ideevy
Product Solutions Developers Pricing Company
Try for free Book a demo

Privacy Policy

Effective date: June 19, 2026

This Policy applies to the IDEEVY website, dashboard, APIs, Document Verification Hub services, provider workflows, and related support.

Company: INTEGRITYTECH HK LIMITED
Website: ideevy.com
Company Registration No.: 3339122
Business Registration No.: 75921776
Registered Address: Room 905, Block 2, Cyberport, 100 Cyberport Road, Hong Kong

1. Scope and who we are

This Privacy Policy explains how IDEEVY, operated by INTEGRITYTECH HK LIMITED, processes personal data in connection with the IDEEVY website, dashboard, APIs, document verification services, and related support services.

IDEEVY provides a Document Verification Hub. This means that IDEEVY may perform its own document checks and may also route verification cases through customer-configured provider workflows, fallback paths, second-opinion checks, or external verification providers, depending on the Business Customer configuration.

In this Policy, “Business Customer” means the company or organization that integrates with IDEEVY and submits verification cases. “End User” means the individual whose identity document or related data is submitted for verification.

2. Our role in processing personal data

For most End User verification cases, the Business Customer determines why a verification is performed, what data is submitted, which workflow is configured, and how the result is used. In that context, the Business Customer is usually the controller of the personal data and IDEEVY acts as a processor or service provider.

IDEEVY may act as a controller for limited business purposes, including operating the website, managing customer accounts, billing, security, fraud prevention, product analytics, support, legal compliance, and enforcing our agreements.

Where external providers are used in a workflow, their role depends on the configuration and contractual setup. They may be IDEEVY subprocessors, Business Customer-selected providers, or independent service providers engaged by the Business Customer.

3. Personal data we process

Business Customer data

  • account and contact details, such as name, work email, company, role, and billing contact information;
  • dashboard user details, access permissions, support communications, and contract records;
  • technical metadata such as IP address, device data, browser data, API usage, authentication logs, and security logs;
  • provider workflow configuration, including routing rules, provider identifiers, provider account references, and integration settings; and
  • where enabled by the Business Customer, provider credentials or secrets required to connect to a customer-selected external provider. Such credentials are protected and used only for the configured workflow.

End User verification data

  • identity document images or files submitted for verification;
  • document data extracted from submitted documents, such as name, date of birth, document number, issuing country, expiry date, document type, and machine-readable zone data where present;
  • document quality and authenticity signals, including image quality, tamper indicators, document consistency checks, expiry checks, and other document-level signals;
  • verification case data, workflow status, routing metadata, timestamps, and result metadata;
  • provider-level details returned by external providers when a workflow uses them and when such details are needed for the configured service;
  • webhook delivery logs and API request metadata used to deliver and troubleshoot verification outcomes; and
  • other information submitted by the Business Customer as part of a verification case.

IDEEVY is designed as a document-first verification service. Unless separately agreed or configured, IDEEVY does not require selfie capture, liveness checks, face matching, facial recognition, or the creation of biometric templates as part of its standard service. If a Business Customer configures an external provider that offers additional checks, the scope of such checks must be covered by the Business Customer instructions, notices, and legal basis.

4. How we collect personal data

  • directly from Business Customers when they create accounts, configure workflows, use APIs, or contact support;
  • from Business Customer systems when they submit End User verification cases through the API or dashboard;
  • from external verification providers or customer-selected providers when a workflow routes a case through them; and
  • automatically through website, dashboard, API, security, and operational logs.

5. How we use personal data

  • to provide document verification and workflow orchestration services;
  • to run IDEEVY document checks and produce verification outcomes;
  • to route cases through configured providers, fallback paths, second-opinion checks, or customer-selected provider accounts;
  • to return unified results, verification statuses, provider-level details, and webhook updates to the Business Customer;
  • to operate the dashboard, APIs, billing, support, security, monitoring, and service administration;
  • to detect abuse, secure the platform, prevent unauthorized access, and maintain audit logs;
  • to improve, troubleshoot, and measure our services; and
  • to comply with applicable legal, regulatory, contractual, and dispute-resolution obligations.

6. External providers and customer-selected providers

IDEEVY workflows may involve external verification providers, compliance service providers, issuer or bank-related services, infrastructure providers, or other third-party services. The exact providers may vary by Business Customer configuration, country, document type, risk level, product, or contract.

Some external providers are engaged by IDEEVY as subprocessors. Others may be selected, contracted, or controlled by the Business Customer, including when the Business Customer supplies its own provider identifiers, API keys, credentials, or account configuration. In those cases, the provider may process personal data under the Business Customer relationship rather than as an IDEEVY subprocessor.

Business Customers are responsible for ensuring that they have the required rights, notices, consents, legal bases, and contractual arrangements for any external provider workflow they configure or instruct IDEEVY to use.

7. Legal bases where IDEEVY acts as controller

Where IDEEVY acts as a controller, we rely on legal bases such as performance of a contract, legitimate interests, consent where required, legal compliance, and establishment or defense of legal claims. Our legitimate interests include securing and operating the service, preventing misuse, communicating with customers, improving the product, and managing billing and business operations.

8. Cookies and analytics

We use cookies and similar technologies on the website and dashboard for essential functionality, security, analytics, and user preferences. We may use Google Analytics or similar analytics tools for website measurement where permitted. For more information, see the IDEEVY Cookie Policy.

9. International transfers

IDEEVY may process and transfer personal data internationally where necessary to provide the service, operate infrastructure, support customers, or route cases through configured workflows. We take reasonable steps to protect personal data during such transfers and use contractual, technical, and organizational safeguards where required.

Where a Business Customer configures a customer-selected external provider, the Business Customer is responsible for assessing and authorizing any transfer to that provider, including any country-specific requirements.

10. Retention

Unless a different retention period is agreed in writing, configured in the service, or required by law, IDEEVY may retain verification records for up to one year. Verification records may include document images, extracted data, IDEEVY check results, workflow metadata, routing logs, provider-level details, and webhook records.

Website, dashboard, billing, security, and support records may be retained for longer where needed for business records, security, audit, dispute resolution, legal compliance, or tax purposes.

11. Security

We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls, logging, monitoring, credential protection, and separation of customer configurations. No system can be guaranteed to be completely secure, but we work to maintain appropriate safeguards for the nature of the data and service.

12. Your rights and choices

Depending on applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of their personal data. Because the Business Customer is usually the controller for End User verification data, End Users should first contact the Business Customer that requested the verification.

If you cannot identify or reach the Business Customer, or if your request concerns IDEEVY processing as a controller, contact us at privacy@ideevy.com.

13. Children and minors

IDEEVY is a business service and is not directed to children. Business Customers must not submit documents or personal data relating to minors unless they have a valid legal basis, any required parental or guardian consent, and authority to use the relevant verification workflow.

14. Changes to this Policy

We may update this Policy from time to time. The updated version will be indicated by the effective date above. Material changes may be communicated through the website, dashboard, email, or other appropriate channels.

15. Contact

For privacy questions, contact privacy@ideevy.com. For legal matters, contact legal@ideevy.com. For general support, contact support@ideevy.com.

← Back to home