Privacy notice
Draft last updated
Draft: not yet in force. This page is a draft and not yet in force. It describes how the KYCVerify service at kycverify.me processes data; the bracketed fields are still to be completed and reviewed with counsel. Questions: hello@kycverify.me.
1. Who we are
[Organisation legal name], [registered address], [company registration number] ("we", "us") operates this website and the KYCVerify identity-verification service at kycverify.me.
- For verifications we run on behalf of a business customer, that customer decides why and how you are verified. It is the controller (in India, the Data Fiduciary) and we act as its processor. Its own privacy notice applies, and requests about your verification are best sent to it.
- For this website, our own customer accounts and our own verifications, we are the controller.
- Privacy contact
- hello@kycverify.me
- Grievance officer (India)
- [name, designation, email, address]
- Data protection officer
- [name and email, where one is required]
- EU / UK representative
- [name and address, where one is required]
2. Data processed during a verification
| Category | Examples | Source |
|---|---|---|
| Identity data | Name, date or year of birth, gender, nationality, address | Your document or Aadhaar artefact |
| Document data | Document type, issuing country, expiry, a masked document number and a one-way hash of it | Your document |
| Images | Document front and back, the portrait cropped from it, liveness frames and the selfie, a PAN card photo | Your camera or upload |
| Biometric data | Face embeddings: numeric vectors computed from the document portrait and the selfie | Computed from your images |
| Aadhaar data | The last four digits of your Aadhaar number, demographics and photo from the UIDAI-signed Secure QR or Offline e-KYC file | The artefact you share |
| PAN | Your PAN and the name you enter | You |
| Contact data | Your email address, if the verification asks for it | You |
| Technical data | IP address, browser user agent, and the time of each step, including your consent | Your browser |
| Results | The checks run, their scores and warnings, and the decision | Generated by the service |
The UIDAI-signed Secure QR and Offline e-KYC file contain only the last four digits of your Aadhaar number, and that is all that is kept from them. If the business also accepts a photo of your Aadhaar card, the number is read from the image to validate it and is then kept only masked (last four digits) and as a keyed one-way fingerprint; the card image itself, which shows the full number, is stored encrypted until the retention period ends. Full document numbers are not stored in clear. Your mobile number and email are never read from Aadhaar artefacts; only UIDAI's one-way hashes are used, to confirm an email you typed.
3. Why we process it, and on what basis
| Purpose | Basis |
|---|---|
| Verifying your identity for the business that asked you to: your document, that you are present, that your face matches, your age, and whether your name appears on sanctions lists | [Consent / legal obligation of the business / legitimate interests] |
| Detecting a document or face already used in another verification for the same business, to prevent fraud | [Legitimate interests in fraud prevention / legal obligation] |
| Letting authorised reviewers decide verifications that need a person | [As above] |
| Keeping an audit trail of decisions and administrative actions | [Legal obligation / legitimate interests in accountability] |
| Answering messages you send us through this website | [Legitimate interests / consent] |
Consent is asked for at the start of each verification and recorded with its time, IP address and user agent. Biometric data is processed only to verify you and to detect duplicate verifications; it is never used for marketing or to train models.
4. Automated decisions
Verifications are decided by documented rules: if a check fails the verification is declined (or, if the business has chosen, sent to a person); if any check is uncertain, a person reviews it; otherwise it is approved. A potential sanctions match never fails the screening check by itself: that check goes to review. If another check fails and the business has automatic decline on, the verification is declined and the potential match is recorded with the decision. You can ask for a person to review a decision made about you, and give your point of view, by contacting the business that asked you to verify or us at hello@kycverify.me.
5. Who receives it
- The business that asked you to verify, which receives the decision and the identity data its workflow collects.
- Our staff and the business's staff with a reviewer role or higher, who may see your images to decide a verification.
- [Hosting provider, location], which stores the encrypted data on our behalf.
- Our own mail server, which delivers one-time codes from no-reply@kycverify.me if the verification includes an email step. No outside email provider receives them.
- Authorities, where the law requires us to disclose data.
Verification data is not sent to any third-party identity-verification provider. Sanctions lists are downloaded from their public publishers and screening happens on our servers; your data is not sent to the publishers.
6. Where it is stored, and transfers
Data is stored on servers operated by us in [country, region]. Uploaded files are encrypted with AES-256-GCM under a key we hold. [If data is transferred outside your country: the destination and the safeguard relied on, for example standard contractual clauses.]
7. How long we keep it
Images, face embeddings, document fingerprints, identity data, your email address, IP address and user agent are deleted automatically [90] days after the verification was created, or sooner if the business or you ask. A minimal record that a verification took place, with its outcome and dates, is kept for [period] to meet [obligation, for example record-keeping under anti-money-laundering rules]. The audit log of administrative actions is kept for [period].
8. How we protect it
- Uploaded files encrypted at rest with AES-256-GCM; never published at a public URL.
- Access limited by role and by organisation; every review decision and deletion is logged.
- Passwords hashed with Argon2id; access tokens stored only as hashes.
- Rate limits on sign-in and on the verification link; links expire.
- [Your organisational measures: staff training, access reviews, incident response, backups.]
9. Your rights
Depending on where you live, you may have the right to:
- access the data held about you and get a summary of how it is processed;
- correct inaccurate data, or complete incomplete data;
- erase your data, subject to retention the law requires;
- withdraw consent at any time, which stops further processing based on it but does not undo past processing; a verification cannot be completed without it;
- object to processing based on legitimate interests, and to automated decisions, as described above;
- receive your data in a portable format, where that applies;
- nominate another person to exercise your rights in the event of death or incapacity (India);
- complain to a regulator, such as [the Data Protection Board of India / your data protection authority].
To exercise a right, contact the business that asked you to verify, or us at hello@kycverify.me or our grievance officer. We will verify your request and respond within [period, e.g. 30 days].
10. Children
The service is not intended for people under [18 / the age of digital consent where you live]. [If a business uses age verification to keep minors out, describe what happens to a minor's data.]
11. This website
This website sets no advertising or analytics cookies; see the cookie notice. If you email us, we use your message and address to reply and keep them for [period].
12. Changes
We will post changes on this page and update the date above. Material changes will be [notified by email / shown in the console].