Privacy Notice
IDWise Ltd ("IDWise", "we", "us") is a company registered in England and Wales under company number 13096460, with its registered office at 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
Our Data Protection Officer can be contacted at privacy@idwise.com.
IDWise is registered with the UK Information Commissioner's Office under registration number ZB182501.
This Privacy Notice explains how we process personal data in two different contexts:
Part A applies when you visit our public website, contact us, request a demo, interact with us as a prospective or existing business contact, or receive communications from IDWise.
Part B applies when IDWise processes personal data as part of identity verification, eKYC, fraud prevention and related services provided on behalf of our business customers.
The role IDWise plays under data protection law depends on the processing activity. For the activities described in Part A, IDWise generally acts as data controller. For the customer services described in Part B, IDWise generally acts as data processor on behalf of the relevant customer, which determines the purposes and lawful basis of the processing.
Part A: Website visitors, prospects and business contacts
For the processing described in this Part A, IDWise acts as the data controller.
Personal data we collect and why
| When | Personal data | Purpose | Legal basis |
|---|---|---|---|
| You request a demo, contact us or otherwise engage with IDWise | Contact and business information you provide, such as your name, business email, job title, company, country, phone number and information about your requirements or use case | To respond to your enquiry, arrange meetings or demonstrations, understand your requirements and manage our business relationship | Legitimate interests in responding to and managing business enquiries and relationships |
| You visit our public website | Basic technical and security information such as IP address, browser and device information, requested pages, timestamps and referring information where transmitted by your browser | To deliver, operate, troubleshoot and secure the website and protect against malicious or automated activity | Legitimate interests in operating and securing our website |
| We interact with you as a business contact, including through events, referrals or professional communications | Name, business contact details, company, role, communications and information relevant to our business relationship | To manage our relationship, follow up on discussions and provide relevant information about IDWise | Legitimate interests in developing and maintaining business relationships, subject to applicable direct-marketing rules |
| We send you marketing or business communications | Name, business email, company, role, communications preferences and, where enabled, engagement with our communications | To provide relevant information about IDWise, identity verification, eKYC, fraud prevention and related services | Legitimate interests where permitted by applicable law, or consent where consent is required |
We do not sell personal data and we do not use personal data collected through the public IDWise website for targeted advertising.
We do not currently use advertising cookies, analytics cookies or tracking pixels on the public website. Further information is available in our Cookie Policy.
Where we obtain business contact information
In addition to information you provide directly to us, we may receive professional contact information from sources such as:
- your organisation
- professional networking platforms
- conferences, events and business meetings
- referrals and introductions
- publicly available professional or corporate sources
We use such information only where we have a legitimate business reason to do so and where our communications are permitted by applicable law.
Where required, we will provide or make this Privacy Notice available when we first contact you.
Who we share personal data with
We may share personal data with service providers that help us operate our website and business systems, including:
- HubSpot, for CRM, forms and business communications
- hosting, security and infrastructure providers used to operate and protect the website
- business email, collaboration and communications providers
- professional advisers where reasonably necessary
Where the public website uses Google Fonts or security technologies associated with the demo form, limited technical information may also be transmitted to those providers as described in our Cookie Policy.
We may also disclose personal data where required by law, regulation, court order or competent authority; where reasonably necessary to establish, exercise or defend legal rights; or in connection with a merger, acquisition, financing, restructuring or sale of all or part of our business.
Service providers processing personal data on our behalf are subject to appropriate contractual, confidentiality and data-protection obligations.
International transfers
Some of our service providers may process personal data outside the United Kingdom.
Where personal data is transferred internationally, we use the safeguards required by applicable data protection law. Depending on the destination and circumstances, these may include an adequacy regulation or decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another legally recognised transfer mechanism.
How long we keep personal data
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, taking account of our legal, regulatory and business requirements.
As a general approach:
- enquiry and prospect information is retained for the duration of the relevant discussions or business relationship and generally for up to 24 months after the last substantive interaction, unless there is a reason to retain it for longer
- active marketing information is retained until you unsubscribe, object or the information is no longer relevant
- we may retain a minimal suppression record after you opt out so that we can respect your preference in future
- technical and security logs are retained only for periods reasonably necessary to operate, protect and investigate the security of our systems
Information that has been irreversibly anonymised so that it no longer relates to an identified or identifiable individual may be retained for longer.
Providing personal data
Providing personal data through our public website is generally voluntary.
If you do not provide information reasonably necessary for us to respond to an enquiry or demo request, we may be unable to provide the requested response or arrange the interaction.
Cookies and similar technologies
The public IDWise website has been designed to minimise the use of cookies and similar technologies.
The HubSpot demo form and associated security technologies are loaded only when you choose "Book a demo".
For details of the technologies used, their purposes and available controls, please see our Cookie Policy.
Your rights
Depending on the law that applies to you, you may have rights in relation to your personal data, including the right to:
- request access to your personal data
- ask us to correct inaccurate or incomplete information
- request deletion of your personal data in certain circumstances
- request restriction of processing
- object to processing based on legitimate interests
- withdraw consent where processing is based on consent
- request portability of certain personal data where applicable
- object at any time to the use of your personal data for direct marketing
These rights are subject to the conditions and exemptions set out in applicable data protection law.
To exercise your rights, contact privacy@idwise.com.
If UK data protection law applies, you also have the right to complain to the Information Commissioner's Office (ICO). Depending on where you are located, you may also have the right to complain to another competent data protection authority.
Third-party websites
Our website contains links to third-party websites and services, including our developer documentation and professional networking platforms.
Those services operate under their own privacy notices. IDWise is not responsible for the privacy practices of third-party websites that you visit separately.
Part B: IDWise services provided on behalf of customers
IDWise provides identity verification, eKYC, AML screening, proof-of-address, biometric authentication, device intelligence, fraud detection, ongoing monitoring and related identity, fraud-prevention and compliance services to business customers.
An individual whose personal data is processed through an IDWise-powered journey is referred to in this Part B as an "End User".
When an End User uses an IDWise-powered verification journey through a customer's application, website or service, the customer generally acts as the data controller and IDWise acts as its data processor, processing personal data on the customer's documented instructions and under an applicable data processing agreement.
The customer determines why personal data is processed, which IDWise capabilities are used, the applicable lawful basis, relevant retention requirements and how the results are used.
End Users should therefore also read the privacy notice provided by the organisation whose product or service they are using.
Personal data we may process for customers
The information processed depends on the services and verification journey configured by the customer and may include:
- identity-document images and information contained in or extracted from identity documents, including name, date of birth, nationality, document number, expiry date and photograph
- information read from an identity document's NFC chip where the relevant service is enabled
- selfie images and video captured for facial comparison and liveness detection
- biometric information generated from facial images where facial comparison or authentication is used
- proof-of-address documents and information extracted from them
- sanctions, politically exposed person (PEP), watchlist and adverse-media screening information where screening is enabled
- device, browser and network information, such as device type, operating system, browser, IP address, approximate location and indicators associated with VPN, emulator or other device-risk signals
- information about interactions during a verification journey, such as journey progression, timings, attempts and retries
- information supplied by the customer or obtained from approved data sources where required for a configured verification or screening service
- verification results, matching scores, liveness results, document-authenticity assessments, fraud and risk signals, and configured journey outcomes
The exact information processed depends on the services selected by the customer and the jurisdiction in which the service is provided.
Biometric data
Where specific technical processing of facial images is used for the purpose of uniquely identifying or authenticating an individual, the resulting biometric data constitutes special category personal data under UK and EU data protection law.
The customer, as controller, is responsible for determining the applicable lawful basis for processing personal data and, where special category data is involved, the applicable additional condition required by law.
Depending on the circumstances and applicable law, this may include explicit consent or another legally permitted condition.
IDWise processes biometric data on the customer's instructions and in accordance with the applicable agreement and data protection law.
How we use personal data on behalf of customers
We may process personal data on a customer's instructions to:
- verify the authenticity of identity documents
- extract and validate identity information
- compare facial images and perform liveness detection
- authenticate returning users
- verify address information
- perform configured sanctions, PEP, watchlist and adverse-media screening
- identify device, behavioural, duplicate-account and other fraud-risk signals
- support ongoing monitoring, KYC renewal and re-verification where configured by the customer
- provide verification, risk and workflow results to the customer
- operate, maintain, secure and support the services
- comply with legal obligations applicable to IDWise in connection with providing the services
Automated processing and decisioning
IDWise uses automated technologies, including machine-learning models and rules-based processing, to perform document checks, facial comparison, liveness detection, fraud analysis and other configured services.
These technologies may generate verification results, risk signals and configured workflow outcomes for the customer.
IDWise does not independently determine whether an End User is eligible for a customer's product or service. The customer determines the decision logic, how IDWise outputs are used within its processes, and whether those outputs contribute to a decision producing legal or similarly significant effects for the End User.
Model training and service improvement
IDWise does not use personal data processed on behalf of one customer to train general-purpose or cross-customer models for IDWise's independent purposes.
Where a customer expressly instructs or agrees to specific processing for customer-specific testing, calibration, model tuning or improvement, that processing is governed by the applicable agreement, documented instructions and applicable data protection law.
IDWise may use information that has been irreversibly anonymised so that it no longer relates to an identified or identifiable individual for statistical, performance and service-quality purposes.
Subprocessors and other recipients
To provide the services, IDWise may engage authorised subprocessors for functions such as cloud hosting, infrastructure, security, screening and other supporting technologies.
Depending on the service and deployment selected, these may include cloud infrastructure from Amazon Web Services, Google Cloud Platform and Microsoft Azure, as well as specialist providers supporting particular contracted capabilities.
Where IDWise acts as processor:
- subprocessors are engaged under written contractual obligations
- appropriate confidentiality, security and data-protection requirements apply
- their use is governed by the applicable customer agreement and subprocessor arrangements
Personal data and verification results are also made available to the relevant customer in accordance with the services it has configured.
Where personal data is processed
The location in which personal data is processed depends on the deployment and data-residency arrangements agreed with the customer.
IDWise supports regional and private deployment configurations, including cloud and hybrid architectures. Depending on the agreed deployment, processing may take place using infrastructure provided by Amazon Web Services, Google Cloud Platform or Microsoft Azure, or through an architecture in which some data is stored within the customer's own environment.
Where personal data is transferred internationally, IDWise and the customer apply the transfer mechanism required by applicable law. Depending on the relevant jurisdictions, this may include:
- an adequacy regulation or adequacy decision
- the UK International Data Transfer Agreement
- the UK Addendum to the EU Standard Contractual Clauses
- the EU Standard Contractual Clauses
- another legally recognised transfer mechanism or safeguard
The precise deployment and international-transfer arrangements applicable to a particular customer are governed by the relevant contract and data processing agreement.
Retention
IDWise retains personal data in accordance with the customer's documented instructions, the agreed service configuration and applicable contractual and regulatory requirements.
Unless otherwise instructed or agreed, IDWise's standard service arrangements generally provide for retention of verification data for no longer than 24 months from collection.
Customers may configure shorter retention periods where supported. Longer retention may be provided where lawfully instructed by the customer and separately agreed.
At the end of the applicable retention period, personal data is securely deleted or anonymised in accordance with the applicable agreement and IDWise's retention procedures.
IDWise also supports configurable retention, scoped storage and data-minimisation controls depending on the deployment and service configuration.
Security
IDWise maintains technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss or destruction.
These measures include, as applicable:
- encryption of personal data in transit and at rest
- role-based and need-to-know access controls
- logging and monitoring of relevant system and administrative activity
- vulnerability management and security testing
- secure development and infrastructure practices
- organisational security and confidentiality controls
IDWise maintains an ISO/IEC 27001-certified information security management system (ISMS).
Relevant processing and administrative activities are logged to support traceability, security investigation and customer audit requirements.
Further information about IDWise's security and compliance programme is available through our Trust Center and enterprise due-diligence process.
End User rights
Because the relevant customer generally acts as the data controller, requests relating to personal data processed through an IDWise-powered verification journey should normally be directed to the organisation whose product or service the End User was using.
Depending on applicable law, these rights may include access, correction, deletion, restriction, objection, portability, withdrawal of consent and rights relating to automated decision-making.
If an End User contacts IDWise directly at privacy@idwise.com in relation to data that we process on behalf of a customer, we will, where the relevant customer can be identified, notify or refer the request to that customer and provide the assistance required under our contractual and legal obligations.
End Users may also have the right to complain to the supervisory or data-protection authority responsible for the relevant customer or jurisdiction.
General
Children
The public IDWise website is intended for business users and is not directed at children.
IDWise services may process personal data relating to individuals under the age of 18 where a customer has lawfully configured the service for that purpose. The customer is responsible for establishing an appropriate lawful basis and complying with any consent, age-verification, parental-authorisation or other requirements that apply in the relevant jurisdiction.
Changes to this Privacy Notice
We may update this Privacy Notice from time to time to reflect changes to our services, technologies, practices or applicable law.
The Last updated date at the top of this notice indicates when the current version took effect.
Where a change materially affects how we process personal data, we will take appropriate steps to provide additional notice where required by law.
Contact
For questions about this Privacy Notice, the exercise of privacy rights or IDWise's data-protection practices, please contact:
Data Protection Officer
IDWise Ltd
71-75 Shelton Street
Covent Garden
London WC2H 9JQ
United Kingdom
ICO registration number: ZB182501