Security & Data Protection

How we protect your organisation's data - including the biometric data collected by Alpaka Presence.

Facial recognition and biometric data

Alpaka Presence can be configured for facial recognition only, for facial recognition alongside keypad PIN or ID badge, or for non-biometric methods only - entirely at your organisation's discretion, and this can be set per person, not just per site. This is a configuration instruction you give us, not a choice Alpaka makes on your behalf; see our Data Processing Agreement. Facial matching is special category processing under UK GDPR, and establishing your lawful basis for the configuration you choose is your responsibility as data controller.

When someone is enrolled, an image is submitted to Amazon Rekognition, running in AWS eu-west-1 (Ireland). Rekognition generates a facial recognition template, stores it in a face collection dedicated to your organisation, and returns a reference - a random identifier with no meaning outside that collection - which Alpaka stores against the employee record. At each clock-in, the captured image is compared against your collection and Rekognition returns the matching reference where it finds one.

Alpaka's own database never holds the template itself, only that reference: if it were ever exposed, there would be no biometric data in it to recover, and the identifiers are useless without access to the collection. This is pseudonymisation under Article 4(5) of the UK GDPR, one of the technical measures we rely on under Article 32(1)(a) - though it does not change the legal character of the processing itself, which remains Article 9 special category data regardless of where the template is held.

Where a face is recorded but not yet attached to a person - during initial setup, or when a match can't be made confidently - the template is held unattributed and reviewed. If it isn't attached to an employee within 30 days, it is deleted from the collection. Nobody is paid against a guess: an unattributed reading is never assigned to the wrong employee.

Separately from the recognition match, Alpaka records a photograph at each clock-in as a visual record of who was at the terminal, which is what stops buddy punching. Enrolment photos and clock-in photographs are retained for 3 months, the same period for every customer, visible only to users with specifically configured, opted-in permission to view them - not a general admin right - and deleted automatically at the end of the retention period. The facial recognition template itself is held for as long as the individual is an active employee, and is deleted, together with the reference in Alpaka's systems, automatically on their termination date.

Separating the template from the identity reduces risk, but you still need an Article 9 condition for the processing (in an employment context, normally explicit consent), a Data Protection Impact Assessment before you start, and a genuine alternative on offer with no disadvantage to anyone who uses it - PIN entry and QR badge cover that last point. We don't currently provide a ready-made DPIA template; get in touch and we'll tell you where that stands.

Hosting and infrastructure

Alpaka is hosted on AWS infrastructure in eu-west-1 (Dublin, Ireland), within the UK/EEA, with encrypted connections (TLS) between your devices and our servers. Access to production systems is restricted to authorised engineers and is logged. We run routine backups so that in the event of a system failure, your data can be restored without loss.

Access control

Alpaka has a permission structure that lets you control exactly what each user can see and do - from view-only access to personal data through to full administrative access. You decide who in your organisation can see HR records, timesheets, or biometric data, and can review and revoke access at any time.

Data protection compliance

Alpaka Ltd is registered with the Information Commissioner's Office (ICO). Where you use Alpaka to process personal data about your employees, you are the data controller and we act as data processor under our Data Processing Agreement. See our Privacy Policy for full detail on what data we collect and how it is used.

Data retention and deletion

Your data belongs to you. It is retained for as long as your contract is active and can be exported at any time. On termination of your contract, your data remains available to export for 30 days, after which it is securely and irretrievably deleted. See our Terms & Conditions for full detail.

Biometric data follows a different cycle to the rest of your data. Enrolment photos and clock-in photographs are automatically discarded after 3 months, or sooner if a staff member is removed as a User or on request. Facial recognition templates are held for as long as an individual is an active employee and are deleted automatically on their termination date; an unattributed template that's never attached to an employee is deleted automatically after 30 days. On termination of your contract, your organisation's entire face collection is deleted along with the rest of your data.

Reporting a security concern

If you believe you've found a security vulnerability in Alpaka, please contact us directly at support@alpaka.io rather than disclosing it publicly. We investigate all reports and will keep you updated on the outcome.