verifa
Documents
Documents
Terms of Service Privacy Policy DPA Acceptable Use Biometric Policy Cookie Policy Law Enforcement

Privacy Policy

Effective date: March 30, 2026

Verifa ("we," "us," or "our") provides identity verification services to businesses ("Customers"). This Privacy Policy describes how we collect, use, disclose, and protect personal information when you use our verification services or visit our website.

1. Controller vs. Processor Roles

Verifa's role under data protection law depends on the context of processing:

  • Verification applicant data: When processing personal data submitted during identity verification, Verifa acts as a Processor on behalf of the Customer, who is the Controller. The Customer determines the purposes and means of processing; Verifa processes data solely on the Customer's instructions as set out in our Data Processing Agreement.
  • Customer account data: When processing data related to Customer accounts (e.g., organization details, billing, login credentials), Verifa acts as a Controller.
  • Website visitor data: When processing data collected from visitors to our website (e.g., cookies, analytics), Verifa acts as a Controller.

2. Information We Collect

2.1 Information from Verification Applicants

When you complete an identity verification requested by one of our Customers, we collect:

  • Government-issued ID images: photographs of the front and back of your identity document (e.g., driver's license, passport, state ID)
  • Selfie photograph: a photograph of your face used for comparison against your ID
  • Biometric data: facial geometry derived from your selfie for the purpose of face matching (see our Biometric Data Policy for details)
  • Extracted identity data: name, date of birth, address, document number, and expiration date as read from your ID
  • Device and network information: IP address, browser type, and device type
  • Consent record: timestamp and IP address of your consent to data collection
  • Phone number: if provided during verification, your phone number may be used to send a one-time verification code via SMS
  • Email address: if provided during verification, your email address may be used to send a one-time verification code

2.2 Information from Customers

When businesses sign up for Verifa, we collect:

  • Organization name, website, industry, and country
  • Contact email address
  • Account credentials
  • Billing information (if applicable)

2.3 SMS and Email Verification

During identity verification, you may be asked to provide your phone number or email address for ownership verification. By entering your phone number and clicking "Send Code," you consent to receiving a single transactional SMS containing a one-time verification code. By entering your email and clicking "Send Code," you consent to receiving a single transactional email containing a one-time verification code.

These messages are strictly transactional — no marketing, promotional, or recurring messages are sent. Standard message and data rates may apply for SMS. Each verification code expires in 10 minutes.

3. How We Use Your Information

3.1 Verification Applicants

We use your information solely to:

  • Verify your identity by comparing your selfie to your ID photo using facial geometry analysis
  • Extract identity data from your ID document to confirm your identity information
  • Verify ownership of your phone number or email address via one-time verification codes
  • Check age requirements if the Customer has enabled age verification
  • Check geographic restrictions if the Customer has enabled geo filtering
  • Comply with legal obligations including record-keeping requirements

We do not use your biometric data or personal information for advertising, profiling, or any purpose other than identity verification.

3.2 Customers

We use Customer information to provide and improve our services, communicate about their account, and comply with legal obligations.

4. Legal Basis for Processing (EEA/UK)

Where the EU or UK General Data Protection Regulation (GDPR) applies, we rely on the following lawful bases for each processing purpose:

Processing Purpose Lawful Basis
Identity verification (applicant data) Contractual necessity — processing on behalf of the Customer (Controller) pursuant to our Data Processing Agreement
Customer account management Contractual necessity — required to provide the services the Customer has engaged us to deliver
Fraud detection and prevention Legitimate interest — protecting Verifa, our Customers, and applicants from fraud and abuse
Service communications Consent or contractual necessity, depending on the nature of the communication
Analytics and service improvement Legitimate interest — improving the reliability, performance, and security of our services
Legal and regulatory compliance Legal obligation — where processing is required by applicable law or regulation

Where we rely on legitimate interest, we have conducted balancing tests to ensure that our interests do not override the fundamental rights and freedoms of data subjects. You may contact us to request details of these assessments.

5. Automated Decision-Making

Our identity verification services involve automated processing, including facial comparison (comparing a selfie to an ID photo), document analysis (extracting and validating information from identity documents), and fraud signal detection.

It is important to understand the following:

  • Verifa provides confidence scores, not pass/fail determinations. Our systems produce numerical scores and data extraction results that indicate the likelihood of a match or the validity of a document.
  • Final decisions are made by the Customer, not Verifa. Verification results are provided to the Customer as a tool to assist their decision-making. The Customer (Controller) is responsible for any decisions that affect the applicant based on these results.
  • Right to contest. If you believe an automated verification result has led to a decision that affects you, you have the right to contest that decision and request human review. Because the Customer is the Controller of your verification data, you should direct such requests to the business that asked you to verify your identity. Verifa will cooperate with the Customer to facilitate any review.

6. How We Share Your Information

We share verification results (approved, rejected, or needs review) with the Customer who initiated the verification. This may include extracted identity data from your ID.

We do not sell, rent, or trade your personal information or biometric data to any third party.

We may disclose information if required by law, regulation, legal process, or governmental request.

7. International Data Transfers

Verifa processes and stores data in the United States. If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your personal data will be transferred to the United States for processing.

To protect your data during these transfers, we rely on the following safeguards:

  • Standard Contractual Clauses (SCCs): We enter into EU-approved Standard Contractual Clauses with our Customers and subprocessors as detailed in our Data Processing Agreement.
  • Transfer Impact Assessments: Verifa conducts transfer impact assessments as required to evaluate the legal framework of the destination country and the effectiveness of supplementary measures.
  • Supplementary measures: We implement technical safeguards including encryption at rest and in transit, strict access controls, and data minimization practices.

8. Data Retention and Deletion

We retain personal data only for as long as necessary to fulfill the purposes described in this policy. Specific retention periods are as follows:

  • Verification data (ID images, selfie, biometric data, and extracted identity information): retained for the period configured by the Customer, which defaults to 90 days after the verification is completed. Customers may configure shorter or longer retention periods based on their requirements.
  • Customer account data: retained while the Customer account is active and for a reasonable period thereafter to fulfill any remaining contractual or legal obligations.
  • Audit metadata (verification status, timestamps, non-PII session records): retained for up to 7 years to meet regulatory and audit requirements.

After the applicable retention period expires:

  • Document images and selfies are permanently deleted from our encrypted storage
  • Biometric data (facial geometry) is permanently destroyed
  • Encrypted personal information is purged from our database

Deletion requests: You may request early deletion of your data at any time. Upon receiving a valid deletion request, personal data will be removed from active systems within 30 days. Data in encrypted backups will be purged within 90 days of the request. See Section 10 for details on how to exercise this right.

9. Data Security and Breach Notification

We protect your data using:

  • Encryption in transit: all data is transmitted over HTTPS/TLS
  • Encryption at rest: all documents and personal information are encrypted before storage
  • Access controls: access to personal data is restricted to authorized personnel and systems
  • Key management: encryption keys are managed through a dedicated secrets management system
  • Data isolation: each Customer's data is logically separated

9.1 Data Breach Notification

In the event of a personal data breach that poses a risk to data subjects, Verifa will notify affected Customers (Controllers) without undue delay and no later than 72 hours after becoming aware of the breach, as required by GDPR Article 33.

Where a breach is likely to result in a high risk to the rights and freedoms of individuals, Verifa will assist the Customer (Controller) in notifying affected individuals as required by GDPR Article 34. This assistance includes providing relevant details about the nature of the breach, the categories of data affected, and recommended protective measures.

10. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Right to access: request a copy of the personal data we hold about you
  • Right to deletion: request deletion of your personal data and biometric information. Customers can submit deletion requests through the API (DELETE /api/v1/sessions/{id}/data) or contact us directly.
  • Right to correction: request correction of inaccurate personal data
  • Right to restrict processing: request that we limit how we use your data
  • Right to data portability: receive your personal data in a structured, commonly used, and machine-readable format, and transmit that data to another controller without hindrance, where technically feasible
  • Right to withdraw consent: withdraw your consent at any time (note: this does not affect the lawfulness of processing before withdrawal)
  • Right to lodge a complaint: file a complaint with your local data protection authority

To exercise any of these rights, contact us using the information below.

11. Subprocessors

All face matching, data extraction, and verification decisions are performed within Verifa's own infrastructure. Selfie images may be analyzed by authorized subprocessors for fraud detection (e.g., deepfake detection). Verifa also uses a limited number of subprocessors for ancillary services (such as SMS delivery and infrastructure hosting). A current list of subprocessors is available at /subprocessors.

12. California Residents (CCPA/CPRA)

If you are a California resident, you have the right to:

  • Know what personal information we collect, use, and disclose
  • Request deletion of your personal information
  • Opt out of the sale or sharing of your personal information (we do not sell or share your personal information)
  • Not be discriminated against for exercising your rights

Biometric data is classified as "sensitive personal information" under CCPA/CPRA. We collect it only with your explicit consent and use it solely for identity verification.

Do Not Sell or Share. Verifa does not sell personal information, nor do we share personal information for cross-context behavioral advertising as defined under the CPRA. Because we do not engage in these practices, no "Do Not Sell or Share My Personal Information" mechanism is required.

13. Do Not Track

Verifa does not track users across third-party websites. Our website honors "Do Not Track" (DNT) browser signals. When we detect a DNT signal, we limit data collection to what is strictly necessary for the functionality of our services.

14. Children's Privacy

Our services are not directed to children. We do not knowingly collect personal information from:

  • Children under 13: in compliance with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect, use, or disclose personal information from children under 13 years of age.
  • Children under 16: in compliance with the GDPR, we do not knowingly process personal data of children under 16 years of age (or such lower age as may be provided by EU member state law, but no lower than 13) without verifiable parental consent.

If you believe we have collected information from a child under these age thresholds, please contact us immediately and we will take steps to delete such information.

15. GDPR Representative

Verifa's primary operations are based in the United States. As required under GDPR Article 27, Verifa will appoint a representative in the European Union for data subjects and supervisory authorities to address regarding matters relating to the processing of personal data. Details of the appointed representative will be published on this page. In the meantime, please direct any inquiries to privacy@withverifa.com.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify Customers of material changes. The "Effective date" at the top of this page indicates when the policy was last revised.

17. Contact Us

Verifa — Privacy

Email: privacy@withverifa.com