Privacy Policy

Privacy Policy for Biosyn

Last Updated: September 2026

Biosyn ("we," "us," or "our") operates the Biosyn multi-tenant cloud biometric gateway middleware SaaS platform (`biosyn.dev`). We are committed to protecting the privacy, confidentiality, and security of customer business accounts and data subjects whose attendance and access control events are routed through our platform. This Privacy Policy details how we collect, process, secure, and retain data when you interact with our website, access our APIs, connect biometric devices, or utilize our middleware services.


1. Core Architecture: Cloud Gateway Middleware & Data Boundary

Biosyn functions as a cloud biometric gateway middleware layer connecting physical attendance and access hardware (e.g., ZKTeco biometric terminals) with customer CRM, ERP, HRMS, and payroll systems via real-time webhooks and REST APIs. It is essential to understand our data boundaries:

  • Middleware Processing: Biosyn acts as a secure transit conduit for device transactions (such as attendance logs, verification timestamps, user enrollment syncs, and device status telemetry). We process data to route it to your configured destination webhooks.
  • Data Controller vs. Data Processor Role: You (our Customer) are the sole Data Controller of all biometric templates, fingerprint/facial identification hashes, employee records, RFID card numbers, and attendance logs. Biosyn operates strictly as a Data Processor carrying out processing instructions defined by your account configuration and API requests.
  • Biometric Data Consent Responsibility: As Data Controller, you warrant that you have obtained explicit, voluntary written consent from your employees, contractors, or users prior to capturing or processing their biometric data or attendance logs through connected hardware and Biosyn.

2. Information We Collect

We collect limited information necessary to provide, secure, bill, and optimize our cloud gateway middleware platform:

  • Account & Registration Data: When you register an account or create registered locations, we collect account credentials, organization name, contact email address ([email protected]), billing address, and subscription tier selection.
  • Device Connection Telemetry: When physical devices connect to our cloud gateway, we collect device identification metadata (such as serial numbers, firmware versions, device names, IP addresses, online/offline status, and heartbeat timestamps) required to maintain push SDK communication and command queues.
  • Transaction & Webhook Event Logs: In the normal course of middleware delivery, our servers process event payloads (including user IDs, verification modes, location IDs, timestamp logs, and webhook delivery HTTP response statuses) to ensure reliable real-time event delivery and provide audit logging in your dashboard.
  • Billing & Payment Metadata (Paddle): Payment processing and subscription billing are managed securely by our authorized Merchant of Record, Paddle.com Market Limited ("Paddle"). We do not store, process, or transmit raw credit card numbers on our servers. Paddle collects and handles payment credentials, transaction histories, and invoicing under PCI-DSS standards. We receive transaction identifiers, subscription status, active user counts, and billing metadata to manage your license.
  • Website Analytics & Support Communications: When you visit `biosyn.dev`, read `docs.biosyn.dev`, or contact our technical support team, we collect standard server access logs, cookie identifiers, and voluntary support correspondence.

3. How We Use Information

We process data under lawful bases (contract performance, legal obligation, and legitimate business interest) to:

  • Deliver real-time biometric middleware routing and execute API and webhook integrations.
  • Calculate subscription metered usage based on total enrolled users and connected physical devices across registered locations.
  • Monitor platform health, maintain high gateway availability (99.9% target SLA), detect network anomalies, and prevent API abuse.
  • Provide developer technical support, troubleshoot webhook delivery failures, and dispatch essential system notifications.
  • Comply with tax, financial auditing, and legal regulatory requirements in cooperation with our Merchant of Record, Paddle.

4. Biometric Privacy, Security & Data Protection Standards

Biosyn incorporates stringent physical, technical, and administrative safeguards to protect data in transit and at rest:

  • Encryption Standards: All data transmitted between physical devices, our cloud gateway, web dashboards, and your destination webhooks is encrypted using TLS 1.2/1.3 protocol standards. Data at rest is encrypted using AES-256 standards.
  • Biometric Template Handling: Biosyn does not convert raw biometric images; physical hardware generates proprietary mathematical template hashes. We store and transmit template hashes solely to synchronize device authorization across your permitted locations as instructed by your account.
  • Access Controls & Isolation: Multi-tenant location data is strictly isolated. Access to API endpoints requires valid authentication headers and API keys.

5. Data Retention & Deletion Schedule

  • Middleware Webhook Logs: Detailed real-time transaction event logs are retained for a default operational buffer window (typically 30 to 90 days depending on your plan tier) to allow delivery verification, re-try execution, and audit troubleshooting, after which logs are automatically purged or archived.
  • Billing Default & Non-Payment Purge: In the event of billing failure or account delinquency, tenant data (including device routing tables, API keys, and temporary event logs) is retained for a grace period of 30 calendar days, after which all tenant configuration data and routing records are permanently purged and destroyed.
  • Account & Master Records: Account billing, subscription, and location metadata are retained for the duration of your active subscription and up to 7 years following account closing to fulfill legal tax and accounting requirements.
  • Account Termination Deletion: Upon voluntary subscription cancellation or account closure, device routing keys are revoked, and tenant-scoped location configurations are marked for permanent deletion.

6. Information Sharing & Third-Party Processors

We do not sell, rent, or trade personal or biometric data to third parties or advertisers. Data is shared exclusively with infrastructure sub-processors essential to operating our Service:

  • Merchant of Record & Payment Processor (Paddle): Paddle.com Market Limited manages secure subscription payment processing, invoicing, sales tax compliance, and fraud protection. View Paddle's Privacy Policy for details on their data processing practices.
  • Cloud Infrastructure Providers: Secure tier-4 cloud hosting, database, and Redis cache infrastructure used to host our gateway servers.
  • Transactional Email Services: Providers used strictly to send critical system alerts, password resets, and subscription notices.
  • Legal Disclosures: We may disclose data if required by a valid law enforcement subpoena, court order, or search warrant, provided we notify the Data Controller unless legally prohibited.

7. Global Privacy Rights (GDPR, CCPA/CPRA, BIPA)

Depending on your jurisdiction, Data Controllers and individual data subjects possess specific privacy rights:

  • Right of Access & Correction: Account holders can review and update organization profile details and location settings directly in the account dashboard.
  • Data Subject Requests (Employees/Users): Because Biosyn acts as a Data Processor, end-users whose biometric data or attendance logs pass through our gateway must submit data access, correction, or deletion requests directly to their employer or organization (the Data Controller). We will assist Data Controllers in fulfilling verified data subject requests upon official written request.
  • Right to Erasure & Portability: Account holders may request exports of location data or account closure by contacting support.

8. Children's Privacy

Biosyn is a business-to-business (B2B) cloud middleware service and is not intended for or marketed to individuals under 18 years of age. We do not knowingly collect personal data from children.

9. Policy Updates

We may update this Privacy Policy periodically to reflect changes in legal requirements, device SDK standards, or operational practices. Revised policies will be published on `biosyn.dev` with an updated "Last Updated" date.

10. Contact Us

For questions, privacy inquiries, or data protection officer (DPO) communications regarding Biosyn, please contact us at [email protected] or review technical guides at docs.biosyn.dev.