GDPR 및 데이터 처리

Last updated: 2 July 2026

TrustVerifyID as Data Controller

We are a data controller for our own users: developers, administrators, and billing contacts.

TrustVerifyID as Data Processor

We act as a data processor on behalf of our API clients (the data controllers) who submit applicant data for verification.

Data Processing Agreement (DPA)

A DPA is automatically included in our Terms of Service for all clients. It covers Article 28 GDPR requirements including sub-processors, security measures, and data subject rights. Enterprise clients may request a custom DPA signed by our legal team.

Sub-processors

Sub-processor Purpose Location
StripePayment processingUS (SCC)
Google Cloud Vision (optional)OCR fallbackEU
AWS Rekognition (optional)Face match fallbackEU (SCC)
SendGridTransactional emailUS (SCC)
MinIO / Wasabi (optional)Encrypted file storageEU

Technical & Organisational Measures (TOMs)

🔒

Encryption at Rest

AES-256-GCM for all identity documents and biometric data. Per-applicant encryption keys with master key stored in environment variables.

🔐

Encryption in Transit

TLS 1.3 enforced for all API and dashboard communications. HSTS with 1-year max-age.

👤

Access Control

Role-based access (reviewer / admin / super_admin). TOTP 2FA required for admin accounts. API keys scoped to environments.

📋

Audit Logging

Every data access and modification is logged with actor ID, IP address, timestamp, and action type. Logs are immutable.

🛡️

Malware Scanning

ClamAV antivirus scan on every uploaded file. MIME-type and file size validation before processing.

🗑️

Right to Erasure

Automated erasure request workflow. Applicant data deleted across primary and backup storage within 30 days of approved request.

Data Subject Rights – How to Exercise Them

If you are an applicant whose data was processed by one of our API clients, please contact that organisation first, as they are the data controller. If they cannot assist, contact us at privacy@trustverifyid.com and we will coordinate.

If you are a developer or admin user of TrustVerifyID, submit your request via the developer portal or email us directly. We respond within 30 days.

Data Breach Notification

In the event of a data breach affecting your applicants' data, we will notify you within 72 hours of becoming aware, in accordance with Article 33 GDPR. We maintain an incident response plan and conduct annual security audits.

Supervisory Authority

Our lead supervisory authority is the Office for Personal Data Protection (UOOU), Czech Republic. You have the right to lodge a complaint with any EU supervisory authority.

Request a Custom DPA

Enterprise clients requiring a custom Data Processing Agreement signed by our legal team should contact us.

Contact Legal Team