Privacy Policy
Last updated: May 27, 2026
At KYConnect, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our identity verification services.
1. Introduction
KYConnect ("we", "us", or "our") operates a secure identity verification platform that enables businesses and individuals to verify identities in compliance with global regulatory standards.
This Privacy Policy applies to all users of our platform, including businesses that integrate our services and individuals who undergo verification.
By using KYConnect, you acknowledge that you have read and understood this Privacy Policy.
2. Information We Collect
Personal identification data, document information, and account profile details required for verification workflows.
Biometric information (such as selfie checks and face match vectors) where legally permitted and technically required.
Technical and device telemetry including IP address, browser metadata, and risk signals used to prevent fraud.
3. How We Use Your Data
To deliver identity verification services and produce verification outcomes for authorized customers.
To improve verification accuracy, product quality, and fraud prevention through controlled analysis.
To meet legal and regulatory obligations, including AML and KYC compliance requirements.
Legal Basis for Processing
We process your data based on contractual necessity, legal obligations, legitimate interests in fraud prevention and service improvement, and explicit consent where required.
4. Data Sharing & Disclosure
We share personal information only when necessary with business clients, vetted processors, and lawful authorities.
We apply contractual safeguards and purpose limitations for every approved data recipient.
We do not sell personal data to third parties.
5. Data Security Measures
We implement industry-leading security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction.
AES-256 Encryption
All data encrypted in transit and at rest.
ISO 27001 Certified
International security standards compliance.
Access Controls
Strict role-based access restrictions.
6. Your Privacy Rights
Right to access your personal data and obtain a copy
Right to correct inaccurate or incomplete information
Right to request deletion where legal obligations permit
Right to data portability in a structured format
Right to object to processing based on legitimate interest
Right to withdraw consent where consent is the legal basis
How to Exercise Your Rights
Email [email protected]. We respond within 30 days and may require identity verification.
7. Data Retention Policy
We retain personal data only for as long as necessary to fulfill legal, regulatory, and contractual obligations.
Retention Periods
5-7 Years
Verification Records: Identity verification data and documents retained per KYC/AML regulatory requirements in most jurisdictions.
90 Days
Biometric Data: Facial recognition data and live selfies removed after successful verification unless legally required.
2 Years
Technical Logs: System logs, session metadata, and risk telemetry retained for security and fraud prevention.
Indefinite
Anonymized Analytics: De-identified datasets used for trend analysis and service quality improvement.
8. International Data Transfers
Data may be processed outside your country of residence where our services and providers operate.
We rely on recognized safeguards such as contractual clauses and transfer impact controls.
Transfers are assessed to maintain lawful and secure processing.
10. Children's Privacy
Our services are not directed to children under the age required by applicable law.
If we learn that child data was collected without lawful basis, we take prompt remediation steps.
Parents and guardians may contact us to request review or deletion.
11. Policy Updates
We may update this policy periodically to reflect legal, technical, or business changes.
Material updates are announced through product notices and the "Last Updated" date.
Continued service use after the effective date indicates acceptance of the revised terms.
12. Contact Information
If you have questions, concerns, or requests regarding this policy, contact us through the channels below.
Data Protection Officer
Email: [email protected]
Email (DPO): [email protected]
Phone: +1 (888) 555-0123
Hours: Mon-Fri, 9:00 AM - 6:00 PM EST
Mailing Address
KYConnect Inc.
Privacy Department
123 Verification Boulevard
Suite 500
San Francisco, CA 94105
United States
Supervisory Authority
If you are located in the EEA, you may lodge a complaint with your local data protection authority.
Your Privacy Matters to Us
At KYConnect, we continuously review and improve our controls to ensure your personal information remains secure. Thank you for trusting us with your identity verification needs.
Version 2.1.0 • Effective May 27, 2026
Privacy Support