Data, privacy & compliance
How your users' data is protected, deletion, data processing agreements, certifications, and where data is handled.
5 articles
Your users' data
- How Didit protects your users' dataTLS 1.3 in transit, AES-256 at rest, EU processing by default, independently audited controls, and retention you configure - plus what stays your responsibility as the controller.
- Deleting sessions and personal dataHow to delete a verification session and everything it produced - and exactly what deletion does and doesn't affect. Deletion is immediate and irreversible.
- Opting out of model trainingTurn off the switch that lets Didit use your organization's verification data to improve its models. It lives in Settings on the Account tab, under Privacy and data use. One organization-wide control, effective immediately, and not the same setting as data retention.
Contracts & assurance
- DPAs, data residency and subprocessorsDidit processes in the EU by default, with in-country processing available on enterprise contracts. Here's how to get a DPA, the TOMs, and answers your procurement review will ask for.
- Certifications and complianceSOC 2 Type 2, ISO/IEC 27001 with cloud extensions, iBeta Level 1 PAD, a German youth-protection certification, a Spanish regulator attestation, and an EBA/MiCA legal opinion - with dates.