This Privacy Policy explains how Didit processes personal data when you visit our websites, contact us, use our products and services, or complete an identity or fraud verification flow powered by Didit.
If you are verifying your identity for a bank, fintech, crypto platform, marketplace, employer, or another organization that uses Didit, that organization is the party that decides why the verification is required. In those cases, it is the controller or business, and Didit acts as its processor or service provider. For verification-specific processing, biometric data, and white-label flows, read our Verification Privacy Notice and End User Terms for Identity Verification.
If you are in Australia, Section 13 explains how Didit ID (Australia) Pty Ltd handles your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where Section 13 differs from another part of this Policy, Section 13 prevails for individuals in Australia.
1. Who we are
Depending on the service and geography, your data may be processed by one or more of the following Didit entities:
- Didit Identity Spain, S.L., CIF B22929327, Calle Nápoles 227, P. 1, 08013 Barcelona, Spain. Contracting entity for European Union, United Kingdom, European Economic Area, and Switzerland customers and the establishment that operates the European data plane.
- Didit Identity, Inc., EIN 39-2860573, 1111B S Governors Ave STE 34855, Dover, Delaware 19904, United States. Contracting entity for United States, Canada, Latin America, Asia-Pacific (other than Australia), Middle East, and global customers.
- Didit ID (Australia) Pty Ltd, ACN 702 150 507, ABN 59 702 150 507, C/- Prime Partners, Level 4, 1 James Place, North Sydney NSW 2060, Australia. A company incorporated in Australia. Contracting entity for customers in Australia and the entity that operates the Australian data plane.
When we say "Didit", "we", "us", or "our", we mean the Didit entity or entities providing the applicable service. In Section 13, "Didit Australia" means Didit ID (Australia) Pty Ltd.
- Privacy contact: privacy@didit.me
- Australian privacy contact: Privacy Officer, Didit ID (Australia) Pty Ltd, privacy@didit.me
- Data Protection Officer: dpo@didit.me
- Security contact: security@didit.me
- General contact: hello@didit.me
2. Scope and our role
This Privacy Policy applies when you:
- visit `didit.me` or any Didit-operated website;
- request information, a demo, or support;
- create or manage a Didit business relationship, account, or integration;
- apply for a role with Didit; or
- use a verification, fraud-prevention, authentication, or compliance flow operated by or through Didit.
Our role changes depending on the context:
| Context | Didit's role | What that means |
|---|---|---|
| Website visitors, marketing, recruiting, sales, support, and direct business relationships | Controller | Didit decides why and how the data is processed for those direct interactions. |
| Verification flows requested by a Didit customer | Processor / Service Provider | The customer decides why the verification happens and what checks are enabled. Didit processes data on the customer's behalf. |
| Security, abuse prevention, service integrity, audit logging, legal compliance, fraud-model training and validation on anonymized or pseudonymized data, and legal claims | Independent controller for that specific purpose | Didit may process limited data to secure the platform, train and improve fraud-detection and verification models, comply with law, and establish, exercise, or defend legal claims. Section 11 sets stricter limits for data collected in Australia. |
If you are in a white-label verification flow or on a custom domain, custom branding does not necessarily mean only the branded company processes your data. Didit may still provide the underlying verification technology and related processing. A retained biometric template, when a customer enables one, remains Personal Data processed by Didit as processor or service provider on that customer's documented instruction. It is not part of Didit's independent-controller model-training or cross-customer fraud processing.
Australia. The Privacy Act 1988 (Cth) does not use the terms "controller" and "processor". In Australia, Didit Australia is directly responsible under the Australian Privacy Principles for the personal information it collects, holds, uses, or discloses, including when it acts for a customer. We do not rely on a customer's role to avoid our own obligations. See Section 13.
3. Categories of personal data we process
The categories of data we process depend on the service, workflow configuration, and your relationship with Didit. They may include:
- Identifiers and contact data, name, email address, phone number, mailing address, date of birth, and similar identifying information.
- Business and account data, company name, billing information, account credentials, API usage details, and records of your relationship with Didit.
- Verification data, identity document images, extracted document data, proof-of-address files, questionnaire answers, sanctions or watchlist screening inputs, and verification outcomes. In Australia this includes government related identifiers (such as passport, driver licence, Medicare card, and visa document numbers) and the results of any checks against official records that you consent to (see Section 13).
- Biometric and liveness data, where the workflow includes face verification or similar checks, selfies, face images, videos, liveness captures, anti-spoofing signals, and data derived from scans of facial geometry.
- Device, network, and technical data, IP address, browser type, operating system, language, device identifiers, timestamps, geolocation inferred from network data, and other security or anti-fraud telemetry.
- Communications and support data, messages, support tickets, call records, email exchanges, and operational logs.
- Third-party and public-source data, information provided by our customers, identity or fraud-prevention partners, public authorities, telecom providers, and publicly available sources where permitted by law.
- Recruitment data, CVs, employment history, and other materials submitted during hiring.
We do not need every category listed above for every interaction. The exact data used depends on the services requested and the configuration selected by the relevant customer.
Sensitive information. Some laws treat certain data as especially sensitive. Under the Privacy Act 1988 (Cth), biometric information used for automated biometric verification or identification, and biometric templates, are "sensitive information". In Australia we collect sensitive information only with your consent, or where the law otherwise permits (see Sections 13.3 and 13.5).
4. How we use personal data
We may use personal data for the following purposes:
- To operate our websites and services, account access, product delivery, customer support, billing, and communications.
- To provide identity and fraud infrastructure services, User Verification (Know Your Customer / KYC), Business Verification (Know Your Business / KYB), Transaction Monitoring, Wallet Screening (Know Your Transaction / KYT), and other configured checks.
- To verify your identity at the request of a customer, including, where you give express consent, by checking the details on your identity document with the agency or official record holder that issued it (see Section 13.5).
- To secure the platform, prevent abuse, detect spoofing, prevent fraud, monitor suspicious activity, and maintain service integrity.
- To train, evaluate, and improve fraud-detection and verification models using anonymized or pseudonymized data derived from verification activity, where permitted by law. Section 11 restricts this for Australia and contains the opt-out.
- To respond to requests, demo requests, support questions, due diligence requests, and business communications.
- To manage recruiting and hiring, review applications and communicate with candidates.
- To comply with legal and regulatory obligations, maintain records, respond to lawful requests, enforce contracts, and carry out internal or external audits.
- To establish, exercise, or defend legal claims and protect the rights, safety, and security of Didit, our customers, and affected individuals.
Australia. In Australia we use and disclose personal information only for the purposes in this Policy, for a related purpose you would reasonably expect (a directly related purpose, for sensitive information), with your consent, or as required or authorised by law. Government related identifiers are subject to the additional limits in Section 13.6.
5. Legal bases for processing
Where the General Data Protection Regulation (GDPR), United Kingdom GDPR, Swiss data protection law, or similar laws apply, Didit relies on one or more of the following legal bases:
- Performance of a contract or steps taken at your request before entering into a contract.
- Legitimate interests, securing our platform, supporting customers, preventing fraud, maintaining records, training and improving fraud-detection and verification models on anonymized or pseudonymized data, and communicating with business contacts, provided those interests are not overridden by your rights.
- Consent, including where consent is required for marketing communications, certain cookies, or biometric processing in a particular jurisdiction or workflow.
- Legal obligation, where processing is required to comply with applicable law, regulation, court order, or lawful request from authorities.
- Establishment, exercise, or defense of legal claims.
Where special-category or sensitive data is processed, including biometric data used to uniquely identify you, Didit processes that data only where permitted by applicable law. In verification flows, the relevant customer is responsible for determining and documenting the primary legal basis for the verification itself, including whether explicit consent is required.
Australia. The Privacy Act 1988 (Cth) does not work through "legal bases" in the GDPR sense. In Australia we collect personal information only where it is reasonably necessary for our functions or activities. We collect sensitive information, including biometric information and templates, only with your consent or where another exception in the Australian Privacy Principles applies. We use and disclose personal information only as the Australian Privacy Principles allow. In verification flows we ask for your express, informed consent before we collect biometric information or check your document details against official records (see Section 13.5). The customer that asked us to verify you remains responsible for its own lawful basis for requiring the verification.
6. How we disclose personal data
We may disclose personal data to:
- The customer that asked us to perform the verification, so the customer can complete onboarding, fraud review, compliance checks, or related business processes.
- Didit group entities, where necessary to operate, support, secure, or provide the relevant services.
- Document issuers, official record holders, and the third-party systems and service providers that connect us to them, where you give express consent to a check of your identity document details against official records (see Section 13.5).
- Service providers and sub-processors, providers of cloud hosting, storage, infrastructure, communications, support, analytics, fraud prevention, document processing, security, audit, and professional services. A current sub-processor list is available to customers and prospective customers on request to privacy@didit.me. Individuals in Australia can ask for the categories and locations of the service providers that may handle their information at privacy@didit.me.
- Professional advisers, lawyers, auditors, insurers, and consultants, where needed for legitimate business, compliance, or legal purposes.
- Public authorities, regulators, courts, law enforcement, or other third parties, when required by law, legal process, or enforceable governmental request, and when administrators of the verification services we use audit our compliance.
- Successors and transaction counterparties, if Didit is involved in a merger, acquisition, financing, insolvency process, or sale of assets, subject to confidentiality and legal safeguards.
Didit does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
7. International transfers
Didit may process data in multiple countries. When personal data is transferred outside the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, Didit uses appropriate safeguards where required, including:
- adequacy decisions;
- the European Commission's 2021 Standard Contractual Clauses (SCCs) and any equivalent UK or Swiss addenda;
- intra-group transfer arrangements; or
- another lawful transfer mechanism recognized by applicable law.
Australia. Personal information collected in Australia is hosted and processed on the Australian data plane in Australia. Before we disclose personal information to a recipient outside Australia, we take reasonable steps in the circumstances to ensure the recipient does not breach the Australian Privacy Principles (other than APP 1) in relation to that information. In some circumstances we remain accountable under the Privacy Act for what the recipient does with it. The countries involved, and any overseas access to Australian personal information, are described in Section 13.8.
8. Retention
Didit retains personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- provide and support the relevant services;
- follow customer instructions in processor relationships;
- comply with contractual, legal, tax, accounting, and regulatory obligations;
- maintain security and fraud-prevention records;
- resolve disputes; and
- establish, exercise, or defend legal claims.
Retention periods vary by service, workflow configuration, applicable law, and the role Didit plays in the processing:
- Business relationship data is typically retained for the duration of the relationship and for lawful post-termination recordkeeping periods.
- Support and audit records may be retained for operational, security, and compliance purposes.
- Recruitment data is retained for the recruitment process and any lawful follow-up period, or longer if you separately consent.
- Verification data, the default retention is indefinite ("unlimited"), unless the customer configures a shorter period. Customers configure general verification-data retention per application in the Business Console between 30 days and 10 years.
- Retained biometric templates, if a customer enables retention after operational session deletion, require a separate finite duration. The template remains biometric data, but is image-free, tenant-scoped, and separately managed. It expires at the earliest applicable customer instruction, configured finite period, purpose-end event, contractual or statutory deadline, privacy-erasure instruction, or termination deletion instruction. It is not used for model training or cross-customer fraud processing.
An operational session deletion removes the session and its session-owned data but may leave an opted-in retained template until expiry or earlier purge. A privacy-erasure instruction also purges every retained template attributable to the person or instruction scope. User deletion, explicit purge, expiry, purpose end, and termination where the customer selects deletion also trigger purge. An accepted request remains `deletion requested` until every in-scope store confirms completed purge or approved beyond-use handling.
When data is no longer needed, Didit deletes, redacts, anonymizes, de-identifies, or securely destroys it. For biometric data and verification media, see the Verification Privacy Notice.
Australia. The "indefinite" default for verification data does not apply to personal information collected through the Australian data plane. In Australia:
- we keep personal information only while it is needed for a purpose the Australian Privacy Principles permit, or while the law requires us to keep it;
- verification data is kept for the period the customer sets, 30 days by default. A longer period applies only if the customer has configured it and has told us that a law or another permitted purpose requires it, for example record-keeping duties under anti-money laundering and counter-terrorism financing law;
- government related identifiers and the results of official record checks are kept for no longer than the verification data they belong to (30 days by default); and
- when personal information is no longer needed for any permitted purpose, and we are not required by law to keep it, we take reasonable steps to destroy it or to de-identify it (APP 11.2).
9. Your rights
Depending on your location and the applicable law, you may have the right to:
- access your personal data;
- request correction of inaccurate or incomplete data;
- request deletion or erasure;
- request restriction of processing;
- object to certain processing, including processing on the basis of legitimate interests (see Section 11 for the model-training opt-out);
- withdraw consent where processing is based on consent;
- request portability of the data you provided;
- not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to the conditions and exceptions in Article 22 GDPR; and
- lodge a complaint with a supervisory authority. Didit's lead supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos / AEPD) at `aepd.es`. In Australia, the regulator is the Office of the Australian Information Commissioner (OAIC) at `oaic.gov.au` (see Section 13.12).
When Didit acts as controller, submit privacy requests to privacy@didit.me or dpo@didit.me.
When Didit acts as processor or service provider for a customer verification flow, direct your request to the organization that asked you to verify. That customer controls the purpose of the verification and is best positioned to respond. If Didit receives such a request directly, we may forward it to the relevant customer. A valid privacy-erasure instruction covering the person purges both the verification session and any attributable retained biometric template; it is not treated as an operational session deletion.
Australia. If you are in Australia, you can ask Didit Australia for access to, or correction of, your personal information, deal with us anonymously or by pseudonym where that is practicable, withdraw your consent to future processing, and make a complaint. You can send your request to the Australian privacy contact in Section 17 or to the customer that asked you to verify. Didit Australia remains responsible for the information it holds and may work with the customer to respond. Sections 13.3, 13.11, and 13.12 explain how each of these works.
10. Cookies and similar technologies
Didit uses cookies and similar technologies on its websites for functionality, security, analytics, and attribution. Read our Cookies Policy for the full inventory, the consent banner controls, and our Global Privacy Control (GPC) and Do Not Track (DNT) posture.
11. Model training, your opt-out
Didit trains, evaluates, and improves its identity-verification, biometric, and fraud-detection models using anonymized or pseudonymized data derived from verification activity, such as document features, fraud signals, attack patterns, and model-error samples. Didit applies anonymization, pseudonymization, aggregation, and access controls to this work.
This processing is grounded in Didit's legitimate interest in improving the accuracy, safety, fairness, and security of its identity and fraud infrastructure.
Organization opt-out. Model training is allowed by default. An organization owner or administrator can opt the organization out at any time, directly in the Business Console and without contacting Didit: under Organization Settings → Account → Privacy and data use, turn off Allow Didit to use my organization's verification data to improve models and confirm Opt out. The opt-out takes effect immediately, and the setting then shows as Opted out. From that moment, Didit excludes the organization's historical and newly collected verification data from future model training, fine-tuning, evaluation, validation, dataset curation, and training-data exports. Turning the setting back on makes eligible data available for future model work.
The preference does not delete verification records, change retention settings, affect the verification and fraud-prevention services delivered to the organization, or limit processing required for security, support, legal, or compliance purposes. It does not reverse updates already incorporated into a model before the opt-out took effect.
An end user may object to model-training processing of data associated with a specific verification by contacting the organization that requested the verification or emailing privacy@didit.me with the relevant session identifier. Deletion and other privacy rights remain separate from the model-training preference. Retained biometric templates are never used for model training or cross-customer fraud processing.
Australia. We do not use personal information collected through the Australian data plane, or verification data of organizations registered in Australia, to train, evaluate, or improve our models. Pseudonymized data is still personal information under the Privacy Act, so this restriction applies to it. We never use government related identifiers, the results of official record checks, or biometric information collected in Australia for model training. For organizations registered in Australia, model training is disabled and the organization setting described above does not apply.
12. United States, California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) Addendum
This section supplements this Privacy Policy for California residents and applies whenever Didit is a "business" under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). When Didit is a "service provider" or "contractor" to a Didit customer (a "business" under the CCPA), the customer's privacy notice governs the relevant verification flow and Didit processes personal information under the relevant Data Processing Agreement.
Categories of personal information collected in the last 12 months (CCPA categories):
- Identifiers (name, email, phone, IP address, device identifiers).
- Customer records (billing, contact, account).
- Internet or network activity (browsing, interactions, telemetry).
- Geolocation data (inferred from IP).
- Sensory data (selfies, face images, liveness video, document images).
- Professional or employment data (for candidates).
- Sensitive personal information (SPI), including biometric information used to uniquely identify a consumer, government identifiers contained in identity documents, and account log-in credentials.
- Inferences drawn from any of the above (risk scores, fraud signals, decision outcomes).
Purposes, the purposes listed in Section 4.
Sale or sharing of personal information. Didit does not sell or share (as those terms are defined under the CCPA/CPRA) personal information, including biometric information.
Use and disclosure of sensitive personal information. Didit uses sensitive personal information only for the purposes permitted under California Civil Code § 1798.121(a) and the implementing regulations, to provide and secure the verification service, prevent fraud and security incidents, comply with legal obligations, and other purposes permitted without a separate consumer right to limit.
Your California rights:
- right to know what personal information is collected, used, disclosed, and sold/shared;
- right to delete personal information;
- right to correct inaccurate personal information;
- right to opt out of sale or sharing (Didit does neither);
- right to limit use and disclosure of sensitive personal information (Didit's processing is already limited to purposes that do not trigger the right);
- right to data portability; and
- right to non-discrimination for exercising any of the above.
Submit California requests to privacy@didit.me. Verification of your identity may be required before responding. Authorized agents may submit requests with proof of authorization.
Global Privacy Control (GPC) and Do Not Track (DNT). Didit honors browser-based Global Privacy Control signals on the marketing site as an opt-out of sale or sharing, even though Didit does not sell or share personal information, GPC signals are recorded so that no advertising or analytics cookie that could be construed as sharing is set for that browser. Didit does not currently respond to legacy Do Not Track (DNT) headers because there is no industry consensus on how to interpret them; the GPC signal supersedes DNT for Didit's purposes.
13. Australia: Privacy Act 1988 (Cth) and the Australian Privacy Principles
This Section applies to personal information about individuals in Australia, and to personal information handled by Didit ID (Australia) Pty Ltd ("Didit Australia", "we", "us"). It explains how we meet the 13 Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth) (the Privacy Act). If this Section conflicts with another part of this Policy, this Section prevails for individuals in Australia.
13.1 Who we are and how we are bound
Didit Australia is a company incorporated in Australia. It has a physical presence in Australia and is subject to Australian civil and criminal law.
Didit Australia is an APP entity and is bound by the Privacy Act and the APPs.
We handle personal information about individuals in Australia in line with the APPs, and with any registered APP code that binds us, as if we were an APP entity.
13.2 What personal information we collect and hold
We collect and hold the kinds of personal information listed in Section 3. For individuals in Australia this commonly includes:
- your name, date of birth, residential address, email address, and phone number;
- images of your identity document and the details extracted from it, including government related identifiers such as passport, driver licence, Medicare card, and visa document numbers;
- where you consent, the result of checking your document details with the document issuer or official record holder: a match or no-match result and related technical response codes, not a copy of the official record;
- biometric information: a selfie or face image, liveness capture, and the biometric template derived from them. This is sensitive information under the Privacy Act;
- device and network data, location inferred from your IP address, and other security and fraud signals;
- a record of your consent and the outcome of your verification; and
- your communications with us, and business contact details for our customers' staff, prospects, and suppliers.
We hold this information electronically on the Australian data plane (see Section 13.9).
13.3 How we collect personal information, and anonymity (APPs 2 to 4)
We collect personal information by lawful and fair means, and only where it is reasonably necessary for our functions or activities. We collect it:
- directly from you, when you complete a verification flow, contact us, or use our websites;
- from our customers, who may give us your details so that we can verify you;
- from document issuers and official record holders, where you consent, and from other third parties and public sources where it is unreasonable or impracticable to collect it from you (for example, to check independently that your document is genuine); and
- through cookies and similar technologies on our websites.
We collect sensitive information, including biometric information, only with your consent or where the law otherwise permits.
You can deal with us anonymously or by pseudonym when you make a general enquiry about our services or use our public website. This is not possible for a verification, because verifying who you are requires us to identify you, or where the law requires you to identify yourself.
If we receive personal information we did not ask for, we decide within a reasonable period whether we could have collected it. If we could not, we destroy it or de-identify it as soon as practicable, where that is lawful and reasonable.
13.4 Why we collect, hold, use and disclose personal information (APPs 1, 5 and 6)
Our purposes are listed in Section 4. In summary, we collect personal information to verify identity and prevent fraud for our customers, to run, secure, and support our services, to meet legal and regulatory obligations, and to run our business. At or before the time we collect your information, we tell you about these purposes, and the other matters in APP 5.2, through this Policy and the notices shown in each verification flow.
If you do not give us the information we ask for, we may not be able to complete your verification, and the customer that asked for it may not be able to provide you with its product or service.
We use or disclose personal information for another purpose only if you consent, if you would reasonably expect it and it is related (or, for sensitive information, directly related) to the purpose we collected it for, if the law requires or authorises it, or if another exception in APP 6 applies. We do not sell personal information.
13.5 Consent for official record checks and biometric information (APPs 3 and 5)
Some identity checks compare the details on your identity document with the records of the agency or body that issued it, using third-party systems. We run an official record check only after you give your express consent. When we ask for it:
- It is express and informed. You take a positive step, such as ticking an unticked box, on the screen where you enter or confirm your document details. We never treat silence, a pre-ticked box, or an opt-out as consent. The statement confirms that you are authorised to provide the details, and that you consent to them being checked with the document issuer or official record holder via third-party systems to confirm your identity.
- It is separate. Consent to the official record check is not bundled with acceptance of our terms, this Policy, marketing, or any other consent or requirement. Consent to collect biometric information is also asked for expressly and is not bundled with any unrelated consent.
- What we collect and send. The details shown on your identity document, such as your name, date of birth, and the document type and number. The document number may be a government related identifier. We get back a match or no-match result and related technical response codes, not a copy of the official record.
- Why we collect it. To confirm your identity for the organisation you are dealing with (the customer that asked us to verify you) and to help prevent identity fraud. We use the result only for that purpose.
- Who may receive it. The document issuer or official record holder, the third-party service providers that connect us to the systems used for the check and that carry or process the information for that purpose, and our customer, which receives the verification result. Our hosting and security providers may also process the information for us. These providers act as our agents and handle the information only for the check. We do not allow them to use it for their own purposes. The categories of providers are listed in Section 6.
- If you decline. You do not have to agree. If you decline, we will offer another way to verify your identity where the customer allows it, or we will tell the customer that you declined. This may mean the customer cannot provide its product or service to you.
- Your rights and complaints. Your rights to access and correct your information, and how to complain, are in Sections 13.11 and 13.12.
- Capacity to consent. We generally accept consent from individuals aged 15 or over unless there is a sign that they do not understand what they are agreeing to. For individuals under 15, we require the consent of a parent or guardian. If you need support to give consent, such as an interpreter or another way to communicate, contact us or the customer.
- A record of your consent. We keep a time-stamped record of your consent. You can withdraw your consent for future checks at any time. Withdrawing does not undo checks already made.
13.6 Government related identifiers (APP 9)
A government related identifier is a number or other identifier assigned to you by a government agency, such as a passport, driver licence, Medicare, or visa number.
- We do not adopt a government related identifier as our own identifier for you.
- We use or disclose a government related identifier only where it is reasonably necessary to verify your identity for the purposes of our activities and functions (which include verifying identity for customers that need to know who they are dealing with), where the law requires or authorises it, or where another exception in APP 9.2 applies.
- We do not use identification information from an official record check to create a data profile of you, to offer or promote goods or services (ours or anyone else's), to conduct market research, to train models, or for any other secondary purpose.
- Customers that receive verification results must have their own lawful basis to receive and use them. We require them by contract to use the results only for the verification you consented to.
13.7 Direct marketing (APP 7)
We use or disclose personal information for direct marketing only where the Privacy Act and the Spam Act 2003 (Cth) allow it. This is usually with your consent, or where we collected the information from you, you would reasonably expect it, and we give you a simple way to opt out. We use sensitive information for direct marketing only with your consent, and we never use government related identifiers or official record check results for direct marketing.
Every marketing message has an unsubscribe option. You can also ask us to stop at any time at privacy@didit.me, and ask us where we got the information we use to market to you. We do not charge for this, and we act on requests within a reasonable period.
13.8 Overseas disclosure and access (APP 1.4 and APP 8)
Personal information collected through the Australian data plane is stored in Australia (see Section 13.9).
Personnel and service providers located outside Australia cannot access Australian verification data, including images of identity documents, biometric information, government related identifiers, and the results of official record checks. They can see only limited operational and security data that does not identify you.
These rules apply equally to the service providers that support us, including those that connect us to the systems used for official record checks.
13.9 Storage, security and oversight (APP 11)
We hold personal information in electronic form on Amazon Web Services infrastructure in Sydney, Australia. We take reasonable steps to protect it from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. These include:
- encryption at rest (AES-256) and in transit (TLS 1.3), with key management in AWS in the Australian region;
- role-based access limited to the people who need it for their role, multi-factor authentication, and access restricted to Didit Australia personnel and authorised contractors;
- logging and monitoring of access to, and use of, verification data, with regular review of the logs;
- environment separation, continuous monitoring, regular security testing, and incident response procedures;
- written contracts with service providers that require them to protect personal information and to use it only to provide services to us; and
- staff training and confidentiality obligations.
We cooperate with the compliance reporting and independent audits required by the administrators of the verification services we use, and we use those services only for the purpose for which we have been given access.
When we no longer need personal information for any permitted purpose, and we are not required by law to keep it, we take reasonable steps to destroy it or de-identify it (see Section 8).
13.10 Quality of personal information (APP 10)
We take reasonable steps to make sure the personal information we collect, use, or disclose is accurate, up to date, complete, and relevant. This includes checking document data against the document itself and, where you consent, against the official record, and letting you correct it (see Section 13.11).
13.11 Access and correction (APPs 12 and 13)
You can ask us for access to the personal information we hold about you, or to correct it, at any time. Contact the Australian privacy contact in Section 17. We may need to confirm your identity first.
- Access. We respond within a reasonable period, which we aim to keep to 30 days, and give access in the way you ask if that is reasonable and practicable. We do not charge for making a request. If we charge for giving access, the charge will not be excessive. We may refuse access only in the limited situations the Privacy Act allows, for example where access would be unlawful or would unreasonably affect another person's privacy. If we refuse, we will give you written reasons, unless it would be unreasonable to do so, and tell you how to complain.
- Correction. If you ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading, or we find that it is, we take reasonable steps to correct it. We respond within a reasonable period and do not charge. If we refuse, we will give you written reasons and tell you how to complain, and on request we will attach your statement to the information. If we have disclosed the information to another APP entity and you ask us to, we will tell them about the correction, unless that is impracticable or unlawful.
- Customers. If your request relates to a verification you completed for a customer, we may need to consult the customer before we respond.
13.12 Complaints
If you think we have breached the Privacy Act or the APPs, contact the Australian privacy contact in Section 17 and give us the details. We will acknowledge your complaint promptly, investigate it, and respond within 30 days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at `oaic.gov.au` or on 1300 363 992 (Monday to Thursday, 10 am to 4 pm AEST/AEDT).
13.13 Notifiable data breaches
If we have a data breach that is likely to result in serious harm to an individual, we will assess it quickly and within 30 days at the latest. If it is an eligible data breach, we will notify the OAIC and the affected individuals as soon as practicable, as the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act requires. We will also tell the relevant customer.
13.14 Automated decisions (APP 1.7 to 1.9, from 10 December 2026)
Our services use computer programs that analyse personal information and may produce, or help a customer reach, a decision that could significantly affect your access to that customer's product or service.
- Personal information used: images and extracted data from identity documents, face images and biometric templates, liveness signals, device and network data, official record check results, and details supplied by the customer.
- Decisions made solely by a computer program: for example, an automatic "approved" or "declined" verification status where the customer has set up automatic decisions.
- Decisions where a computer program does something substantially and directly related to the decision: for example, document authenticity findings, face-match and liveness results, and risk or fraud scores that a customer's staff or systems rely on to approve, decline, or review an applicant.
If you think a result is wrong, you can ask the customer that requested your verification, or us at the Australian privacy contact in Section 17, to review it.
14. Security
Didit uses administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, and unlawful destruction, including encryption at rest with AES-256, encryption in transit with TLS 1.3, key management in AWS KMS, role-based access control, environment separation, continuous monitoring, vendor oversight, and incident response procedures. See the Information Security Policy for the full posture and certifications.
No security measure is perfect. You should also protect your own devices, credentials, and communications.
Australia. For individuals in Australia, see Section 13.9 (storage, security and oversight) and Section 13.13 (notifiable data breaches).
15. Children
Didit's public websites and standard business services are not directed to children. Some customers may lawfully use Didit for age-related or identity-related checks involving younger users, but that use must be supported by an appropriate legal basis and the customer's own notices. If you believe personal data was submitted to Didit without proper authorization, contact privacy@didit.me.
Australia. Section 13.5 explains how we approach capacity to consent for individuals under 18. If you believe personal information about a child in Australia was submitted to us without proper authority, contact the Australian privacy contact in Section 17.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, operational, or product changes. The effective date at the top of the policy reflects the last refresh. Material changes will be communicated where required by law.
Australia. We review this Policy at least annually and whenever the law changes, so that it stays clearly expressed and up to date.
17. Contact
- General: hello@didit.me
- Privacy: privacy@didit.me
- Australian privacy contact: Privacy Officer, Didit ID (Australia) Pty Ltd, C/- Prime Partners, Level 4, 1 James Place, North Sydney NSW 2060, Australia, privacy@didit.me
- Data Protection Officer: dpo@didit.me
- Security and trust pack: security@didit.me
- Legal / contracts: legal@didit.me
This Policy is available free of charge at didit.me/terms/privacy-policy. If you would like a copy in another form, such as an accessible PDF, ask the Australian privacy contact in Section 17 and we will take reasonable steps to provide it.