UK AGE ASSURANCE AND ACCESS CONTROL STATEMENT
Issuer: INVAI LTD (the “Company”)
Applies to: Users located in the United Kingdom, and users treated as UK users where location is uncertain
Purpose and scope:
This Statement describes how the Company applies age assurance and access controls for UK users in relation to pornographic content made available on the Company’s interactive AI entertainment service (the “Service”). The Company’s objective is to ensure that children are not normally able to encounter pornographic content on the Service, using highly effective age assurance before access is granted.
This Statement applies to all UK user access paths, including web and in-app environments. The Company does not accept self-declaration, tick-box confirmations, or contractual assertions of being 18+ as a compliant age assurance method for UK users. The Service does not permit the creation, upload, generation, or depiction of minors or underage-looking persons under any circumstances.
This UK Age Assurance and Access Control Statement forms part of the Company’s broader online safety framework and should be read together with the Company’s general Safety Policy and Content Moderation Policy, which set out additional measures relating to prohibited content, moderation, reporting, and enforcement across the Service.
UK legal and regulatory basis:
For UK users, the Company’s measures are designed to align with the UK Online Safety Act 2023 framework for services making pornographic content available, as supervised and enforced by Ofcom, including Ofcom’s published expectations on “highly effective” age assurance and the requirement to apply age checks so that children are not normally able to encounter such content.
Outsourcing and accountability: The Company outsources the performance of age assurance checks to Ondato (the “Age Assurance Provider”). The Age Assurance Provider operates the verification journey and returns to the Company only the minimum output needed for access control (typically a pass/fail decision and/or a tokenised attestation). Outsourcing does not transfer regulatory accountability: the Company remains responsible for ensuring that the age assurance solution and its implementation are highly effective and that access controls are correctly enforced for UK users.
The Company conducts ongoing monitoring, periodic reviews, and configuration audits of the Age Assurance Provider to ensure continued compliance with Ofcom’s effectiveness expectations.
Access control rule for UK users: no access until assured:
For UK users, pornographic content is placed behind an access gate. The Service is designed so that pornographic content is not intended to be displayed, previewed, or otherwise made accessible until the user has successfully completed age assurance and the result has been validated by the Company’s access control systems. Ofcom’s framework expects that regulated pornographic content should not be available prior to completion of age assurance.
Age assurance process (Ondato flow):
When a UK user attempts to access age-restricted areas, the Service redirects the user to Ondato’s verification environment.
Ondato first requests that the user completes a liveness (selfie) check. Based on this, Ondato performs biometric age estimation and assigns the user to an age group. If the assigned age group is equal to or above the configured threshold, the user passes and Ondato returns a positive outcome to the Service (for example, a pass result and/or tokenised attestation). If the assigned age group does not meet the threshold, the user is asked to provide a valid identity document to evidence age. If the identity document confirms the user is 18 or over, the user passes. If the user cannot be verified as 18 or over, the user is rejected and is not permitted to access pornographic content on the Service.
Effectiveness safeguards: threshold setting and secondary verification:
To reduce the risk that older teenagers are incorrectly treated as adults, the Company applies a “challenge age” approach when configuring age estimation, meaning that age estimation is used as a routing step and cases that are not clearly adult are directed to stronger verification. The Company’s default operational setting is to configure the age estimation threshold above 18 and require documentary verification (or another strong method, where available) when age estimation does not clearly meet the adult threshold. Ofcom’s guidance contemplates a challenge-age buffer and indicates that an inappropriately low threshold may undermine compliance.
Where a UK user fails age assurance, does not complete it, or cannot provide acceptable evidence that they are 18 or over, the Service denies access to pornographic content. There is no fallback access for UK users based on self-declaration.
Tokenisation, session integrity, and re-checking:
To preserve privacy and reduce repeat collection of identity data, the Company is designed to rely on Ondato’s tokenised outcomes for access decisions rather than storing identity documents. Verification outcomes are applied to the relevant user session and/or account controls. If an outcome expires, is invalidated, or risk signals indicate possible circumvention, the Company may require the user to re-complete age assurance before access to pornographic content is permitted.
Anti-circumvention approach:
The Company and Ondato apply measures intended to reduce circumvention risks, including liveness checks (to reduce the use of static images), session and token integrity controls, and rejection handling for failed verification attempts. The Company reviews circumvention risks and adjusts controls where required to maintain effectiveness. Ofcom’s framework expects providers to have regard to robustness and circumvention when implementing age assurance.
Data handling, minimisation, and retention (Ondato processing):
Age assurance processing is performed by Ondato. The Company’s objective is that the Company receives only the verification outcome needed to operate access controls, and does not receive or store identity documents or biometric artefacts by default.
Ondato has confirmed that data storage settings are configurable by the client and that the default logic can be indefinite retention unless the client sets an automatic retention period or deletes identifications via API. For UK age assurance, the Company’s policy is to disable indefinite retention for age assurance artefacts and to configure a defined retention schedule and deletion mechanism that is proportionate and minimised, subject to any legal hold requirements. The Company’s approach is to retain only the minimum outcome data and limited metadata needed to operate access controls and to evidence operation of the age assurance gate in the event of a legitimate regulatory enquiry.
User support and challenge of outcomes:
UK users who believe an age assurance outcome is incorrect, or who experience technical difficulties completing age assurance, may contact the Company via the published contact email. The Company’s process is designed to support re-attempts or alternative strong verification pathways where available and appropriate, subject to anti-fraud safeguards. Data protection guidance recognises the importance of enabling users to challenge inaccurate age assurance outcomes.
Governance, records, and review:
The Company maintains governance over its UK age assurance framework, including due diligence of Ondato, configuration management (including threshold and retention settings), monitoring of performance and circumvention signals, and readiness to respond to regulatory requests. The Company maintains the internal written record required for its UK age assurance approach and keeps it under review. This Statement is reviewed and updated when there are relevant changes to law, regulatory expectations, provider capabilities, or the Service’s features that may affect age assurance effectiveness.
Approved by: Rafael Georgiou – Director
Version: 12.2025
