Verazify Legal & Trust

Privacy Policy

How Verazify collects, uses, and protects personal data — and the distinct roles we play for our customers' account data and for their end users' verification data.

Effective date: August 11, 2026

This Privacy Policy explains how Devlpfy LLC and its affiliates (“Verazify,” “we,” “us”) handle personal data in connection with our identity verification and AML compliance platform (the “Service”). Verazify operates across Latin America and the Caribbean and serves business customers worldwide. Because our role differs depending on whose data is involved, this policy first explains those roles and then describes our practices.

01Our roles: processor and controller

Data protection law distinguishes between the party that decides why and how personal data is processed (the “controller”) and the party that processes data on the controller’s behalf (the “processor”). Equivalent concepts exist across the region — for example, “responsable” and “encargado” under Mexico’s LFPDPPP, and “controlador” and “operador” under Brazil’s LGPD.

Which hat we wear

  • Processor — for the personal and biometric data of our customers’ end users that is submitted to the Service for verification. Our customer is the controller; we process this data on their documented instructions under our Data Processing Addendum.
  • Controller — for account data about our customers and their personnel (for example, the people who sign up, log in, and administer an account), and for data we collect when you visit our website or contact us.

This policy describes our practices in both roles. Where we act as a processor, the relevant controller’s own privacy notice governs the end user’s relationship, and end users should direct requests to that business in the first instance.

02Data we collect

End-user verification data (we act as processor)

When our customers use the Service to verify an individual, we process the data they and their end users provide, which may include:

  • identity document images and the data extracted from them (name, date of birth, document number, nationality, expiry date, and machine-readable-zone data);
  • a selfie or short video and derived biometric data used for face matching and liveness detection;
  • contact and address details, where the customer’s flow collects them;
  • sanctions, watchlist, and PEP screening results associated with the individual; and
  • technical and fraud-signal metadata about the verification session (for example, device and network signals and timestamps) used to detect manipulation, spoofing, and replay.

Account & website data (we act as controller)

  • account registration and profile data (name, work email, role, organization);
  • authentication and security data (hashed credentials, multi-factor settings, session and audit logs);
  • billing and usage records; and
  • website, cookie, and support data as described in our Cookie Policy.

03Biometric data & consent

Face matching and liveness detection rely on biometric data, which is a special category of personal data under the GDPR and sensitive personal data under many Latin American laws. We treat it with heightened care.

  • Consent is the controller’s responsibility. Our customers, as controllers, must obtain the end user’s explicit, informed consent (or establish another valid legal basis) before submitting biometric data to the Service.
  • Purpose limitation. We use biometric data only to perform the verification requested — comparing a face to a document and confirming a live human is present. We never build facial-recognition databases, never sell biometric data, and never use face or other biometric data to train or improve our models.
  • Protection. Biometric data is encrypted in transit and at rest and is subject to strict access controls and short, configurable retention windows.
Verazify does not use end-user biometric data for any purpose other than delivering the verification our customer requested. We do not sell personal data.

04How we use data

As a processor, we use end-user data only to:

  • perform the identity, document, biometric, and screening checks the customer requests;
  • return results, scores, and evidence to the customer;
  • detect and prevent fraud and abuse of the Service; and
  • maintain security, availability, and audit logs, and comply with law.

As a controller for account and website data, we use it to:

  • provide, secure, and support the Service and administer your account;
  • bill for usage and manage our relationship with you;
  • send service, security, and (where permitted) product communications; and
  • improve reliability and performance using aggregated, de-identified analytics.

Improving our verification technology (opt-in, documents only)

We work continuously to make document reading more accurate across the many ID types we support. Where — and only where — an end user (or the controller, on a documented lawful basis) has given specific, opt-in consent, we may use identity-document images and the fields extracted from them to train and improve our document-recognition models. This use is strictly limited:

  • Documents only — never biometrics. We do not use selfies, face templates, or any biometric data to train or improve models; that remains prohibited (see “Biometric data & consent”).
  • Opt-in and revocable. This never happens by default. It requires explicit, separate opt-in consent, which may be withdrawn at any time; withdrawal stops future use, and we remove the relevant records from the training set on request.
  • Minimized and secured. We de-identify document data used for model improvement wherever feasible, keep it only as long as needed for that purpose, and protect it with the same encryption and access controls as the rest of the Service.
  • Never sold. We do not sell this data or share it for others’ model training.

Your choice

Improving our models with your document data is optional and stays off unless you opt in. Declining has no effect on your verification result.

06Sharing & sub-processors

We do not sell personal data and do not share it except as described here. We share data with:

  • Sub-processors — vetted service providers who host infrastructure or perform components of a verification (for example, cloud hosting, document intelligence, and sanctions data). Our current list is published at verazify.com/subprocessors, and they are bound by contractual data-protection obligations.
  • Our customer — when we act as processor, we return results to the controller that requested the verification.
  • Legal and corporate — where required to comply with law, respond to lawful requests, enforce our terms, or in connection with a merger or acquisition, subject to appropriate safeguards.

07International transfers

Verazify operates across Latin America and the Caribbean and relies on sub-processors that may process data in other regions, including the United States and the European Union. Where personal data is transferred across borders, we use appropriate safeguards recognized by applicable law, such as the European Commission’s Standard Contractual Clauses, adequacy findings where available, and equivalent transfer mechanisms recognized under local frameworks. We take supplementary measures, including encryption, to protect data in transit and at rest.

08Data retention

For end-user verification data, retention is configurable and governed by our customer’s instructions and the DPA. By default we retain verification data only as long as needed to deliver results and to meet the customer’s and our legal and audit obligations, after which it is deleted or de-identified. For account and billing data, we retain data for the life of the account and for the period required to meet tax, accounting, and legal obligations, after which it is deleted or anonymized.

09Security

We protect personal data with technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest (AES-256), strict role-based access controls, network isolation and rate limiting, logging and monitoring, and a formal vulnerability-management and responsible-disclosure process. Learn more on our Security page. No system is perfectly secure, and we cannot guarantee absolute security.

10Your rights

Depending on where you live and the law that applies, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Under the GDPR these are the data-subject rights; under Mexico’s LFPDPPP they are the “ARCO” rights (access, rectification, cancellation, and opposition); under Brazil’s LGPD they include confirmation, access, correction, anonymization, portability, and deletion; and comparable rights exist under other Latin American and Caribbean laws (for example, Colombia’s Ley 1581 and Argentina’s data-protection law) and the CCPA in California.

If we process your data as a controller, contact us using the details below and we will respond within the timeframe required by applicable law. If your data was submitted to the Service by one of our customers (so we act as processor), please contact that business directly; we will support them in fulfilling your request as required by the DPA. You also have the right to lodge a complaint with your local data-protection authority.

11Children

The Service is intended for use by businesses to verify adults or, where a customer’s regulated use case permits, minors with appropriate guardian consent and legal basis established by the controller. We do not knowingly collect personal data directly from children for our own purposes. If you believe a child’s data has been provided to us in error in our capacity as controller, contact us and we will take appropriate steps to delete it.

12Changes to this policy

We may update this Privacy Policy to reflect changes in our practices or the law. When we make material changes, we will update the “Effective date” above and, where appropriate, provide additional notice. We encourage you to review this page periodically.

13Contact

For privacy questions, to exercise your rights where we are the controller, or to reach our data protection contact, use the details below.

Privacy contact

For privacy questions and data-subject / ARCO requests where Verazify is the controller.
Legal entity:
Devlpfy LLC (d/b/a Verazify)
Registered address:
1317 Edgewater Drive, Suite #7262, Orlando, FL 32804, USA — operating across Latin America & the Caribbean
    Privacy Policy — Verazify · Verazify