Data privacy
The following subsections describe data privacy features. For more detailed information see the Gatekeeper security data sheet.
Data encryption
Gatekeeper encrypts all sensitive information. Encryption in the system is defined per scope. Gatekeeper applies multiple layers of encryption using envelop encryption techniques. Encryption keys are stored in Kubernetes secrets that reside in a key store such as Azure Key Vault. By default the encryption keys are provided and managed by Nuance.
Data retention
Gatekeeper follows persistent data and records management policies that mandate the deletion of certain data after the data retention period. These policies are in place to protect privacy and data subject rights. Refer to the retention policy of each category below:
| Entity | Retention period |
|---|---|
Enrollment audio:
|
Never deleted automatically |
|
18 months |
| Billing data and summarization | 7 years |
| Export data through HTTP (5-min zip file) | 30 days |
| Logs | 60 days |
Note:
All data is retained for 90 days after your contract expires. After 90 days, all your data might be purged.Data subject rights and personal information
You can retrieve and delete personal information. At times, there may be some ambiguity regarding the owner of the personal information. When this occurs, the following logic applies:
- If the information was received during verification, the system implicitly sets the owner to the person specified in the claimed ID.
- If the information was received during identification, the system implicitly sets the owner to the highest scoring person.
- If the information was used for two verifications or two enrollments in the same session, the system implicitly sets the owner to the claimed ID of the first operation.
- If the information was not used for processing at all, the client application must explicitly specify the owner.
- If the interaction was marked as fraud, the system does not set an owner for the information. As a result, this information is not be retrieved or deleted.
Auto redaction of credit card numbers
To comply with PCI regulations, configure the system to automatically redact credit card numbers from all audio and texts in your scope. Redaction is performed immediately after a session, after the audio closes. Sensitive text is replaced with asterix (configurable) and sensitive audio segments are replaced with silence. This action consumes an additional license fee (for more information, refer to the price book). Redaction is limited to digits and ignores characters. Alternatively, you can mask sections of audio segments to conceal sensitive data. Masking does not replace credit card information with silence, but rather marks the interval as sensitive. When the user retrieves the audio, it is delivered with silence in place of the sensitive data.
Layer7 API Gateway
Nuance uses a Layer7 API Gateway to protect Gatekeeper services. It uses an open source and Kubernetes-native microservices API gateway.
Compliance with standards
This product complies and is certified with ISO 9001:2015 and ISO 27001:2013. ISO validates requirements and operates as a technical testing organization for safety, efficiency, and quality. It focuses on certifying against relevant ISO (International) standards, proven technical aspects, and local law. The certification assures customers that the biometrics system meets world-class industry standards in relation to the design and integrity of its security and privacy capabilities, both technically and procedurally. It also provides confidence that the system aligns to the customer’s overarching information security management program. Nuance is a PCI-DSS compliant Level-1 Service Provider. For more details see Resources