1. Who we are and when these terms apply
Perspicax is a remote identity-verification service operated by Avancer, Inc. ("avancer.ai", "we"). It is used by organisations that need to verify the identity of their customers — for example a bank or payment provider (the "requesting organisation").
These terms apply to every verification session you start from a link or QR code sent to you by a requesting organisation. The version you agreed to is recorded with your session.
2. Your consent
By tapping Start you confirm that you have read these Terms and Conditions and the Privacy Policy, and you consent to your personal data being processed to verify your identity, as described below. The date, time, consent version, IP address and browser user agent are recorded as proof of that consent.
Giving consent is voluntary. If you do not agree, do not start the verification and contact the requesting organisation to ask about other ways to verify your identity.
3. Purpose of processing
Your personal data is processed for one purpose: to verify your identity for the requesting organisation, as part of the customer due diligence it must carry out, including under Jordan's Anti-Money Laundering and Counter-Terrorist Financing Law No. 20 of 2021.
Your data is not used for marketing, not sold, and not used for any purpose unrelated to the verification.
4. Data we collect
- ID card images: photos of the front and back of your national ID card.
- Selfie and liveness capture: frames of your face captured during the liveness check, and a short video-only liveness recording with no audio.
- Identity fields: the details read from your card, such as your name in Arabic and English, national number, date of birth, sex, document number, issue and expiry dates and the machine-readable zone.
- Device and browser information: your IP address, browser user agent and the technical details of each capture, such as timing and image quality.
Location metadata embedded in photos is removed when they are uploaded.
5. Automated decision and human review
Perspicax reads your card, checks the fields and the machine-readable zone, looks for signs of tampering, compares your face with the portrait on the card, confirms that a live person completed the check and screens your name. A versioned set of rules then produces an automated outcome: approved, declined, or sent for review.
Borderline sessions are reviewed by a person on the requesting organisation's compliance team, and approving a high-risk case requires a second reviewer. You can ask the requesting organisation for a human review of any automated decision and to explain how it was reached.
6. Screening against watchlists
Your name, together with its spelling variants in Arabic and Latin script, your date of birth and your national number, is always screened against the requesting organisation's internal watchlist of blocked persons. Where the requesting organisation has connected it, your name is also screened against OpenSanctions data: sanctions lists (including the United Nations, the US OFAC, the European Union and the UK's OFSI) and lists of politically exposed persons (PEPs). These lists are continuously updated.
A possible match does not mean that you are on a list. It sends your session for review by a person before a decision is made.
7. Service providers
To read your card and check it for tampering and presentation attacks, images are processed by Google Gemini, an AI service used by Perspicax. Where the requesting organisation connects it, sanctions and PEP data comes from OpenSanctions. The verification outcome is shared with the requesting organisation, and with regulators or other authorities where the law requires it.
8. How long data is kept
Raw media — your ID card images, selfie frames and liveness recording — is deleted automatically after a short retention window once a decision has been made (72 hours by default, set by the requesting organisation).
The extracted identity fields, the decision and the evidence behind it are kept for the period the requesting organisation must retain customer due-diligence records under the applicable regulations.
9. Your rights
Under Jordan's Personal Data Protection Law No. 24 of 2023 you have the right to:
- Access: ask what personal data is held about you and receive a copy of it.
- Correction: ask for inaccurate or incomplete data to be corrected.
- Withdrawal: withdraw your consent at any time. This does not affect processing already carried out, and the requesting organisation may then be unable to complete your verification.
- Complaint: complain to the requesting organisation, to us, or to the competent personal data protection authority in Jordan.
Requests are normally handled by the requesting organisation. You can also write to us and we will answer directly or pass your request on.
Contact: [email protected]
10. Your responsibilities
Use only your own, genuine identity document and complete the checks yourself. Sessions that use another person's document, an altered image or a photo or screen instead of a live face are declined or sent for review.
11. Security
Images are available only through short-lived signed links, national numbers are masked in lists and logs, access to the compliance panel is role-based, and every administrative action is recorded in a hash-chained audit log that makes later changes detectable.
12. Changes and contact
We may update these terms. A new version applies only to sessions started after it is published; the version you agreed to stays recorded with your session.
Avancer, Inc., 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA.
Contact: [email protected]
Version history
The version in force when you tap Start is the one recorded with your session; a new version applies only to sessions started after it is published. To receive the full text of an earlier version, contact us.
Version 2 ·
Section 6: your name is always screened against the requesting organisation's internal watchlist, and against OpenSanctions sanctions and PEP lists (now named: the United Nations, the US OFAC, the European Union and the UK's OFSI) only where the requesting organisation has connected it. Section 7: OpenSanctions is a provider only where it is connected.
Version 1 ·
First published version.
Contact: [email protected]