Privacy Policy
Policy version 3.0 · in force from 15 August 2026
1. How this policy is arranged
Verifit answers one question on the record: was this person, this supplier or this document what it was presented to be, and can that be shown again afterwards. Every answer of that kind lives in a file. Rather than list headings in the usual order, this policy walks through a single file from the instruction that opens it to the destruction of its last exhibit, stating at each stage what personal data is involved, on what authority it is held, and who is permitted near it.
Read straight through, it gives the whole life of a case. Read out of sequence it still works, because the stages are numbered in the order they happen: intake at section 4, exhibits at section 5, examination at section 8, custody at section 10, weeding at section 13, disclosure at section 14. Material that Verifit keeps for its own account — server records, correspondence, applications for work — never enters a case file at all, and is set out separately at section 18.
Words used throughout. Verifit is VERIFIT LIMITED. The instructing customer is the organisation whose staff opened the file. The subject is the person a check concerns. An exhibit is an item of evidence held on the file: usually a document image, sometimes a screening result, sometimes a note of what a reviewer saw. Expressions such as personal data, controller, processor and special category data carry the meanings given to them by the UK General Data Protection Regulation and the Data Protection Act 2018.
2. The organisation that holds the file
VERIFIT LIMITED, registered in Northern Ireland with company number NI736605 and trading as Verifit, is the body answerable for everything described here. Correspondence about data protection reaches the accountable person at support@verifit.uk; putting Data protection in the subject line carries the message past general support triage. Letters may be sent to the registered office, marked for the attention of the data protection lead.
Responsibility for this subject rests with a named member of the senior team and is not contracted out. That person keeps the record of processing activities current, signs off impact assessments, approves each new supplier that will touch personal data, answers requests from individuals, and leads the response when something goes wrong.
Data Protection Officer. The question is assessed against Article 37 of the UK GDPR. Verifit is not a public authority; at its present scale its core activity involves neither the regular, systematic and large-scale observation of people nor Article 9 material handled at that volume, so the statutory trigger for appointing an officer has not been reached and no appointment has been made. That assessment is treated as live rather than settled: it is revisited each year, and whenever a materially larger customer or a materially different kind of processing arrives. If the trigger is reached, an officer will be appointed and their contact details published in this section.
Registration with the Commissioner. Verifit registers with the Information Commissioner's Office and pays the data protection fee set by the Data Protection (Charges and Information) Regulations 2018. The registration number is deliberately absent from this page, because a number transcribed into a web page can go stale without anyone noticing. It is supplied on request for a diligence questionnaire, and can be confirmed independently against the Commissioner's public register of fee payers.
3. Two capacities, one company
The same company handles two different classes of record, and the legal position is not the same for both.
For its own business records, Verifit settles the purpose and the method, and is therefore the controller. That covers everyone who visits the website, everyone who writes in, the account and sign-in records of administrators and named users at customer organisations, the contacts at Verifit's own suppliers and advisers, and applicants for work.
For the case files themselves, the instructing customer settles who is checked, why, by which route, and for how long the record survives. Verifit holds and works those files on that customer's documented instruction and is therefore the processor. The arrangement runs on a written data processing agreement carrying the terms Article 28(3) requires. It is offered to every business customer at contracting and can be obtained from support@verifit.uk. Where that agreement and this policy differ about file material, the agreement governs.
| Activity | Capacity | Who settles the purpose |
|---|---|---|
| Serving verifit.uk; blocking abuse, scraping and attack | Controller | Verifit |
| Enquiries, demonstrations and sales correspondence | Controller | Verifit |
| Account creation, authentication, administrator audit records | Controller | Verifit |
| Invoicing, credit control and statutory accounting | Controller | Verifit |
| Holding document images and other exhibits lodged on a file | Processor | The instructing customer |
| Running validation, screening and workflow across a file | Processor | The instructing customer |
| The in-file audit trail of who examined what, and when | Processor | The instructing customer |
| Supplier and counterparty diligence records | Processor | The instructing customer |
| Counts of feature use that carry no identifier | Controller | Verifit |
One boundary is worth stating plainly, because platforms of this kind often leave it vague: material lodged on a customer's files is not mined to build products, benchmarks, training sets or models. Where Verifit needs to understand how the platform is used, it counts events that carry no document content and no identifier for any subject.
4. Stage one — the instruction that opens a file
A file begins when a named user at a customer organisation opens a case and states what is to be established. Nothing is gathered speculatively. There is no standing pool of identity records waiting to be matched, and no data is acquired about anyone who has not been put forward by a customer for a stated reason.
The instruction itself records:
- which user opened the file, the organisation they act for, and the moment they did it;
- the class of check requested — Right to Work, identity, qualification, or supplier and counterparty diligence;
- the customer's own reference for the matter, with any deadline or review date attached to it; and
- the subject's name and, where the chosen route needs them, date of birth and a contact address to which the invitation to submit evidence is sent.
Where the subject supplies evidence directly, that invitation names the organisation that asked for the check, says what is needed, and points to that organisation's own privacy notice. Verifit takes no part in deciding whether a check should happen. That decision, and the duty to explain it to the subject, belong to the instructing customer.
Lawful basis at intake. For file material the lawful basis is the customer's, recorded in the customer's own notice. In employment checking it is most often the legal obligation at Article 6(1)(c), read with sections 15 to 25 of the Immigration, Asylum and Nationality Act 2006; in diligence on a supplier it is more often legitimate interests at Article 6(1)(f). Verifit's own lawful basis for operating the platform on that instruction is Article 6(1)(b), performance of its contract with the customer, together with Article 6(1)(f) for keeping the service secure and available. Lawful bases for records that fall outside a case file are tabulated at section 18.
5. Stage two — the exhibits lodged
What arrives on a file depends on the class of check. The categories below are exhaustive for the product as it stands.
| Class of exhibit | Typical contents | How it arrives |
|---|---|---|
| Identity document image | Passport page, national identity card, residence permit or driving licence: name, date of birth, nationality, document number, issuing authority, expiry date, photograph | Captured by the subject on their own device, uploaded by the customer, or captured in person by the customer |
| Right to Work evidence | A Home Office share code with the result of the online check, or a prescribed original document, together with any endorsement or restriction on the work permitted | Entered by the customer, or returned by the Home Office online service |
| Qualification and licence evidence | Certificate image, registration number, awarding or licensing body, date of award, expiry date | Uploaded by the subject or by the customer |
| Supplier and counterparty record | Registered company details, names of directors and beneficial owners, addresses, filings, and screening results the customer obtained elsewhere | Entered by the customer, or taken from public registers by the customer |
| Examination record | Machine signals raised, the reviewer's identity, timestamps, and the reason recorded for any override | Generated by the platform as work on the file proceeds |
| Correspondence on the file | Invitations, reminders and notes exchanged about the case | Generated by the platform or written by the customer |
Volume is bounded by the check. The platform asks for the fields a given route actually requires and stops there; it supports blurring of fields the check does not need before an image is stored; it indexes nothing the check does not use; and a new workspace opens on the shorter retention option rather than the longer one. Where a capability of that sort is still reaching general availability, the product and the customer documentation say so rather than implying it is already everywhere.
6. Restricted exhibits: nationality, status and Article 9 material
Right to Work checking exists because sections 15 to 25 of the Immigration, Asylum and Nationality Act 2006 make it unlawful to employ a person who lacks permission to do the work in question, and give an employer a statutory excuse against a civil penalty where a prescribed check was carried out properly. Files of that class necessarily carry nationality and immigration status.
Neither of those is, by itself, special category data within Article 9(1). Both sit close to it. Nationality is capable of revealing ethnic origin; a name or a document can imply religious affiliation; a photograph carries more than any check needs. The whole class is therefore treated as restricted: narrow access, encryption, an access record for every view, and the shortest retention the customer's configuration and the law between them allow.
Article 9 material is never a field the product asks for. It arrives incidentally, inside an image lodged for a different purpose, and it is neither extracted, nor indexed, nor put to use. The conditions relied on are these.
| Situation | Article 9(2) condition | Schedule 1 condition | Whose condition it is |
|---|---|---|---|
| Article 9 material incidentally present in a document lodged for an employment-related check | Article 9(2)(b) — obligations in the field of employment law | Schedule 1, Part 1, paragraph 1, which calls for an appropriate policy document | The instructing customer as controller; mirrored by Verifit as processor |
| Health information volunteered so that an adjustment can be made | Article 9(2)(b), or Article 9(2)(a) explicit consent outside an employment context | Schedule 1, Part 1, paragraph 1 where 9(2)(b) is relied on | Verifit as controller |
| Material needed to bring or defend a legal claim | Article 9(2)(f) | None required | Whichever party is controller for the claim |
| Any future capability that identifies a person from biometric measurement | Article 9(2)(a) — explicit consent | None required where consent is the condition | Taken from the individual at the point of use |
Where a Schedule 1 condition calls for one, an appropriate policy document is maintained under paragraph 5 of Part 4 of Schedule 1 to the Data Protection Act 2018. It explains how the Article 5 principles are satisfied for that processing and when the material is erased, and it is produced to the Commissioner on request and to customers during diligence.
Three limits on the product follow from all this, and they are limits on what the software does rather than promises about intention:
- No facial recognition, face matching or liveness-derived biometric template is produced from an image on file. Were such a capability built, biometric data used to identify a person uniquely would be Article 9 material: explicit consent would be taken separately at the point of use, refusable without the loss of any other part of the service, and withdrawable afterwards. It would not arrive switched on, and it would not be buried in a settings panel.
- Health, sex life, sexual orientation, political opinion, religious or philosophical belief and trade union membership are not fields in the product and are not requested at any point.
- Precise location, device contacts, microphone audio and advertising identifiers are outside what the apps read at all (section 21).
Where more than the check requires is lodged — a full medical certificate where a name page would have done — the instructing customer, as controller, should remove it, and Verifit will assist technically. A subject who believes an unnecessary sensitive document about them sits on a file should raise it with that organisation and may copy support@verifit.uk, and the matter will be put to the customer promptly.
7. Restricted exhibits: Article 10 criminal-offence material
Article 10 permits processing of data about convictions, offences and related security measures only under the control of official authority, or where domestic law authorises it with appropriate safeguards — which in the United Kingdom means meeting a condition in Part 1, 2 or 3 of Schedule 1 to the Data Protection Act 2018.
Criminal record checking is not a Verifit function. There is no connection to any criminal records service, and no registered-body status for DBS or AccessNI purposes. Material of that kind can nonetheless reach a file indirectly: a customer records the outcome of a sanctions, adverse-media or disqualified-director screening run elsewhere, or attaches a declaration a supplier made about itself.
Where that happens, the instructing customer is the controller and must hold both an Article 6 basis and a Schedule 1 condition — commonly paragraph 10 for preventing or detecting unlawful acts, paragraph 12 for regulatory requirements concerning unlawful acts and dishonesty, or paragraph 33 for legal claims, most of which call for an appropriate policy document of the customer's own. The data processing agreement asks customers to confirm that position before material of this class is lodged. Verifit applies the restricted-access and access-logging controls described at section 10, and puts the material to no purpose of its own.
8. Stage three — examination by machine and by examiner
Machine assistance on a file runs to: classification of the document type; optical character recognition of the printed fields; checksum and format validation of document numbers; arithmetic on expiry dates; tamper and image-quality signals; and flags raised where two things on the file fail to reconcile. Between them they cut down retyping and surface the obvious problems early. They assist. They do not adjudicate.
No outcome is produced by automated means alone. Every finding that bears on a person — pass, refer or fail — is confirmed by a human examiner at the instructing customer before it is recorded as final, so Article 22 is not engaged. A case cannot be closed on a machine signal by itself; the platform is built so that the attempt fails.
The examiner sees each signal beside the underlying exhibit and may accept it, override it, or escalate the case. An override cannot be saved without a recorded reason. The examiner's identity, the time, the signals shown and the decision all pass to the audit trail, so it stays possible to establish afterwards that a person made the call, and which person that was.
Were a capability ever built that could produce a solely automated decision with legal or similarly significant effect, it would not be enabled without a lawful basis under Article 22(2), a fresh impact assessment, and safeguards including human intervention, the right to put a point of view, and the right to contest the outcome. This section would carry that description before the capability went live, not afterwards.
Impact assessments and records. Processing identity documents at scale, in a context tied to employment and immigration status, is precisely the processing for which Article 35 expects an assessment. One is carried out before processing of that kind begins, covering its nature, scope, context and purposes, its necessity and proportionality, the risks to individuals and the measures that answer them. It is revisited when the product changes materially — a new document class, a new capture route, a new supplier, anything touching biometrics. Where a residual high risk could not be brought down, the Commissioner would be consulted under Article 36 before proceeding. Written records of processing activities are kept for both capacities as Article 30 requires, and are produced to the Commissioner on request.
9. Stage four — the finding, and disputing it
The finding is a short record: what was checked, against which evidence, by whom, when, with what result, and the review date for any time-limited permission. It is the artefact the customer relies on afterwards, and by design it outlives the exhibits themselves (section 13).
A subject who believes a finding about them is wrong takes it first to the organisation that ordered the check. That organisation is the controller: it owns the record and the decision made on it, must consider the challenge, and must correct inaccurate data without undue delay under Article 16. It can be asked to re-examine the file with a human, to explain what the finding rested on, and to attach a note of disagreement where the finding stands. The audit trail is built to carry that note. Where the organisation does not respond at all, a message to support@verifit.uk will be escalated to it, with technical assistance offered on the Verifit side.
10. Stage five — custody and security
Article 32 requires protection proportionate to the risk. The risk here is high, because the files hold identity documents. The measures below are the ones actually applied.
Technical.
- Traffic to the website, the platform and the apps travels over HTTPS with TLS 1.2 or above and HSTS set; service-to-service traffic inside the platform is encrypted as well.
- Databases, the object storage holding exhibits, and backups are encrypted where they rest.
- Production access is granted by role to the small number of people whose work requires it, protected by multi-factor authentication, reviewed on a schedule, and withdrawn on the day a person's need for it ends.
- Every view of an exhibit is written to an access record, so it can be established afterwards who opened what, and when.
- Exhibits are addressed by unguessable identifiers and served through short-lived signed links rather than from predictable public paths.
- Changes reach production through review and automated checks; dependencies are watched for known vulnerabilities and patched on a defined cycle.
- Backups are taken, encrypted, and restored in test rather than assumed to work.
Organisational. Confidentiality obligations in every contract of employment and engagement; data protection training before production access is granted, refreshed each year; a written incident procedure with a named lead (section 15); pre-engagement checks proportionate to the role for anyone who can reach production; assessment of every supplier before it touches personal data; and an equipment policy covering disk encryption, screen locks and remote wipe.
Nothing carried across a public network is beyond risk, and the paragraphs above describe measures rather than guarantees. Where a control is added or materially altered, the version line on this page moves with it.
11. Who is allowed near a file
Personal data is not sold, rented or traded. It reaches a third party only where a supplier is needed to run the service, where a professional adviser is engaged under a duty of confidence, or where the law compels disclosure (section 14).
| Recipient | Function | Material involved | Capacity | Where processed |
|---|---|---|---|---|
| Cloudflare, Inc. | Hosting, content delivery, DNS, denial-of-service protection, firewall and bot management, and storage for the platform | Connection records; account data; exhibits at rest | Sub-processor for file material; processor for Verifit's own records | Global edge network; platform storage pinned to the UK or EU |
| Apple Inc. and Apple Distribution International Ltd | App Store distribution, store billing for any in-app purchase, and crash diagnostics where the device owner has turned sharing on | Store account data held by Apple; diagnostics; subscription status | Independent controller for store account and payment data; processor for diagnostics passed on | Ireland, the United States and other Apple locations |
| Google LLC and Google Ireland Ltd | Google Play distribution, Play billing, Android crash and ANR reporting where enabled, and delivery of the typefaces the website loads | Store account data held by Google; diagnostics; subscription status; font request data | Independent controller for store account and payment data; processor for diagnostics passed on | Ireland, the United States and other Google locations |
| The business email provider | The support@verifit.uk mailbox, and transactional mail such as invitations, credential resets and expiry reminders | Correspondence; account addresses; the content of notifications | Processor | UK or EU where the provider offers regional processing |
| The payment processor, where Verifit invoices directly | Taking card payment for subscriptions not billed through a store | Billing contact, amount, payment status; card numbers are neither received nor stored | Independent controller, as a regulated payment service | UK or EU, with possible onward transfer inside the provider's group |
| Accountants, auditors, insurers and legal advisers | Statutory accounts, tax, insurance and legal advice | Accounting records; correspondence relevant to the matter | Independent controllers under professional duties, or processors, depending on the engagement | United Kingdom |
Where a recipient is described generically above — the email provider, the payment processor — the named entity appears in the sub-processor list issued with the data processing agreement, which is the authoritative and maintained version. A list that is kept current serves a customer better than a name printed here that quietly goes out of date.
Changing a sub-processor. Customers give general written authorisation for sub-processors to be engaged. At least 30 days before one is added or replaced, notice goes to the customer's nominated contact and the list is updated. A customer may object inside that window on reasonable data protection grounds; where the objection cannot be resolved, the affected part of the service may be ended without penalty and the unused prepaid balance returned. Each sub-processor is assessed before engagement, bound by contract to terms no less protective than these, and Verifit stays liable to the customer for what it does.
12. Files that cross a border
Exhibits are stored and worked in the United Kingdom by default and, where a provider cannot offer UK-only storage, within the UK or the European Economic Area. Some providers are headquartered elsewhere, and support, engineering or routing functions can involve access from, or transit through, other countries. Every international transfer runs on one of the mechanisms below, and which mechanism covers which transfer is recorded.
| Mechanism | When it is used | Example |
|---|---|---|
| UK adequacy regulations | The destination is a country the UK Government has found adequate, so no further instrument is needed | Material processed by the Irish entity of a provider |
| The UK Extension to the EU–US Data Privacy Framework | A recipient in the United States holds a current certification covering the data in question, verified before anything is sent | A United States provider whose certification has been checked that quarter |
| The International Data Transfer Agreement (IDTA) | Verifit contracts directly with a recipient outside the UK where neither adequacy nor a certification applies | An infrastructure or support supplier contracting on UK terms |
| The UK Addendum to the EU standard contractual clauses | The recipient's terms are built on the EU clauses, so the Addendum issued under section 119A of the Data Protection Act 2018 is added to them | A large international provider whose processing addendum incorporates the EU clauses |
| Article 49 derogations | Narrow and occasional cases only, such as a transfer necessary to bring or defend a legal claim; never for routine processing | Sending a file to overseas counsel in a dispute |
Where the IDTA or the Addendum is relied on, a transfer risk assessment is documented first: what is going, to whom, under which legal system, whether that system undermines the protection the instrument promises, and what supplementary measures — encryption on the wire and in storage, custody of the keys, tight access limits, a standing policy of challenging unlawful demands — restore protection to a standard essentially equivalent to the United Kingdom's. The assessment is repeated when the law or the provider changes. A copy of the instrument covering a particular transfer, with commercially confidential terms removed, is available from support@verifit.uk.
13. Stage six — weeding, destruction and account deletion
Nothing survives merely because its destruction was never scheduled. Where a period is fixed by law, the law is applied; where the period is a matter of judgement, one is set, the reasoning recorded, and the material destroyed on time.
| Record | Capacity | Period | Reasoning |
|---|---|---|---|
| Website connection and security records | Controller | A short rolling window set at the edge, ordinarily under thirty days | Long enough to investigate an attack, and no longer |
| Enquiries and general correspondence | Controller | Twenty-four months from the last exchange | Covers the natural life of a business conversation and its follow-up |
| Prospect and pipeline notes | Controller | Twenty-four months from last contact, then reviewed | Past that point the note is stale and no longer necessary |
| Platform account records | Controller | The life of the account, plus thirty days after a verified closure request | The window allows recovery from an accidental or disputed closure |
| Sign-in and security event records | Controller | Thirteen months | Permits year-on-year comparison during a security investigation |
| Administrative audit trail | Controller | The subscription term plus twelve months | Accountability for configuration changes after the relationship ends |
| Support tickets and correspondence | Controller | Twenty-four months from resolution | Recurrence analysis, and evidence of what was advised |
| Feature-use counts | Controller | Thirteen months at event level; identifier-free aggregates may be kept indefinitely | Seasonal comparison; aggregates are no longer personal data |
| Mobile crash and diagnostic reports | Controller | Twelve months | Long enough to fix a fault and confirm the fix across releases |
| Right to Work evidence | Processor | As configured by the customer; the statutory expectation is the duration of employment plus two years | Preserves the employer's statutory excuse under the Immigration, Asylum and Nationality Act 2006 |
| Other identity, qualification and diligence records | Processor | As configured by the customer for its own lawful purpose | The customer is the controller and sets the period against its own obligations |
| Document images on a file | Processor | The shorter of the customer's configured period and any earlier deletion instruction | Images are the most sensitive artefact and are held for the briefest period the purpose permits |
| The audit trail after images are destroyed | Processor | As configured by the customer; ordinarily kept once the images have gone | Evidence that a check happened, and by whom, without keeping the underlying image |
| File material after the contract ends | Processor | Deleted or returned at the customer's election, with a thirty-day export window unless immediate destruction is asked for | Required by Article 28(3)(g); the window prevents accidental loss of records the customer must keep |
| Invoicing and accounting records | Controller | Six years from the close of the financial year concerned | Companies Act 2006 and HMRC record-keeping requirements |
| Contracts, processing agreements and related correspondence | Controller | Six years from the close of the contract | The limitation period for contract claims in Northern Ireland |
| Unsuccessful applications for work | Controller | Twelve months | Answering questions about the decision; the discrimination claim window |
| Records of individual requests, and of incidents | Both | Three years for requests; incident records for as long as Article 33(5) requires | Demonstrating accountability to the Commissioner |
Account deletion. An administrator may close a platform account by writing to support@verifit.uk. Credentials stop working at once, and the account record itself goes thirty days later, which leaves room to reverse a closure made in error or under dispute. Removing a mobile app from a device clears what that device held and nothing further: the account, and any file already lodged, are untouched by it.
Backups. Taking a record out of the live system does not empty it from encrypted backups in the same moment. Backups roll off on a fixed cycle, and material deleted from live systems disappears as those backups expire, within ninety days in the ordinary course. A restored backup is re-processed so that deletions applied before the restore are applied again. A backup is never restored in order to bring back something a person asked to have destroyed.
14. Stage seven — disclosure outside the ordinary route
Occasionally something on a file is demanded by someone who is not a supplier and not the customer.
Legal compulsion. Where a court order, statutory notice, regulatory demand or law-enforcement request arrives, its validity and scope are examined before anything is handed over, and only what the instrument actually reaches is produced. Where the material belongs to a customer's file, the customer is told so that it can respond as controller and, where it prefers, deal with the requester directly — unless telling it is itself prohibited by law. Overbroad demands are pushed back on.
Corporate transactions. If the business or part of it were sold, merged or reorganised, records relating to the part transferred would pass to the successor under confidentiality, minimised or pseudonymised at the diligence stage, and customers would be notified as their processing agreement requires. A successor takes the obligations in this policy with the records.
15. When custody fails
The term for it is a personal data breach, and it covers any security failure that destroys, loses or alters personal data, or exposes it to somebody with no business seeing it — by accident as readily as by act.
Where the failure touches file material, Verifit acts as processor: the instructing customer is told without undue delay once the incident is confirmed, with whatever is known at that point, and the customer settles what to report and to whom. Where the failure touches Verifit's own records, Verifit is controller: notification goes to the Commissioner inside the 72-hour window Article 33 sets, counted from the moment awareness begins, unless the incident is unlikely to put anyone at risk. Where the risk to individuals is high, the people affected are told directly and in plain terms.
A notification carries what is known and says so where knowledge is incomplete: what happened, which categories and roughly how many people and records are involved, the likely consequences, the steps already taken to contain it, the steps recommended to those affected, and a point of contact. Later detail follows in stages rather than being held back until the picture is complete.
Every incident, including one judged not to be notifiable, is entered in an internal record with its facts, its effects and the remedial action taken, as Article 33(5) requires. Suspected security problems can be reported to support@verifit.uk; where a researcher reports in good faith, taking no data out and leaving the service running, the response will not be a legal one.
16. The person named in the file: rights
The UK GDPR gives individuals the following rights. Which organisation must answer depends on the capacity in section 3: for anything on a case file, the instructing customer is the controller and holds the duty; Verifit assists it, and a request sent to Verifit by mistake is passed on rather than ignored.
- Access — confirmation that data is held, a copy of it, and the surrounding detail this policy sets out.
- Rectification — correction of inaccurate data, and completion of data that is incomplete.
- Erasure — destruction where the purpose no longer needs the data, where consent has been withdrawn and nothing else holds it up, or where the processing was unlawful to begin with. It yields where a legal duty, or a claim being brought or defended, requires the record to stand.
- Restriction — a pause on processing while accuracy is contested or an objection is considered.
- Portability — for data processed by automated means on the strength of consent or a contract, a copy in a portable electronic form another system can read.
- Objection — to processing that rests on legitimate interests, which stops unless compelling grounds override the objection; an objection to direct marketing is absolute.
- Withdrawal of consent — at any time, where consent was the basis, without unpicking what was lawfully done before.
- Human intervention — the safeguards described at section 8 in relation to automated decision-making.
A request goes to support@verifit.uk with Rights request in the subject line. Enough information is needed to identify the records and to be satisfied the request comes from the person it concerns; proportionate proof of identity may be asked for, and no more than the situation warrants. The answer follows within one month, extendable by a further two months where the request is complex or several have been made at once, in which case the extension and its reason are explained inside the first month. Making a request costs nothing. A manifestly unfounded or excessive request may attract a reasonable fee or be refused, and the reasons for that, together with the route to complain, are given in writing.
17. Complaints, and the route to the ICO
A complaint about the handling of personal data should be sent to support@verifit.uk with Data protection complaint in the subject line. It goes to the accountable person named in section 2 rather than into a support queue, and the reply addresses what was raised rather than confirming receipt.
Anyone dissatisfied may complain to the supervisory authority, and there is no obligation to come here first. The authority for the United Kingdom is the Information Commissioner's Office:
Information Commissioner's Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
Telephone 0303 123 1113 · ico.org.uk
Where the complaint concerns a case file, the Commissioner will usually look to the instructing customer, since that organisation decided the check should happen. The right to a judicial remedy under Articles 79 and 82 sits alongside the right to complain and is unaffected by it.
18. Records kept outside any case file
Not every record Verifit holds belongs to a case. The categories below are held in the controller capacity, on Verifit's own decision, and none of them is placed on a customer's file.
| Whose data | What is held | Where it comes from | Purpose | Lawful basis |
|---|---|---|---|---|
| Website visitors | IP address, user agent, the page requested, referring page, response status, timestamp, country inferred from the address; the strictly necessary security cookies listed in the Cookie Policy | Recorded automatically at the edge when a browser asks for a page | Serving the site; detecting and blocking attack, scraping and abuse; diagnosing faults | Article 6(1)(f) legitimate interests — keeping the site available and free of abuse (section 19) |
| People who write in or ask for a demonstration | Name, work email, organisation, job title, what was asked, the correspondence itself and any notes taken | Given by the sender | Answering the enquiry and taking a business conversation forward | Article 6(1)(f) legitimate interests, or Article 6(1)(b) steps taken before a contract |
| Administrators and named users at customers | Name, work email, role and permissions, authentication data, sign-in times and addresses, actions taken in the administrative interface | Created by the customer, or by the user in use | Providing accounts, authenticating them, keeping the platform secure, and proving who changed a setting | Article 6(1)(b) contract with the organisation, and Article 6(1)(f) for security |
| Contacts at suppliers and advisers | Name, work contact details, role, correspondence, contract and payment records | Given by the supplier, or agreed in contracting | Managing the relationship, paying invoices, keeping statutory accounts | Article 6(1)(b), Article 6(1)(c) for accounting, and Article 6(1)(f) |
| Applicants for work | Application, CV, correspondence, interview notes, references where taken, right-to-work evidence for a successful candidate | Given by the applicant, or by a referee with the applicant's knowledge | Assessing the application and running the recruitment process | Article 6(1)(b) steps before a contract, Article 6(1)(f), and Article 6(1)(c) with Article 9(2)(b) for right-to-work evidence |
Retention for each of these appears in the table at section 13. The rights at section 16 apply to all of them, and for these records Verifit answers directly rather than passing the request on.
19. Legitimate interests, assessed
Where Article 6(1)(f) is relied on, the interest, its necessity and the balance against the individual are assessed and recorded before the processing starts. In summary:
- Security and abuse prevention. The interest is keeping a service that holds identity documents available and unbreached. Connection records are the minimum that makes attack visible; they are short-lived, are not used to build profiles, and no reasonable visitor expects a site of this kind to run without them.
- Answering enquiries. The interest is responding to a person who chose to make contact. Only what they sent is held, for a bounded period, and objection ends it.
- Account security and administrative audit. The interest is being able to show who changed what in a compliance system. Users are told this at account creation, and the alternative — an unaccountable audit trail — would defeat the purpose of the product.
- Business correspondence with organisations. The interest is contacting the person at a company whose role concerns verification. It runs to work contact details only, and stops on request.
The assessment for any of these is summarised on request at support@verifit.uk.
20. Young people named in a file
Verifit is a working tool for organisations. The website, the platform and the apps are not directed at children, and accounts are not knowingly created for anyone under 18.
There is one place a young person's data legitimately appears. An employer checking the right to work of a sixteen or seventeen year old worker processes data about a child, which is lawful and ordinary in employment. In that case the customer is the controller, every protection in this policy applies unchanged, and the customer is expected to have thought about how it explains the check in language a young person can follow.
Personal data is not knowingly collected from children under 13 for any purpose. If a child under 13 appears to have sent personal data directly, a message to support@verifit.uk will have it destroyed promptly.
21. The capture app: store obligations and device permissions
A Verifit capture app for iOS and Android is in development, so that a subject or a reviewer can photograph a document properly, with the quality checks running on the device itself before anything is sent. The commitments below are settled now, because they shape what is being built rather than describing it afterwards, and they govern the app from the day it reaches a store.
Permissions asked for. Camera access, to take the photograph; and, when it is wanted, access to one chosen item from the device's file picker so that an existing image can be lodged. Each prompt appears at the moment it is needed, with the reason stated beside it. Precise location, the contact list, the calendar, health data, microphone audio and the photo library taken as a whole sit outside what is read at all. Refusing a permission narrows the app to the routes that work without it.
What stays on the device. A capture waits in the app's private sandbox while the quality checks run, and goes once it has been lodged on a file or discarded. Session tokens live in the iOS Keychain, or in Keystore-backed storage on Android. Removing the app clears both, and clears nothing held on the server.
App Tracking Transparency. Apple obliges an app to seek permission through the App Tracking Transparency framework before it follows a person across the apps and websites of other companies, or reads the device's advertising identifier. Neither is part of this app. No advertising, attribution or analytics SDK is compiled into it, the advertising identifier is left alone, and no profile is assembled or passed on for advertising. With none of that happening, no ATT prompt is shown, because there would be nothing for it to ask about. Introducing anything of the sort would put the prompt first, and a refusal would cost the user nothing but the tracking.
Play Data Safety. The Google Play listing will carry a Data Safety declaration setting out what the Android app collects, for what, whether any of it is shared, whether it travels encrypted, and how its deletion is requested. That declaration and this policy are maintained as one statement: read together they describe the same handling, and neither is changed without the other. Apple's privacy labels on the App Store listing are kept on the same footing.
Store diagnostics. Where a device owner has switched on crash and diagnostic sharing at the operating-system level, Apple or Google may forward crash traces and performance data. These carry technical detail about the fault and the hardware rather than the contents of any file, are used to fix the fault, and are held for the period the table at section 13 gives.
22. Correspondence and marketing
Messages sent by Verifit fall into two classes. Service messages — invitations, credential resets, expiry reminders, notices about the platform and changes to these documents — go to the people who administer or use an account and are part of providing the service, so they continue for as long as the account does.
Marketing messages go to business contacts at organisations, under the Privacy and Electronic Communications Regulations 2003 and on the legitimate interests basis assessed at section 19. Every one of them carries an unsubscribe that works and is honoured promptly, and an objection made by reply is treated the same way. Contact lists are not bought, rented, sold or passed to anyone else for their own marketing, and no marketing message is sent to a subject because they appeared on a customer's file.
23. Amendments to this policy
This policy changes when the handling it describes changes — a new supplier, a new class of exhibit, a new transfer route, a new capability in the product. The version line above moves with each revision, and superseded versions are held and supplied on request so that a customer can see what was in force on a given date.
Where a change materially affects individuals, notice goes out before it takes effect: to customer administrators by email, and by a notice on this page. Where a change would broaden the purposes for which existing data is used, a fresh lawful basis is settled first, and consent is sought where consent is what the law requires.
24. Where to send a data protection message
One address carries all of it: support@verifit.uk. A subject line makes the routing quicker — Data protection, Rights request, Data protection complaint or Security report — and each of those reaches the accountable person described at section 2 rather than the general queue. Post may be addressed to VERIFIT LIMITED at its registered office in Northern Ireland, marked for the data protection lead.
Related documents: the Cookie Policy for what is written to a device, and the Terms of Use for the terms on which the website, the platform and the apps are used.