verkyc Privacy Policy
The operator details (name, registration number, address, contact) will be added to this document once approved. The terms apply as set out in this version.
Version of 3 October 2026.
1. Who processes the data
1.1. The verkyc service (https://verkyc.com) is provided by [to be confirmed], registration number [to be confirmed], address [to be confirmed] (the "Operator"). Personal data contact: privacy@verkyc.com, [to be confirmed].
1.2. The Service verifies the identity of people and data about organisations at the request of customer organisations: banks, payment and financial institutions, marketplaces and other companies that need to know who they deal with.
1.3. Depending on the data, the Operator acts in one of two roles:
- processor on behalf of the customer, for the data the applicant provides during a verification (document, photos, results). The purposes and legal bases of processing are determined by the customer that sent the applicant to the verification; its name is shown on the verification page. The applicant exercises rights regarding this data through the customer or through the verification page (section 7);
- independent controller, for data of customer employees, website visitors, billing of customers and for the Operator's own purposes of security of the Service and the audit log.
2. What data and why
2.1. Applicant data (on behalf of the customer)
| Data | Purpose | Legal basis |
|---|---|---|
| Document data and machine readable zone, document images | checking the document and its data | the customer's basis: performance of a contract with the applicant, a legal obligation (for example under anti-money laundering law), the applicant's consent |
| Document chip data | checking authenticity of the document against the issuing state's signature | as above |
| Face image, biometric template, comparison result | liveness check and comparison of the face with the document photo | explicit and, where the law requires, written consent of the applicant; without such consent no face comparison is performed |
| Results of screening against sanctions and politically exposed persons lists | the customer's compliance with sanctions and customer due diligence requirements | the customer's legal obligation or legitimate interest |
| Technical session data (IP address, device, browser, capture events) | protection against spoofing and reuse of materials | legitimate interest in fraud prevention; consent in some countries |
2.2. Data the Operator processes for itself
| Data | Purpose | Legal basis |
|---|---|---|
| Name, e-mail address, role and activity log of customer employees | console access, security, audit log | performance of the contract with the customer, legitimate interest in security |
| Customer details, invoices, payment data | billing under the contract | performance of the contract, tax and accounting obligations |
| Security and audit log (without document content) | incident investigation, evidence that checks were correct | legitimate interest, legal obligations |
| Support requests | answering the request | performance of the contract, legitimate interest |
2.3. The Operator does not use applicant data for advertising, does not sell it and does not take decisions about the applicant: the customer takes the decision on the verification.
2.4. Applicant data is not used to train models. An exception is possible only on a separate instruction of the customer and with a separate consent of the applicant where the law of the applicant's country requires it; otherwise such use is switched off.
3. Automated processing
3.1. The Service automatically assesses the quality and authenticity features of the document, the face match and matches against lists. The result states the grounds of each check. The customer can reject an application only by the rules it has configured and must ensure human review where the law of the applicant's country requires it or where the applicant contests the decision. The applicant may express their point of view and contest the result through the verification page or through the customer.
4. Where data is stored
4.1. All data is stored and processed in Germany (region eu-de-1), including backups. Germany is a member state of the European Union and a party to Council of Europe Convention 108 on data protection.
4.2. If the applicant is in another country, the transfer of their data for processing in Germany is made by the customer on the basis of its law. The customer is responsible for meeting its country's requirements for such a transfer and for storing data of its citizens in that country where such requirements exist.
5. Who receives the data
5.1. Data is received only by:
- the customer at whose request the verification is carried out;
- the Operator's infrastructure providers: Hetzner Online GmbH (servers and storage, Germany), Climails (delivery of service e-mails, Germany);
- verification sources to the extent of the request: state and open registers, official sanctions lists, the provider of data on politically exposed persons, only when the customer has enabled such a check;
- the payment provider NerezPay, only payment data of customers;
- public authorities, only on a request based on law.
6. How long data is kept
6.1. Applicant data is kept for the period set by the customer within the bounds of the Service and is deleted when it ends or on the customer's instruction. Typical periods:
| Data | Period |
|---|---|
| Unfinished verification (the applicant did not complete collection) | up to 7 days after the case is created, then materials are deleted |
| Document images, video frames, biometric template | until the verification is complete and the period set by the customer; the biometric template no longer than needed for the comparison |
| Document data, results and report | the period required by the law of the customer's country (for example 5 years after the end of the client relationship under anti-money laundering law) |
| Security and audit log | up to 5 years |
| Backups | deleted data disappears from backups within 35 days |
| Customer employee data | the term of the contract with the customer and 3 years after it |
| Invoices and payments | the period required by tax and accounting law |
7. Data subject rights
7.1. Data subjects have the right to information about processing and a copy of their data, to rectification of inaccurate data, erasure, restriction of processing, to object to processing based on legitimate interest, to withdraw consent, to receive data in a machine-readable format, not to be subject to a decision based solely on automated processing where the law grants that right, and to lodge a complaint with the supervisory authority of their country or of the Operator's country.
7.2. For verification data a request is made on the verification page (help section "Request about your data") or to the customer. A request made to the Operator is passed to the customer within 1 working day; the Operator helps the customer answer within the time set by the law of the data subject's country. For data the Operator processes for itself, the Operator answers within 30 days or, where the law of the data subject's country sets a shorter period, within that period.
7.3. Withdrawal of consent does not affect the lawfulness of processing before the withdrawal. After consent to biometric processing is withdrawn, the biometric template and face image are deleted unless the customer must keep them by law.
8. Security
8.1. The Operator encrypts data at rest and in transit, separates customers' data, requires a second sign-in factor, keeps a log of access to materials with the reason for disclosure, isolates parsing of uploaded files and scans them for malware, regularly tests restoration from backups and scans software for vulnerabilities. The Operator notifies the customer of incidents affecting applicant data within 12 hours of discovery.
9. Cookies
9.1. The Service uses only strictly necessary cookies for sign-in and session protection. Details are in the Cookie Policy.
10. Children
10.1. The Service is not intended for verifying persons below the age at which the law of their country allows them to consent to data processing on their own, without the involvement of a legal representative.
11. Changes
11.1. A new version is published at https://verkyc.com/legal with its effective date. Customers are notified of material changes in the console at least 30 days in advance.