Ver.iD Privacy Policy
Last updated: 7 November 2024
This Privacy Policy includes important information about your personal data and we encourage you to read it carefully.
We provide services and software that allow our clients (“Client”) to collect, verify and issue data to and from their customers (“Customer”) through the use of digital credentials. This Privacy Policy (“Policy”) describes the “Personal Data” that we collect about you (“you”, “your”) as a user of our software and services. This Policy describes how we use Personal Data, how we share it, your rights and choices, and how you can contact us about our privacy practices. This Policy also outlines your data subject rights, including the right to object to some uses of your Personal Data by us.
“Ver.iD”, “we”, “our” or “us” means the Subst.id B.V. entity responsible for the collection and use of Personal Data under this Privacy Policy.
“Personal Data” means any information that relates to an identified or identifiable individual, and can include information about how you engage with our Services (e.g. device information, IP address, data you shared or obtained through our services that links to you as an individual).
“Services” means the products and services that Ver.iD indicates are covered by this Policy. Our “Credential Services” are Services provided by Ver.iD to our Clients who directly or indirectly provide us with their Customer Personal Data. Our “Sites” means Ver.iD and other websites that Ver.iD indicates are covered by this Policy. Collectively, we refer to Sites and Credential Services as “Services”.
Depending on the context, “you” means Representative, Customer or Visitor:
- When you are acting on behalf of an existing or potential Client (e.g. you are an executive of a company, or administering an account for a Client), we refer to you as a “Representative.”
- When you do business with, or otherwise interact with, a Client (e.g. when you share your personal data with a Client) but are not directly doing business with us, we refer to you as an “Customer”.
- When you visit a Site without being logged into a Ver.iD account or otherwise communicate with Ver.iD, we refer to you as a “Visitor.”
Depending on the activity, Ver.iD acts as a “data controller” or “data processor”.
We note that our Clients have their own privacy policies regarding how they use Personal Data of their Customers that is managed on their behalf, see also below.
To provide Credential Services, we collect, use and share Personal Information from Representatives of our Clients.
If you register for a Ver.iD account for a Client we collect your name and account log-in credentials. If you register for an event that Ver.iD organizes or attends or if you sign up for Ver.iD communications, we collect your registration and profile information. If you are a Representative of a potential Client, we receive your Personal Data from third parties (including data providers) in order to advertise to, market and communicate with you as described further below.
We generally use Personal Data of Representatives to provide the Credential Services to the associated Clients, as well as for the purposes described below.
- Credential Services. We use and share Personal Data of Representatives with Clients to provide the Services. In some cases our Credential Service may require us to submit your Personal Data to a government entity.
- Advertising. With your permission or where allowed by applicable law, we use and share Representative Personal Data with others so that we may advertise and market our products and services to you, including through interest-based advertising subject to any consent requirements under applicable law. We do not sell Representative Personal Data.
Ver.iD offers Credential Services to our Clients (e.g. verification of personal credentials). When we are acting as a Client’s data processor, we will process Personal Data in accordance with the terms of our agreement with the Client and the Client’s lawful instructions. For example, when we process personal credentials because you decided to register on their website.
Clients are responsible for making sure that their Customer’s privacy rights are respected, including ensuring appropriate disclosures about data collection and use that happens in connection with their services. If you are a Customer (e.g., a individual that shares Personal Data with a Client), please refer to the privacy policy or notice of the Client for information regarding the Client’s privacy practices, choices and controls, or contact the Client directly.
- Credential Services. If you are a Customer, whenever you share credentials to a Client or receive credentials from a Client that use our Credential Services, we will receive "Credential Data” and facilitate a “Credential Exchange” as the intermediate party between you and the Client. The Credential Data that we collect in this exchange include Personal Data, and may include, but is not limited to your name, email address, address information, bank information (such as your bank account information), your location, your email address, your social security number or date of sharing. The exact data that we process depend on the Client’s requirements. We may also receive other relevant data that contains your history with the Client or metadata that the Client sends us to help us facilitate the Credential Exchange.
- During the Credential Exchange we temporary collect and store Credential Data in our systems. We keep this data for the shortest amount of time possible until the Credential Exchange has been completed. After completion and related infrastructure monitoring, either due to failure in the process or due to successful delivery of credentials, we remove all Credential Data in our systems, and we do not keep or track any information regarding the Credential Exchange that is directly or indirectly linkable to your Personal Data.
We use and share Personal Data of Customers with Clients to provide Credential Services as described below.
- Credential Services. The Client you choose to do business with through our Credential Services with will receive Credential Data that may include your Personal Data, as described above. We note that the Client may share that Personal Data with other parties that are directly authorized by the Client. Please review the Client’s privacy policy to learn more about how they use your Personal Data.
- Ver.iD is not responsible for any losses, whether direct or indirect, that you as a Customer may incur as a result of any failure of a Client’s responsibility in managing your Personal Data.
Visitors to Ver.iD sites who are not Representatives or Customers.
When you visit our Sites, we generally receive your Personal Data either from you providing it to us or through our use tracking technologies, which are detailed below. This data helps us improve user experience and analyze how visitors engage with our content. Importantly, this data cannot be used to identify individual users and does not include any personally identifiable information (PII). When you choose to fill in a form on the Site or on third party websites featuring our advertising (e.g. LinkedIn or Facebook), we will collect the information included in the form, usually your contact information and other information about your question related to our Services.
Tracking & Analytics Data:
- UTM Parameters: We collect UTM tags (Campaign, Content, Medium, and Source) to understand how users find our site, such as through specific campaigns or referral sources.
- Browser & Device Information: We track the name and version of the user's browser and operating system, both for the initial visit and subsequent interactions.
- Referring URL: We capture the URL that led the user to our website.
- Geographical Data: We collect rough geographic information such as city, country, continent, and region based on IP address. However, we do not store IP addresses—only approximate location data derived from them, which is not always fully accurate.
- Engagement Tracking: We may track certain user interactions, such as clicks on specific buttons (e.g., the "Try Demo" button), to understand engagement with our content and improve website features.
- Personalization. We use information about you via the Trackings & Analytics data technologies to measure website performance and engagement with the content on the Sites, to improve relevancy and navigation, to personalize your experience and to tailor content about Ver.iD and our Services to you. Additionally, we understand the sources of traffic and can therefore optimize marketing efforts.
- Advertising. With your permission or where allowed by law, we use and share Visitor Personal Data with others so that we may advertise and market our products and services to you, including through interest-based advertising where allowed by applicable law, including subject to any consent requirements.
- Demoing and Sandboxing. If you use demo's and/or Sandboxes on our website we may receive "Credential Data”. The Credential Data that we may collect in this exchange include Personal Data, and may include, but is not limited to your name, email address, address information, bank information (such as your bank account information), your location, your email address, your social security number or date of sharing. The exact data that we process depend on the demo and/or sandbox application used. We may also receive other relevant data that contains your history or metadata that help us facilitate the Credential Exchange. During the Credential Exchange we temporary collect and store Credential Data in our systems. We keep this data for the shortest amount of time possible until the Credential Exchange has been completed. After completion, either due to failure in the process or due to successful delivery of credentials, we remove all Credential Data in our systems, and we do not keep or track any information regarding the Credential Exchange that is directly or indirectly linkable to your Personal Data.
In addition to the ways we collect, use and share Personal Data that are described above, we also process Personal Data of Visitors and Representatives as follows.
- Online Activity. Depending on the Service you use and the Clients’ implementation of our Credential Services, we will collect information about:
- Devices and browsers across our Sites, Credential Services and third-party websites, apps and other online services (“Third-Party Sites”),
- Usage data associated with those devices and browsers, including IP address, plug-ins, language used, time spent on Sites, Credential Services and Third-Party Sites, pages visited, links clicked, and the pages that led or referred you to Sites and Third-Party Sites. For example, activity indicators, like mouse activity indicators, help us detect fraud.
- We do not make use of cookies, however we apply different tracking technologies to facilitate and secure the use of our Services by Representatives.
- Communication and Engagement Information. We will collect any information you choose to provide to us, for example, through support tickets, emails or social media. When you respond to Ver.iD emails or surveys, we collect your email address, name and any other information you choose to include in the body of your email or responses. If you contact us by phone, we will collect the phone number you use to call Ver.iD, as well as other information you may provide during the call. We will also collect your engagement data such as your registration for, attendance of, or viewing of Ver.iD events and other interaction with Ver.iD personnel.
- Forums and Discussion Groups. Where our Sites allow you to post content, we will collect Personal Data that you provide in connection with the post.
In addition to the ways described above in which we collect Personal Data, we use Personal Data in the following ways:
- Improving and Developing our Services. We use analytics on our Sites and Services to help us analyze your use of our Sites and Services and diagnose technical issues. We also collect and process Personal Data through our different Services, whether you are a Representative, Customer or Visitor, to improve our Services, develop new Services and support our efforts to make our Services more relevant and more useful to you.
- Communications. We will use the contact information we have about you to perform the Services, which may include sending codes via SMS to authenticate you. If you are a Representative or Visitor, we may communicate with you using the contact information we have about you (e.g. using email, phone, text message or videoconference) to provide information about our Services and our affiliates’ services, invite you to participate in our events or surveys, or otherwise communicate with you for our marketing purposes, provided that we do so in accordance with applicable law, including any consent or opt-out requirements. For example, when you submit your contact information to us or when we collect your business contact details through our participation at trade shows or other events, we may use the information to follow-up with you regarding an event, send you information that you have requested on our products and services and include you on our marketing information campaigns.
- Social Media and Promotions. If you choose to submit Personal Data to us to participate in an offer, program or promotion, we will use the Personal Data you submit to administer the offer, program or promotion. Based on your permission or opt-out, we will also use that Personal Data and Personal Data you make available on social media to market to you.
- Fraud Prevention and Security. We collect and use Personal Data to help us to detect and manage the activity of fraudulent and other bad actors across our Services, to enable our fraud detection Credential Services, and to otherwise seek to secure our Services against unauthorized access, use, modification or misappropriation of Personal Data, information and funds. We may collect information from you, and about you from Clients and in some cases third parties. For example, to protect our Services, we may receive information from third parties about IP addresses that malicious actors have compromised. The Personal Data (e.g. name, address, phone number, country) helps us to confirm identities subject to applicable law and prevent fraud.
- Compliance with Legal Obligations. We use Personal Data to meet our contractual and legal obligations and prohibitions on doing business with restricted persons or in certain business areas, and other legal obligations. We strive to make our Services safe, secure and compliant, and the collection and use of Personal Data is critical to this effort.
- Minors. The Services are not directed to minors and we request that they do not provide Personal Data through the Services. In some countries, we may impose higher age limits as required by applicable law.
In addition to the ways described above, we share Personal Data in the following ways:
- Ver.iD Affiliates. We share Personal Data with other Ver.iD affiliated entities. When we share with these entities, it is for purposes identified in this Policy.
- Service Providers or Processors. In order to provide Services to our Clients and to communicate, market and advertise to Representatives and Visitors regarding our Services, we will rely on others to provide us services. We authorize such service providers to use or disclose the Personal Data of our Users that we make available to perform services on our behalf and to comply with applicable legal requirements. We require such service providers to contractually commit to protect the security and confidentiality of Personal Data they process on our behalf.
- Wallet Providers Wallet Providers may require us to report to them Personal Data of the Representative of a Client that is a so-called relying party for them.
- Others with Consent. In some cases, we may not provide a service, but instead refer you to, or enable you to engage with, others to get services. In these cases, we will disclose the identity of the third party and the information that will be shared with them and seek your consent to share the information.
- Corporate Transactions. In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, sale, joint venture, assignment, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, we may share Personal Data with third parties in connection with such transaction. Any other entity which buys us or part of our business will have the right to continue to use your Personal Data, but subject to the terms of this Policy.
- Compliance and Harm Prevention. We share Personal Data as we believe necessary: (i) to comply with applicable law, (ii) to comply with rules imposed by Wallet Providers, (iii) to enforce our contractual rights; (iv) to secure or protect the Services, rights, privacy, safety and property of Ver.iD, you or others, including against other malicious or fraudulent activity and security incidents; and (v) to respond to valid legal process requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.
For the purposes of the General Data Protection Regulation, we rely upon a number of legal bases to enable our processing of your Personal Data.
We process Personal Data for the purpose of entering into business relationships with prospective Clients and to perform the respective contractual obligations that we have with these Clients. Activities include:
- Creation and management of Ver.iD accounts and Ver.iD account credentials, including the evaluation of applications to commence or expand the use of our Services; and
- Accounting, auditing, and billing activities.
We process Personal Data to verify the identity of our Clients in order to comply with fraud monitoring, prevention and detection obligations, laws associated with the identification and reporting of illegal and illicit activity, such as Know-Your-Customer ("KYC")" obligations, and financial reporting obligations if and when they are applicable to us. These obligations may be imposed on us by the operation of law, industry standards, and may require us to report our compliance to third parties, and to submit to third party verification audits.
Where allowed under applicable law, we rely on our legitimate business interests to process Personal Data about you. The following list sets out the business purposes for which we have a legitimate interest in processing your data:
- Detect, monitor and prevent fraud and unauthorized use of verification processes;
- Mitigate financial loss, claims, liabilities or other harm to Clients and Ver.iD;
- Determine eligibility for and offer new Ver.iD products and services;
- Respond to enquiries, send Service notices and provide support;
- Promote, analyze, modify and improve our Services, systems, and tools, and develop new products and services, including reliability of the Services;
- Manage, operate and improve the performance of our Sites and Services by understanding their effectiveness and optimizing our digital assets;
- Analyze and advertise our Services;
- Conduct aggregate analysis and develop business intelligence that enable us to operate, protect, make informed decisions, and report on the performance of, our business;
- Share Personal Data with third party service providers that provide services on our behalf and business partners which help us operate and improve our business;
- Enable network and information security throughout Ver.iD and our Services.
We may rely on consent to collect and process Personal Data as it relates to how we communicate with you and for the provision of our Services. When we process data based on your consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on such consent before the consent is withdrawn.
You may have choices regarding our collection, use and disclosure of your Personal Data:
If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, our Clients may still send you messages and direct us to send you messages on their behalf.
Depending on your location and subject to applicable law, you may have the following rights with regard to the Personal Data we control about you:
- The right to request confirmation of whether Ver.iD processes Personal Data relating to you, and if so, to request a copy of that Personal Data;
- The right to request that Ver.iD rectifies or updates your Personal Data that is inaccurate, incomplete or outdated;
- The right to request that Ver.iD erases your Personal Data in certain circumstances provided by law;
- The right to request that Ver.iD restricts the use of your Personal Data in certain circumstances, such as while Ver.iD considers another request that you have submitted (including a request that Ver.iD makes an update to your Personal Data);
- The right to request that we export your Personal Data that we hold to another company, where technically feasible;
- Where the processing of your Personal Data is based on your previously given consent, you have the right to withdraw your consent at any time; and/or
- Where we process your information based on our legitimate interests, you may also have the right to object to the processing of your Personal Data. Unless we have compelling legitimate grounds or where it is needed for legal reasons, we will cease processing your information when you object.
To exercise your data protection rights please contact us.
We make reasonable efforts to provide a level of security appropriate to the risk associated with the processing of your Personal Data. We maintain organizational, technical and administrative measures designed to protect Personal Data covered by this Policy against unauthorized access, destruction, loss, alteration or misuse. Personal Data is only accessed by a limited number of personnel who need access to the information to perform their duties. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
To help us protect personal data, we encourage you to use a strong password and never share your password with anyone or use the same password with other sites or accounts. If you have reason to believe that your interaction with us is no longer secure (e.g. you feel that the security of your account has been compromised), please contact us immediately.
We retain your Personal Data as long as we are providing the Services to you or the Client you are related with (as applicable) or for a period during which we reasonably anticipate providing the Services. After we stop providing Services directly to the Client you are related with, we retain your Personal Data for a period of x months unless we are obliged to retain your Personal Data for a longer period in order to comply with our legal and regulatory obligations. We may also be obliged to keep Personal Data to comply with our contractual commitments to Wallet Providers. In cases where we keep Personal Data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.
We are an European business. Personal Data may be stored and processed in any country within the EU where we do business, where our service providers do business or if you use an international Wallet Provider service, the countries in which that Wallet Provider operates. We may transfer your Personal Data to countries other than your own country within the Europe. Other countries may have data protection rules that are different from your country. When transferring data across borders, we take measures to comply with applicable data protection laws related to such transfer. In certain situations, we may be required to disclose Personal Data in response to lawful requests from Officials (such as law enforcement or security authorities).
Where applicable law requires a data transfer mechanism, we use one or more of the following: EU Standard Contractual Clauses with a data recipient outside the EEA, Switzerland or the UK, verification that the recipient has implemented Binding Corporate Rules, or other legal methods available to us under applicable law.
We may change this Policy from time to time to reflect new services, changes in our privacy practices or relevant laws. The “Last updated” legend at the top of this Policy indicates when this Policy was last revised. Any changes are effective when we post the revised Policy on the Services.
We may provide you with disclosures and alerts regarding the Policy or Personal Data collected by posting them on our website and, if you are a Client, by contacting you through your Ver.iD Dashboard, email address and/or the physical address listed in your Ver.iD account.
If applicable law requires that we provide notice in a specified manner prior to making any changes to this Policy applicable to you, we will provide such required notice.
If you have any questions or complaints about this Policy, please contact us through compliance@ver.id.