Privacy · 2026-08-05.1

IKFace Customer Portal Privacy Notice

Version: 2026-08-05.1

Effective date: 5 August 2026

1. Controller

INFOKRAUSE SRL, Italian VAT number and tax code 04126260928, REA CA-365199, with registered office at Via delle Speronelle 15, 09045 Quartu Sant'Elena (CA), Italy, is the controller for the processing described in this notice.

Privacy enquiries and rights requests: privacy@infokrause.com.

INFOKRAUSE has not currently appointed a data protection officer. The contact above receives all privacy enquiries and rights requests.

2. Scope

This notice applies to the IKFace Customer Portal, company registrations, demo requests, enrolments, Managed Appliances, licences, support and related communications. The portal is strictly business-to-business and intended for company representatives and authorised users.

It does not govern images, biometric templates or other data that a customer processes within its own IKFace Edge installation. The customer determines the purposes and responsibilities for that processing.

3. Data processed

We may process:

  • first and last name, corporate email, telephone number, language, and a
  • password stored only as a cryptographic hash;

  • legal and trading company names, address, city, country, and the user's
  • relationship with the company;

  • demo requests, approvals, rejections and communications;
  • customer, enrolment, intent, appliance, installation and licence identifiers;
  • technical identifiers such as device UUID, system UUID, fingerprint, serial
  • number or model where available;

  • operating system, processor, installed version, update status, capacity,
  • modules, last connection, IP address and interfaces where needed for security, activation or support;

  • evidence of acceptance, consent withdrawal and legal-document versions;
  • security and audit events, including network and browser information,
  • pseudonymised where compatible with the purpose;

  • requests to exercise privacy rights.

We do not request biometric data to create an account, process a demo or administer licences.

4. Purposes and legal bases

We process data as needed to:

  1. create and verify accounts, link users to companies and process demos as
  2. pre-contractual steps requested by the user and to manage the business relationship;

  3. administer appliances, licences, capacity, updates and support to perform
  4. the contractual relationship;

  5. prevent abuse, investigate incidents, preserve evidence and protect the
  6. service based on our legitimate interests in security, integrity and legal defence;

  7. comply with legal duties and valid authority requests;
  8. send marketing news only with separate, optional and revocable consent.

Marketing consent is not required to use the account or request a demo.

5. Recipients, processors and reCAPTCHA

Access is limited to authorised INFOKRAUSE personnel and providers required to operate the service:

  • infrastructure, storage and backups managed by INFOKRAUSE;
  • Google Workspace or Gmail SMTP for transactional email;
  • Google reCAPTCHA to prevent abuse and automation;
  • Chatwoot and chat.infokrause.cl and soporte.infokrause.cl for customer
  • service and support.

reCAPTCHA may receive technical and interaction data, including IP address, device or browser characteristics and usage signals, and use strictly necessary technologies such as the _GRECAPTCHA cookie, under Google's terms and policies.

Providers receive only the data needed for their function and are subject to their contractual terms and data-protection commitments. We do not sell personal data.

6. International transfers

Some providers may process data outside the European Economic Area (EEA) or the user's country. We apply the required contractual safeguards and transfer mechanisms. Where the GDPR applies, we rely on an adequacy decision, standard contractual clauses or another permitted mechanism. Information about these safeguards is available through the privacy contact.

7. Retention

We apply the following periods:

  • unverified accounts: 7 days;
  • verification tokens: 24 hours;
  • expired sessions: immediate technical deletion; related security evidence:
  • 90 days;

  • rejected or abandoned demo requests: 24 months;
  • inactive accounts without licences: 24 months;
  • licences, activations and contractual evidence: 5 years after the
  • relationship ends;

  • security and audit logs: 24 months, unless an investigation or legal duty
  • requires longer retention;

  • backups: no more than 90 days;
  • marketing data: until consent is withdrawn.

At the end of a period, data is erased or anonymised unless a legal duty, dispute or investigation justifies retention. Backups are not used to restore erased data and expire through their rotation cycle.

8. Security

We use access control, least privilege, transport encryption, password and token hashing, secure sessions, CSRF protection, rate limiting, audit logging and separation between the portal, License Manager and appliances. No system is infallible; we apply the appropriate legal and operational measures if an incident occurs.

9. Rights

Subject to applicable law, individuals may request access, rectification, erasure, restriction, objection and portability, and may withdraw consent without affecting earlier processing. They may also complain to the competent supervisory authority.

We may request reasonable information to verify identity. A request may be limited by law, security, fraud prevention or the need to retain contractual evidence; if so, we will explain the basis.

10. Automated decisions and children

We do not make decisions producing legal or similarly significant effects solely through automated processing. The portal is for businesses and is not directed to children.

11. Cookies and third-party services

IKFace uses cookies or storage that are strictly necessary for security, session management, language, and requested operation. The privacy choice is stored for no longer than 180 days in ikface_privacy_consent, together with the version, selected categories, and date of the decision.

Chatwoot support chat is optional. Its code is not loaded before the user allows it or explicitly requests to open the chat. Chatwoot may then use technical storage to maintain the conversation and support session.

Google reCAPTCHA is loaded only when the user submits a protected form, such as registration or password recovery. It may receive technical data and use _GRECAPTCHA to prevent fraud and automation.

We currently do not use advertising, remarketing, or audience analytics cookies on these pages. If introduced, they will remain blocked until the required consent is obtained. The choice can be reviewed or withdrawn at any time through “Cookie preferences” in the footer.

12. Changes

Each change will be published with a new version and effective date. For material changes, we will notify users and request renewed acceptance when required. We retain the accepted version as evidence.