Legal

Privacy policy

How Neetix Liveliness handles data — written to be read, not skimmed past.

Effective 10 August 2026Operator: Neetix, Indiatech@neetix.in

Who we are

Neetix Liveliness is a face-match and liveness verification API operated by Neetix from India. This policy covers the API, the website, the developer console, and the sandbox. If anything here is unclear, write to tech@neetix.in and a human will answer.

What we process

We keep the list short on purpose:

  • Account email — used to issue your API key, send billing receipts, and notify you of material changes to the service.
  • API keys — stored as salted hashes. We can verify a key; we cannot read it back. If you lose one, you rotate it.
  • Verification images — the selfie and document images you submit are decoded and scored in memory for the duration of the request. By default the original images are not written to disk and are not retained after the response is returned.
  • Audit logs — request metadata: timestamp, endpoint, key identifier, originating IP, latency, decision, and the numeric scores returned. No image content.
  • Credit ledger — every debit and top-up against your prepaid balance, kept as the billing record of truth.

Biometric data

Facial images are biometric data. We process them on behalf of the API customer who submits them: under the Digital Personal Data Protection Act, 2023 the customer is the data fiduciary and Neetix acts as a data processor, handling images only to perform the verification the customer requested.

We do not build face galleries across customers, we do not use submitted images to train models, and we do not sell or share biometric data with anyone. Customers are responsible for obtaining valid consent from their end users before sending us their images — this is also a condition of our terms of service.

Retention

  • Verification images: not persisted. Processed in memory, discarded when the response is sent.
  • Audit logs: retained while your account is active, as the operational and dispute record.
  • Credit ledger: retained as required for accounting and tax purposes under Indian law.
  • Account email and hashed keys: retained until you close your account, after which they are deleted from live systems within 30 days.

Security

All traffic is TLS-encrypted in transit. API keys are hashed at rest. API responses are signed so you can verify they came from us and were not altered. For customers who cannot let images leave their infrastructure at all, a self-hosted deployment is available — in that mode, images never reach Neetix servers.

Payments

Payments are handled by Dodo Payments, our merchant of record. Card and payment-instrument data goes directly to them and never touches Neetix servers. We receive only a confirmation that a payment succeeded, which credits your ledger.

Your rights and contact

You can request access to, correction of, or deletion of the data we hold about your account by emailing tech@neetix.in. If you are an end user whose image was verified through one of our customers, direct your request to that customer first — as the data fiduciary they control the purpose of the processing — and we will assist them in fulfilling it.

Changes to this policy

When this policy changes, the updated version is published here with a new effective date. For material changes we email account holders before the new version takes effect. Continued use of the API after the effective date means the updated policy applies.