SightRadar Data Processing Agreement
Last updated: September 25, 2026
This Data Processing Agreement ("DPA") is between SightRadar and you (the "Customer"). It forms part of the SightRadar Terms of Service and governs how we handle personal data — including biometric face data — on your behalf.
1. Key terms
Controller — that's you. You decide which images to submit, whose faces to index, and why (your users, your photos, your application).
Processor — that's us, SightRadar. We process the data only to give you face detection, indexing, search, and comparison results and related services.
Subprocessor — vendors we use to help process data (for example, our cloud hosting providers).
Customer Content — the images you submit through the API or console, and the face embeddings (numeric vectors), face IDs, bounding boxes, quality scores, and metadata we derive from them.
2. Scope of processing
When you call the SightRadar API, we process the images you send to detect faces, compute face embeddings, and return results. For indexing, the embedding is stored in a collection you own. For detection, comparison, and search-by-image, the image is processed in memory to compute a result and is not retained.
Face embeddings are biometric data. You are responsible for ensuring that your application complies with GDPR, the UK GDPR, India's DPDP Act, Illinois BIPA, and any other applicable data-protection or biometric-privacy law, including obtaining explicit or written consent from the individuals whose faces you submit where the law requires it.
We also process your account data (email address, authentication identifiers, API key metadata) and usage data (timestamps, operation type, credits charged, request IDs) to run your account, secure the Service, and bill you.
We process Customer Content only to provide you with the Service. We never use your images or embeddings to train, fine-tune, or improve any model. We never build a cross-customer face database. We never sell or share your data with third parties.
3. Data retention
Customer account data is kept until you delete your account.
Customer Content retention is under your control:
- Indexed faces stay in your collections until you delete them via the API or console.
- Deleting a collection hides it immediately and permanently purges its face vectors after a 7-day grace window, during which you can restore it.
- For verified erasure requests (for example, GDPR Article 17), you can choose immediate deletion, which purges the data right away and cannot be undone.
- Detect, compare, and search-by-image requests are processed in memory; the submitted image is not stored.
Usage and billing records are kept for as long as needed to run your account and to meet legal, tax, and accounting obligations. You can request deletion at any time.
4. Subprocessors
We currently use the following trusted vendors to process data:
| Subprocessor | Purpose | Location |
|---|---|---|
| AWS (Amazon Web Services, Inc.) | Cloud infrastructure for the face-recognition engine, API gateway, vector database, and storage of indexed face data. | Asia Pacific (Mumbai), India — ap-south-1 |
| Cloudflare (Cloudflare, Inc.) | Edge network, DNS, TLS termination, and hosting of the sightradar.com website, developer console, and static assets. | Global edge network (data in transit only) |
Each subprocessor is bound by data-protection obligations no less protective than this DPA, and we remain responsible for their performance. We may add or replace subprocessors, and will update this page when we do so you can object where you have that right.
5. International data transfers
Our face-recognition engine, vector database, and stored Customer Content are hosted in India (AWS Asia Pacific, Mumbai). Our website and console are served through Cloudflare's global edge network. This means personal data of EU, EEA, and UK residents will be transferred internationally.
Where a transfer is made to a country without an applicable adequacy decision, the parties rely on the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), incorporated by reference and completed with the details in Sections 1 and 2, together with our subprocessors' own compliance commitments.
6. Security measures
We implement the following security measures:
- Encryption in transit via HTTPS (TLS) for every API and console request.
- Encryption at rest for stored face vectors and account data.
- Per-tenant isolation — each account's face vectors are namespaced and can never be searched by, or disclosed to, another customer.
- Scoped API keys, shown once at creation and revocable at any time from the console.
- Least-privilege access controls so only authorised SightRadar personnel can reach production systems, under confidentiality obligations.
- Backups to prevent accidental loss of important data.
- Secure hosting with reputable vendors (see Section 4).
7. Roles and responsibilities
Your responsibilities
- Ensure you have a lawful basis to collect and process the personal data you submit, including explicit or written consent for biometric data where required.
- Provide a privacy notice to the individuals whose faces you process, as required by law.
- Issue only lawful instructions, and comply with our Acceptable Use Policy — no covert surveillance, no identifying people without their consent.
- Handle access, correction, and deletion requests from the individuals in your data; we will assist you.
Our responsibilities
- Process data only on your documented instructions (which include your use of the API and console), except where the law requires otherwise.
- Keep data secure and confidential, and ensure our personnel are bound by confidentiality.
- Notify you without undue delay after becoming aware of a personal-data breach affecting your data.
- Assist you, within reason, in meeting your data-protection obligations, including data-subject requests, security, breach notification, and impact assessments.
- Delete or return your personal data at the end of the engagement, as described in Section 3.
- Make available the information reasonably necessary to demonstrate compliance, and allow for audits, subject to reasonable confidentiality and security conditions.
8. Data access and exports
SightRadar provides access to all Customer Content processed on your behalf via its API and console. You can list, export, and delete collections and faces at any time. Exports reflect the data as processed and stored by the platform (face IDs, metadata, and embeddings); we do not retain or export the original images you submitted.
9. Governing law
This DPA is governed by the laws of India. Any disputes will be resolved exclusively in the courts of competent jurisdiction in India. If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls.
By using SightRadar, you agree to this DPA.
This agreement is generated digitally and takes effect without signatures from either party. If your own records need a signed copy, you may sign the downloaded PDF; SightRadar does not countersign.
Data-protection queries: privacy@sightradar.com or legal@sightradar.com.