIES ON OUR WEBSITE

Cookies are small files placed on your device by websites you visit. We use a small number of cookies on our website. We don't set any cookie that is not essential to operating the website until you have made a choice through the cookie banner. When you visit our website for the first time, we ask for your consent to store non-essential cookies on your device. Any cookies that are not defined as ‘strictly necessary’ to provide the services across our website require your consent. Cookies deemed as helpful or convenient but not essential require clear and positive consent from you.

10.1 What we set

Cookie typeWhy we use itSet without consent?
Strictly necessaryMake the site work - for example, holding your cookie preference itself, and keeping you signed in if you log in to a serviceYes - these are essential and do not require consent
AnalyticsHelp us understand which pages are useful, where visitors come from, and how to improve the site. We use a respected analytics provider configured to minimise personal data (e.g., truncated IP addresses)No - set only with your consent through the cookie banner
FunctionalRemember choices you make on the site (such as language preference)No - set only with your consent
Marketing / trackingWe do not currently set marketing or third-party tracking cookies. If we ever do, we will update this notice and the cookie banner before doing so

10.2 How to change your cookie choices

You can change your cookie choices at any time using the "Cookie settings" link in the footer of our website. You can also block or delete cookies through your browser settings; please note that some parts of the site may not work as well without strictly necessary cookies.

11. CHANGES TO THIS NOTICE

We review this notice at least once a year, and earlier if anything material changes - for example, if we change suppliers, introduce a new processing purpose, or if the law or DVSTF rules change. The "Last updated" date at the top of this notice tells you when it last changed.

12. A BRIEF GLOSSARY

WordWhat it means in this notice
Personal dataInformation about a living individual who can be identified from it, directly or indirectly (e.g., a name, an email address, a photograph, an identifier).
Special category personal dataPersonal data that the law treats as particularly sensitive - including biometric data used to identify someone, health data, racial or ethnic origin, religious beliefs and similar categories.
Biometric dataPersonal data resulting from specific technical processing of physical, physiological or behavioural characteristics of an individual that uniquely identify them - in our case, mathematical templates derived from your face image.
ControllerThe organisation that decides why and how personal data is processed. Where PPAC is the controller, we have the primary responsibility for your data under data protection law.
ProcessorAn organisation that processes personal data on the controller's instructions - for example, our biometric supplier processes data on our instructions.
UK GDPRThe UK General Data Protection Regulation, the main UK data protection law since 2021.
DPA 2018The Data Protection Act 2018 - UK law that sits alongside the UK GDPR.
DVSTFUK Digital Verification Services Trust Framework - the framework under which we operate our identity verification service.
OfDIAOffice for Digital Identities and Attributes - the UK government function that oversees the DVSTF.
GPG 45Good Practice Guide 45 - UK government guidance on identity verification, which our service is built around.
ICOInformation Commissioner's Office - the UK independent regulator for data protection.
PPAC

PPAC SOLUTIONS LIMITED

11 West Street, Epsom, Surrey, KT18 7RL

Index

About UsContactBlogOur Policies

Keep up to date with PPAC

  • CSCS Group
  • ADVP
  • UKAS ISO 27001
  • Cyber Essentials