Back to home

Privacy Policy

Last updated: February 13, 2026

1. Introduction

At AuthUser, we process personal data to provide age and identity verification services with a focus on data minimization, security, and regulatory compliance.

This policy explains what data we process, why we process it, the legal basis we rely on, how long we keep it, and your rights.

2. Controller and contact

3. Data we process

Depending on the verification flow, we may process:

  • Verification data: phone number, verification outcome (approved/rejected), timestamp, and minimal audit traces.
  • Identity and liveness data: ID image and/or liveness capture when required by the flow.
  • Biometric data: facial patterns used to verify authenticity and reduce fraud, subject to strict retention limits.
  • Technical data: IP address, browser/device signals, security logs, essential cookies, and optional cookies based on consent.
  • Business/support contact data: name, corporate email, company, and message content.

4. Processing purposes

We process data to:

  1. Deliver requested age/identity verification services.
  2. Detect and prevent fraud, abuse, and impersonation.
  3. Comply with legal and regulatory obligations.
  4. Maintain platform security and service continuity.
  5. Respond to business and support requests.
  6. Improve product quality using proportionate analytics.

5. GDPR lawful basis

Depending on the purpose, we rely on:

  • Performance of a contract (Art. 6(1)(b) GDPR): delivering the requested service.
  • Legal obligation (Art. 6(1)(c) GDPR): required retention/disclosure under applicable law.
  • Legitimate interests (Art. 6(1)(f) GDPR): security, fraud prevention, and service improvement with balancing safeguards.
  • Consent (Art. 6(1)(a) GDPR): non-essential cookies and optional processing.

Where biometric data is processed as special category data, we additionally rely on an applicable Art. 9 GDPR condition and enhanced safeguards.

6. Retention and deletion

We apply minimization and storage limitation:

  • Raw biometric evidence (image/video): early deletion after verification completion, unless legal obligations or legal claims require temporary retention.
  • Verification outcome and minimal audit logs: limited and proportionate retention.
  • Business contact data: retained while relationship/legitimate need exists, plus required legal periods.

7. Recipients and processors

We may share data with service providers acting as processors (infrastructure, messaging, analytics, technical support), under contractual confidentiality and security obligations.

We do not sell personal data.

8. International transfers

If data is transferred outside the EEA/UK or equivalent-protection jurisdictions, we apply appropriate safeguards (e.g., Standard Contractual Clauses) and supplementary measures where required.

9. Security measures

We apply technical and organizational controls proportionate to risk, including access controls, stronger authentication, in-transit encryption, incident response processes, and periodic reviews.

10. Your rights

Subject to applicable law, you may request access, rectification, erasure, objection, restriction, and portability, and withdraw consent where consent is the legal basis.

To exercise your rights, contact: [email protected]

11. Minors

Our service is designed for age verification. We apply enhanced safeguards where flows may involve minors and limit retention to the minimum required.

12. Cookies

We use necessary cookies and, where applicable, optional cookies managed through consent choices.

13. Policy updates

We may update this policy due to legal, technical, or operational changes. The updated date will be published when material updates occur.

14. Contact

Privacy and Data Protection Team