Last updated: 2 July 2026
We are a data controller for our own users: developers, administrators, and billing contacts.
We act as a data processor on behalf of our API clients (the data controllers) who submit applicant data for verification.
A DPA is automatically included in our Terms of Service for all clients. It covers Article 28 GDPR requirements including sub-processors, security measures, and data subject rights. Enterprise clients may request a custom DPA signed by our legal team.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | US (SCC) |
| Google Cloud Vision (optional) | OCR fallback | EU |
| AWS Rekognition (optional) | Face match fallback | EU (SCC) |
| SendGrid | Transactional email | US (SCC) |
| MinIO / Wasabi (optional) | Encrypted file storage | EU |
AES-256-GCM for all identity documents and biometric data. Per-applicant encryption keys with master key stored in environment variables.
TLS 1.3 enforced for all API and dashboard communications. HSTS with 1-year max-age.
Role-based access (reviewer / admin / super_admin). TOTP 2FA required for admin accounts. API keys scoped to environments.
Every data access and modification is logged with actor ID, IP address, timestamp, and action type. Logs are immutable.
ClamAV antivirus scan on every uploaded file. MIME-type and file size validation before processing.
Automated erasure request workflow. Applicant data deleted across primary and backup storage within 30 days of approved request.
If you are an applicant whose data was processed by one of our API clients, please contact that organisation first, as they are the data controller. If they cannot assist, contact us at privacy@trustverifyid.com and we will coordinate.
If you are a developer or admin user of TrustVerifyID, submit your request via the developer portal or email us directly. We respond within 30 days.
In the event of a data breach affecting your applicants' data, we will notify you within 72 hours of becoming aware, in accordance with Article 33 GDPR. We maintain an incident response plan and conduct annual security audits.
Our lead supervisory authority is the Office for Personal Data Protection (UOOU), Czech Republic. You have the right to lodge a complaint with any EU supervisory authority.
Enterprise clients requiring a custom Data Processing Agreement signed by our legal team should contact us.
Contact Legal Team