Privacy Policy
Last updated: June 27, 2026
This Privacy Policy explains how HaloKYC collects, uses, stores, shares, and protects personal data when you visit our website, contact us, create an account, use our dashboard, integrate our API, or complete an identity verification flow powered by HaloKYC.
HaloKYC provides identity verification, liveness detection, face matching, document OCR, duplicate detection, risk scoring, manual review, and related compliance tools for businesses.
When an end user completes verification for one of our customers, that customer usually decides why verification is required and how the result is used. In those cases, HaloKYC acts as a processor or service provider. For our own website, business operations, security, fraud prevention, billing, and support activities, HaloKYC may act as a controller.
Note: This Privacy Policy is not legal advice. It should be reviewed with a qualified lawyer before publishing.
1. Who we are
Company name: [Insert Legal Entity Name]
Registered address: [Insert Address]
Email: privacy@halokyc.com
Security contact: security@halokyc.com
General contact: hello@halokyc.com
2. Scope and our role
This Privacy Policy applies when you visit our website, request a demo, manage a business account, use our API, or complete an identity verification flow powered by HaloKYC.
| Context | Role | Meaning |
|---|---|---|
| Website, sales, billing, direct accounts | Controller | We decide why and how this data is processed. |
| Verification flows for customers | Processor | The customer decides why verification is needed. |
| Security, fraud prevention, audit logs | Independent Controller | Limited processing to protect the platform and comply with law. |
3. Personal data we process
3.1 Identity & Contact
Name, email, phone, DOB, address, nationality, and government ID information.
3.2 Business & Account
Company name, billing details, login credentials, API keys, and usage records.
3.3 Verification Data
ID document images, extracted OCR data, selfie images, and verification status.
3.4 Biometrics & Liveness
Face images, liveness frames, anti-spoofing signals, and face embeddings.
We also process device/network data (IP, browser) and communications (support tickets) as needed for platform security and operation.
4. How we use personal data
- Provide and operate the HaloKYC website, dashboard, and API.
- Perform identity document OCR, liveness checks, and face matching.
- Detect duplicate accounts and prevent fraud, spoofing, and identity theft.
- Secure our platform and monitor system integrity.
- Comply with legal, regulatory, tax, and security obligations.
- Improve verification accuracy using anonymized or pseudonymized data.
5. Legal bases for processing
- Contract: To provide requested services.
- Consent: For biometric processing and non-essential cookies.
- Legitimate Interests: Platform security, fraud prevention, and reliability.
- Legal Obligation: Compliance with applicable laws and audits.
6. How we share personal data
We may share data with the customer requesting verification, trusted infrastructure providers, professional advisers, and public authorities when required by law.
We do not sell biometric identifiers or biometric information.
7. International transfers
HaloKYC may process data in countries other than where it was collected. We use appropriate safeguards, such as standard contractual clauses, to ensure lawful transfers.
8. Retention
We retain personal data only as long as reasonably necessary.
| Data Type | Retention Period |
|---|---|
| Session Metadata | Until account closure or customer deletion. |
| ID & Selfie Media | 30 days by default (configurable). |
| Face Embeddings | Until duplicate detection is no longer required. |
| Audit Logs | 1 to 7 years based on compliance needs. |
9. User rights
Depending on your location (GDPR, CCPA, DPDP), you may have rights to access, correct, or delete your data.
If you verified via a business, contact that business first. For HaloKYC-direct requests, email privacy@halokyc.com, or use the privacy dashboard to track an active DSR.
10. Cookies
We use essential cookies for security and session management. Non-essential cookies (analytics) require your explicit opt-in via our consent banner.
11. AI & Model Improvement
We may use anonymized or pseudonymized data to improve OCR, liveness, and fraud detection. We do not use identifiable biometric data for advertising.
To opt-out of future model-improvement datasets, contact privacy@halokyc.com.
12. Security
We employ encryption in transit and at rest, role-based access controls, and rigorous audit logging to protect your data.
13. Children
HaloKYC is not for general use by children. Customers performing age verification are responsible for obtaining necessary parental consent.
14. Customer Responsibilities
Customers must provide their own privacy notices to end users, obtain required consents, and use verification results lawfully.
15. Changes
We may update this policy periodically. The “Last updated” date at the top reflects the most recent change.
16. Contact
Privacy
privacy@halokyc.com
Security
security@halokyc.com
General
hello@halokyc.com