Legal

Privacy Policy

Last updated: 3 August 2026

Gekonova (“we”, “us”) designs palm vein recognition software and hardware. This page summarises how we handle personal and biometric data across our products and this website. It is a plain-language summary, not a substitute for the full legal terms provided in a client agreement.

Biometric data

Our devices and software are built around data minimisation: we do not capture or retain raw palm images. What is generated is a mathematical feature template derived from vein and surface patterns, which cannot be reverse-engineered into a viewable image. Templates are encrypted with AES-256 at rest and TLS/SSL in transit.

Data residency

In most deployments, biometric data is stored on infrastructure owned and controlled by the client, not on a third-party biometric cloud. This is a deliberate architectural choice to support data residency and sector-specific compliance requirements.

Your rights

Where applicable law grants you rights over your personal or biometric data — including access, correction and deletion — requests can be directed to the organisation operating the specific deployment, or to Gekonova at info@gekonova.com. Deletion requests are logged in an auditable history.

Compliance frameworks

Our architecture is designed to support compliance with GDPR, CCPA, LGPD, PDPA and POPIA, and aligns with ISO/IEC 30107-3 (biometric presentation attack detection) and payment standards including PCI DSS and EMVCo where relevant.

Website analytics & cookies

Like most business websites, gekonova.com may use essential and analytics cookies to understand site usage. You can control cookies through your browser settings.

Contact

Questions about this policy can be sent to info@gekonova.com or +44 (0) 203 865 0955.