Skip to content

Privacy notice

Draft last updated

Draft: not yet in force. This page is a draft and not yet in force. It describes how the KYCVerify service at kycverify.me processes data; the bracketed fields are still to be completed and reviewed with counsel. Questions: hello@kycverify.me.

1. Who we are

[Organisation legal name], [registered address], [company registration number] ("we", "us") operates this website and the KYCVerify identity-verification service at kycverify.me.

  • For verifications we run on behalf of a business customer, that customer decides why and how you are verified. It is the controller (in India, the Data Fiduciary) and we act as its processor. Its own privacy notice applies, and requests about your verification are best sent to it.
  • For this website, our own customer accounts and our own verifications, we are the controller.
Privacy contact
hello@kycverify.me
Grievance officer (India)
[name, designation, email, address]
Data protection officer
[name and email, where one is required]
EU / UK representative
[name and address, where one is required]

2. Data processed during a verification

CategoryExamplesSource
Identity dataName, date or year of birth, gender, nationality, addressYour document or Aadhaar artefact
Document dataDocument type, issuing country, expiry, a masked document number and a one-way hash of itYour document
ImagesDocument front and back, the portrait cropped from it, liveness frames and the selfie, a PAN card photoYour camera or upload
Biometric dataFace embeddings: numeric vectors computed from the document portrait and the selfieComputed from your images
Aadhaar dataThe last four digits of your Aadhaar number, demographics and photo from the UIDAI-signed Secure QR or Offline e-KYC fileThe artefact you share
PANYour PAN and the name you enterYou
Contact dataYour email address, if the verification asks for itYou
Technical dataIP address, browser user agent, and the time of each step, including your consentYour browser
ResultsThe checks run, their scores and warnings, and the decisionGenerated by the service

The UIDAI-signed Secure QR and Offline e-KYC file contain only the last four digits of your Aadhaar number, and that is all that is kept from them. If the business also accepts a photo of your Aadhaar card, the number is read from the image to validate it and is then kept only masked (last four digits) and as a keyed one-way fingerprint; the card image itself, which shows the full number, is stored encrypted until the retention period ends. Full document numbers are not stored in clear. Your mobile number and email are never read from Aadhaar artefacts; only UIDAI's one-way hashes are used, to confirm an email you typed.

3. Why we process it, and on what basis

PurposeBasis
Verifying your identity for the business that asked you to: your document, that you are present, that your face matches, your age, and whether your name appears on sanctions lists[Consent / legal obligation of the business / legitimate interests]
Detecting a document or face already used in another verification for the same business, to prevent fraud[Legitimate interests in fraud prevention / legal obligation]
Letting authorised reviewers decide verifications that need a person[As above]
Keeping an audit trail of decisions and administrative actions[Legal obligation / legitimate interests in accountability]
Answering messages you send us through this website[Legitimate interests / consent]

Consent is asked for at the start of each verification and recorded with its time, IP address and user agent. Biometric data is processed only to verify you and to detect duplicate verifications; it is never used for marketing or to train models.

4. Automated decisions

Verifications are decided by documented rules: if a check fails the verification is declined (or, if the business has chosen, sent to a person); if any check is uncertain, a person reviews it; otherwise it is approved. A potential sanctions match never fails the screening check by itself: that check goes to review. If another check fails and the business has automatic decline on, the verification is declined and the potential match is recorded with the decision. You can ask for a person to review a decision made about you, and give your point of view, by contacting the business that asked you to verify or us at hello@kycverify.me.

5. Who receives it

  • The business that asked you to verify, which receives the decision and the identity data its workflow collects.
  • Our staff and the business's staff with a reviewer role or higher, who may see your images to decide a verification.
  • [Hosting provider, location], which stores the encrypted data on our behalf.
  • Our own mail server, which delivers one-time codes from no-reply@kycverify.me if the verification includes an email step. No outside email provider receives them.
  • Authorities, where the law requires us to disclose data.

Verification data is not sent to any third-party identity-verification provider. Sanctions lists are downloaded from their public publishers and screening happens on our servers; your data is not sent to the publishers.

6. Where it is stored, and transfers

Data is stored on servers operated by us in [country, region]. Uploaded files are encrypted with AES-256-GCM under a key we hold. [If data is transferred outside your country: the destination and the safeguard relied on, for example standard contractual clauses.]

7. How long we keep it

Images, face embeddings, document fingerprints, identity data, your email address, IP address and user agent are deleted automatically [90] days after the verification was created, or sooner if the business or you ask. A minimal record that a verification took place, with its outcome and dates, is kept for [period] to meet [obligation, for example record-keeping under anti-money-laundering rules]. The audit log of administrative actions is kept for [period].

8. How we protect it

  • Uploaded files encrypted at rest with AES-256-GCM; never published at a public URL.
  • Access limited by role and by organisation; every review decision and deletion is logged.
  • Passwords hashed with Argon2id; access tokens stored only as hashes.
  • Rate limits on sign-in and on the verification link; links expire.
  • [Your organisational measures: staff training, access reviews, incident response, backups.]

9. Your rights

Depending on where you live, you may have the right to:

  • access the data held about you and get a summary of how it is processed;
  • correct inaccurate data, or complete incomplete data;
  • erase your data, subject to retention the law requires;
  • withdraw consent at any time, which stops further processing based on it but does not undo past processing; a verification cannot be completed without it;
  • object to processing based on legitimate interests, and to automated decisions, as described above;
  • receive your data in a portable format, where that applies;
  • nominate another person to exercise your rights in the event of death or incapacity (India);
  • complain to a regulator, such as [the Data Protection Board of India / your data protection authority].

To exercise a right, contact the business that asked you to verify, or us at hello@kycverify.me or our grievance officer. We will verify your request and respond within [period, e.g. 30 days].

10. Children

The service is not intended for people under [18 / the age of digital consent where you live]. [If a business uses age verification to keep minors out, describe what happens to a minor's data.]

11. This website

This website sets no advertising or analytics cookies; see the cookie notice. If you email us, we use your message and address to reply and keep them for [period].

12. Changes

We will post changes on this page and update the date above. Material changes will be [notified by email / shown in the console].