Skip to content

Legal

Biometrics: what we do and why

Assessment reviewed 31 July 2026. Kept under review, and re-dated when it changes.

This page is our proportionality assessment under the Biometric Processing Privacy Code 2025. It is not indexed by search engines - you've reached it from the verification screen or our privacy policy. It's written to be honest about our reasoning, not to sell you anything. It is not legal advice.

What the check is

Before a listing goes live, the person behind it verifies their identity. Our verification partner, Sumsub, photographs a government ID and takes a short live selfie, and checks by machine that the face on the ID is the same live person. That face-match is biometric processing under New Zealand's Biometric Processing Privacy Code 2025.

We engage Sumsub to collect and process facial images and related identity information on our behalf, for identity, age and liveness verification. Sumsub does that overseas, under its own security. What comes back to us is ordinarily the result - verified or not, with a reference and risk information - rather than the underlying images or the biometric template.

Read that carefully, because the difference matters and it would be easy to write it misleadingly. Section 11 of the Privacy Act treats information held by an agent on our behalf as held by us. So the honest statement is not "we don't collect biometric information" - we do, through Sumsub, and we remain responsible for it under New Zealand privacy law. What is true is narrower: the images do not reach our own systems, so a breach of our servers cannot leak your face. Both things are true at once, and only saying the second one would be a way of dodging the first.

Why we do it - the lawful purpose

This is an adult platform, and the single gravest thing that can go wrong on it is a person under 18 being advertised on it. New Zealand law makes that a serious offence, and it is the harm we most need to prevent. Identity verification is also how we keep the platform honest for the people who use it: a verified badge means the person is real, is who they say they are, and is old enough - which protects both the advertiser and the people contacting them.

Why a face-match, and not something weaker

A tick-box saying "I am over 18" is not a check - it stops nobody, and it was the exact weakness that let unverified listings exist before. A document photo on its own can be borrowed, bought, or lifted from someone else's ID. The live face-match is what ties the document to the actual person in front of the camera, which is the whole point: it is the least elaborate method that actually establishes the thing we need to establish. We could not achieve the same protection as effectively by a means with less privacy risk, which is the test the Code sets.

The privacy risk, and how we hold it down

  • The images never reach our own systems. We receive a result, so a breach of our servers cannot leak anyone's face or ID, and that is the biggest single risk reduction available to a platform this size. It is a limit on where the data sits, not a limit on our responsibility: under section 11 of the Privacy Act what Sumsub holds for us is held by us, and we answer for it.
  • The data is used for one purpose: verifying age and identity. It is never repurposed for any other kind of matching, tracking, or surveillance - the Code forbids that, and so do we.
  • Accuracy is not uniform across faces. Automated face-matching is known to be less accurate for some groups than others, and can struggle where someone's appearance has changed, or for gender-diverse people whose ID may not match how they present. We treat a failed automated check as a starting point, not a verdict. We have asked Sumsub for its false-match and false-rejection rates and its demographic performance data, and we have not yet been given them: until we have, this is a known weakness we are managing by never letting the machine have the last word, rather than a measured one.
  • The face check is how identity is verified here, and it is the route we expect nearly everyone to take. It is not the only one. Anyone it genuinely does not suit - for accessibility reasons, an appearance change, an ID mismatch, or an objection to having their face processed at all - can ask for a person instead, and we arrange that individually. It is slower and it is deliberately not a self-service second front door; it is also real, it is not a dead end, and asking costs nothing.
  • Cultural impact on Māori is a mandatory factor under the Code. We have weighed it, we keep it under review, and anyone with a concern about how this check affects them can raise it with our privacy officer.
  • The consequence of getting it wrong - being unable to advertise or earn - is exactly why the manual route and the ability to query a result exist. A misread must not silently shut someone out of their livelihood.

Where it goes, and how long it stays

  • Who processes it: Sumsub, as our verification partner, acting on our instructions. Nobody else receives your ID or your selfie from us, because we never have them to give.
  • Where: overseas. Sumsub processes and stores this material outside New Zealand under its own infrastructure and security. That is a disclosure we are accountable for, and the exact countries and sub-processors are part of what we are reviewing with them before launch.
  • How long: Sumsub sets its own retention for the images and template under our agreement with it. What WE keep is the result, the reference, and the date - not the images - for as long as the account exists, and then under the retention schedule in our privacy policy.
  • What happens if you say no: ask us, and we will arrange for a person to confirm your age and identity another way. That is an exception we arrange case by case rather than a second front door, and you do not have to justify wanting it. If you do neither, we cannot confirm your age or identity, so a listing cannot be published. That is a hard gate and it is meant to be - it is the whole reason the check exists.
  • What matching happens: your selfie is compared with the photo in your document, and the check also looks for duplicates among the other people who have verified for THIS site, so that one person cannot hold several verified identities here. Since 14 August 2026 Private Encounters has its own separate account with our verification partner, so that comparison no longer reaches across to any other business we run, and being verified elsewhere cannot cause you to be refused here.
  • What we do NOT do: no tracking, no reuse for advertising or profiling, and no sharing of the result outside what is described here.

The manual route, and what it means for your documents

The face check is the standard route here, and the manual one is an exception we arrange rather than a second front door standing permanently open. You can still ask for a person, with no reason required, and one of us will arrange another way to confirm your age. We do not receive identity documents at all today - not through the automatic check, and not through the manual one. That changes only in two situations: if you ask for a person and we arrange it with you, or if our verification partner becomes unavailable to us or cannot evidence its accuracy, in which case we would verify by hand until that is resolved. If either happens this section changes with it and sets out exactly what we would hold and for how long.

This check is running as a trial, and here is what that means

From 13 August 2026 to 13 February 2027, the automatic identity check is operating as a formally documented trial under the Biometric Processing Privacy Code. We think it is the right control and we can explain why. What we cannot yet do is show independent figures on how accurately it performs, and particularly whether it performs differently for different groups of people. The Code allows that question to be answered with real-world evidence over a limited period, provided the people being checked are told it is happening. This is us telling you.

  • It runs for six months and no longer. One further six-month extension is possible if there is a reason, which we would have to write down first. If we still cannot show the check works well enough by the end, we stop using it and either change providers or verify people by hand.
  • We are counting outcomes, not people: how many pass, how many are refused, how many refusals a person overturns, how many choose the non-biometric route and how they fare. That is the comparison the trial is for.
  • We are NOT collecting anything new about you to run it. In particular we are not asking anybody their ethnicity to build a local dataset. Accuracy across groups is a question for the provider and for independent testing, not something we should be profiling advertisers to answer.
  • The trial does not weaken anything. A person still looks at every refusal, a reason is still recorded either way, and you can still ask to skip the face check entirely without giving a reason.
  • It is not retrospective. It began the day we wrote it down and applies from then on.

Our conclusion

Weighing the benefit - preventing minors and impersonators on an adult platform, and a genuine safety benefit to the verified person - against a privacy risk we have designed down by holding no images ourselves, using the data for one purpose only, and offering a manual route for anyone the automated check doesn't suit, we consider biometric identity verification proportionate for this use. We keep that judgement under review, and it changes if the balance does.

One part of it is not finished, and pretending otherwise would defeat the point of writing this down. The Code asks us to weigh how often the check wrongly matches or wrongly rejects, and how that differs across groups of people. We do not have those figures, and we have not yet obtained them from our verification partner. Until we do, the conclusion above rests on the design rather than on measured accuracy: no images held by us, one purpose only, two controls that exist precisely because the numbers are missing, and the time-limited trial described above, which is how the evidence gets collected rather than assumed.

Those two controls are real, and as of 12 August 2026 they are built rather than promised. Every result the automatic check rejects goes to a person before it counts for anything, and that person can and does overturn it. And you can skip the face check altogether: there is a button on your verification page that puts you in front of a human, with no reason required. Wrongful rejection is the failure nobody reports - people simply leave - so it is the one we decided to catch by hand. When the accuracy numbers arrive this page gets revisited and re-dated, and if they are bad enough the conclusion changes.

Your rights, and who to ask

You can ask what is held about you, ask for it to be corrected, or complain. Reach our privacy officer at privacy@privateencounters.co.nz (details on our operator page), or complain to the Office of the Privacy Commissioner at privacy.org.nz. Because the biometric data is held by Sumsub, an access or correction request about the images themselves may need to go to them - we'll help you do that.