What happens to my data

Your document photo and selfie are encrypted, processed in the EU by default, and held for as long as the business that asked for the verification decides - and they can delete it.

Short answer

Your data is encrypted in transit and at rest and processed in the EU by default. The business that asked you to verify decides how long it's kept and can delete it - so a request to erase your data goes to them, not to Didit.

#Who holds your data, and who decides about it

Two different roles, and the distinction determines who you talk to:

  • The business that sent you the link decides what to collect, why, how long to keep it, and whether to delete it. In data-protection terms they are the controller.
  • Didit performs the verification on their instructions. In data-protection terms Didit is the processor.

That's why a request about your data - a copy of it, or its erasure - goes to the business. They have the tools to act on it directly, and Didit cannot make that decision on their behalf.

#What's collected

Typically the photo (or photos) of your identity document, a selfie or short liveness recording, and the data read from the document - your name, date of birth, document number, and expiry. Depending on what the business configured, it may also include a phone number, an email address, a proof-of-address document, or answers to questions they asked.

You should have been told what's being collected and why before you started. If you weren't, that's a question for the business.

#How it's protected

  • Encrypted in transit using TLS 1.3, and at rest using AES-256.
  • Processed in the EU by default.
  • Access is restricted by role, so only authorised people can reach it, and every access is logged.
  • The platform's security controls are independently audited - SOC 2 Type 2 and ISO/IEC 27001, among others - rather than self-declared.

The technical detail is in how Didit protects your users' data, written for the businesses that integrate it.

#How long it's kept

The business chooses the retention period - anywhere from a month to several years - or can choose to delete the verification as soon as they've recorded the outcome. Some businesses have their own legal obligation to keep records for a set period; that obligation is theirs, and they can tell you what it is.

#Asking for your data to be deleted

Send the request to the business you verified with. When they delete a verification, it's immediate and irreversible: the decision, the extracted data, and all the images and video are removed, and any links to that media stop working.

If they're unsure how, the mechanism is documented for them: deleting sessions and personal data.

#Your rights

If you're in the EU or UK, GDPR gives you rights over your personal data - including access, correction, and erasure - and biometric data attracts stricter protection than ordinary personal data. Those rights are exercised against the controller: the business that asked you to verify.

Other jurisdictions have comparable regimes. In every case, the business is your first point of contact, and they are required to have a route for these requests.

#If the business won't respond

If you've asked the business and got nowhere, your escalation route is your national data protection authority, not the verification provider. Didit cannot compel a customer to answer you, and cannot act on your data without their instruction.

#What Didit will not do

To be direct about the limits, because people reasonably ask:

  • Didit will not tell you why a business declined you.
  • Didit will not delete your data on your say-so without the controller's instruction.
  • Didit will not restart your verification or manage your account with them.

None of that is unhelpfulness - it's the same separation of responsibility that stops anyone else being able to reach into your verification either.