Legal

Privacy Policy.

Last updated 8 July 2026 · v1.0-pilot

At a glance

INKAN provides software to brands and talent agencies that records and cryptographically seals two kinds of record: (1) a person's stated consent to the use of their likeness, and (2) likeness licences between talent and brands. This policy explains what personal data we handle, why, on what legal basis, who we share it with, how long we keep it, and your rights.

Headline facts:

  • We do not process any biometric data. No face image, no liveness check, no biometric reference. Consent is captured by a person clicking to attest via a secure single-use link. If we ever launch a biometric feature, we will update this policy first and it will operate on explicit consent.
  • Our database is hosted in the EU (Frankfurt, Germany).
  • Sign-in is passwordless (email magic link or enterprise SSO). We store no passwords.
  • INKAN holds and moves no money. We only record whether a licence has been issued, invoiced, or paid.
  • The service is for adults (18+) only.

This policy covers two groups of people:

  • Part A — Customer users (people at brands and agencies who use INKAN). We collect your data directly from you.
  • Part B — Talent (people whose consent or likeness licence is recorded). Your data usually reaches us through the brand or agency, so Part B includes the legally required "where did you get my data?" disclosure.

Who is responsible for what. For your account, the capture page, the verify page, and our website, INKAN decides how and why data is used — we are the controller. For the *contents* of consent and licence records, the customer (the brand or agency that created them) decides — they are the controller and INKAN is their processor, acting on their instructions. This affects who you should contact: see section 7.

1. Who we are

This service is operated by INKAN Ltd ("INKAN", "we", "us"), a company in the process of incorporation in England & Wales; the company registration number and registered office will be added here on incorporation.

Contact for privacy and legal matters: privacy@inkanbio.com.

We have not appointed a statutory Data Protection Officer, as we are not currently required to; the founder is the accountable data protection lead, reachable at the address above. We process personal data under UK GDPR and the Data Protection Act 2018.

2. Scope

This policy applies to: the website at inkanbio.com; the INKAN web application (including app.inkanbio.com); the capture page (the single-use link a person opens to attest consent); the public verify page; and our communications with users and prospective customers.

It does not cover our customers' own websites, systems, or privacy practices. Each brand or agency is responsible for its own privacy notice to its talent.

3. A note on biometric data — none is processed today

INKAN does not currently collect or process any biometric data. There is no face capture, no liveness check, and no biometric template or reference anywhere in the live service. Consent records are created by a person attesting — reviewing the stated scope on a capture page and clicking to agree.

We plan to offer an optional biometric liveness feature in future. Before any such feature launches, we will update this policy to describe exactly what is processed, on what legal basis (explicit consent), for how long, and through which providers — and we will treat any biometric reference as special-category data under Article 9 UK GDPR.

Part A — If you are a customer user (brand or agency)

*This is your Article 13 notice — data we collect directly from you. INKAN is the controller for everything in this Part.*

A1. What we collect and why

What we collectWhyLegal basis (UK GDPR)
Name, work email, organisation, roleTo create and run your account and workspaceContract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)) in operating the service
Sign-in data: magic-link tokens (single-use, ~10-minute expiry), SSO identifiers, session dataTo authenticate you securely without passwordsContract (Art 6(1)(b)); legitimate interests (Art 6(1)(f)) in security
Audit-log records of actions you take in the serviceSecurity, integrity, and accountability of the records you createLegitimate interests (Art 6(1)(f))
Support messages and correspondenceTo respond and provide supportLegitimate interests (Art 6(1)(f))
Prospect/relationship data (if you are not yet a customer)B2B outreach about INKAN; we honour opt-outs on every messageLegitimate interests (Art 6(1)(f))

We do not store passwords, and we do not ask customer users for special-category (sensitive) data.

A2. How long we keep it

For the duration of your organisation's account, plus up to 12 months afterwards for legal, audit, and security purposes, then we delete or anonymise it. Data your organisation exports during the 30-day offboarding window (see our Terms of Service) is your organisation's responsibility once exported.

Part B — If you are talent (your consent or licence is recorded)

*This is your Article 14 notice — your data usually reaches us through a brand or agency rather than directly from you, so it includes the required "source" disclosure.*

B1. What this is, in plain English

A brand or agency you work with uses INKAN to make a durable, tamper-evident record of:

  • your stated consent to the use of your likeness (recorded when you open a single-use link, review the scope, and click to attest — or recorded by the organisation on your behalf); and/or
  • a likeness licence between you and a brand (scope, territory, term, and fee).

INKAN seals each record with a digital signature so that any later alteration can be detected. The seal proves the record's integrity, not the identity of the person who completed a link and not the truth of what the record says.

B2. Who is responsible for your data

ActivityControllerINKAN's role
The contents of your consent and licence records — what is recorded about you, why, and whether it staysThe brand or agency that created the recordProcessor — we act only on their documented instructions
Operating the capture page, the public verify page, and this websiteINKANController

In short: for what is recorded about you, the brand or agency is your first point of contact — though you can always contact us and we will route your request (section 7). For how the capture and verify pages themselves work, INKAN is responsible directly.

B3. What we process, why, and on what legal basis

Data in your records (processed as processor, on the customer's instructions): your name and contact details; the scope, territory, term, and fee of any licence; your attestation (the fact, content, and time of your click-to-agree); capture metadata; and settlement status (issued / invoiced / paid). The customer, as controller, is responsible for the legal basis for these records and for having your valid consent where required.

The capture page (INKAN as controller): when you open a capture link we process technical data needed to serve the page and record your attestation securely (for example, timestamps and link-validity checks). Legal basis: our legitimate interests (Art 6(1)(f)) in operating a secure, fraud-resistant capture flow.

The public verify page (INKAN as controller): anyone can check that a sealed record's signature is valid against our published public key. The page is designed to confirm seal integrity only, not to publish a browsable directory of records or identities.

INKAN holds and moves no money. We record and report only whether a licence has been issued, invoiced, or paid. We are not a payment service and hold no funds (section 8).

B4. Where we obtained your data (the "source" disclosure)

  • Most of your data reaches us from the brand or agency you work with — for example your name, contact details, and licence terms. They are the source.
  • Your attestation is created at the moment you complete the capture link yourself.
  • For records the customer states were based on consent obtained elsewhere (out-of-band), the customer provided that information and is responsible for its accuracy.

These are not publicly accessible sources.

B5. How long we keep talent data

Records are retained on the instructions of the controller (the brand or agency), and in any event: sealed records and audit-log entries are kept while the customer's account is active and for up to 6 years from the end of the relevant relationship, reflecting the period in which legal claims about a consent or licence could arise — then deleted or irreversibly anonymised.

Append-only ledger and your right to erasure. Our ledger is tamper-evident and append-only — its value is that history cannot be silently rewritten. We reconcile this with your right to erasure by logically revoking the record and rendering the personal data within it permanently irrecoverable, rather than editing history. Where the law entitles the controller to keep proof of a consent (for example, to defend a legal claim), that proof may be retained for the period above.

5. Who we share data with, and where it is processed

The sections from here on apply to everyone. We use the following service providers ("sub-processors") to run the service. They process data only to provide their service to us, under contract. We do not sell personal data.

ProviderWhat they doLocation
NeonDatabase (all application data)EU — Frankfurt, Germany (eu-central-1)
VercelApplication hosting / computeUS company operating EU-region infrastructure
ResendTransactional email (magic links, notifications)US provider
GitHubSource-code hosting — no customer dataUS

Where your data is held. Application data is stored in the EU (Frankfurt). Some providers are US companies; where any personal data could be processed outside the UK/EU, we put an appropriate safeguard in place — the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or reliance on an approved adequacy mechanism — before any such transfer.

We maintain an up-to-date sub-processor list and will notify customer controllers of changes as required. AWS Rekognition is not currently used — it will be added to this list, with full transfer analysis, only if and when a biometric feature launches (section 3).

6. Your rights

Subject to conditions and exemptions in the law, you have the right to: access your personal data; have inaccurate data rectified; have your data erased; restrict processing; portability of certain data; object to processing based on legitimate interests, and to direct marketing at any time; and to withdraw consent where processing relies on it, as easily as you gave it. Exercising these rights is free in most cases, and we aim to respond within one month.

7. How to make a request (and how it is routed)

Customer users (Part A): contact INKAN directly at privacy@inkanbio.com — we are the controller for your account data.

Talent (Part B): it depends what your request is about:

  • Your consent or licence records (what is recorded, correcting it, deleting it): the brand or agency is the controller, so they are usually the quickest route. You can still contact us — if you do, we will promptly forward your request to the relevant controller and assist them, and we will tell you we have done so.
  • The capture page, verify page, or this website: contact us directly at privacy@inkanbio.com.

You do not need an INKAN account to make a request. To help us find your data, tell us which brand or agency you dealt with and roughly when. We may ask you to verify your identity so we do not disclose your data to the wrong person.

8. We do not handle money

INKAN records and reports settlement status only — whether a licence has been issued, invoiced, or paid. INKAN does not receive, hold, control, or transfer any funds, and is not a payment service, e-money issuer, or money handler. Any payment between talent and a brand happens outside INKAN.

9. Adults only

The service is for adults aged 18 and over only. Customers confirm to us that the talent whose data they record are adults, and the capture flow is not intended for anyone under 18. If you believe a record has been created for someone under 18, contact privacy@inkanbio.com and we will act.

10. Security

We use appropriate technical and organisational measures to protect personal data, including: EU database hosting (Frankfurt); encryption in transit and at rest; per-tenant database isolation (row-level security); passwordless authentication (single-use, short-expiry magic links / SSO — no stored passwords); a tamper-evident, append-only audit log; access controls and least privilege; and Ed25519 cryptographic sealing of records. Our records are tamper-evident — alteration is detectable — and record timestamps are generated from our server clock.

11. Complaints

If you are unhappy with how we have handled your personal data:

  • You can complain to INKAN first — you have a statutory right to complain to the controller, and we will acknowledge and respond. Contact privacy@inkanbio.com. (If your concern is about the contents of a consent or licence record, the brand or agency may be the appropriate controller — see section 7.)
  • You can also complain to the regulator — the Information Commissioner's Office (ICO), ico.org.uk, helpline 0303 123 1113. We would appreciate the chance to resolve your concern first.

12. Changes to this policy

We may update this policy from time to time — and we will update it before launching any biometric feature. We will post the updated version here with a new "Last updated" date and, where changes are significant, take reasonable steps to notify affected customers (who should notify their talent).

Prepared for pilot use; solicitor review scheduled. Questions: privacy@inkanbio.com