In short
- Verification runs only when the sender turns it on for a document, and only after you agree.
- Your biometric data is used only to confirm that you are the person on the document.
- Biometric data is never sold, leased, or used for advertising.
- You can refuse, ask for another way to proceed, or ask for a human review of the result.
What this covers
Customers can add identity verification (KYC) to a document on any plan. When they do, the signer is asked to verify their identity before signing. The verification is performed by Didit (didit.me), our identity verification provider. This page is also our biometric data notice and retention policy.
Coverage
The KYC add-on supports:
- More than 230 countries and territories.
- More than 14,000 identity document types, including passports, national identity cards, driver’s licenses, and residence permits.
- Verification without a document, by checking the data you provide against official or authorized registries, in 36 countries today, including Colombia.
Roles
The customer who sends the document decides to use KYC and is the controller of the verification. Nubesti processes the verification for the customer under the data processing agreement, and Didit processes it as our subprocessor. The customer receives the result and decides what to do with it.
What is collected
Depending on the method, a verification can process:
- Images of the front and back of an identity document, and the data printed on it or stored in its chip, such as name, date of birth, nationality, document number, and expiry date.
- A selfie photo or short video.
- A facial template, which is a mathematical representation of facial features created from the selfie and the document photo, used to compare them.
- Liveness signals that show a real person is present, and device and network details such as IP address and browser.
- For verification without a document: the identifiers you enter, such as a national identity number, and the response from the registry.
- The result, such as approved, declined, or needs review, with the reasons and the time of the check.
Consent and legal basis
Before any capture begins, the signer sees a notice that explains the purpose, the provider, and the retention period, and must actively agree. Biometric data is processed only on the basis of that explicit consent, as required by article 9 of the GDPR and by biometric privacy laws such as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington biometric identifiers law and My Health My Data Act, and the Colorado Privacy Act.
You can refuse. If you do, the verification does not run, and you can ask the sender whether there is another way to proceed. The customer relies on its own legal basis, such as a contract, a legal obligation, or a legitimate interest in preventing fraud, for the rest of the verification data.
How the check works
The check is automated. It reads the document, confirms that it looks genuine, compares the selfie with the document photo, and checks liveness. For verification without a document, it compares your data with the registry. The customer sees the result and decides whether to continue. If the result affects you, you can ask the sender, or us, for a human review, give your point of view, and contest the decision.
Automated checks can make mistakes, for example with poor lighting, damaged documents, or changes in appearance. A declined check is not a finding that you acted dishonestly.
Use and disclosure limits
Biometric data is used only to verify that the signer is the person on the document or in the registry, for that document. Nubesti and Didit do not sell, lease, trade, or otherwise profit from biometric data. We do not use it for advertising, profiling, or training general-purpose models. We disclose it only to Didit to perform the check, to the customer as a verification result, or when a valid legal order requires it.
Retention and destruction
Verification data is kept only as long as needed:
| Data | Retention |
|---|---|
| Facial template and liveness signals | Deleted as soon as the verification result is produced |
| Document images and selfie | The period the customer sets, which by default is 30 days after the check, and never longer than the law allows |
| Verification result and summary | Kept with the signature evidence for as long as the customer keeps the document |
| Registry check response | Kept with the result, without the full registry record |
In every case, biometric identifiers are permanently destroyed when the purpose of the verification has been met, or within three years of the signer’s last interaction with the customer, whichever comes first, unless a longer period is required by law or by a valid warrant or subpoena.
Security
Verification data is encrypted in transit and at rest, access is restricted to the people and systems that need it, and access is logged. We protect biometric data with the same care, or more, than we use for other confidential information.
Your rights
You can ask to access, correct, or delete verification data, and to withdraw consent for processing that has not yet happened. Because the customer is the controller, we may pass your request to the customer. Write to the sender of the document, or to [email protected] with the subject “KYC request”. The regional privacy rights page explains the rights that apply where you live.
Transfers and age
Didit and our other providers may process verification data outside your country, under the transfer safeguards described in the privacy policy. Identity verification is not intended for people under 18.