Legal

Privacy Policy

How UNiQ collects, uses, and protects your data

Effective Date: January 1, 2025

UNiQ ("we", "our", "us") is operated by Ignite Eduventure. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our biometric fingerprint intelligence analysis service. Please read this policy carefully. By using UNiQ, you agree to the practices described herein.

1 Data We Collect

We collect the following categories of information:

  • Fingerprint ridge patterns — Processed locally on-device during scanning. Raw fingerprint images are captured solely for the purpose of deriving mathematical ridge-count values (TFRC — Total Finger Ridge Count) and are never transmitted or stored as images.
  • Personal identification information — Full name, age, date of birth, and gender provided during registration.
  • Contact information — Email address and phone number, used for report delivery and account communication.
  • Device information — Device type, operating system version, and app version collected for technical support and service improvement.
  • Usage data — App interaction logs used anonymously to improve algorithm accuracy.

2 How We Use Your Data

Information collected is used exclusively for:

  • Generating your personalised neural intelligence report based on derived fingerprint ridge-count data.
  • Delivering your completed report via email to the address provided at registration.
  • Improving the accuracy and reliability of our dermatoglyphic analysis algorithms using anonymised, aggregated data.
  • Providing technical support and responding to customer service enquiries.
  • Sending service-related notifications (e.g., report availability, account updates).

We do not use your data for advertising, profiling for commercial sale, or any purpose beyond the scope of report generation and service delivery.

3 Fingerprint Data Handling

Raw fingerprint images are never stored. Only derived mathematical ridge-count data (TFRC values) is retained for report generation. This numerical data cannot be used to reconstruct a fingerprint image.

The fingerprint scanning process works as follows:

  • Your fingerprints are scanned locally on your device using the UNiQ mobile application.
  • Ridge patterns are processed on-device to derive numerical TFRC values for each finger.
  • Only the resulting numerical values (not the image) are transmitted securely to our servers for report generation.
  • All derived fingerprint data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.
  • Fingerprint-derived data is associated with your account solely for the purpose of generating and storing your intelligence report.

4 Third-Party Services

We use the following third-party service for data storage:

  • Supabase — A secure, SOC 2-compliant database hosting provider. Your data is stored in encrypted databases hosted by Supabase. Supabase processes data solely on our behalf and in accordance with our instructions.

We do not sell, rent, trade, or otherwise disclose your personal data or fingerprint-derived data to any third party for commercial purposes. We do not share data with advertisers, data brokers, or marketing companies.

We may disclose information if required by applicable law, court order, or governmental authority, or if necessary to protect the rights, property, or safety of UNiQ, our users, or the public.

5 Data Retention

We retain your data for the following periods:

  • Intelligence report data — Retained for 5 years from the date of report generation to allow you to access your report at any time.
  • Account information — Retained for the duration of your account's existence plus 1 year after account deletion.
  • Usage logs — Anonymised and aggregated after 12 months; raw logs are deleted after 90 days.

You may request the deletion of all your data at any time by emailing cs@igniteeduventure.com. Data deletion requests are processed within 30 days.

6 Children's Privacy

UNiQ is specifically designed to serve children and students. Given this, we take children's privacy with particular seriousness.

  • The service is intended for users of all ages, including minors.
  • For users under 18 years of age, a parent or legal guardian must provide explicit consent before registration and data collection.
  • We do not knowingly collect data from minors without verified parental or guardian consent.
  • Parents and guardians may request access to, correction of, or deletion of their child's data by contacting us at cs@igniteeduventure.com.
  • Data of minors is subject to the same encryption and retention standards as adult data, with no additional disclosure to third parties.

7 Your Rights

You have the following rights regarding your personal data:

  • Right of Access — Request a copy of all personal data we hold about you.
  • Right to Rectification — Request correction of inaccurate or incomplete data.
  • Right to Erasure — Request deletion of your data, subject to legal retention requirements.
  • Right to Data Portability — Request your data in a structured, machine-readable format.
  • Right to Withdraw Consent — Withdraw consent for data processing at any time (this will not affect the lawfulness of prior processing).

To exercise any of these rights, contact us at cs@igniteeduventure.com. We will respond within 30 days.

8 Data Security

We implement the following security measures to protect your data:

  • AES-256 encryption for all data at rest.
  • TLS 1.3 encryption for all data in transit.
  • Access controls restricting data access to authorised personnel only.
  • Regular security audits and vulnerability assessments.
  • Secure database hosting via Supabase with SOC 2 compliance.

While we implement industry-standard security practices, no digital system is completely immune to breach. In the event of a data breach that affects your personal data, we will notify you within 72 hours in accordance with applicable law.

9 Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

  • Update the "Effective Date" at the top of this page.
  • Notify registered users by email of significant changes.
  • Provide a 14-day notice period before material changes take effect.

Your continued use of the service after the effective date of changes constitutes acceptance of the updated policy.

10 Contact Us

For any privacy-related questions, data requests, or concerns, please contact us:

We are committed to resolving privacy concerns promptly and transparently.