Skip to main content
Version: 11.3.0

Biometric Data and the Privacy Notice

This page describes the HYPR Affirm verification steps that capture biometric data, the privacy notice and consent that requesters see, and the settings administrators control.

How HYPR collects, uses, processes, shares and retains personal and biometric data, including the service providers involved and retention periods, is set out in HYPR's published policies:

For HYPR's security and compliance information, see the HYPR Trust Center.

Steps That Capture Biometric Data​

Two verification steps capture images of the requester's face. The following table lists them, including Photo ID and Liveness Capture with an anchor image.

StepWhat the requester provides
Document and Biometric VerificationPhotos of an identity document and, when Liveness Check is selected, a selfie photo or a short head-turn video
Photo ID and Liveness CaptureA photo ID image and one live selfie photo
Photo ID and Liveness Capture with an anchor imageOne live selfie photo, compared with a photo from your own directory

Both steps are off until an administrator turns them on for a verification flow. In Document and Biometric Verification, Liveness Check is also off until an administrator selects it. Without it, that step checks the document only and captures no selfie.

The other built-in steps do not ask the requester for photos. In the Approver Chat and Video step, the requester can turn on their camera for a live video call with the approver.

Every verification flow shows a consent screen before the requester enters a login identifier and before any verification step. The consent screen is a fixed step that administrators cannot remove.

The notices shown on the consent screen depend on the steps in the flow:

  • When the flow includes either step that captures biometric data, the consent screen shows the HYPR Affirm Biometric Data Policy and Consent.
  • When the flow includes neither step, it shows the HYPR Affirm Non-Biometric Data Policy and Consent.
  • When the flow includes Document and Biometric Verification, it also shows the identity verification provider's consent notice.
  • When your organization has added its own consent language, that text appears above the HYPR notice.

The linked HYPR policies are the authoritative text of the notice the requester accepts. The one-time passcode disclaimer in the Phone Number or Email Verification step links the non-biometric policy and the HYPR Privacy Policy.

The requester must scroll to the end of the notices before Accept is enabled. The screen has no decline button. A requester who does not accept cannot continue past the consent screen.

Before the consent screen, the instructions screen lists the steps the requester completes and tells the requester that consent follows.

For the full consent screen behavior, the default instructions text and the text administrators can add, see Customizable Consent Screen.

What Approvers and Requesters See​

In Document and Biometric Verification, the identity verification provider's capture screens, embedded in the Affirm page, collect the document photos and the selfie or video. Affirm shows the provider's results, including confidence levels such as Face match confidence and Spoofing detection (Low, Medium or High), in the approver's review. The requester sees them when Report Visibility for Requester is selected.

In Photo ID and Liveness Capture, the requester uploads or photographs a photo ID, then takes a selfie with the device camera. Affirm compares the face on the ID with the face in the selfie, and the result is match or no match. The approver's review shows the face from the ID beside the face from the selfie.

When an anchor image is used, Affirm retrieves the requester's photo from your directory through your image repository customization instead of asking for a photo ID.

Data Retention Setting​

The Data retention policy setting controls how long Document and Biometric Verification data is stored after a session completes. It is set per verification flow under Advanced Customization → Data retention policy. The options are 1 day and 7 days (default). An administrator can change the setting only while the flow includes Document and Biometric Verification.

Confirm with your HYPR representative that the 1-day option is available for your tenant. The period applied to each verification is shown as Data Retention Policy in its Activity Log record. See Data Retention.

For HYPR's retention terms, see the HYPR Affirm Biometric Data Policy and Consent.

Writing Images to Your Own Directory​

Directory Image Writeback sends the images captured by a verification to a destination your organization controls, such as your user directory. It runs only after a successful verification and only when an administrator has configured it for the flow.

Writeback can send the selfie, the photo ID and cropped face images from Photo ID and Liveness Capture. From Document and Biometric Verification, it can send the document photos, front and back, and the selfie. Once images reach your destination, your organization's own retention rules apply to them.

What Administrators Control​

Administrators control the following per verification flow:

  • Whether Document and Biometric Verification or Photo ID and Liveness Capture runs
  • Whether Document and Biometric Verification takes a selfie (Liveness Check) or a head-turn video (With Motion Detection)
  • The custom consent language shown above HYPR's notice
  • The data retention setting for Document and Biometric Verification
  • Whether the requester sees their own results (Report Visibility for Requester)
  • Whether a directory photo is used as the anchor image
  • Whether images are written back to your directory, and how often

Administrators cannot change the HYPR or provider consent notices.

Audit and Activity Records​

Affirm records the following events in the Audit Trail:

  • AFFIRM_WORKFLOW_CONSENT when the requester clicks Accept on the consent screen
  • AFFIRM_WORKFLOW_DOCUMENT_UPLOAD and AFFIRM_WORKFLOW_FACE_MATCH for each Photo ID and Liveness Capture attempt, with whether a face was found and whether the faces matched
  • AFFIRM_WORKFLOW_ANCHOR_IMAGE for each anchor-image lookup, with its outcome
  • AFFIRM_WORKFLOW_DOCUMENT_BIOMETRIC_START and AFFIRM_WORKFLOW_DOCUMENT_BIOMETRIC_FINISH for each Document and Biometric Verification attempt
  • AFFIRM_WRITEBACK_TRIGGERED, AFFIRM_WRITEBACK_SUCCESS, AFFIRM_WRITEBACK_SKIPPED and AFFIRM_WRITEBACK_FAILURE for image writeback

The Activity Log records each verification's results. For Photo ID and Liveness Capture it shows Liveness Verified. For Document and Biometric Verification it shows Document Type, Document Authentication, Name Check, Biometric Liveness Check and Data Retention Policy. The Activity Log and the Audit Trail record results and events, not images.