Back to home
HaloKYC

Privacy Policy

Last updated: June 27, 2026

This Privacy Policy explains how HaloKYC collects, uses, stores, shares, and protects personal data when you visit our website, contact us, create an account, use our dashboard, integrate our API, or complete an identity verification flow powered by HaloKYC.

HaloKYC provides identity verification, liveness detection, face matching, document OCR, duplicate detection, risk scoring, manual review, and related compliance tools for businesses.

When an end user completes verification for one of our customers, that customer usually decides why verification is required and how the result is used. In those cases, HaloKYC acts as a processor or service provider. For our own website, business operations, security, fraud prevention, billing, and support activities, HaloKYC may act as a controller.

Note: This Privacy Policy is not legal advice. It should be reviewed with a qualified lawyer before publishing.

1. Who we are

Company name: [Insert Legal Entity Name]

Registered address: [Insert Address]

Email: privacy@halokyc.com

Security contact: security@halokyc.com

General contact: hello@halokyc.com

2. Scope and our role

This Privacy Policy applies when you visit our website, request a demo, manage a business account, use our API, or complete an identity verification flow powered by HaloKYC.

ContextRoleMeaning
Website, sales, billing, direct accountsControllerWe decide why and how this data is processed.
Verification flows for customersProcessorThe customer decides why verification is needed.
Security, fraud prevention, audit logsIndependent ControllerLimited processing to protect the platform and comply with law.

3. Personal data we process

3.1 Identity & Contact

Name, email, phone, DOB, address, nationality, and government ID information.

3.2 Business & Account

Company name, billing details, login credentials, API keys, and usage records.

3.3 Verification Data

ID document images, extracted OCR data, selfie images, and verification status.

3.4 Biometrics & Liveness

Face images, liveness frames, anti-spoofing signals, and face embeddings.

We also process device/network data (IP, browser) and communications (support tickets) as needed for platform security and operation.

4. How we use personal data

  • Provide and operate the HaloKYC website, dashboard, and API.
  • Perform identity document OCR, liveness checks, and face matching.
  • Detect duplicate accounts and prevent fraud, spoofing, and identity theft.
  • Secure our platform and monitor system integrity.
  • Comply with legal, regulatory, tax, and security obligations.
  • Improve verification accuracy using anonymized or pseudonymized data.

5. Legal bases for processing

  • Contract: To provide requested services.
  • Consent: For biometric processing and non-essential cookies.
  • Legitimate Interests: Platform security, fraud prevention, and reliability.
  • Legal Obligation: Compliance with applicable laws and audits.

6. How we share personal data

We may share data with the customer requesting verification, trusted infrastructure providers, professional advisers, and public authorities when required by law.

We do not sell biometric identifiers or biometric information.

7. International transfers

HaloKYC may process data in countries other than where it was collected. We use appropriate safeguards, such as standard contractual clauses, to ensure lawful transfers.

8. Retention

We retain personal data only as long as reasonably necessary.

Data TypeRetention Period
Session MetadataUntil account closure or customer deletion.
ID & Selfie Media30 days by default (configurable).
Face EmbeddingsUntil duplicate detection is no longer required.
Audit Logs1 to 7 years based on compliance needs.

9. User rights

Depending on your location (GDPR, CCPA, DPDP), you may have rights to access, correct, or delete your data.

If you verified via a business, contact that business first. For HaloKYC-direct requests, email privacy@halokyc.com, or use the privacy dashboard to track an active DSR.

10. Cookies

We use essential cookies for security and session management. Non-essential cookies (analytics) require your explicit opt-in via our consent banner.

11. AI & Model Improvement

We may use anonymized or pseudonymized data to improve OCR, liveness, and fraud detection. We do not use identifiable biometric data for advertising.

To opt-out of future model-improvement datasets, contact privacy@halokyc.com.

12. Security

We employ encryption in transit and at rest, role-based access controls, and rigorous audit logging to protect your data.

13. Children

HaloKYC is not for general use by children. Customers performing age verification are responsible for obtaining necessary parental consent.

14. Customer Responsibilities

Customers must provide their own privacy notices to end users, obtain required consents, and use verification results lawfully.

15. Changes

We may update this policy periodically. The “Last updated” date at the top reflects the most recent change.

16. Contact

Privacy

privacy@halokyc.com

Security

security@halokyc.com

General

hello@halokyc.com