Skip to content
ProductSecurityPricingDevelopersContact
EN· English
  • EN · English
  • ES · Español
  • DE · Deutsch
  • FR · Français
  • IT · Italiano
  • PT · Português
Sign inStart free
ProductSecurityPricingDevelopersContactSign in
Home/Legal/Identity verification and biometrics

Privacy and data

Identity verification and biometrics

How the KYC add-on checks identity documents, selfies, and registries, and how biometric data is protected and deleted.

Updated September 22, 2026Effective September 22, 2026

On this page
  1. What this covers
  2. Coverage
  3. Roles
  4. What is collected
  5. Consent and legal basis
  6. How the check works
  7. Use and disclosure limits
  8. Retention and destruction
  9. Security
  10. Your rights
  11. Transfers and age

In short

  • Verification runs only when the sender turns it on for a document, and only after you agree.
  • Your biometric data is used only to confirm that you are the person on the document.
  • Biometric data is never sold, leased, or used for advertising.
  • You can refuse, ask for another way to proceed, or ask for a human review of the result.

01What this covers

Customers can add identity verification (KYC) to a document on any plan. When they do, the signer is asked to verify their identity before signing. The verification is performed by Didit (didit.me), our identity verification provider. This page is also our biometric data notice and retention policy.

02Coverage

The KYC add-on supports:

  • More than 230 countries and territories.
  • More than 14,000 identity document types, including passports, national identity cards, driver’s licenses, and residence permits.
  • Verification without a document, by checking the data you provide against official or authorized registries, in 36 countries today, including Colombia.

03Roles

The customer who sends the document decides to use KYC and is the controller of the verification. Nubesti processes the verification for the customer under the data processing agreement, and Didit processes it as our subprocessor. The customer receives the result and decides what to do with it.

04What is collected

Depending on the method, a verification can process:

  • Images of the front and back of an identity document, and the data printed on it or stored in its chip, such as name, date of birth, nationality, document number, and expiry date.
  • A selfie photo or short video.
  • A facial template, which is a mathematical representation of facial features created from the selfie and the document photo, used to compare them.
  • Liveness signals that show a real person is present, and device and network details such as IP address and browser.
  • For verification without a document: the identifiers you enter, such as a national identity number, and the response from the registry.
  • The result, such as approved, declined, or needs review, with the reasons and the time of the check.

05Consent and legal basis

Before any capture begins, the signer sees a notice that explains the purpose, the provider, and the retention period, and must actively agree. Biometric data is processed only on the basis of that explicit consent, as required by article 9 of the GDPR and by biometric privacy laws such as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington biometric identifiers law and My Health My Data Act, and the Colorado Privacy Act.

You can refuse. If you do, the verification does not run, and you can ask the sender whether there is another way to proceed. The customer relies on its own legal basis, such as a contract, a legal obligation, or a legitimate interest in preventing fraud, for the rest of the verification data.

06How the check works

The check is automated. It reads the document, confirms that it looks genuine, compares the selfie with the document photo, and checks liveness. For verification without a document, it compares your data with the registry. The customer sees the result and decides whether to continue. If the result affects you, you can ask the sender, or us, for a human review, give your point of view, and contest the decision.

Automated checks can make mistakes, for example with poor lighting, damaged documents, or changes in appearance. A declined check is not a finding that you acted dishonestly.

07Use and disclosure limits

Biometric data is used only to verify that the signer is the person on the document or in the registry, for that document. Nubesti and Didit do not sell, lease, trade, or otherwise profit from biometric data. We do not use it for advertising, profiling, or training general-purpose models. We disclose it only to Didit to perform the check, to the customer as a verification result, or when a valid legal order requires it.

08Retention and destruction

Verification data is kept only as long as needed:

DataRetention
Facial template and liveness signalsDeleted as soon as the verification result is produced
Document images and selfieThe period the customer sets, which by default is 30 days after the check, and never longer than the law allows
Verification result and summaryKept with the signature evidence for as long as the customer keeps the document
Registry check responseKept with the result, without the full registry record

In every case, biometric identifiers are permanently destroyed when the purpose of the verification has been met, or within three years of the signer’s last interaction with the customer, whichever comes first, unless a longer period is required by law or by a valid warrant or subpoena.

09Security

Verification data is encrypted in transit and at rest, access is restricted to the people and systems that need it, and access is logged. We protect biometric data with the same care, or more, than we use for other confidential information.

10Your rights

You can ask to access, correct, or delete verification data, and to withdraw consent for processing that has not yet happened. Because the customer is the controller, we may pass your request to the customer. Write to the sender of the document, or to [email protected] with the subject “KYC request”. The regional privacy rights page explains the rights that apply where you live.

11Transfers and age

Didit and our other providers may process verification data outside your country, under the transfer safeguards described in the privacy policy. Identity verification is not intended for people under 18.

Questions about this policy go to [email protected].

Back to top

Related policies

Privacy Policy

What we collect for accounts, documents, signatures, add-ons, advertising, and support, and how to use your rights.

Cookie Policy

The cookies we use, why, for how long, and how to accept, reject, or change your choice at any time.

Mobile app data

The iOS and Android apps are planned and not yet a public download. They will follow these same policies.

Data processing agreement

The processor terms for documents and signer data, including the EU Standard Contractual Clauses. Ask if you need a signed copy.

Subprocessors

The companies that host the service, deliver messages, verify identity, take payment, and measure advertising.

Legal center

Terms, privacy, cookies, data processing, identity verification, and signature policies for inSigner, published by Nubesti LLC.

Your documents. Your signatures.
Your control.

A clear electronic signature service for sending, signing, sealing, and verifying important documents.

Start freeDocumentation

Evidence receipt

Agreement completed

Signer
Verified
Timestamp
Recorded
Document hash
7F3A…91C2

01Simple to start

02Unlimited documents

03Evidence-ready

Product

  • Features
  • Pricing
  • Templates
  • API and webhooks
  • Add-ons
  • Signature creator

Resources

  • Documentation
  • Changelog
  • Blog
  • FAQ
  • Help Center
  • Roadmap

Company

  • About inSigner
  • Contact
  • Security
  • Enterprise
  • Legal Center
  • Free signing

Popular Guides

  • Where inSigner is legal
  • E-signature legality
  • How to sign a PDF
  • Sign documents online

Compare inSigner

  • vs Documenso
  • vs DocuSign
  • vs PandaDoc
  • vs Adobe Sign
  • vs HelloSign
  • vs SignNow
  • vs Zoho Sign
  • vs YouSign
  • vs DocuSeal

Countries

  • Australia
  • United Kingdom
  • United States
  • Japan
  • European Union
  • Germany
  • France
  • Spain
  • Italy
  • See all countries
LegalPrivacy PolicyTerms of ServiceDisclaimerSecurityYour privacy choices

© 2026 inSigner. All rights reserved.

EN· English
  • EN · English
  • ES · Español
  • DE · Deutsch
  • FR · Français
  • IT · Italiano
  • PT · Português

Electronic signatures for teams everywhere.

Your privacy, your choice

We use strictly necessary cookies to run this site. With your permission, we also use analytics cookies to improve it and advertising cookies to measure our ads. You can change your choice at any time from Cookie settings in the footer. Read the cookie policy

Your browser sends a Global Privacy Control signal, so advertising stays off unless you turn it on here.

Cookie settings

Choose which optional cookies we may use. Strictly necessary cookies are always on because the site cannot work without them. Read the cookie policy

Your browser sends a Global Privacy Control signal, so advertising stays off unless you turn it on here.

  • Strictly necessary

    Security, bot protection, sign-in, signing sessions, and remembering this choice. Provided by inSigner and Cloudflare.

    Always on
  • Help us understand how the site is used so we can improve it. Provided by Google Analytics and Microsoft Clarity.

  • Measure our ads and show relevant ads on other sites. Provided by Google Ads, Microsoft Advertising, Meta, and TikTok.