Privacy Policy
Last updated: April 2025
This Privacy Policy describes how Authentific ("we", "us", or "our") collects, uses, and protects personal data when you visit our website at authentific.com, use our product authentication platform, or interact with us.
Information we collect
Website enquiries and forms
When you submit a contact form, demo request, or newsletter signup on our website, we collect the personal information you provide - such as name, email address, company name, and any details you include in your message. This data is used solely to respond to your enquiry and follow up as part of the commercial process you initiated.
Consumer scan events
When a consumer scans an Authentific-protected product QR code, our authentication API records a scan event. This event log includes the time and date of the scan, the product identifier being verified, the approximate geographic location of the scan (derived from IP address), and the outcome of the authentication check. We do not collect device identifiers, create consumer profiles, or track individual consumers across multiple scan events.
Platform account data
Enterprise platform customers who access the Authentific management console provide account registration information including name, email address, company, and role. This data is used to administer the platform account and communicate about the service.
Website analytics
We may collect anonymous, aggregated website usage data to understand how visitors use our site and improve our content. We apply data minimization principles and do not use tracking cookies or third-party behavioural analytics.
How we use personal data
- To respond to enquiries and demo requests submitted through our website
- To administer enterprise platform accounts and provide the authentication service
- To provide brand owners with scan event analytics for their products
- To detect and investigate suspected counterfeit or diversion activity
- To comply with applicable legal obligations
Data sharing
We do not sell personal data. We do not share personal data with third parties for marketing purposes. We may share data with trusted service providers who process data on our behalf under appropriate data processing agreements. We will disclose personal data if required to do so by law or in response to a valid legal request.
Scan event data is shared with the brand owner of the authenticated product in aggregated and anonymised form for analytics and diversion detection purposes. Individual consumer scan events are not attributed to identifiable individuals in brand owner reports.
Data retention
Website enquiry data is retained for a maximum of 24 months from the date of submission, or until the commercial relationship is concluded, whichever is later. Platform account data is retained for the duration of the enterprise service agreement plus a reasonable period for record-keeping. Scan event logs are retained for the period agreed under the applicable enterprise service agreement.
Your rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict the processing of your personal data. To exercise any of these rights, please contact us with the subject line "Privacy Request" and we will respond within the timeframe required by applicable law.
Cookies
For information on our use of cookies, please see our Cookie Policy.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated to enterprise platform customers directly. The current version is always available at this URL.
Contact
For questions about this Privacy Policy or our data practices, please contact us.