본문으로 건너뛰기
Didit, 신원·사기 방지 인프라 구축 위해 750만 달러 투자 유치
Didit
법률

확인 개인정보처리방침

업데이트됨: September 4, 2026

이 페이지에서

This Verification Privacy Notice explains how Didit processes personal data, including biometric data, when Didit provides an identity verification, fraud prevention, authentication, or compliance workflow on behalf of one of its customers.

This notice supplements our Privacy Policy and our End User Terms for Identity Verification.


1. Scope

This notice applies when you interact with a verification flow, hosted page, SDK, API-based journey, mobile flow, or white-label experience powered by Didit for a Customer.

It covers the processing of:

  • identity and contact data;
  • documents and files you submit;
  • selfies, face images, videos, and liveness captures;
  • biometric data derived from those submissions;
  • device, IP, location, and anti-fraud telemetry;
  • verification results, risk signals, and audit records; and
  • related support, compliance, and security records connected to the verification session.

2. Who are the parties and what are their roles?

PartyTypical roleWhat that means
CustomerController / BusinessThe Customer decides why your verification is required, which checks are enabled, and how the result is used.
DiditProcessor / Service ProviderDidit provides the verification technology and processes data on the Customer's behalf to perform the configured checks.
DiditIndependent controller for limited purposesDidit may process limited data for security, abuse prevention, legal compliance, audit logging, and legal claims.

If the verification journey is white-labeled or uses a custom domain, Didit may still be the technology provider processing your data behind the branded interface. If the Customer enables retained biometric templates, Didit processes them only as a processor or service provider on that Customer's documented instruction inside that Customer's tenant.


3. Categories of data used in verification

Depending on the configured workflow, Didit may process:

  • Identity data, such as name, date of birth, address, phone number, email, nationality, and other identifying details.
  • Document data, such as passports, ID cards, residence permits, driver's licenses, proof-of-address documents, and data extracted from those materials.
  • Biometric and liveness data, such as face images, selfie images, videos, liveness captures, anti-spoofing signals, and data derived from scans of facial geometry used to compare your face to the identity document or to confirm that a real person is present.
  • Technical and fraud-prevention data, such as IP address, browser, device data, timestamps, session data, geolocation inferred from network data, and similar integrity or risk signals.
  • Questionnaire and workflow data, such as declarations, answers, uploaded files, consent records, and status transitions.
  • Verification outputs, such as match scores, warnings, fraud indicators, review outcomes, and audit evidence.

4. Purposes of processing

Didit may process the data above to:

  • verify identity and authenticate a person;
  • check document authenticity and completeness;
  • detect spoofing, manipulation, fraud, or abuse;
  • comply with legal, regulatory, sanctions, Anti-Money Laundering (AML), Know Your Customer (KYC), and risk-management requirements configured by the Customer;
  • secure the verification flow and underlying infrastructure;
  • support manual review, resubmission, escalation, and audit processes;
  • respond to lawful requests and defend legal claims; and
  • maintain service integrity, troubleshoot incidents, and perform quality and security monitoring.

Where law permits and appropriate controls are in place, Didit may also use anonymized or pseudonymized verification-related data for service testing, quality assurance, fraud-model training and validation, and security improvement. Where a separate notice, consent, or additional legal basis is required for a secondary use, Didit will obtain it or refrain from that use.

Model training is allowed by default. An organization owner or administrator may opt the organization out under Organization Settings in the Business Console. Once effective, the preference excludes the organization's historical and newly collected data from future model training, fine-tuning, evaluation, validation, dataset curation, and training-data exports. It does not affect the verification or fraud-prevention service, change retention, or reverse updates already incorporated into a model. You may object to model-training processing for a specific verification by contacting the Customer or emailing privacy@didit.me with the relevant session identifier. A retained biometric template is not used for model training or cross-customer fraud processing. A privacy-erasure instruction separately purges it.


5. How Didit handles biometric data

For purposes of this notice, biometric data includes data derived from scans of facial geometry or similar biometric characteristics extracted from images or video, where that data is used to verify identity, confirm liveness, or prevent fraud.

When a workflow includes face verification or liveness, Didit may:

  • capture or receive selfie images, face images, and/or video;
  • extract facial characteristics from those submissions and from the portrait on your identity document;
  • compare those signals to verify that the person presenting the document is the same person shown on the document;
  • analyze liveness and anti-spoofing indicators to confirm a real person is present; and
  • generate verification results, confidence indicators, and fraud or review signals.

Didit:

  • uses biometric data only for the lawful purposes described in this notice, the Customer's instructions, and applicable law;
  • applies safeguards designed for sensitive data, including access controls, monitoring, and secure handling practices;
  • does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information; and
  • expects Customers using API or white-label journeys to clearly disclose Didit as the verification provider and to obtain any notice or consent required by law before biometric capture begins.

If the Customer opts in to retention after an operational session deletion, Didit may keep one separately managed biometric template anchored to that Customer's User record. The template is image-free and tenant-scoped; it does not contain the selfie, liveness video, identity-document media, verification decision, or copied profile fields. It remains biometric data, requires a finite expiry, and is independently deletable.


6. Additional U.S. biometric privacy disclosures

If you are located in Illinois, Texas, Washington, or another jurisdiction with biometric privacy requirements, the following additional points are important:

  • Biometric data may include data derived from scans of face geometry, selfie images, liveness video, or similar identity-verification media.
  • You may be asked to provide explicit electronic or written consent before biometric data is captured or uploaded.
  • The Customer should identify Didit as a verification provider or processor when presenting the required notices in white-label or API-based journeys.
  • Didit uses biometric data to perform identity verification, liveness, anti-spoofing, fraud prevention, security, and related compliance operations requested by the Customer.
  • Didit retains biometric data only for as long as needed to provide the service, follow lawful Customer instructions, satisfy legal obligations, resolve disputes, or defend claims, and in no event longer than applicable law permits.
  • Didit uses a reasonable standard of care designed for sensitive data and does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.

If a jurisdiction requires a shorter retention period, a separate public schedule, or additional disclosures, Didit and the Customer will apply the shorter or stricter requirement that governs the relevant verification flow.

Other jurisdictions with biometric privacy requirements. The points above apply, with appropriate adjustments, to any other state, province, country, or jurisdiction with biometric privacy requirements, including (without limitation) the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) treatment of sensitive personal information, the Colorado Privacy Act (CPA), the Virginia Consumer Data Protection Act (VCDPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), New York's biometric privacy proposals, the European Union's General Data Protection Regulation (GDPR) Article 9 framework for biometric data, the United Kingdom GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Law 25, Brazil's Lei Geral de Proteção de Dados (LGPD), and any future biometric privacy law that applies to the relevant verification flow.


7. Disclosures and service providers

Didit may disclose verification-related data to:

  • the Customer that asked you to verify;
  • Didit group entities involved in delivering, supporting, or securing the service;
  • providers of hosting, cloud storage, communications, identity, fraud, analytics, audit, security, and professional services;
  • regulators, courts, law enforcement, or public authorities where legally required; and
  • transaction counterparties in a merger, acquisition, restructuring, or asset transfer, subject to lawful safeguards.

The exact recipients depend on the service, region, workflow configuration, and legal requirements.


8. International transfers

Verification data may be processed in countries other than the country in which you began the verification flow. Where required by law, Didit applies appropriate transfer safeguards such as adequacy decisions, standard contractual clauses, or other recognized legal mechanisms.


9. Retention and destruction

General verification-data retention. The default retention period for verification data is indefinite ("unlimited") unless the Customer configures a shorter period or you exercise a deletion right. Customers can configure retention per application in the Business Console between 30 days and 10 years.

Retained biometric templates. If the Customer enables retention after an operational session deletion, the template requires a separate finite duration. It expires at the earliest Customer instruction, configured finite period, purpose-end event, contractual or statutory deadline, privacy-erasure instruction, or termination deletion instruction. No unlimited setting authorizes indefinite biometric-template retention. The template remains biometric data, is image-free and tenant-scoped, and is not used for model training or cross-customer fraud processing.

An operational session deletion removes the session and session-owned data but may leave an opted-in retained template until expiry or earlier purge. A privacy-erasure instruction also purges every retained template attributable to you or the instruction scope. User deletion, explicit purge, expiry, purpose end, and termination where the Customer selects deletion also trigger purge. An accepted request remains `deletion requested` until every in-scope store confirms completed purge or approved beyond-use handling.


10. Automated processing and human review

Didit may use automated systems to review document integrity, liveness, face match, fraud indicators, and other verification signals. Some sessions may also be routed for human review, quality assurance, or escalation depending on the Customer's workflow and risk configuration.

Except where a specific service states otherwise, the Customer remains responsible for how it uses the verification result in its own business decision-making.


11. Rights and requests

If you want to access, correct, delete, restrict, object to, or otherwise exercise rights over data processed in a specific verification session, you should generally contact the Customer first. The Customer usually determines the main purpose of the verification and is the best point of contact for rights tied to that relationship.

If Didit receives a request directly in a processor context, Didit may forward or redirect the request to the relevant Customer where appropriate. If Didit acts as an independent controller for a limited processing purpose, you may also contact privacy@didit.me or Didit's Data Protection Officer at dpo@didit.me. A valid privacy-erasure instruction covering you purges both the verification session and any retained biometric template attributable to you; an operational session deletion may have a different retained-template outcome and must state it.

You may also lodge a complaint with a supervisory authority. Didit's lead supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos / AEPD) at `aepd.es`. You may also lodge a complaint with your local data-protection authority.


12. Security

Didit uses technical, organizational, and administrative safeguards designed to protect verification data, including sensitive and biometric data. These safeguards may include encryption, access controls, environment separation, logging, monitoring, and incident response procedures.


13. Children

Didit does not intend this verification notice to authorize unlawful collection of children's data. If a verification flow is used for age-related or youth-related checks, the Customer must ensure a lawful basis, appropriate notices, and any required parental or guardian permissions.


14. Changes to this notice

Didit may update this Verification Privacy Notice from time to time to reflect legal, operational, or product changes. When we do, we will update the effective date at the top of this notice.


15. Contact

If you have questions about this notice, contact:

특정 문서에 대해 궁금한 점이 있으신가요?

legal@didit.me, privacy@didit.me 또는 security@didit.me로 이메일을 보내거나 WhatsApp으로 메시지를 보내주세요. 적절한 담당자에게 연결해 드립니다.

문의하기
AI에게 이 페이지 요약 요청