This Privacy Policy explains how Devlpfy LLC and its affiliates (“Verazify,” “we,” “us”) handle personal data in connection with our identity verification and AML compliance platform (the “Service”). Verazify operates across Latin America and the Caribbean and serves business customers worldwide. Because our role differs depending on whose data is involved, this policy first explains those roles and then describes our practices.
01Our roles: processor and controller
Data protection law distinguishes between the party that decides why and how personal data is processed (the “controller”) and the party that processes data on the controller’s behalf (the “processor”). Equivalent concepts exist across the region — for example, “responsable” and “encargado” under Mexico’s LFPDPPP, and “controlador” and “operador” under Brazil’s LGPD.
Which hat we wear
- Processor — for the personal and biometric data of our customers’ end users that is submitted to the Service for verification. Our customer is the controller; we process this data on their documented instructions under our Data Processing Addendum.
- Controller — for account data about our customers and their personnel (for example, the people who sign up, log in, and administer an account), and for data we collect when you visit our website or contact us.
This policy describes our practices in both roles. Where we act as a processor, the relevant controller’s own privacy notice governs the end user’s relationship, and end users should direct requests to that business in the first instance.
02Data we collect
End-user verification data (we act as processor)
When our customers use the Service to verify an individual, we process the data they and their end users provide, which may include:
- identity document images and the data extracted from them (name, date of birth, document number, nationality, expiry date, and machine-readable-zone data);
- a selfie or short video and derived biometric data used for face matching and liveness detection;
- contact and address details, where the customer’s flow collects them;
- sanctions, watchlist, and PEP screening results associated with the individual; and
- technical and fraud-signal metadata about the verification session (for example, device and network signals and timestamps) used to detect manipulation, spoofing, and replay.
Account & website data (we act as controller)
- account registration and profile data (name, work email, role, organization);
- authentication and security data (hashed credentials, multi-factor settings, session and audit logs);
- billing and usage records; and
- website, cookie, and support data as described in our Cookie Policy.
03Biometric data & consent
Face matching and liveness detection rely on biometric data, which is a special category of personal data under the GDPR and sensitive personal data under many Latin American laws. We treat it with heightened care.
- Consent is the controller’s responsibility. Our customers, as controllers, must obtain the end user’s explicit, informed consent (or establish another valid legal basis) before submitting biometric data to the Service.
- Purpose limitation. We use biometric data only to perform the verification requested — comparing a face to a document and confirming a live human is present. We never build facial-recognition databases, never sell biometric data, and never use face or other biometric data to train or improve our models.
- Protection. Biometric data is encrypted in transit and at rest and is subject to strict access controls and short, configurable retention windows.
04How we use data
As a processor, we use end-user data only to:
- perform the identity, document, biometric, and screening checks the customer requests;
- return results, scores, and evidence to the customer;
- detect and prevent fraud and abuse of the Service; and
- maintain security, availability, and audit logs, and comply with law.
As a controller for account and website data, we use it to:
- provide, secure, and support the Service and administer your account;
- bill for usage and manage our relationship with you;
- send service, security, and (where permitted) product communications; and
- improve reliability and performance using aggregated, de-identified analytics.
Improving our verification technology (opt-in, documents only)
We work continuously to make document reading more accurate across the many ID types we support. Where — and only where — an end user (or the controller, on a documented lawful basis) has given specific, opt-in consent, we may use identity-document images and the fields extracted from them to train and improve our document-recognition models. This use is strictly limited:
- Documents only — never biometrics. We do not use selfies, face templates, or any biometric data to train or improve models; that remains prohibited (see “Biometric data & consent”).
- Opt-in and revocable. This never happens by default. It requires explicit, separate opt-in consent, which may be withdrawn at any time; withdrawal stops future use, and we remove the relevant records from the training set on request.
- Minimized and secured. We de-identify document data used for model improvement wherever feasible, keep it only as long as needed for that purpose, and protect it with the same encryption and access controls as the rest of the Service.
- Never sold. We do not sell this data or share it for others’ model training.
Your choice
05Legal bases for processing
Where the GDPR or a comparable framework applies, we rely on the following legal bases as controller: performance of a contract (to provide the Service and manage your account); legitimate interests (to secure and improve the Service and prevent fraud, balanced against your rights); consent (for optional analytics cookies and certain communications, and — for using identity-document data to train or improve our verification models — a separate, opt-in consent you may withdraw at any time); and compliance with legal obligations. When we act as a processor, the controller is responsible for establishing the legal basis for the end-user data it submits.
07International transfers
Verazify operates across Latin America and the Caribbean and relies on sub-processors that may process data in other regions, including the United States and the European Union. Where personal data is transferred across borders, we use appropriate safeguards recognized by applicable law, such as the European Commission’s Standard Contractual Clauses, adequacy findings where available, and equivalent transfer mechanisms recognized under local frameworks. We take supplementary measures, including encryption, to protect data in transit and at rest.
08Data retention
For end-user verification data, retention is configurable and governed by our customer’s instructions and the DPA. By default we retain verification data only as long as needed to deliver results and to meet the customer’s and our legal and audit obligations, after which it is deleted or de-identified. For account and billing data, we retain data for the life of the account and for the period required to meet tax, accounting, and legal obligations, after which it is deleted or anonymized.
09Security
We protect personal data with technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest (AES-256), strict role-based access controls, network isolation and rate limiting, logging and monitoring, and a formal vulnerability-management and responsible-disclosure process. Learn more on our Security page. No system is perfectly secure, and we cannot guarantee absolute security.
10Your rights
Depending on where you live and the law that applies, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Under the GDPR these are the data-subject rights; under Mexico’s LFPDPPP they are the “ARCO” rights (access, rectification, cancellation, and opposition); under Brazil’s LGPD they include confirmation, access, correction, anonymization, portability, and deletion; and comparable rights exist under other Latin American and Caribbean laws (for example, Colombia’s Ley 1581 and Argentina’s data-protection law) and the CCPA in California.
If we process your data as a controller, contact us using the details below and we will respond within the timeframe required by applicable law. If your data was submitted to the Service by one of our customers (so we act as processor), please contact that business directly; we will support them in fulfilling your request as required by the DPA. You also have the right to lodge a complaint with your local data-protection authority.
11Children
The Service is intended for use by businesses to verify adults or, where a customer’s regulated use case permits, minors with appropriate guardian consent and legal basis established by the controller. We do not knowingly collect personal data directly from children for our own purposes. If you believe a child’s data has been provided to us in error in our capacity as controller, contact us and we will take appropriate steps to delete it.
12Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or the law. When we make material changes, we will update the “Effective date” above and, where appropriate, provide additional notice. We encourage you to review this page periodically.
13Contact
For privacy questions, to exercise your rights where we are the controller, or to reach our data protection contact, use the details below.
Privacy contact
- Email:
- privacy@verazify.com
- Legal entity:
- Devlpfy LLC (d/b/a Verazify)
- Registered address:
- 1317 Edgewater Drive, Suite #7262, Orlando, FL 32804, USA — operating across Latin America & the Caribbean