1. Introduction
This Privacy Policy explains how we collect, use, process, and protect personal data to ensure the authenticity and integrity of online events. By using our services, you agree to the terms outlined in this policy.
2. Information We Collect
We collect and process the following types of personal information depending on the services used and configuration set by the online event organization:
- First name
- Last name
- Email address
- Learner image (photo)
- Facial representation (a biometric identifier derived from facial geometry)
- Government-issued ID (processed but not stored)
- Online event name and completion status
- Device and browser details (e.g., operating system, screen size, network type)
- IP address (used for session verification; not retained)
- Usage information (e.g., pages accessed, time spent, navigation patterns)
- Communications with support and/or instructors (e.g., chat transcripts)
3. Real-Time Verification and Processing
All required disclosures and user acknowledgements are provided prior to the collection or processing of any personal data.
All verification activities take place directly on the participant's device, with one limited exception described below.
- No video is ever recorded
- The camera is used solely for real-time face verification
- The live camera feed is processed locally on the participant's device and is never streamed, stored, or recorded
- Screen sharing and camera input may be analyzed in real time to detect potential violations
Limited Exception (Identity Verification via AWS LLM Service)
During the session, limited data may be transmitted to a secure AWS-hosted service strictly to perform identity verification.
- Name
- Selfie photo
- Facial representation
- Government-issued ID
This data is:
- Used strictly for identity verification and liveness detection
- Processed under our instructions as a service provider
- Immediately deleted after processing
- Never stored, reused, or used for AI training or model improvement
Government-issued ID documents are never stored. They are processed only to extract necessary identity attributes (e.g., name and face) and are immediately discarded.
4. How We Use Collected Data
Collected data is used solely for the following purposes:
- To verify user identity and participation in online events
- To support integrity and fairness in event monitoring
- To maintain a secure record of participation and outcomes
- To share event outcomes with authorized organizations (e.g., employers, regulators)
- To comply with legal and regulatory obligations
- To improve system reliability using anonymized analytics where applicable
5. Data Retention and User Control
We maintain a publicly available data retention and destruction schedule.
After the event, we retain only the following information:
- First name
- Last name
- Email address
- Learner image (photo)
- Facial representation (biometric identifier)
- Online event name and completion status
Additional details:
- IP address and device-related technical data are not retained
- Government ID data is never stored
- Data processed by the AWS service is immediately deleted
Biometric data is permanently deleted:
- When the purpose for collection has been satisfied, or
- Within three (3) years of the user's last interaction with the service, whichever occurs first
Users may:
- Request access to their data
- Request deletion
- Request restriction of processing
Requests can be submitted via the verification portal or by contacting: privacy@asgard1.com
Important: Deleting your data will remove verification records and may require retaking the event.
6. Data Sharing and Public Verification
We do not sell, lease, trade, or otherwise profit from personal data, including biometric identifiers.
Biometric data is not disclosed to any third party except:
- With user consent
- Where necessary to complete the requested verification service
- Where required by law
Verification information may be shared with:
- The original online event organization
- Authorized third parties (e.g., employers, regulators, credentialing bodies)
A limited verification record may be publicly accessible to parties who possess both:
- The individual's last name, and
- Email address
No additional personal information or media is publicly shared.
7. Security Measures
To protect your information, we implement:
- End-to-end encryption for data in transit and at rest
- Primary processing of sensitive data on-device where possible
- Strict access controls limited to authorized personnel
- Internal logging and auditing procedures
- Data minimization practices
- Secure infrastructure with region-specific data storage (AWS regions selected by clients)
We store, transmit, and protect biometric data using a standard of care equal to or greater than that used for other sensitive personal information.
8. Sub-Processors
We do not share personal data with third-party organizations for processing, sale, or secondary use.
Limited Exception (AWS Service):
- We use a secure AWS-hosted service solely for identity verification
- Data is processed under our instructions as a service provider
- Data is processed transiently and immediately deleted
- Data is never stored, reused, or used for AI training
No other third-party processors or external AI services are used.
9. Human Review (Support Purposes Only)
Automated systems are the primary method of processing and verification.
Limited Human Access:
In certain cases, authorized personnel may access limited user data strictly to:
- Provide technical support
- Investigate verification issues
- Respond to user-reported problems
This access is:
- Granted on an individual, case-by-case basis only
- Restricted to trained and authorized personnel
- Logged and subject to internal audit controls
- Limited to only the data necessary to resolve the specific issue
Human review is reactive only and does not involve continuous monitoring of users or sessions.
No human access is permitted for any purpose outside of these support-related functions.
10. Legal Compliance
We comply with applicable privacy and data protection laws, including:
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA)
- EU General Data Protection Regulation (GDPR)
- UK GDPR and Data Protection Act 2018
- Australia's Privacy Act 1988
- Applicable U.S. state-level data protection laws
11. Cookies and Tracking Technologies
We do not use cookies, third-party tracking tools, or persistent identifiers.
Session functionality may rely on temporary, session-based mechanisms that do not track users across sessions.
12. Changes to This Policy
We will notify users of any material changes that reduce privacy protections. Notifications will be provided via email or through an in-product notice before changes take effect.
13. No Processing of Minors' Data
Our services are not intended for minors. Identity verification requirements (including government-issued ID) help ensure only eligible users participate.
14. Jurisdiction and Data Storage
Data is stored in secure cloud infrastructure, with the storage region determined by client configuration (e.g., AWS region selection).
We operate in accordance with applicable laws and regulatory requirements in the jurisdictions of our clients.
15. Contact Information
For questions, concerns, or data requests, contact: privacy@asgard1.com
By using our services, you acknowledge that you have read and understood this Privacy Policy.