Privacy Notice
Authentiq is a fraud-detection and identity-resolution platform used by online businesses to tell genuine visitors apart from bots, automation, and fraud. This notice explains what we process, why, and the roles we and our customers play under data-protection law.
Two roles: our customers and us
Authentiq is embedded by the businesses that use it (our "customers"). When an end user visits a customer's site, the customer decides why fraud detection runs and what happens with the result. In GDPR terms:
- Our customer is the controller of the end-user data processed through their integration — they determine the purpose and means.
- Authentiq is the processor, acting on the customer's documented instructions under a data-processing agreement.
For our own operations — this website, our waitlist, sales, and support — Authentiq is the controller. This notice covers both, and flags which is which.
What we process
End-user signals (as processor, on a customer's site)
When fraud detection runs on a customer's page, the Authentiq SDK and our edge collect signals used to fingerprint the device and assess trust. These include:
- Device and browser characteristics — a browser fingerprint (canvas, WebGL, audio, fonts, screen, navigator, and similar attributes).
- Network-layer fingerprints — TLS and TCP fingerprints (JA3/JA4/JA4H/JA4T) derived from the connection, plus IP address and derived geolocation.
- Behavioral telemetry — coarse interaction signals (pointer capability, keystroke and click timing, form-engagement patterns) used to distinguish humans from automation. Field values are not captured; PII-bearing labels are redacted at the SDK before transmission.
- Customer-supplied identifiers — where a customer chooses to send them, a hashed email and/or the customer's own account identifier, used to resolve a persistent identity across sessions.
Email addresses supplied for identity resolution are hashed; we do not store the raw email. The result we return to the customer is a trust verdict and a factor breakdown — not a dossier.
Our own visitors (as controller, on this site)
On authentiq.io we process what you submit — for example an email address to join the waitlist — and standard server/operational logs. We use our own SDK on this site to demonstrate and improve the product.
Why we process it
- To detect and prevent fraud, bots, and automated abuse — the core service.
- To resolve and de-duplicate identities across sessions and devices for that purpose.
- To operate, secure, and improve the platform.
- To respond to you and manage the waitlist and customer relationships.
Retention
End-user signals are retained for the period configured with each customer and no longer than needed for fraud detection. Waitlist and contact data are kept until you ask us to delete them or they are no longer needed.
Sharing and subprocessors
We do not sell personal information. We share data with vendors that help us run the service (for example, infrastructure hosting and IP-geolocation / email-risk enrichment), each under contract and only as needed to provide the service.
International transfers
We offer EU and US data residency. Where data is transferred across borders, we rely on appropriate safeguards.
Your rights
Depending on where you live, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object or request portability. Because we act as processor for end-user data on customer sites, requests about that data are best directed to the business whose site you used; we will support that business in responding. For data we control, contact us directly.
Changes
We will update this notice as the platform and our practices evolve, and will revise the "last updated" date above.