LEGAL
Privacy Policy
LAST UPDATED: AUGUST 28, 2026 · BARANDIKO (US C-CORP, DELAWARE)
This policy covers two things: data this website collects (limited), and how Barandiko border systems process biometric and operational data (governed by the deploying authority). They are addressed separately because the answer to "what happens to biometric data" is the question most visitors care about, and the answer is not about this website.
1. Border system deployments — biometric and operational data
The short version: Barandiko operates as a technology provider. Biometric and border-transaction data in a deployment belongs to, and is controlled by, the commissioning authority — not by Barandiko.
- Controller. Where a Barandiko system is deployed by a government, border authority, or concession operator, that authority is the data controller. Retention periods, access controls, lawful basis, and data residency are set by the authority's legal framework, the concession agreement, and applicable national data-protection law.
- Biometric templates vs. raw data. Barandiko systems are designed to operate on biometric templates (mathematical representations), with raw capture imagery discarded after template extraction and match, subject to the authority's configuration.
- Data residency. Deployments can be configured so that biometric and transaction data remains on national infrastructure under the authority's control. Barandiko does not operate a biometric database of any population.
- No marketing of biometric data. Barandiko does not sell, share, or use biometric data from deployments for product development, marketing, or any secondary purpose.
- Processor obligations. Where Barandiko acts as a processor (e.g., maintenance, support), it does so under contract with the authority, with access logged, limited to what the task requires, and bound by confidentiality.
- Alignment. System design aligns to ICAO standards for document and identity verification, and to the deploying authority's data-protection framework.
Questions from authorities, data protection officers, or evaluators: support@barandiko.io. We answer governance questionnaires as part of normal procurement.
2. This website (barandiko.io)
What we collect
- Server logs. Our hosting provider records standard request data (IP address, user agent, timestamps) for security and availability monitoring.
- Analytics (if enabled). If analytics is enabled, aggregate visit data (pages viewed, approximate region, device type) is used to understand which content technical buyers need. No cross-site tracking, no advertising pixels, no data brokers.
- Contact email. If you email us, we keep the correspondence and your email address, for as long as needed to handle the inquiry and any resulting business relationship.
What we do not do
- No account creation, no forms beyond email, no newsletters at present.
- No sale or sharing of personal data with third parties for their marketing.
- No biometric data is collected by this website. It is an information site.
Legal bases (where GDPR/UK GDPR applies)
- Server logs & security: legitimate interest in keeping the site available and secure.
- Analytics (if enabled): consent, where required, withdrawable at any time.
- Correspondence: legitimate interest / steps preparatory to a contract.
Your rights
Depending on your jurisdiction (including GDPR/UK GDPR and California CCPA/CPRA), you may have rights to access, correct, delete, export, or object to processing of your personal data, and to lodge a complaint with a supervisory authority. To exercise any right: support@barandiko.io. We respond within 30 days.
International transfers
Our hosting and email providers may process data in the United States. Where required, transfers rely on standard contractual clauses or equivalent safeguards.
3. Children
This site is directed at government, infrastructure, and business audiences. It is not directed to children, and we do not knowingly collect data from children.
4. Security
The site is served over HTTPS. Access to our systems is limited to personnel who need it. No system is perfectly secure; if a breach affecting personal data occurs, we will notify affected individuals and regulators as required by law.
5. Changes
We may update this policy; material changes will be reflected by the "last updated" date above. This policy does not replace or alter the data-governance terms of any deployment contract.
6. Contact
Barandiko (US C-Corp, Delaware) · support@barandiko.io · barandiko.io
← BARANDIKO.IO