Emovid Privacy Policy

1. Collection of Your Personal Information

To fulfill your requirements, we will send your Emovid video to those you request us to send it, or give access, to. We do not have any control over what these recipients may do with that video (for example taking screen shots of it or otherwise copying information from the video).

2. Use of Your Personal Information

3. Emovid Biometric Policy Open Emovid Biometric Policy

3.1. Purpose for Collection

Emovid and its third-party service providers collect, store, and use biometric identifiers and biometric information (specifically “scans of face geometry”) for the following limited purposes:

  • Identity Verification: To confirm that the individual creating an account or accessing a service is the authorized user.
  • Fraud Prevention & Liveness Detection: To prevent the use of deepfakes, synthetic media, or static photos to bypass security measures (confirming “liveness”).
3.2. Disclosure to Third Parties

Emovid does not sell, lease, or trade your biometric data. We may disclose your biometric data to our certified liveness-verification partner, BioID GmbH, which assists in verification and liveness detection. This provider is contractually prohibited from using your data for any other purpose and must adhere to security standards as protective as our own.

3.3. Retention Schedule and Destruction Guidelines

In accordance with BIPA, Emovid adheres to the following retention and destruction schedule:

  • Retention Period: We will retain biometric data only until the initial purpose for collection has been satisfied (e.g., identity is verified).
  • Statutory Policy Limit (BIPA): In compliance with legal requirements under BIPA, Emovid maintains a formal retention schedule stating that biometric data will be retained only until the initial verification purpose is satisfied, with a strict legal hard deadline to permanently destroy any biometric records within three (3) years of the last interaction. Because the purpose is satisfied instantly during capture, destruction occurs immediately.
  • Destruction Method: Data is securely deleted using industry-standard protocols to ensure it cannot be recovered or reconstructed.
3.4. Data Security Standards

We protect your biometric data using a reasonable standard of care within our industry. We store, transmit, and protect biometric identifiers in a manner that is the same as or more protective than the way we protect other sensitive personal information, such as account numbers or passwords.

3.5. Updates and Contact Information

4. Control of Your Personal Information

5. Data Security

6. Information Received from Cookies and Third Parties

Partners. Emovid collects your information from third parties to facilitate activities and transactions for the operation of the Website and its services, to improve your Website user experiences, and to further Emovid’s mission. Examples of such third parties are Google (using Google Analytics) or Amplitude (using their analytics tools).

7. Referral Service and Third Party Information

8. Special Notice about Children and Minors

9. Special notice for residents of certain states

Please note that under applicable law, certain information may be exempt from the requests above. For example, we may not be able to alter or delete certain information if we are required to retain it to fulfill our obligations to you, for security reasons, to comply with applicable law, for internal business purposes, or for other valid legal reasons.

10. Changes to this Privacy Policy

11. Contact Information

Emovid Corporation

Information for California residents.

Right to “Request to Delete” Personal Information
Consumers have the right to “request to delete” personal information that we have collected. We may not have to comply with the request as provided above or in CPRA Section 1798.105(d).

Information collectedCategoryPurposeSourceHow used or sharedLegal Basis (In EU and UK)
Name, email, social media account handlesIdentifier, personal informationEstablish your account with us.User provided, or provided by an employer if a business account is established.User Consent/Carry out contract with user
IP addressOnline activityFacility operation of the WebsiteCookiesLegitimate Interest
Use of our website, website pages viewed, links clicked onOnline activityOperation of our Website, improve the user experience, and further Emovid’s missionThird party analytics providers such as Google Analytics and Amplitude, cookiesCompile anonymized and aggregated website usage. May be shared with third parties.Legitimate Interest
Payment informationCommercial informationPay for use of our services at various tiersUser providedUsed by our third-party payment processor. Emovid does not have or collect this data.Legitimate Interest
Emovid videoSensory DataCreate video to send to recipient(s) designated by userUser providedTo designated recipient(s)User Consent, Carry out contract with user
Image of userSensory DataAlterations by AI pursuant to user instructions for use in Emovid videoUser providedTo designated recipient(s)User Consent, Carry out contract with user
Audio & PromptsSensory / User Content Automated transcription, summaries, AI Suggestions, and Emovid AI AnalysisUser provided (via video recordings and messaging)OpenAI (Third-party AI service) Performance of Contract / User Consent
Face / Liveness snapshot Sensory Data / Biometric verification Verified Human Seal (real-time passive liveness check) User provided (camera snapshot; user opt-in only) BioID GmbH (0-second retention; discarded immediately after real-time pass/fail check)User Consent

GDPR AND PIPEDA SPECIFIC MECHANISM CHART

ScenarioSpecific mechanismWhy it covers the requirement
EU/EEA to a country with Commission adequacyAdequacy decision (Article 45)Transfers are treated like intra‑EU flows; no additional safeguards are required under GDPR.
EU/EEA to a non‑adequate countryEC Standard Contractual Clauses (Decision 2021/914) + TIA + supplementary measures as neededSCCs provide Article 46 safeguards; TIAs and supplementary measures ensure essentially equivalent protection post‑Schrems II.
UK to third countriesUK IDTA or UK Addendum to EU SCCs + UK TRAUK‑specific transfer tools mirroring GDPR approach post‑Brexit. 
Canada (PIPEDA) to foreign processorsContracts ensuring “comparable level of protection” + transparency on foreign accessPIPEDA relies on accountability with contractual or other means; no SCC‑style instrument is mandated. 

Information for European Union or UK residents

What data we collect

How we collect data

Why we process data and lawful bases

Information for Canadian Residents 

Cross-Border Data Transfers