Zyphe Inc. ("Zyphe," "we," "us") builds compliance infrastructure that lets regulated companies complete KYC, KYB, and AML work without holding their customers' personal data in a central store. This policy explains what personal data we hold, why, on what legal basis, how long we keep it, and who else sees it. It covers this website and the Zyphe platform.
Where this policy makes a commitment we cannot keep, we would rather say nothing. If you find a statement here that does not match what you observe, write to privacy@zyphe.com and we will correct it.
The two roles we play
Almost every question about your data depends on which of two roles we are in, so this is the first thing to establish.
- Zyphe as controller. When you visit this website, submit a form, download a guide, book a demo, or apply for a job, Zyphe decides why and how your data is processed. We are the controller, and the rest of this policy applies to us directly.
- Zyphe as processor. When a bank, exchange, or other regulated company uses Zyphe to verify you, that company is the controller. It decides that a check is required, what the outcome means, and how long any record must be kept under anti-money-laundering law. Zyphe acts on its documented instructions. In that role, your rights are exercised against that company first, and we support it in answering you. If you are unsure who asked for your verification, we can tell you.
What we collect as controller, and why
This table covers the website and our commercial and hiring activity. Each row gives the legal basis under the GDPR and how long we keep the data.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, work email, phone number, company, website, and the content of your message. Submitted through the contact, demo, guide download, and readiness quiz forms. | Answering your enquiry, running a demo, sending the document you asked for, and following up commercially. | Performance of a contract or steps taken at your request (GDPR Art. 6(1)(b)), and our legitimate interest in responding to business enquiries (Art. 6(1)(f)). Marketing email is sent on consent (Art. 6(1)(a)) where you ticked the marketing box. | 24 months after our last contact with you, then deleted from the CRM. |
| The IP address the form was submitted from, and the UTM parameters and referring page recorded when you first arrived on the site. | Rate limiting and spam filtering on the submission endpoint, and attributing the enquiry to a marketing channel. | Legitimate interest in keeping the endpoint usable and in understanding which channels produce enquiries (Art. 6(1)(f)). | IP addresses used for rate limiting are held in memory for one minute. The attribution recorded against a lead follows the lead retention above. |
| Name, surname, email, and LinkedIn profile URL submitted through the careers form, plus anything you send us during a hiring process. | Assessing your application and communicating with you about it. | Steps taken at your request prior to entering a contract (Art. 6(1)(b)), and legitimate interest in running a hiring process (Art. 6(1)(f)). | 12 months after the process closes, unless you ask us to keep your details on file for future roles. |
| Pages viewed, clicks, scroll depth, session recordings, device and browser type, approximate location derived from IP, and, where you have accepted marketing cookies, the company or contact record matched to your visit. | Understanding how the site is used, measuring advertising, and identifying which businesses are researching us. | Consent, given through the cookie banner (Art. 6(1)(a) and the ePrivacy Directive). Nothing in this row is collected before you accept the relevant category. | As configured in each platform listed under "Who receives your data". Withdrawing consent stops further collection. |
We do not buy contact lists, and we do not enrich your record with data bought from brokers. The one exception to "we only know what you tell us" is the visitor identification tool listed in the recipients table below, which runs only if you accept marketing cookies.
Identity verification data, processed for our clients
When you are verified through Zyphe on behalf of a regulated company, the data involved typically includes your identity document and the details printed on it, a facial image used to check that you are the person the document describes, and the contact details the company gave us to reach you.
Biometric data is special category data. A facial image used to identify you uniquely falls under Article 9 of the GDPR, and under California law it is sensitive personal information. It is processed on your explicit consent, collected at the point of verification, and only for the purpose of matching your face to your document. It is not used to train models, it is not reused for any other check, and it is not disclosed to anyone other than the company that asked for the verification.
Where it lives. Zyphe keeps no reconstructable copy of your identity record at rest. Identity data is encrypted and split into shards distributed across 60,000+ storage nodes, and reconstruction requires 29 of 100 shares, so no single node, operator, or jurisdiction holds a usable record. Shards are geo-locked, so an EU customer's data stays in the EU or EEA, a Swiss customer's stays in Switzerland, and a UK customer's stays onshore.
What this means for erasure. Because we hold no whole copy, an erasure request is executed by revoking access to the shards rather than by hunting through backups. There is no separate vendor retention copy on our side to chase. The regulated company that verified you may still be required by anti-money-laundering law to keep its own record of the check, typically for five years, and that obligation is theirs, not ours.
Automated decisions. Zyphe agents prepare a case and attach their reasoning. A named person at the regulated company approves it or sends it back. Agents do not make final KYC, KYB, or AML decisions. Article 18(3) of the EU anti-money-laundering regulation reserves six categories of decision to the obliged entity, including the customer risk profile and the decision to enter a business relationship, and Article 22 of the GDPR constrains decisions taken solely by automated means where they have legal or similarly significant effects. Human approval is therefore built into the product rather than offered as a setting.
Who receives your data
We do not sell personal data, and we do not pass it to anyone for their own independent purposes. We do use the service providers below, each under a contract that limits them to processing on our instructions. The advertising and analytics entries load only if you accept the matching cookie category.
| Recipient | What it does | Applies to |
|---|---|---|
| Google (Analytics 4, Tag Manager, Google Ads) | Website analytics and advertising measurement | Statistics and marketing cookies |
| Microsoft Clarity | Session recording and heatmaps. Not loaded on the careers area. | Statistics cookies |
| PostHog | Product and website analytics | Statistics cookies |
| Meta | Advertising pixel and conversion measurement | Marketing cookies |
| LemReveal | Matches website visits to business contact records | Marketing cookies |
| HubSpot | CRM. Holds enquiries, demo requests, and the resulting correspondence. | Form submissions |
| n8n (self-hosted by Zyphe) | Routes form submissions to the CRM and to our inboxes | Form submissions |
| Google Workspace | Email and document storage for the correspondence itself | Form submissions |
| Slack | Internal notification that a form was submitted, so the team sees it without delay. Carries the name, business email, company and any phone number you entered. | Form submissions |
| Cloudflare | Hosting, CDN, and edge security. Processes request IP addresses. | All visitors |
Two of these deserve to be named plainly rather than buried. We run an advertising pixel and conversion measurement, which means Meta and Google receive a signal when you visit certain pages or submit a form, and we run a visitor identification tool that attempts to match a visit to a business contact record. Both are gated on the marketing category in the cookie banner and neither loads if you decline. Under the California Consumer Privacy Act as amended, this kind of advertising activity may count as "sharing" personal information for cross-context behavioural advertising, so Californian residents can opt out of it, as described below.
If you are a business customer, our data processing agreement and the current sub-processor list are available on request at privacy@zyphe.com. We do not publish them, because they form part of a customer contract rather than a notice to the public.
Beyond these providers, we disclose personal data only where the law requires it, for example a court order or a valid regulatory demand. Where we are permitted to tell you, we will, and we will disclose the minimum the demand requires.
International transfers
Zyphe Inc. is incorporated in Delaware, in the United States. Identity verification data stays in the region it was collected in, because residency is enforced by the storage layer rather than by configuration, so verification does not normally involve a cross-border transfer of your identity record.
Website, lead, and hiring data is a different matter and we will not pretend otherwise. Our CRM, email, analytics, and advertising providers are predominantly United States companies, so if you contact us from the EEA, the UK, or Switzerland, your enquiry is transferred to the United States. Those transfers rely on the European Commission's Standard Contractual Clauses, on the UK Addendum where the UK GDPR applies, and, where a provider is certified, on the EU-US Data Privacy Framework. You can ask us which mechanism covers a specific provider.
How we protect data
- Encryption. Personal data is encrypted in transit and at rest with AES-GCM-256. Zyphe operates no master key and no backdoor that would decrypt a full identity record.
- No central store to breach. Identity data is sharded and geo-locked as described above, so there is no single database holding whole records.
- Access control. Role-based access control and strict authentication on every system interaction. Zyphe employees and contractors have no direct access to customer personal data.
- Assurance. SOC 2 Type II audit in progress: Type I is targeted for October 2026, with the Type II observation period beginning Q1 2027. ISO/IEC 27001 certification in progress: Stage 1 is targeted for October 2026 and Stage 2 for November to December 2026. Neither is certified today. For the current status of either audit, contact privacy@zyphe.com.
- Monitoring and testing. Firewalls, intrusion detection, continuous network monitoring, secure coding practices, and regular penetration testing.
- Incidents. A documented incident response plan, with notification to supervisory authorities and affected individuals as required by law.
Your rights in the EEA, the UK, and Switzerland
You have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent at any time where consent is the basis we rely on. Withdrawing consent does not affect processing that already happened.
Where we rely on legitimate interest, you can object, and we will stop unless we can show compelling grounds that override your interests. You can object to direct marketing at any time and we will stop without qualification.
Write to privacy@zyphe.com. We answer within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. We may need to confirm your identity before acting, and we will ask for the minimum needed to do so.
If you were verified through Zyphe on behalf of another company, send your request to that company. It is the controller. Tell us as well and we will make sure it reaches them.
You can lodge a complaint with your national supervisory authority at any time. We would appreciate the chance to fix the problem first, but that is your right and it does not depend on contacting us.
Your rights in the United States
If you live in California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, you have the right to know what personal information we have collected, to obtain a copy of it, to correct it, to delete it, to limit our use of sensitive personal information, and to opt out of targeted advertising and of the sale or sharing of personal information. We will not treat you differently for exercising any of these rights.
We do not sell personal information for money. We do run advertising and visitor identification tools that may count as "sharing" for cross-context behavioural advertising under California law. To opt out, decline or turn off the marketing category in our cookie banner. We also honour the Global Privacy Control signal, so if your browser sends one, we treat it as an opt-out without any further step from you.
Requests can be sent to privacy@zyphe.com. We confirm receipt within 10 business days and answer within 45 calendar days. If a request is complex we may take a further 45 days, and we will tell you why before the first period runs out. An authorised agent may act for you with written proof.
Cookies
Essential cookies keep the site working and are always on. Statistics and marketing cookies are off until you accept them, and nothing in those two categories loads first and asks later. You can change your choice at any time through the cookie settings link in the footer, which reopens the same panel you saw on your first visit. Our Cookies Policy lists what each category loads and how long each cookie lasts.
Children
This website and the Zyphe platform are for business use by adults. We do not knowingly collect personal data from children. If you believe a child has given us data, write to us and we will delete it.
Contact
Privacy questions, rights requests, and complaints: privacy@zyphe.com.
Zyphe Inc. is registered in Delaware, United States, at 2140 S Dupont Hwy, Camden, DE 19934. That is our registered office address; post reaches us but email is faster.
Changes to this policy
We update this policy when what we do changes, and the date at the top tells you when it last happened. If a change materially affects how we use data you have already given us, we will tell you before it takes effect, by email where we have your address and on this site otherwise. Material changes to processing based on your consent will be put to you as a fresh choice rather than announced.