Global Privacy Policy v1.2
Last updated: September 1, 2026 at 08:13
Global Privacy Policy & Biometric Data Notice (v1.2)
Operator: Bizbio Inc. (“Bizbio”, “we”, “us”), operating Verified Reality.
Version: 1.2
Effective date: 1 September 2026
Supersedes: Global Privacy Policy & Biometric Data Waiver v1.0 (1 June 2026)
Current public Privacy Policy. This Version 1.2 is the current public Privacy Policy of Bizbio Inc. for Verified Reality, effective 1 September 2026. It supersedes Version 1.1 (31 August 2026) and Global Privacy Policy & Biometric Data Waiver v1.0 (1 June 2026). Bizbio may publish a later numbered version under Section 14; until then, this Version 1.2 governs.
This Policy describes how Bizbio collects, uses, stores, and discloses personal information in connection with the Verified Reality websites, Command Centre, mobile capture application, Desktop Auditor, and related services (the “Service”). It applies to clients, independent Verifiers, and other users.
This Policy is a notice, not a waiver of statutory privacy rights. Using the Service constitutes acknowledgement that you have read this Policy. Click-wrap or in-app consent screens, where shown, record consent for specific processing described at that time.
Section 1: What this Policy covers
1.1 Roles
Clients commission captures, store Truth Packets, and may act as a data controller for mission instructions and the personal information they supply about their own matters.
Independent Verifiers (Sovereign Witnesses) are independent contractors. Bizbio is not their employer. Verifier dossier and device data are processed so missions can be matched, sealed, and paid.
Bizbio operates the infrastructure: capture-time authentication, cryptographic sealing, integrity checks, vault storage, and an auditable chain of custody that authorized recipients can re-verify.
1.2 What Verified Reality does — and does not — claim
Verified Reality records capture-time provenance, device telemetry, and integrity indicators. A matching hash shows that bytes match a prior reference. It does not prove that a depicted scene was honest, unstaged, complete, or admissible in court. Automated audits are technical triage, not legal opinions, insurance determinations, or expert reports. Admissibility and evidentiary weight are determined by the applicable court or decision-maker.
Section 2: Personal information we collect
2.1 Account and commercial data
Depending on the product path, this may include name, email, phone, organization, billing and payout details (including Stripe Connect identifiers), addresses, and communications with support.
2.2 Verifier identity photos (facial geometry)
Where a Verifier uploads dossier photos, Bizbio may use Amazon Rekognition or similar logic to compare a live or session image against the registered dossier in order to reduce account sharing (“ghost verifying”). This is identity matching of the enrolled Verifier, not a claim that a depicted bystander or scene subject has been identified, and not a commissioned notary act.
Consent: this processing is purpose-specific. A Verifier may withdraw consent by contacting privacy@verifiedreality.ca or using in-app controls where offered. Withdrawal may mean the Verifier cannot complete missions that require dossier matching.
2.3 Sensor fingerprinting (PRNU)
The Service may capture Photo-Response Non-Uniformity (PRNU) noise patterns from a camera sensor. PRNU may associate media with a camera sensor. It does not bind a human operator’s identity to that sensor and is not treated as a biometric identifier of a person. It is used for device association, emulator/virtual-camera detection, and integrity review.
2.4 Capture telemetry and session data
This may include GNSS/GPS (where permitted), gyroscope and accelerometer streams, network time checks, device model and OS integrity signals, SHA-256 content hashes, C2PA provenance on device paths that support it, and session identifiers. Missing or conflicting telemetry is treated as an anomaly for review (technical quarantine), not as a legal finding.
2.5 Incidental third-party images
Field video and photos may incidentally depict bystanders. Clients and Verifiers are responsible for lawful capture in the field (including any required notices or permissions). Bizbio processes that media as part of the Truth Packet the user created.
Section 3: Purposes of processing
We use the information in Section 2 to:
generate, store, and deliver Truth Packets (capture-time authentication, sealing, and chain of custody);
prevent fraud (emulators, virtual cameras, injection tools, account sharing);
operate dispatch, payout, licensing (when a user opts in), and customer support;
produce technical integrity reports (Axel, Stella, Desktop Auditor) — not legal advice;
comply with law, including producing records we actually hold when legally compelled;
improve the Service using aggregated or de-identified diagnostics where feasible.
We do not sell personal biometric profiles. Secondary licensing of eligible capture files is opt-in and, when the Exchange launches, will be governed by a separate licensing agreement. Demand and earnings are not guaranteed.
Section 4: Storage, encryption, and access (not a blind-only vault)
4.1 Encryption and access control
Truth Packets and related vault objects are encrypted in transit and at rest using prevailing industry practices (currently including AES-256-GCM for packet payloads). Access by Bizbio personnel is restricted, logged, and used for support, security, product operation, and lawful process — not casual browsing of client media.
4.2 Key escrow (honest architecture)
v1.0 described Bizbio as a “Blind Custodian” with no technical means to recover keys. That overstated the live architecture. Bizbio maintains limited key-escrow / recovery capability so that users can recover access, so support can function, and so Bizbio can comply with lawful demands for data it is technically able to decrypt.
Bizbio is not a no-keys cryptographic host. We still do not use vault media for advertising profiles, and we do not treat staff access as a substitute for client authorization on ordinary commercial requests.
4.3 Lawful process
Where Bizbio can decrypt or otherwise produce records, we may disclose them in response to a valid Canadian warrant, court order, or other compulsory legal process, or where disclosure is required by law. Where we cannot decrypt a particular object, we will say so.
4.4 Data residency
Unless an SLA or directed export says otherwise, primary application data is stored in Canada or in SOC 2 Type I (or comparable) jurisdictions used by our processors. Users who direct an export to another country are responsible for the lawfulness of that transfer.
Section 5: Retention (by data type and tier — not a universal seven-year mandate)
Retention depends on data type, account tier, and what the client or Verifier selected (including optional Arweave public-ledger (hash and/or encrypted payload) anchoring and paid vault plans). There is no single legally mandated seven-year retention for every Truth Packet.
Typical patterns (subject to the applicable plan and any legal hold):
Account and billing records: kept as needed for tax, payout, and dispute purposes.
Vault media: kept for the selected storage tier; may be purged or made inaccessible after the plan ends unless a legal hold applies.
Integrity hashes and audit logs: may be kept longer than playable media because they are required to show whether a file later changed.
Dossier photos / facial templates: kept while the Verifier account is active and for a short wind-down after closure, unless a longer hold is required by law.
A tombstone (making a file unavailable in product UI) is not the legal equivalent of deletion. Public ledger hashes, backups, and logs may remain.
Section 6: Optional public ledger (Arweave)
Users may elect to anchor a cryptographic hash of a Truth Packet to Arweave (or a similar public ledger). That hash is a proof-of-existence for those bytes. It is not a claim that the scene was true, complete, or admissible.
Arweave is operated by third parties. Once a hash is successfully written, Bizbio cannot delete it using currently available means. That is a technical limit, not a contractual waiver of PIPEDA (or GDPR, where it applies) rights in company-held personal information.
If you request erasure of company-held copies, we will delete or de-identify what we control, subject to legal holds and backups. The public hash may still exist. We will explain that limit in plain language when you opt into anchoring. Optional public-ledger writes are the user's choice. Under this Service, ledger payloads are encrypted. Ciphertext may remain on a third-party ledger after a successful write. Disposing of or losing decryption keys, together with deletion or de-identification of company-held copies and keys Bizbio controls, is treated as practical erasure of the readable personal information. Remaining hash or ciphertext without usable keys is not playable media in Bizbio's control. This Policy does not require a waiver of PIPEDA or GDPR erasure rights in company-held personal information as a condition of using the core Service.
Section 7: Your privacy rights
Subject to PIPEDA and other applicable law, you may request:
Access to personal information we hold about you;
Correction of inaccurate information;
Withdrawal of consent for optional processing (including dossier matching and public anchoring), understanding that some Service features may then be unavailable;
Deletion of company-held personal information, subject to legal retention duties and the technical limits in Section 6;
A complaint to the Office of the Privacy Commissioner of Canada if we cannot resolve your concern.
Requests: privacy@verifiedreality.ca (or support@verifiedreality.ca). We will respond within the time PIPEDA requires.
This Version 1.2 does not ask you to waive a statutory right of erasure as a condition of using the core Service. Optional public anchoring is a separate, informed technical choice. EEA and UK visitors: see Section 15 for GDPR / UK-GDPR lawful bases, transfers, and rights.
Section 8: Processors and subprocessors
We use processors such as hosting, object storage, email, payments (Stripe), and (for Verifier dossier matching) Amazon Rekognition. They process data on our instructions. A current list can be requested from privacy@verifiedreality.ca.
Section 9: Automated forensic triage
Agents such as Axel and Stella, and the Desktop Auditor, extract metadata, hashes, telemetry correlations, and media-structure indicators. Outputs are integrity checks and structured triage. They are not expert opinions, legal advice, insurance determinations, damage-causation findings, or guarantees of admissibility.
Section 10: Incidents
If a breach of unencrypted personal information meets PIPEDA’s real-risk-of-significant-harm threshold, Bizbio will notify affected individuals and the Privacy Commissioner as soon as feasible. A 72-hour target may be used operationally for unencrypted PII incidents; it is not a promise that encrypted vault objects were accessed, and it is not a substitute for the statutory standard.
Section 11: Session termination (panic-wipe)
Where the mobile app offers session termination that shreds local session keys, Bizbio may be unable to recover that local session. That is a safety feature, not a deletion of already-uploaded vault objects.
Section 12: Children
The Service is directed at businesses and independent adult contractors. It is not directed at children.
Section 13: Governing law
This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein. Courts in London, Ontario have jurisdiction over disputes that cannot be resolved informally, without limiting any non-waivable statutory complaint right (including to the Privacy Commissioner).
Section 14: Changes
Bizbio may update this Policy as the product and the law change. Material changes will be posted on this page with a new version number and effective date. Continued use after the effective date constitutes acceptance of the updated Policy, except where applicable law requires a fresh consent for a new purpose.
Questions: privacy@verifiedreality.ca · Bizbio Inc., London, Ontario, Canada.
Section 15: EEA and United Kingdom (GDPR / UK-GDPR)
This section applies when GDPR or UK-GDPR applies to you (for example you are in the EEA or the UK). It does not replace PIPEDA rights in Section 7. Where both apply, you keep the stronger protection.
15.1 Lawful bases
We process personal information on these bases, depending on the purpose:
Contract (GDPR Art. 6(1)(b)): creating and operating your account, performing the Client MSA or Verifier ICA, delivering Truth Packets, payouts, and support you request.
Legitimate interests (Art. 6(1)(f)): security, fraud and emulator detection, PRNU sensor association (not operator identity), integrity logs, and de-identified product diagnostics. We do not use these interests to override your rights.
Consent (Art. 6(1)(a)): Verifier dossier facial matching; optional Arweave public-ledger (hash and/or encrypted payload) anchoring; non-essential advertising/measurement cookies (Google Ads). You may withdraw consent; withdrawal does not affect processing already completed.
Legal obligation (Art. 6(1)(c)): tax, accounting, and producing records we actually hold when lawfully compelled.
Special category / biometric data: Verifier dossier facial-geometry matching is purpose-specific identity matching of the enrolled Verifier (Section 2.2). Where GDPR Art. 9 applies, we rely on explicit consent. PRNU is not treated as a biometric identifier of a person.
15.2 Transfers
Primary application data is stored in Canada. The European Commission has an adequacy decision for commercial organizations in Canada that are subject to PIPEDA; the UK has a comparable recognition. Processors in the United States (including Stripe, Amazon Rekognition for Verifier dossier matching, and Google if you accept advertising cookies) receive data under their processor terms, which include Standard Contractual Clauses or another lawful transfer tool those processors publish. Request the current processor list from privacy@verifiedreality.ca.
15.3 Regional rights
Subject to GDPR / UK-GDPR and any exceptions, you may request: access; rectification; erasure; restriction; portability; objection to processing based on legitimate interests; and withdrawal of consent. You may lodge a complaint with a supervisory authority (including the ICO in the UK, or the authority in your EEA member state) as well as the Office of the Privacy Commissioner of Canada. Contact privacy@verifiedreality.ca. We aim to respond within one month.
15.4 Cookies and advertising measurement
Google Ads and similar advertising tags, when loaded, use Consent Mode with a denied default. Non-essential advertising cookies are not stored until you accept the site banner. Rejecting leaves measurement cookies off. This banner is Bizbio first-party consent control, not a certified IAB TCF consent-management platform.