Free guide: How to use AI in compliance

GDPR

Identity verification under the GDPR, stated in the terms your DPO will check.

Where identity data is processed and stored, what Zyphe retains, how erasure works, how biometrics are treated, which transfer mechanism applies, and what stays with you as controller. Every statement here restates the data processing agreement or the privacy policy.

In one paragraph

Is Zyphe a GDPR-compliant identity verification provider?

Zyphe processes identity documents and biometrics transiently, then encrypts them with AES-256, splits them into shards and stores them in the end user's own vault rather than in a central database. Data belonging to EEA and UK end users is processed and stored on EEA and UK nodes and cloud regions; US end-user data stays in US regions. Zyphe retains verification results, audit logs and cryptographic proofs for the term of the agreement or as required by law, and holds no copy of the document or the face. Erasure is executed by revoking access to the shards. Biometric data is processed on explicit consent as special category data under Article 9, is not used to train models, and liveness and face matching run in-house rather than through a third-party biometric vendor. Verification data is processed under a data processing agreement that includes the Standard Contractual Clauses and the UK Addendum, with the sub-processor list in Annex III. Human approval of every KYC, KYB and AML decision is structural, in line with Article 22. Zyphe is not yet SOC 2 or ISO/IEC 27001 certified; both audits are in progress. No vendor makes a customer GDPR compliant on its own: the lawful basis for the check, the privacy notice to your customers and the retention of your own anti-money-laundering record remain yours as controller.

Certification statements on this page render from Zyphe's security and trust register, so when an audit completes this page changes with it. Data handling terms are in the privacy policy.

Roles

Who is controller and who is processor.

The answer differs for the two kinds of personal data Zyphe touches, and it is the first thing a data protection officer asks.

Verification data: you are controller, Zyphe is processor

When your business runs a KYC, KYB or AML check through Zyphe, the identity data belongs to your relationship with your customer. Zyphe processes it on your documented instructions under a data processing agreement, for the purpose of returning a verification result to you. The lawful basis for the check, the notice to the person being verified, and the retention of your own compliance record are decisions the agreement leaves with you.

Website, lead and hiring data: Zyphe is controller

Enquiries, demo bookings, downloads and job applications are Zyphe's own processing, described purpose by purpose with legal basis and retention in the privacy policy. Zyphe Inc. is incorporated in Delaware, and the CRM, email and analytics providers for that data are predominantly United States companies, so a contact from the EEA, the UK or Switzerland is transferred under the Standard Contractual Clauses, the UK Addendum where the UK GDPR applies, or the EU-US Data Privacy Framework where a provider is certified.

Due diligence

The ten questions a DPO asks an identity verification vendor.

Answered once, in the order they usually arrive. Hold any provider you are evaluating to the same ten.

  1. 01

    Where is identity data processed and stored?

    Regionally, following the end user's location. EEA and UK end-user data is processed and stored on EEA and UK nodes and cloud regions, and US end-user data in US regions. Residency is a property of where the encrypted shards live, enforced by the storage layer, rather than a per-market setting a customer configures and can get wrong.

  2. 02

    Does the vendor keep a copy of the document and the face?

    No. Documents and biometrics are processed transiently, encrypted with AES-256 and split into shards distributed across 60,000+ storage nodes. Reconstructing a record requires 29 of 100 shares, so no single node, operator or jurisdiction holds a usable copy, and Zyphe operates no master key that would decrypt one. There is no central database of identity records to breach because there is no database holding whole records.

  3. 03

    What is retained, and for how long?

    Verification results, audit logs and cryptographic proofs, for the term of the agreement or as required by law. Screening identifiers are kept only while ongoing monitoring is switched on for that customer. The identity documents and biometrics themselves are not held by Zyphe; they sit encrypted in the end user's vault.

  4. 04

    How is a right-to-erasure request executed?

    By revoking access to the shards, because the record is held by the data subject rather than duplicated onto Zyphe servers. A deletion request is checked against every recipient's retention obligations, access that is no longer needed is revoked at once, a daily job deletes data as obligations lapse, and the person receives a completion notice. There is no separate vendor retention copy to chase. The regulated company that ordered the check may still be required by anti-money-laundering law to keep its own record, typically for five years; that obligation is the controller's.

  5. 05

    How is biometric data treated under Article 9?

    A facial image used to identify a person uniquely is special category data. It is processed on the person's explicit consent, collected at the point of verification, used only to match the face to the document, not used to train models, not reused for any other check, and not disclosed to anyone other than the company that asked for the verification. Biometric data is destroyed within the limits set by BIPA and CUBI, as recorded in section 10.3 of the data processing agreement.

  6. 06

    Which sub-processors see the data?

    Fewer than a conventional stack. Liveness, face matching and injection-attack detection run in-house rather than through a third-party biometric vendor, which is one fewer sub-processor in your data map. The current list, including the register-data supplier used for business verification, is Annex III of the data processing agreement and is available on request.

  7. 07

    Are there international transfers of identity data?

    Not in the ordinary course. Identity verification data stays in the region it was collected in, so a verification does not normally involve a cross-border transfer of the identity record. Where a transfer mechanism is needed, the data processing agreement includes the Standard Contractual Clauses and the UK Addendum.

  8. 08

    Are decisions made solely by automated processing?

    No. Zyphe agents prepare each case as a decision-ready file with the reasoning attached, and a named member of your team approves it. Article 22 constrains decisions based solely on automated processing that produce legal or similarly significant effects on a person, and the EU anti-money laundering regulation, Article 18(3), reserves the customer risk profile, the decision to enter a business relationship and reporting to the FIU to the obliged entity. Human approval is structural, not a configurable option.

  9. 09

    What security measures apply under Article 32?

    Encryption in transit and at rest with AES-GCM-256, no master key, granular role-based access control with strict authentication on every system interaction, no direct employee or contractor access to customer personal data, firewalls, intrusion detection and continuous network monitoring, secure coding practices and regular penetration testing, and a documented incident response plan with notification as required by law. No breach of identity data has been reported; Zyphe maintains the industry KYC and IDV breach tracker and does not appear on it.

  10. 10

    Which certifications and audits back this up?

    SOC 2 Type II audit in progress: Type I is targeted for October 2026, with the Type II observation period beginning Q1 2027. ISO/IEC 27001 certification in progress: Stage 1 is targeted for October 2026 and Stage 2 for November to December 2026. Neither is certified today, and this page will change when that changes. GDPR-compliant data handling with regionalised storage applies now, and the operating model is aligned to the EU anti-money laundering regulation.

Your side of the line

What no identity verification vendor can take off your desk.

A page that implied otherwise would be the kind of overclaim a DPO discounts the whole page for.

The lawful basis and the notice

You decide the legal basis on which your customers are verified and you tell them, in your privacy notice, that a verification provider processes their document and face on your behalf. Zyphe processes on your instructions; it does not supply the basis.

Your own compliance record

Anti-money-laundering law requires the obliged entity to keep its record of the check, typically for five years. That record is yours, held on your side, and its retention is not shortened by Zyphe erasing the identity data it processed.

The risk decisions the law reserves for you

The customer risk profile, the decision to enter or end a business relationship, and any report to the financial intelligence unit stay with your MLRO. Zyphe returns a decision-ready file with the reasoning attached; a named person on your team approves it.

Your impact assessment, if one is required

Processing biometric data at scale is the kind of processing that can call for a data protection impact assessment. The answers on this page, the data processing agreement and its annexes are written to be pasted into one; ask privacy@zyphe.com for anything the assessment needs that is not here.

Documents

What you can ask for, and where.

The agreement and its annexes form part of a customer contract rather than a public notice, so they are provided on request rather than published.

Request any of these at privacy@zyphe.com.

  • Data processing agreement

    Annexes I to III: subject matter and duration, technical and organisational measures, sub-processor list. Includes the Standard Contractual Clauses and the UK Addendum.

  • Sub-processor list

    Annex III of the agreement, including the register-data supplier used for business verification.

  • Penetration test schedule and latest report

    Available to customers under NDA.

  • Certification status

    Current status of the SOC 2 and ISO/IEC 27001 audits and the control documentation behind them.

GDPR questions, answered

The questions procurement questionnaires and data protection reviews ask about an identity verification provider.

Zyphe processes identity documents and biometrics transiently and stores them encrypted in the end user's own vault rather than centrally, keeps EEA and UK end-user data in EEA and UK regions, retains only verification results, audit logs and cryptographic proofs, executes erasure by revoking access to the shards, and provides a data processing agreement with the Standard Contractual Clauses and the UK Addendum. It is not yet SOC 2 or ISO/IEC 27001 certified; both audits are in progress. The lawful basis for your checks and the retention of your own AML record remain your responsibility as controller.

Both, for different data. For identity verification run on behalf of a business customer, the customer is controller and Zyphe is processor under a data processing agreement. For its own website, lead and hiring data, Zyphe is controller, and the privacy policy sets out each purpose with its legal basis and retention period.

On EEA nodes and cloud regions. Residency is enforced at the storage layer: encrypted shards are geo-locked, so an EU customer's data stays in the EU or EEA, a Swiss customer's in Switzerland, and a UK customer's onshore, without the customer configuring residency per market.

No. The document and the live capture are processed transiently, then encrypted and stored in the individual's own vault. Zyphe retains the verification result, the audit log and the cryptographic proof, not a store of ID images or a database of faces.

Verification results, audit logs and cryptographic proofs are kept for the term of the agreement or as required by law, and screening identifiers only while ongoing monitoring is switched on. The identity documents and biometrics are not held by Zyphe.

No. Liveness detection, face matching and injection-attack detection run in-house, which is one fewer sub-processor in your data map. The full sub-processor list is Annex III of the data processing agreement.

No. It is processed on explicit consent, used only to match the face to the document, not reused for any other check, not disclosed to anyone other than the company that asked for the verification, and destroyed within the limits set by BIPA and CUBI as recorded in the data processing agreement.

Not in the ordinary course. Identity verification data stays in the region it was collected in. Where a mechanism is needed, the data processing agreement includes the Standard Contractual Clauses and the UK Addendum. Website and lead data is a different matter and is transferred to US providers under the Standard Contractual Clauses, the UK Addendum or the EU-US Data Privacy Framework, as set out in the privacy policy.

No vendor does. The lawful basis for verifying your customers, the privacy notice you give them, the retention of your own anti-money-laundering record and any data protection impact assessment remain yours as controller. What a provider can do is process on your instructions, keep the data where it should be, hold as little of it as possible, and put all of that in writing. That is what this page and the data processing agreement do.

privacy@zyphe.com for the data processing agreement, the sub-processor list, certification documentation and data subject rights requests. Rights requests are answered within one month, extendable by two further months for complex requests. General or commercial questions: hello@zyphe.com.

Book a demo

Bring your DPIA questions to the demo.

Book a demo and bring your data protection questionnaire. We will walk the data flow, the retention model and the approval boundary against your own controls.