Data Privacy Statement  of Identomat Inc. v3.0

Last updated: 25 September 2026

‍

Version 3.0 · Effective 25 September 2026

This Privacy Policy explains how Identomat Inc. handles personal data. It has two parts, because we handle personal data in two different capacities.

     
  • Part A applies if you visit identomat.com, contact us, book a meeting, subscribe to our communications, chat with us, apply for a job with us, or otherwise deal with us as a business contact. In these situations we decide why and how your personal data is used, and we are the controller
  • Part B applies if your identity was verified through the Identomat platform because a bank, financial institution, or other organisation asked you to complete a verification, including through the Identomat mobile app. In these situations that organisation is the controller and we act only as its processor, on its instructions.

Part C sets out information that applies to both parts: security, children, changes to this Policy, and how to contact us.

‍

‍

Who we are

‍

Company: Identomat Inc., a corporation incorporated under the laws of the State of Delaware, United States of America
‍

Registered office: The Green, Ste A, Dover, Delaware 19901, USA (principal office and postal address: 60 Hazelwood Dr, Champaign, IL 61820, USA)
‍

Mailing address: 60 Hazelwood Dr, Champaign, IL 61820, USA
‍

Privacy contact: Data Protection Officer, legal@identomat.com

‍

‍

Part A: Website visitors, business contacts and applicants

‍

In everything described in Part A, Identomat Inc. is the controller.

‍

‍

A1. Personal data we collect

‍

Contact and business data
What it includes: Name, business email address, telephone number, employer, job title, country, and the content of your enquiry or message.
Where it comes from: You, via our contact form, meeting booking, chat widget, email, or events.

‍

Meeting and scheduling data
What it includes: Meeting date and time, time zone, attendees, agenda notes, calendar invitation data.
Where it comes from: You, via the scheduler embedded on our Request a Meeting page.

‍

Chat data
What it includes: Chat transcript, the page you were on, and any contact details you give us in chat.
Where it comes from: You, via the live chat widget.

‍

Marketing and engagement data
What it includes: Subscription status and preferences, whether you opened or clicked an email, content you downloaded, events you registered for.
Where it comes from: You, and our email and marketing tools.

‍

Technical and usage data
What it includes: IP address, approximate location derived from it, device type, operating system, browser type and version, referring URL, pages viewed, time and duration of visit, clicks and scrolling, and (where enabled and consented to) session replay and heatmap data.
Where it comes from: Collected automatically through cookies and similar technologies — see our Cookie Policy.

‍

Company identification data
What it includes: The organisation associated with your IP address, and publicly available information about that organisation such as sector, size and location.
Where it comes from: Leadinfo B.V., a B2B visitor identification provider, where you have consented to marketing technologies.

‍

Advertising data
What it includes: Identifiers and event data used to measure advertising campaigns and to build audiences.
Where it comes from: Google, Meta and LinkedIn advertising tools, where you have consented.

‍

Recruitment data
What it includes: CV, cover letter, work history, qualifications, references and interview notes.
Where it comes from: You, or a recruiter or job board acting for you.

We do not ask for, and do not want to receive, special category data (such as health, religious or political information) through our website. We do not collect biometric data through our website; there is no self-service identity verification demo on identomat.com.

‍

‍

A2. Why we use it, and our legal basis

‍

To respond to your enquiry, arrange and hold a meeting or demonstration, and prepare a quotation or proposal
Legal basis (GDPR Art. 6): Art. 6(1)(b) — steps prior to entering a contract; or Art. 6(1)(f) — legitimate interests where you contact us on behalf of an organisation.
Notes: Our interest is in responding to commercial enquiries about our products.

‍

To operate, secure and maintain the website, prevent abuse, and keep records of what we published and when
Legal basis (GDPR Art. 6): Art. 6(1)(f) — legitimate interests in the security and integrity of our own systems.
Notes: Strictly necessary cookies are used for this purpose and do not require consent.

‍

To measure and analyse how the website is used, including page views, traffic sources, heatmaps and A/B tests
Legal basis (GDPR Art. 6): Art. 6(1)(a) — your consent, given through our cookie banner.
Notes: You can withdraw consent at any time.

‍

To measure our advertising, build audiences and show ads to people who have visited our site
Legal basis (GDPR Art. 6): Art. 6(1)(a) — your consent, given through our cookie banner.
Notes: Includes Google Ads, Meta and LinkedIn tools.

‍

To identify the organisation a visitor is browsing from, so that we can direct our business development to relevant organisations
Legal basis (GDPR Art. 6): Art. 6(1)(a) — your consent, given through our cookie banner.
Notes: Carried out by Leadinfo using your IP address. This is not used to take any decision about you personally.

To send you information about our products, events and publications
Legal basis (GDPR Art. 6): Art. 6(1)(a) — your consent; or Art. 6(1)(f) where we contact a business address about products relevant to your professional role, in accordance with applicable marketing law.
Notes: Every message contains an unsubscribe link and we act on it promptly.

‍

To assess a job application
Legal basis (GDPR Art. 6): Art. 6(1)(b) and Art. 6(1)(f) — steps prior to an employment contract and our interest in recruiting suitable staff.

‍

To comply with law, respond to lawful requests, and establish, exercise or defend legal claims
Legal basis (GDPR Art. 6): Art. 6(1)(c) — legal obligation; Art. 6(1)(f) — legitimate interests in defending claims.

Where we rely on legitimate interests, we have considered the effect on you and concluded that the processing is limited, expected in a business-to-business context, and does not override your rights. You can ask us for our assessment.

We do not take decisions about you by automated means alone that produce legal effects for you or otherwise significantly affect you, and we do not profile you for that purpose, in connection with your use of our website.

‍

‍

A3. Who we share it with

‍

We do not sell your personal data. We share it with the following categories of recipients:

     
  • Service providers acting on our instructions, including our website hosting platform, our customer relationship management, form, scheduling, chat and analytics providers, our email and advertising platforms, and our consent management provider. Each is bound by a written contract that meets the requirements of GDPR Art. 28. The specific tools operating on our website, and the cookies they set, are listed in our Cookie Policy.
  • Advertising and analytics platforms that act as independent or joint controllers for some of their own purposes, in particular Google, Meta and LinkedIn. Where consent is required for those tools, they load only after you have given it.
  • Professional advisers — lawyers, auditors, accountants and insurers — where they need the information to advise us.
  • Authorities, courts and counterparties where we are required to disclose information by law, or where disclosure is necessary to establish, exercise or defend legal claims.
  • An acquirer or successor, if we are involved in a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality protection.
    ‍
    ‍

A4. International transfers

‍

Identomat Inc. is established in the United States, and some of the providers we use for our website and marketing are established in the United States. Personal data collected under Part A is therefore transferred outside the European Economic Area and the United Kingdom.

Where we transfer personal data out of the EEA or the UK, we rely on one or more of the following: the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum where UK data is involved; the recipient's certification under the EU–U.S. Data Privacy Framework and its UK Extension, where applicable; or your explicit consent. Copies of the relevant safeguards are available on request from legal@identomat.com.
‍

‍

A5. How long we keep it

‍

Enquiries, meeting records and correspondence that do not lead to a contract
Retention period: 24 months from our last substantive contact with you.
Then: Deleted.

‍

Records relating to a client relationship
Retention period: For the term of the agreement and 7 years afterwards.
Then: Deleted.

‍

Marketing subscription and engagement data
Retention period: 24 months from your last engagement, or until you unsubscribe or object, whichever is earlier.
Then: Deleted, except a minimal suppression record kept so that we do not contact you again.

‍

Chat transcripts
Retention period: 12 months.
Then: Deleted.

‍

Website analytics data
Retention period: As set out in our Cookie Policy; analytics event data is retained for no longer than 14 months.
Then: Deleted or aggregated so that it no longer relates to an identifiable person.

‍

Company identification data from Leadinfo
Retention period: For the period configured in that tool, and no longer than 12 months.
Then: Deleted.

‍

Recruitment data for unsuccessful applicants
Retention period: 6 months after the recruitment process closes, unless you agree to a longer period.
Then: Deleted.

‍

Records we must keep by law, and records relating to a dispute
Retention period: For the period required by law, or until the dispute and any appeal period ends.
Then: Deleted.

‍

‍

A6. Your rights

‍

Subject to the conditions and exceptions in applicable law, you have the right to:

     
  • be informed about how we use your personal data, which is the purpose of this Policy
  •  
  • access the personal data we hold about you and receive a copy of it;
  •  
  • have inaccurate or incomplete personal data corrected;
  •  
  • have your personal data erased where we no longer have a valid reason to keep it;
  •  
  • restrict how we use your personal data while a concern is resolved;
  •  
  • object to processing based on our legitimate interests, and to object at any time to direct marketing, which we will always act on;
  •  
  • receive your personal data in a portable format, where we process it by automated means on the basis of your consent or a contract;
  •  
  • withdraw your consent at any time, including your cookie consent, without affecting processing already carried out; and
  •  
  • not be subject to a decision based solely on automated processing that has legal effects for you.

To exercise any of these rights, email legal@identomat.com. We will respond within one month, and will tell you if we need longer because the request is complex. We may need to ask you for information to confirm your identity before we act. Exercising your rights is free of charge unless a request is manifestly unfounded or excessive.

‍

If you are unhappy with how we have handled your personal data you may complain to a supervisory authority. In the European Union you may complain to the authority in the country where you live or work; in the United Kingdom, to the Information Commissioner's Office; and in Georgia, to the Personal Data Protection Service. We would appreciate the chance to address your concern first.

‍

A7. Additional information for residents of United States states

‍

This section applies to residents of United States states with comprehensive privacy legislation, including California, and supplements Part A. In the twelve months before the date of this Policy we collected the categories of personal information described in section A1, for the purposes described in section A2, from the sources described in section A1, and disclosed them to the categories of recipients described in section A3.

‍

We do not sell personal information for money. Some of the advertising tools described in our Cookie Policy may constitute a "sale" or "sharing" of personal information for cross-context behavioural advertising under California law. Those tools operate only where you have consented through our cookie banner, and you can withdraw that consent at any time through the "Cookie settings" link in our website footer. We honour the Global Privacy Control signal. We do not knowingly collect or sell the personal information of anyone under 16.

‍

Where state law grants them, you also have the right to know, to delete, to correct, to opt out of targeted advertising, profiling and sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. You may exercise them by writing to legal@identomat.com, and you may use an authorised agent. If we deny a request you may appeal by replying to our decision.

‍

‍

Part B: Individuals verified through the Identomat platform

‍

In everything described in Part B, Identomat Inc. is a processor. The organisation that asked you to verify your identity is the controller.

‍

‍

B1. Our role

‍

Identomat provides an identity verification and compliance platform to banks, financial institutions, and other regulated and commercial organisations. When one of those organisations asks you to verify your identity, it decides that the verification will take place, decides what data is needed, and decides how long the results are kept. Under the GDPR it is the controller and we are its processor. We act only on its documented instructions, and we do not use the data for our own purposes.

This means that if you want to know why you were asked to verify your identity, to see the data recorded about you, or to have it corrected or deleted, you should contact that organisation. Its own privacy notice governs the processing. If you contact us directly we will not answer the request on our own account: we will refer you to the organisation and tell it about your request without undue delay, and in any event within two business days.

Where a client deploys the platform on its own premises, the entire platform runs inside that client's infrastructure and we neither receive nor have access to any personal data. In that deployment we supply licensed software only.

‍

‍

B2. What the platform processes

The data processed in a given verification depends on which modules the organisation has enabled and how it has configured its verification flow. It may include:

  • identification data — name, surname, personal identification number, date of birth, gender, nationality and the other information shown on your identity document;
  • document data — an image of your passport, identity card or other accepted document, its issuing authority, number, expiry date and security-feature check results, and, where the document supports it, data read from its contactless (NFC) chip;
  • biometric data — the biometric vector map derived from the images and short video frames of your face captured during the liveness check (the “selfie”), used to confirm that you are physically present and that you are the person shown in the document;
  • contact data — telephone number and email address, where one-time-password or link-based verification is enabled;
  • address data — residential address and any supporting document, where proof of address is enabled;
  • screening data — the results of sanctions, politically exposed person, adverse media and watchlist matching, which may include information relating to criminal convictions and offences;
  • business and beneficial ownership data, where business verification is enabled;
  • transaction data, where transaction monitoring is enabled;
  • audiovisual data — a recording of a video verification session, where the organisation enables recording; and
  • technical and session data — session identifier, timestamps, IP address, device and browser characteristics, geolocation where enabled, and an audit log of the actions and outcomes in the session.

    ‍

B3. Biometric data

‍

Biometric data is used to derive the characteristic points of your face, to compare them with the portrait in your identity document, and to determine that a live person is present rather than a photograph, mask, screen or deepfake.

In the platform's default configuration no persistent biometric template is created: the biometric vector map is generated for that one-to-one comparison and liveness determination and is deleted as soon as the similarity score has been produced; it is not stored. The facial images and any liveness video captured during the session are stored with the session record for the period described in section B6. Where the organisation (the controller) expressly enables one-to-many matching — a face database used to detect duplicate or previously rejected applications — a template may be created and kept in that organisation’s own database for the period that organisation configures, and it remains responsible for the lawfulness of that additional processing and for telling you about it. In every configuration the system is designed so that raw biometric data cannot be reconstructed from the other information recorded, consistent with ISO/IEC 24745:2022.

We use your biometric data and facial images only for the verification requested by the organisation. We never use them for advertising, marketing or data mining, to track you or to build a profile of you, or to create, train, test or improve any facial recognition algorithm or other model, and we never sell, rent or trade them.

The legal basis for processing your biometric data is determined by the organisation, not by us. In regulated-sector use it is usually a legal obligation under Art. 6(1)(c) read with Art. 9(2)(g) of the GDPR and the national law implementing it; otherwise the organisation must obtain your explicit consent under Art. 9(2)(a) or rely on another Art. 9(2) exemption.

‍

‍

B4. Automated processing and human review

‍

The platform returns a verification outcome — approved, rejected, or referred for manual check — together with the underlying evidence. The decision whether to accept you as a customer is taken by the organisation, not by us. Where that organisation's process would otherwise produce a decision based solely on automated processing with legal or similarly significant effects for you, the platform can be configured to route the case to human review, and manual-check and video verification workflows exist for that purpose.

Several components of the platform — document reading and authenticity analysis, face similarity, and liveness and presentation attack detection — are machine-learning systems and therefore artificial intelligence systems within the meaning of Regulation (EU) 2024/1689 (the AI Act). Identomat is the provider of that system and has assessed it against the obligations applying to high-risk AI systems, which, following Regulation (EU) 2026/1744, apply from 2 December 2027. The organisation deploying the platform is responsible for the deployer obligations, including assigning competent human oversight and informing you that a high-risk AI system is being used.

‍

‍

B5. Sub-processors and international transfers

‍

In the cloud deployment the platform is hosted within the European Economic Area. We engage the following sub-processors, and we will not add or replace a sub-processor without first notifying our client and giving it the opportunity to object:

‍

Amazon Web Services EMEA SARL
Establishment: 38 Avenue John F. Kennedy, L-1855, Luxembourg
Processing location: Frankfurt, Germany (EU)
Role: Hosting of the platform and of the data processed in it.

‍

Google Cloud EMEA Limited
Establishment: 70 Sir John Rogerson's Quay, Dublin 2, Ireland
Processing location: Frankfurt, Germany (EU)
Role: Backup, restore and disaster recovery for the above.

‍

Cloudflare, Inc.
Establishment: 101 Townsend Street, San Francisco, CA 94107, USA
Processing location: Global edge network Role: Network-layer protection: DNS, load balancing, DDoS mitigation, TLS termination and web application firewall. Processes connection and request metadata only. Cloud deployment only.

‍

Each sub-processor is bound by a written contract that requires it to protect personal data to at least the standard described in this Policy, to process it only on our instructions and to delete it when the service ends. No third-party artificial intelligence service receives verification data.

Where a client contracts an external data source directly — for example a government registry or a sanctions data provider — we transmit the query and return the result, and that provider is not our sub-processor. Where we contract such a source on the client's behalf, it is engaged as a sub-processor and is subject to the same notification and objection mechanism.

‍

Identomat Inc. is established in the United States. Where performance of a client agreement requires personal data originating in the EEA to be transferred to, or accessed from, a third country, that transfer takes place under the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 — Module Two, and Module Three for onward transfers — incorporated into the data processing agreement, supported by a transfer impact assessment and by the technical measures described in section C1. We maintain a documented procedure for handling requests from public authorities for access to personal data, under which we notify the client where lawfully permitted, provide only the minimum legally required, and challenge requests that appear unlawful or disproportionate. Clients that require personal data never to leave a defined territory are offered the on-premises deployment, in which no international transfer occurs.

‍

‍

B6. Retention and deletion

‍

The organisation that engaged us controls how long verification data is kept, within the term of its agreement with us, and can delete an individual session or a set of sessions at any time through the management console or the API. Deletion removes the session record together with all images and video associated with it. On termination of the agreement the data is returned to that organisation and then permanently deleted from our systems without the possibility of recovery, within five business days of the transfer being completed. We retain a security and audit log — session identifier, IP address and a record of the actions in the session, with no images, biometric data or document data — for three years after termination, for security and audit purposes.

If back-up is configured by the organisation (the client), deleted sessions remain only in encrypted backups until those backups are overwritten, within [X] days, and backups are used only to restore the platform after a failure.

‍

‍

B7. The Identomat mobile app

‍

The Identomat mobile app is one of the ways in which you can complete a verification that an organisation has requested. It has no account and no login. It opens a session only from the link, QR code or session code issued by the organisation, and then loads that organisation’s verification configuration.

The organisation, as controller, decides which steps the verification includes and configures the information you are given and any consent it asks you for, as required by the law that applies to it. The app presents those notices and consent requests as the organisation has configured them, before the steps to which they relate.

The app uses the camera only while a verification screen is open during a session you have started, to capture your identity document and your face as described in sections B2 and B3. Nothing is captured in the background. The images are sent directly to the platform over an encrypted connection; they are not saved to your photo library and are not kept on your device after the session.

Data captured through the app is processed in the same way, for the same purposes and for the same periods as any other verification on the platform, as described in sections B2 to B6. The app does not access your contacts, your photo library or your advertising identifier, and it does not track you across other apps or websites.

You can ask for your data, including your face data, to be accessed or deleted, and you can withdraw your consent, at any time. Contact the organisation that invited you, or write to us at legal@identomat.com with the name of that organisation and the date of your verification, and we will pass your request on as described in section B1.

Where Identomat itself invites you to a verification, for example for a product demonstration or a test of the app, Identomat is the controller of that session. The flow for those sessions shows a notice and asks for your explicit consent before your face is captured, and the session is deleted automatically after 2 days.

‍

‍

Part C: Information applying to both parts

‍

C1. Security

We maintain an information security management system aligned with ISO/IEC 27001 and ISO/IEC 27002, and we use ISO/IEC 27701 as our reference framework for privacy information management. Our controls have been independently examined and confirmed under a SOC 2 Type II attestation covering Security, Availability and Confidentiality, and the control environment is monitored continuously. Our measures include

     
  • encryption of personal data in transit using TLS 1.2 or TLS 1.3, with legacy protocol versions disabled, and at rest using AES-256, with encryption keys managed separately from the data and access to them restricted and logged
  • pseudonymisation of verification sessions through session tokens;
  • role-based access control on unique named credentials with multi-factor authentication, granted only where strictly necessary, disabled by default in the production environment, and logged;
  • logging and monitoring of access and of security-relevant events, with alerting;
  • backup, restore and disaster recovery arrangements, with data replicated to a geographically separate provider;
  • independent penetration testing at least annually, together with regular vulnerability scanning and security assessments;
  • hosting exclusively in data centres certified to ISO/IEC 27001 and SOC 2, with controlled access, surveillance and environmental protection; and
  • confidentiality obligations on all personnel and contractors with access to personal data, which survive the end of their engagement.

The liveness and presentation attack detection functions of the platform have been tested against ISO/IEC 30107-3 by iBeta Quality Assurance, an independent NVLAP-accredited laboratory, and found conformant at Level 1 and Level 2; renewed conformance testing is in progress. Our identity proofing service has been audited against the eIDAS framework and ETSI TS 119 461 and ETSI EN 319 401, and was certified by QSCert in November 2025. Our SOC 2 Type II report, penetration testing attestations and certification evidence are available to clients and prospective clients on request under a non-disclosure agreement.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal data breach occurs we will act without undue delay to contain and mitigate it. Where the breach affects personal data we process for a client, we will notify that client without undue delay after becoming aware of it, and in any event within 24 hours, with the information it needs to make its own notifications. Where we are the controller, we will notify the competent supervisory authority and, where required, affected individuals, in accordance with Arts. 33 and 34 of the GDPR.

‍

‍

C2. Children

‍

Our website is directed at businesses and professionals, and we do not knowingly collect personal data from children through it. Where the platform is used for age verification, that processing is carried out on the instructions of the organisation concerned, which is responsible for the lawfulness of processing children's data. If you believe a child has provided us with personal data, contact legal@identomat.com and we will delete it.

‍

‍

C3. Third-party websites

‍

Our website links to and embeds content from third parties, including documentation, interactive product tours, scheduling tools and social media. Those services have their own privacy notices, which we do not control and are not responsible for. Embedded tools that are not strictly necessary load only where you have consented.

‍

‍

C4. Changes to this Policy

‍

We may update this Policy to reflect changes in our practices, our technology or the law. The current version is always available at identomat.com/privacy-policy, with the version number and effective date shown at the top. Where a change materially affects how we use personal data for which we are the controller, we will give notice on the website and, where we hold your contact details and the change requires it, by email. Where a change concerns processing carried out for a client, we notify the client in accordance with our agreement with it. If new cookies or trackers are introduced in a category requiring consent, you will be asked for consent again.

‍

‍

C5. How to contact us

‍

For any privacy question, request or complaint:

Data Protection Officer: legal@identomat.com
Postal address: Identomat Inc., 60 Hazelwood Dr, Champaign, IL 61820, USA

Version history: v1.0 (Privacy Policy, 4 May 2020, "Raizomat" LLC) → v2.0 (Data Privacy Statement of Identomat Inc., 30 October 2024) → v3.0 (this document, 25 September 2026).

‍