Security & Data Protection

How we protect your organisation's data - including the biometric data collected by Alpaka Presence.

Facial recognition and biometric data

Alpaka Presence can be configured for facial recognition only, for facial recognition alongside keypad PIN or ID badge, or for non-biometric methods only - entirely at your organisation's discretion. This is a configuration instruction you give us, not a choice Alpaka makes on your behalf; see our Data Processing Agreement. Facial matching is special category processing under UK GDPR, and establishing your lawful basis for the configuration you choose is your responsibility as data controller.

At clock-in, a photo is compared against a reference photo on file via a third-party facial matching service, which returns a match or no-match result. We do not generate, store, or have access to any facial geometry, template, or biometric embedding at any point, and the matching provider does not retain the photo after comparison. The reference photo itself is the only image data we retain - it is encrypted at rest and in transit, never sold, never used for advertising, and never compared against any external database or used for surveillance beyond clocking in and out. We automatically discard reference photos after 3 months, or sooner if a staff member is removed as a User or on request.

Hosting and infrastructure

Alpaka is hosted on AWS infrastructure in the EU (Dublin), within the UK/EEA, with encrypted connections (TLS) between your devices and our servers. Access to production systems is restricted to authorised engineers and is logged. We run routine backups so that in the event of a system failure, your data can be restored without loss.

Access control

Alpaka has a permission structure that lets you control exactly what each user can see and do - from view-only access to personal data through to full administrative access. You decide who in your organisation can see HR records, timesheets, or biometric data, and can review and revoke access at any time.

Data protection compliance

Alpaka Ltd is registered with the Information Commissioner's Office (ICO). Where you use Alpaka to process personal data about your employees, you are the data controller and we act as data processor under our Data Processing Agreement. See our Privacy Policy for full detail on what data we collect and how it is used.

Data retention and deletion

Your data belongs to you. It is retained for as long as your contract is active and can be exported at any time. On termination of your contract, your data remains available to export for 30 days, after which it is securely and irretrievably deleted. See our Terms & Conditions for full detail.

Reference photos used for facial recognition follow a shorter cycle: they are automatically discarded after 3 months of retention, or sooner if a staff member is removed as a User or on request.

Reporting a security concern

If you believe you've found a security vulnerability in Alpaka, please contact us directly at support@alpaka.io rather than disclosing it publicly. We investigate all reports and will keep you updated on the outcome.