Security & Data Retention
Effective date: June 19, 2026
This document summarizes IDEEVY security and retention practices for the Document Verification Hub.
Company: INTEGRITYTECH HK LIMITED
Website: ideevy.com
Company Registration No.: 3339122
Business Registration No.: 75921776
Registered Address: Room 905, Block 2, Cyberport, 100 Cyberport Road, Hong Kong
1. Overview
This Security and Data Retention document summarizes the technical, organizational, and retention practices IDEEVY applies to protect its Document Verification Hub, customer configurations, verification cases, provider workflows, and related records.
This document is informational and may be supplemented by contractual commitments in an order form, data processing addendum, or security schedule.
2. Security principles
- protect verification data throughout the verification workflow;
- limit access to authorized personnel and systems;
- secure API, dashboard, webhook, and provider integration paths;
- separate customer configurations, workflows, and data;
- log security-relevant activity and monitor for abuse; and
- retain data only for defined business, security, legal, or contractual purposes.
3. Data in transit and at rest
IDEEVY uses encrypted transport for API, dashboard, and webhook communications where technically supported. Stored data is protected using access controls and security measures appropriate to the data type and infrastructure. Business Customers are responsible for securing their own systems, API clients, webhook endpoints, and networks.
4. Access controls
Access to production systems, verification records, provider workflows, and support tools is restricted to authorized personnel or systems with a business need. IDEEVY uses authentication, access permissions, and operational controls to limit access.
Dashboard user access and permissions should be managed by the Business Customer. Business Customers should promptly remove access for personnel who no longer require it.
5. Provider credentials and workflow configuration
Where a Business Customer configures customer-selected provider accounts, IDEEVY may process provider identifiers, account references, API keys, secrets, or credentials needed to operate the configured workflow.
Such credentials are used only for the configured service purpose and should be rotated or revoked by the Business Customer when no longer required. Business Customers must not submit provider credentials unless they have authority to do so.
6. Logging, monitoring, and audit records
IDEEVY may maintain logs for API requests, dashboard events, workflow routing, provider interactions, webhook delivery, errors, security events, and operational troubleshooting. Logs help maintain service integrity, investigate incidents, and support customers.
7. Webhooks
Webhook delivery may include verification status, result metadata, and configured outcome details. Business Customers should use secure endpoints, authentication or signing mechanisms where available, TLS, and appropriate access controls for webhook receivers.
8. Data retention
- Verification records — up to 1 year unless otherwise agreed, configured, or required by law. This may include document images, extracted data, IDEEVY checks, provider-level details, workflow logs, and webhook records.
- Security and audit logs — retained as needed for security, investigation, service integrity, and legal purposes.
- Billing and contract records — retained as needed for accounting, tax, dispute, and legal purposes.
- Support records — retained as needed to provide support, maintain service history, and resolve disputes.
- Backups — retained and deleted according to backup cycles and operational safeguards.
Retention periods may vary based on configuration, contract, legal obligations, security requirements, or deletion requests.
9. Deletion and return
Business Customers may request deletion or return of personal data according to the agreement, dashboard capabilities, support processes, and applicable law. Some records may remain in backups, security logs, billing records, or legal archives for limited periods.
10. Incident response
IDEEVY maintains processes to identify, investigate, contain, and respond to security incidents. Where an incident affects personal data processed for a Business Customer, IDEEVY will notify the Business Customer according to the applicable agreement or data processing addendum.
11. Shared responsibility
Security is shared between IDEEVY and the Business Customer. IDEEVY secures the platform and service components under its control. The Business Customer secures its API keys, users, provider accounts, webhook endpoints, internal systems, legal basis, and workflow configuration.
