Privacy

Privacy Policy

Last updated: May 27, 2026

At KYConnect, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your data when you use our identity verification services.

1. Introduction

KYConnect ("we", "us", or "our") operates a secure identity verification platform that enables businesses and individuals to verify identities in compliance with global regulatory standards.

This Privacy Policy applies to all users of our platform, including businesses that integrate our services and individuals who undergo verification.

By using KYConnect, you acknowledge that you have read and understood this Privacy Policy.

2. Information We Collect

Personal identification data, document information, and account profile details required for verification workflows.

Biometric information (such as selfie checks and face match vectors) where legally permitted and technically required.

Technical and device telemetry including IP address, browser metadata, and risk signals used to prevent fraud.

3. How We Use Your Data

To deliver identity verification services and produce verification outcomes for authorized customers.

To improve verification accuracy, product quality, and fraud prevention through controlled analysis.

To meet legal and regulatory obligations, including AML and KYC compliance requirements.

Notice

Legal Basis for Processing

We process your data based on contractual necessity, legal obligations, legitimate interests in fraud prevention and service improvement, and explicit consent where required.

4. Data Sharing & Disclosure

We share personal information only when necessary with business clients, vetted processors, and lawful authorities.

We apply contractual safeguards and purpose limitations for every approved data recipient.

We do not sell personal data to third parties.

5. Data Security Measures

We implement industry-leading security measures to protect personal information from unauthorized access, disclosure, alteration, or destruction.

AES-256 Encryption

AES-256 Encryption

All data encrypted in transit and at rest.

ISO 27001 Certified

ISO 27001 Certified

International security standards compliance.

Access Controls

Access Controls

Strict role-based access restrictions.

6. Your Privacy Rights

Right to access your personal data and obtain a copy

Right to correct inaccurate or incomplete information

Right to request deletion where legal obligations permit

Right to data portability in a structured format

Right to object to processing based on legitimate interest

Right to withdraw consent where consent is the legal basis

Rights info

How to Exercise Your Rights

Email [email protected]. We respond within 30 days and may require identity verification.

7. Data Retention Policy

We retain personal data only for as long as necessary to fulfill legal, regulatory, and contractual obligations.

Retention Periods

5-7 Years

Verification Records: Identity verification data and documents retained per KYC/AML regulatory requirements in most jurisdictions.

90 Days

Biometric Data: Facial recognition data and live selfies removed after successful verification unless legally required.

2 Years

Technical Logs: System logs, session metadata, and risk telemetry retained for security and fraud prevention.

Indefinite

Anonymized Analytics: De-identified datasets used for trend analysis and service quality improvement.

8. International Data Transfers

Data may be processed outside your country of residence where our services and providers operate.

We rely on recognized safeguards such as contractual clauses and transfer impact controls.

Transfers are assessed to maintain lawful and secure processing.

9. Cookies & Tracking

We use essential and security cookies to operate, secure, and improve the platform.

Analytics cookies are configured to minimize data and support performance insights.

You can manage browser controls and cookie preferences where applicable.

10. Children's Privacy

Our services are not directed to children under the age required by applicable law.

If we learn that child data was collected without lawful basis, we take prompt remediation steps.

Parents and guardians may contact us to request review or deletion.

11. Policy Updates

We may update this policy periodically to reflect legal, technical, or business changes.

Material updates are announced through product notices and the "Last Updated" date.

Continued service use after the effective date indicates acceptance of the revised terms.

12. Contact Information

If you have questions, concerns, or requests regarding this policy, contact us through the channels below.

DPOData Protection Officer

Email: [email protected]

Email (DPO): [email protected]

Phone: +1 (888) 555-0123

Hours: Mon-Fri, 9:00 AM - 6:00 PM EST

AddressMailing Address

KYConnect Inc.

Privacy Department

123 Verification Boulevard

Suite 500

San Francisco, CA 94105

United States

AuthoritySupervisory Authority

If you are located in the EEA, you may lodge a complaint with your local data protection authority.

Trust

Your Privacy Matters to Us

At KYConnect, we continuously review and improve our controls to ensure your personal information remains secure. Thank you for trusting us with your identity verification needs.

Version 2.1.0 • Effective May 27, 2026

Privacy Support