GDPR Compliance
Last Updated:
1. Our Commitment to Data Protection
Because EasyVerify.ai processes highly sensitive Personally Identifiable Information (PII) including passports, visas, and financial documents, compliance with the General Data Protection Regulation (GDPR) and the UK GDPR is foundational to our architecture. We treat data privacy as a strict engineering constraint, not just a legal obligation.
2. Data Controller vs. Data Processor
Under GDPR definitions:
- You (The Agency) act as the Data Controller. You determine the purpose for collecting the documents (e.g., Right to Work or Right to Rent checks) and are responsible for obtaining the lawful consent of the data subjects (applicants or tenants).
- EasyVerify.ai acts as the Data Processor. We only process the uploaded data upon your instruction, specifically to perform forensic fraud analysis.
We offer a standard Data Processing Agreement (DPA) to all enterprise clients, which can be signed and integrated into your compliance documentation.
3. Data Minimization & Zero-Retention Policy
The core tenet of our GDPR compliance is data minimization. By default, EasyVerify.ai operates on a zero-retention architecture for document scans:
We only retain the anonymized forensic metadata (e.g., "Pixel manipulation detected at coordinates X,Y") and the final risk score required for your audit trail, unless your specific enterprise DPA mandates a custom retention window.
4. Security Measures & Encryption
To protect data against unauthorized processing and accidental loss, we implement rigorous technical and organizational measures:
- In Transit: All data transferred between your systems and EasyVerify.ai is encrypted using TLS 1.2 or higher.
- At Rest: Temporary processing storage utilizes AES-256 encryption.
- Access Control: Strict logical separation of tenant data and multi-factor authentication (MFA) requirements for all our engineering staff.
5. Data Subject Rights (SARs)
As a Data Processor, EasyVerify.ai will promptly assist you (the Data Controller) in fulfilling Data Subject Access Requests (DSARs), Right to Rectification, and Right to Erasure requests. Because of our zero-retention architecture, in most cases, raw user data is already purged from our systems, drastically simplifying your compliance burden.
6. Sub-Processors & Data Location
Our processing infrastructure is hosted in heavily certified, ISO-27001 compliant data centers. We restrict data processing to geographic regions that ensure GDPR compliance (such as the EU or UK). A full, up-to-date list of our authorized sub-processors is available to all active clients upon request.
7. Contact Our DPO
If you need to request our signed DPA, review our security whitepaper, or speak directly with our Data Protection Officer, please contact us at dpo@easyverify.ai.