WebinarPix Fraud 2026: Are Your Fraud Controls Ready for the Next Generation of Instant Payment Scams?Explore Now WebinarPix Fraud 2026: Are Your Fraud Controls Ready for the Next Generation of Instant Payment Scams?Explore Now Pix Fraud 2026 — Are Your Fraud Controls Ready?Explore Gavel on AMLR rule bookAMLR applies 10 July 2027. See your stack against every obligationBook a Demo AMLR applies 10 July 2027. See your stack against every obligationBook A Demo AMLR applies 10 July 2027 — see your stackBook Demo Globe with pKYC, Onboarding, Screening and Transactions labelsShufti’s Glocal PlatformGlobal Coverage. Local Depth. Full Compliance Lifecycle.Explore More Global Coverage. Local Depth. Full Compliance Lifecycle.Explore More Glocal Platform — Global Coverage. Local Depth.Explore Shufti x ACFEWebinarAI has changed fraud. Now we need to change how we fight it.Microphone icon for Shufti and ACFE fraud webinar5th October, 2026Register Now Shufti x ACFEAI has changed fraud. Now we need to change how we fight it.5th October, 2026Register Now AI has changed fraud — change how we fight itRegister INNOVATION DROPSUMMER
EDITION
20
26
Qualified Electronic Signature
WATCH NOW
INNOVATION DROP - Qualified Electronic SignatureWatch Now Innovation Drop — Qualified Electronic SignatureWatch
INNOVATION DROPSUMMER
EDITION
20
26
Transaction Trust Monitoring
WATCH NOW
INNOVATION DROP - Transaction Trust MonitoringWatch Now Innovation Drop — Transaction Trust MonitoringWatch
INNOVATION DROPSUMMER
EDITION
20
26
Travel Rule Compliance
WATCH NOW
INNOVATION DROP - Travel Rule ComplianceWatch Now Innovation Drop — Travel Rule ComplianceWatch
Gavel on AMLR rule bookAMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027. Don't Wait for the Deadline to Find the GapsBook Consultation AMLR Applies 10 July 2027 — Find the GapsConsult Bank card and cashBank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification: Get Secure Payouts with Confirmed OwnershipSee How It Works Bank Account Verification — Secure PayoutsSee How Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance Ties Verified Location to a Verified IdentityBook A Demo Geo Compliance — Verified Location, Verified IdentityBook Demo Journey Builder dot gridConfigure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Configure Verification Flows as Per Your Needs with Journey BuilderSee How It Works Journey Builder — Configure Verification FlowsSee How Shufti MCP toggle with ChatGPT and ClaudeShufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP: Verification Tools, Ready to Use Inside Claude or ChatGPTExplore Agent Shufti MCP — Verification Tools Inside Claude or ChatGPTExplore

Shufti Pro Limited · Services Privacy Notice

Services Privacy Notice

Service Delivery (Processor) + Independent Controller Processing — for end-users being verified through Shufti, and for Client representatives using Shufti's back-office and APIs.

Version 1.2 Last updated September 2026 Contact [email protected]
Version1.2
Last UpdatedSeptember 2026
Notice TypeService Delivery — Processor & Independent Controller Processing

1.Scope and Who This Notice Is For

This notice applies to:

  • a) End-users / Users whose identity, documents, biometrics, AML status, device, or risk signals are processed through Shufti when using Shufti's services.
  • b) Client representatives and authorised users who use Shufti's back-office/API accounts, support channels and service administration functions.

This notice is separate from the Website & Business Interactions Privacy Notice (Website & Business Interactions). It focuses on service delivery and service-related controller processing.

2.Who We Are (and Why This Notice Matters Contractually)

Processor / Controller (depending on activity): Shufti Pro Limited ("Shufti", "we", "us", "our").

Agreement: Shufti's Terms state that the Terms, this Privacy Notice B and Sales Order(s) form the "Agreement."

Contact: [email protected] | [email protected]

DPO: [email protected]. The DPO operates independently and reports to the highest level of management in accordance with Article 38 UK GDPR.

3.Definitions (Plain Language)

Client: The organisation (e.g. bank/fintech/platform) that buys Shufti services and decides why and how end-user data is processed for onboarding/compliance/fraud purposes.

End-user / User: The person being verified or screened. Shufti's Terms call the personal information and proofs "User Information."

Processor: Processes personal data on behalf of a controller.

Controller: Decides purposes/means of processing. Shufti's Terms explicitly state the Client acts as controller of User Information and Shufti acts as processor to the extent Shufti processes on Client instructions.

4.Controller / Processor Roles

Shufti as Processor (Service Delivery for Clients)

For most identity verification, AML screening and related checks, Clients are controllers and Shufti is a processor that performs only those data processing activities that Clients request. Shufti's Terms state that Shufti processes User Information on the Client's documented instructions.

Shufti will not repurpose data received as a processor for independent controller purposes unless this is expressly agreed in writing with the relevant Client, supported by an appropriate lawful basis, and accompanied by transparency to the end-user through appropriate notice. Any such repurposing must be documented and disclosed to the Client in advance.

Shufti as Independent Controller (Improvement / Security)

Shufti may also act as an independent controller where processing is necessary for model training, fraud prevention, service security and product improvement, as Shufti's Terms explicitly state.

Independent controller processing for model training and fraud prevention is subject to the following limitations:

  • Only personal data strictly necessary for the defined improvement or security purpose is used. Shufti does not use broader datasets than required for the specified purpose.
  • Data used for model training or internal improvement purposes is pseudonymised or anonymised wherever technically and operationally feasible prior to use, and is not re-identified except where strictly necessary for quality control.
  • Biometric data used for algorithm training is maintained in segregated datasets, subject to enhanced access controls, with access limited to authorised personnel only and governed by documented access policies.
  • Retention of biometric training data is subject to documented limits (see Section 13). These limits are reviewed at each training cycle and enforced through technical controls.
  • Independent controller processing is subject to documented Legitimate Interest Assessments and, where biometric data is involved, to a dedicated Data Protection Impact Assessment (see Section 9).

Shufti as Independent Controller (Client Representatives and Authorised Users)

When Shufti processes personal data about Client representatives and authorised users, Shufti generally acts as an independent data controller because it decides how to use this data to set up, run, secure and support Client accounts and access to Shufti tools (including the Back Office).

4A.Separation of Processor and Controller Data Sets

Data processed by Shufti on behalf of Clients for service delivery purposes (processor data) is logically and operationally segregated from any datasets used by Shufti for its own controller purposes, including model training, fraud intelligence, and service improvement.

Shufti implements the following technical and organisational controls to maintain this separation:

  • Processor data and controller data are stored in separate logical data environments with distinct access controls. Personnel authorised to access processor data for service delivery purposes do not have unrestricted access to controller datasets used for internal purposes.
  • Data flows between processor and controller environments are governed by documented procedures and are subject to approval by the Data Protection team.
  • Where data is moved from a processor environment to a controller environment (e.g. for pseudonymised model training), this transfer is documented, subject to a written agreement with the relevant Client where required, and disclosed in this notice.
  • Automated controls are implemented to prevent processor data from being inadvertently included in controller datasets or used for purposes beyond those permitted by the Client's instructions.
  • The separation of datasets is reviewed as part of Shufti's annual DPIA and data governance review cycle.

5.What Personal Data We Process

A. Service Delivery and Service Operations

  • A1. Identity and Contact Data: Name, date of birth, email and/or phone number (as required by the Client's configured checks).
  • A2. Document Data: Images and/or videos of identity documents (passport/ID card/driving licence) and related proofs, plus extracted text via OCR when required.
  • A3. Biometric Data (Face / Liveness / Deepfake): Face images and/or videos and derived liveness/deepfake detection results.
  • A4. AML / Screening Data: Screening results and match signals (e.g. sanctions screening against regimes including UN/OFAC/EU/HMT and others). Processed only upon explicit client instructions; Shufti acts only as processor for this data.
  • A5. Device, Behavioural and Risk Data: Device fingerprint attributes such as screen resolution, browser settings and IP address to create a unique identifier (device fingerprinting) and multi-source risk inputs (email/phone/IP/location/transaction history) for risk assessment.
  • A6. SMS / OTP Authentication Data: Shufti may collect an end-user's mobile number to send SMS/OTP for authentication. That mobile information is not shared/sold/rented for marketing. Shufti acts as a processor for this data.

B. Data About Client Representatives / Authorised Users

  • B1. Identity and Contact Details: Full name, business email, business phone number.
  • B2. Organisation/Account Details: Company name, company website, country, verification volume, industry and other information required to set up and administer your account.
  • B3. Communications Data: Emails, messages, meeting notes, support queries and responses relating to account set-up, integration, service delivery, incident handling and commercial administration.
  • B4. Account and Security Data: User IDs, role/permission assignments, authentication logs (e.g. login history), IP addresses and device/security signals associated with account access.

6.Where We Get the Data

  • Directly from end-users when they submit data to Shufti's platform.
  • Via Clients when Clients collect proofs and pass them to Shufti via API/back office. This data is not used for service improvement and training purposes unless otherwise agreed with the client in writing. The necessary licences/consents are acquired by the client in this case.
  • From third-party sources used by Clients/Shufti features (e.g. watchlists/AML databases; eIDV doc-free checks which may involve national/private data sources) and from your device/browser during sessions. Shufti is only acting on the client's instructions as a processor for this data.

7.Why We Process the Data and Lawful Bases

Part 1 — Processing Where Shufti Is a Processor (Client-Controlled Purposes)

When Shufti acts as a processor, the Client (controller) determines and documents the lawful basis and provides privacy information to end-users. Typical controller lawful bases used by Clients include:

  • Legal obligation (e.g. regulated AML/KYC checks);
  • Contract (necessary to provide a service to the end-user);
  • Legitimate interests (fraud prevention / security), subject to balancing;
  • Consent, where the Client chooses consent as the lawful basis.

Shufti processes personal data on documented instructions of the Client unless required to do otherwise by law.

Part 2 — Processing Where Shufti Is an Independent Controller

Consent-based processing and legitimate interest-based processing are kept strictly separate. Shufti does not rely on consent and legitimate interests interchangeably for the same processing activity.

A. Service Delivery (Model Training, Fraud Prevention, Audit)

Lawful basis hierarchy applied:

  • Consent (Article 6(1)(a) UK GDPR): used only where consent is freely given, specific, informed and unambiguous, and is not bundled with or made a condition of access to the service. Where consent is relied upon, clear withdrawal mechanisms are provided.
  • Legitimate interests (Article 6(1)(f) UK GDPR): used for service security, verification efficiency, fraud prevention and model improvement, where consent is not the appropriate basis. Each legitimate interest processing activity is supported by a documented Legitimate Interest Assessment (LIA) that identifies the interest pursued, assesses necessity and proportionality, and records mitigation measures applied to protect individuals' rights. LIAs are reviewed periodically.
  • Legal obligation (Article 6(1)(c) UK GDPR): where Shufti must retain or disclose information to comply with law or lawful requests.
  • Legal claims (Article 6(1)(f) / recital 111 UK GDPR): where needed to establish, exercise or defend legal claims (litigation hold).

B. Client Representatives and Authorised Users (Account Administration)

Lawful bases relied upon:

  • Legitimate interests: account administration, service delivery support, security, misuse prevention and maintaining audit logs — supported by documented LIAs.
  • Contract / steps to enter into a contract: account administration, service delivery support.
  • Legal obligation: where Shufti must process or retain information to comply with applicable laws.
  • Legal claims: where processing is necessary to establish, exercise, or defend legal claims.

8.Legitimate Interests Balancing Summary

For all processing activities relying on legitimate interests, Shufti maintains documented Legitimate Interest Assessments (LIAs) that record:

  • The specific legitimate interest pursued;
  • Why the processing is necessary and proportionate to that interest;
  • The potential impact on individuals' rights and interests;
  • Mitigation measures applied (such as data minimisation, pseudonymisation, access controls, and retention limits);
  • The outcome of the balancing assessment confirming that the interest is not overridden by individuals' fundamental rights and freedoms.

LIAs are reviewed at least annually and updated when processing activities change. Copies are available upon request to the DPO.

9.Special Category Data and Biometrics (Article 9 Conditions)

Shufti processes biometric data (e.g. face images/videos) as part of face verification, liveness/deepfake detection and Fast ID re-verification. Where biometric data is processed 'for the purpose of uniquely identifying a natural person,' it is treated as Special Category data under GDPR/UK GDPR.

If the Client is the controller:

The Client is responsible for identifying a valid Article 9 condition where required. Shufti's Terms require Clients to ensure necessary consents/notifications for lawful transfer and collection on behalf of the Client.

If Shufti is the controller (model training and fraud prevention):

Shufti will rely on an identified Article 9 condition for each specific controller processing activity involving biometric or other special category data. The Article 9 conditions relied upon include:

  • Article 9(2)(a): explicit consent of the data subject, where Shufti obtains and documents explicit consent with withdrawal controls as described in this notice. Consent is not bundled with service access;
  • Article 9(2)(f): establishment, exercise or defence of legal claims, where applicable;
  • Article 9(2)(g): substantial public interest (where supported by applicable law and appropriate safeguards);
  • Other permitted conditions only where applicable law supports them and appropriate safeguards exist.
For each biometric processing activity conducted by Shufti as a controller, Shufti conducts and maintains a documented Data Protection Impact Assessment (DPIA). DPIAs are reviewed when the nature or scale of biometric processing changes and at least every two years. DPIAs are available for review by the ICO upon request.

Enhanced safeguards for biometric data used in model training include: logical segregation of biometric training datasets; restricted access limited to authorised personnel; pseudonymisation or anonymisation prior to use where feasible; documented retention limits; and prohibition on sharing of biometric training data with third parties except under a written agreement incorporating Article 28 requirements.

10.Profiling and Automated Decision-Making

Shufti's Role as Processor

Shufti's Terms describe service modes: Standard Mode (AI engine + human review layer) and Customised Mode (AI-only or HI-only). Shufti's User Risk Assessment describes risk-based decisioning (approve/flag/deny) using inputs like IP/location/transaction history and rules/risk bands.

Shufti performs checks and produces verification outcomes and risk outputs for Clients. Accepted/declined results and verification details are delivered to Clients via API and back office. Shufti may use automated systems and (depending on mode/configuration) human review to perform checks.

Final decisions about individuals — such as whether to onboard, block or report a user — are made by the Client controller using Shufti's outputs. Shufti does not independently make legally binding decisions about individuals when acting as a processor. The responsibility for ensuring that any automated decision-making that has legal or similarly significant effects on individuals meets the requirements of Article 22 UK GDPR rests with the Client as controller.

Where a Client uses Shufti outputs for decisions that are solely automated and have legal or similarly significant effects, the Client must provide required information to end-users and ensure appropriate safeguards, including the right to obtain human intervention, express a point of view and contest the decision.

Shufti's Role as Controller

Where Shufti processes personal data as an independent controller and uses automated processing that produces risk outputs or categorisations that have legal or similarly significant effects on individuals, the following safeguards are applied:

  • Human review is integrated into the decision-making process where required by Article 22 UK GDPR or where the automated output would otherwise constitute a sole basis for a significant decision;
  • Individuals are informed of the existence of automated processing and its logic through this notice;
  • Individuals retain the right to obtain human intervention, express their point of view, and contest outcomes;
  • Automated processing activities conducted as controller are documented in Shufti's ROPA and reviewed as part of the DPIA cycle.

11.Sharing and Recipients

A. Group Companies

In some circumstances, Shufti Pro Limited and its group entities may act as joint controllers of your personal data. Group companies include:

  • Shufti AB (Sweden)
  • Shufti Pro Limited (Cyprus)
  • Shufti LLC (Delaware)
  • Shufti Digital ID Verification Services Limited (Dubai)
  • Shufti PTE Limited (Singapore)

B. Categories of Third-Party Service Providers (Sub-processors)

All sub-processors engaged by Shufti are subject to written agreements incorporating the requirements of Article 28 UK GDPR. Shufti maintains a current list of sub-processors, which is made available to Clients upon request. Clients are notified of any intended material changes to the sub-processor list with reasonable advance notice, providing an opportunity to object where contractually permitted.

a. Service Delivery Sub-processors

  • Cloud infrastructure & hosting providers
  • Data storage / database providers
  • CDN, DDoS protection & load balancing providers
  • AML / sanctions screening providers
  • IP geolocation providers
  • Business / company verification data providers
  • National ID / registry verification providers
  • Live interview/chat platforms for Video KYC
  • SMS / OTP / 2FA delivery providers

b. Client Interaction Sub-processors

  • Email communication providers
  • Live interview/chat platforms
  • Customer support / ticketing systems

c. Payment Processors and Other Recipients

  • Payment gateway providers (e.g. Stripe)
  • Insurers/professional advisers where reasonably necessary
  • Authorities/law enforcement where required by law

12.International Transfers (Service Data)

Shufti has global staff/facilities and personal information may be transferred/accessed internationally. All international transfers of personal data processed by Shufti are recorded in a central transfer register, with accountability assigned internally to the Data Protection team. Transfer mechanisms are mapped per transfer and reviewed periodically.

Prior to any international transfer, Shufti conducts a documented Transfer Impact Assessment (TIA) or Transfer Risk Assessment (TRA) where required by applicable law or regulatory guidance, to assess whether the law and practice in the destination country allows the chosen transfer safeguards to be effective. Where TIAs identify risks that are not sufficiently mitigated by the transfer mechanism alone, supplementary measures are implemented in accordance with EDPB Recommendations 01/2020 or equivalent ICO guidance.

Mechanisms we may use (documented for each transfer) include:

  • Adequacy decisions/regulations: European Commission adequacy decisions (GDPR) and UK Government adequacy regulations (UK GDPR).
  • EU SCCs (Decision 2021/914): used for transfers where adequacy or DPF does not apply.
  • EU–US Data Privacy Framework: Commission adequacy decision (Implementing Decision 2023/1795) for flows to certified US companies.
  • UK transfer tools: UK IDTA and the UK Addendum to the EU SCCs, as described in ICO guidance.
  • UK Extension to EU–US DPF (UK–US data bridge): for certified US companies under the UK extension.

Clients may request further information regarding transfer mechanisms applicable to their data, including copies of relevant transfer agreements, by contacting [email protected].

13.Retention (Purpose-Specific Schedule)

Where Shufti acts as a processor, retention of end-user data is strictly governed by Client instructions. Shufti does not apply a default retention period in its own right; any default applied in the absence of specific instructions will only be used where expressly agreed in writing with the Client.
Where Shufti acts as an independent controller, retention periods are justified by the specific purpose of processing, supported by documented retention policies, and reviewed periodically. Data is securely deleted or irreversibly anonymised upon expiry of the applicable retention period.
Processing Purpose Role Standard Retention Justification Notes
Client verification records (docs, biometrics, results) Processor Per Client instruction only. No default retention applied unless expressly agreed in writing with Client. Client instructions govern. Where a default period is contractually agreed, it reflects the applicable regulatory limitation period for the relevant industry. Shufti will prompt clients to provide retention instructions. Records are deleted at end of retention period unless under legal hold.
Fast ID portability record Processor Per Client instruction only; no blanket default. Justified by client's legal/contractual obligation. Withdrawal of consent available via email and rights form.
Fraud prevention evidence (confirmed abuse) Processor / Controller Per Client instruction as processor. As controller: up to 7 years where justified by legitimate interests in preventing re-fraud; reviewed annually. Legitimate interests (controller): prevention of re-fraud and defence of legal claims. Documented retention policy maintained. Annual review and deletion of records no longer required.
Model training / quality improvement datasets Controller Maximum 12–24 months in pseudonymised form; then delete or anonymise. Legitimate interests with documented LIA. Retention period justified by model improvement cycle; reviewed at each training cycle. DPIA required. Biometric training data subject to enhanced safeguards and documented limits.
Audit and security logs Controller / Processor 12–24 months; reviewed periodically. Security monitoring, compliance and limitation periods. Deleted upon expiry unless subject to legal hold.
Client representative account data Controller Contract term + up to 7 years after termination. Accounting and limitation periods; legitimate interests in managing commercial relationships. Reviewed at end of retention period; deleted promptly.

14.Security Measures (Technical and Organisational)

  • Annual DPIAs and subprocessor evaluation;
  • Privacy by design/default including encryption, pseudonymisation and data minimisation;
  • Evaluation against ISO 27001, SOC 2;
  • Privacy oversight and periodic audits;
  • Role-based access controls and audit logging;
  • Logical segregation of processor and controller datasets (see Section 4A).

15.Your Rights and How to Exercise Them

If You Are an End-User Being Verified for a Client

In most cases, the Client is the controller of your service verification data. You should contact the Client in the first instance for rights requests (access, deletion, objection, restriction, etc). If Shufti receives a rights request from an end-user while acting as a processor, Shufti will acknowledge the request within 5 working days and direct you to contact the relevant Client controller, which manages the request outcome. Shufti will cooperate with Clients in fulfilling data subject rights requests in accordance with its contractual obligations and Article 28(3)(e) UK GDPR.

If Shufti Is Acting as Controller (Model Improvement, Security Logs, Client Reps)

Contact Shufti at [email protected] for rights requests. Use this form for your requests. Shufti will respond within one calendar month of receipt of a valid request (or within three months for complex requests, with notification within one month of the extension). We may ask for information to verify your identity before responding.

Where a request involves processing activities conducted in both processor and controller roles, Shufti will triage the request, identify the relevant controller(s), and coordinate the response to ensure a complete and consistent outcome for the data subject.

Full List of Rights

Depending on applicable law and the context, rights may include:

  • Access: ask for a copy of your personal data.
  • Rectification: correct inaccurate data.
  • Erasure: ask us to delete data (subject to legal obligations/retention).
  • Restriction: ask us to limit processing in certain cases.
  • Portability: receive certain data in a portable format.
  • Object: object to processing based on legitimate interests and to direct marketing.
  • Withdraw consent: where processing is based on consent. Withdrawal does not affect the lawfulness of prior processing.
  • Right not to be subject to solely automated decisions with legal or similarly significant effects (see Section 10).
  • Complain: lodge a complaint with a supervisory authority (ICO in the UK; EEA DPAs via EDPB list).

16.Complaints and Supervisory Authorities

17.If You Do Not Provide Personal Data

Where Shufti acts as a processor, if you are an end user and you do not provide the personal data required for identity verification, Shufti will not be able to complete the verification process or return a result to the Client. As a consequence, the Client may be unable to onboard you or provide access to its products or services.

Where Shufti processes your personal data as a controller (for example, for fraud prevention, security monitoring, service integrity, algorithm training or account management), failure to provide relevant information may limit our ability to operate, secure and improve our services. This will not affect the delivery of core identity verification services.

If you are a representative of one of our Clients or a prospective Client and you do not provide the personal data required to establish or manage the business relationship, we may be unable to create or maintain your organisation's account, provide access to our services, or respond to your enquiries.

18.Children's Data

Our Services are not directed to children under the age of sixteen (16) and we will never knowingly collect personal or other information from anyone we know is under such age.

Shufti implements reasonable measures appropriate to the risk to prevent the processing of children's personal data through its services. These measures include:

  • Age declarations required at the point of verification. However, Shufti recognises that self-declaration alone is insufficient to prevent processing of children's data in all cases.
  • Where biometric processing is involved, additional controls are applied, including review procedures designed to flag verification attempts that may involve individuals who appear to be below the minimum age threshold.
  • Clients are required under Shufti's Terms to ensure that their services are not directed to children under the age of 16 and to obtain any necessary verifiable parental consent where their applicable law requires it.
  • Where Shufti identifies that a child's data has been processed without authorisation, processing will be suspended and the data will be deleted promptly. The relevant Client will be notified.

19.Additional Information for People in the United States

This section applies if you are in the United States. It adds to the rest of this notice. If anything here conflicts with an earlier section, this section applies to you.

It applies whether you are being verified through Shufti or you use our platform on behalf of one of our business customers. Throughout, the Client means the business that asked for the check.

Shufti Pro Limited, registered in England and Wales, is the company you contract with wherever you are, and it is responsible for what this section promises. Our group companies help run the platform; the responsibility stays with Shufti Pro Limited.

19.1 Which states

California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah and Virginia have general privacy laws. If you live in one of them, all of Section 19 applies to you.

Illinois, Texas and Washington also have biometric laws. If you live in one of those three, read Section 20 as well — it takes priority.

New York has no general privacy law. It does require us to protect your information properly and to tell you within 30 days if there is a breach, and New York City has its own rules on biometrics on business premises and on automated hiring tools. Those fall on whoever runs the premises or does the hiring, and we support Clients in meeting them.

19.2 Our role

For nearly everything we do, the Client decides what checks to run and we carry them out. That makes us a service provider or processor. In that role we use your information only for what our contract with the Client says, never for our own purposes, and we do not mix one Client's information with another's.

We act in our own right for a few narrow things: keeping security and access logs, keeping records of confirmed fraud, testing and improving the accuracy of our own systems, and running the accounts of people who use our platform at work.

19.3 What we collect

Section 5 of this notice sets this out in full. Grouped into the categories US law uses:

CategoryWhat we may hold
IdentifiersName, address, email address, phone number, IP address, device identifier, and identity document details such as type, issuing country, number and expiry date.
Customer recordsName, signature, address, phone number, and government numbers including passport, driving licence, state ID and Social Security number.
Protected characteristicsAge, date of birth, sex, nationality and place of birth, as printed on your identity document.
Biometric informationFace images and video, and the face template calculated from them, together with liveness and deepfake results.
Internet activitySession logs, browser and device settings, and how you interacted with the verification screen.
LocationThe rough location your IP address suggests.
Images, video and audioPhotographs and scans of documents, selfies, and video interview recordings.
Professional informationFor people who use our platform at work: employer, job title and business contact details.
Conclusions we drawPass or fail, how closely things matched, confidence scores, and fraud or risk signals.

What we actually collect depends entirely on which checks the Client has turned on. Most verifications use only part of this.

19.4 Where it comes from, why, and who we share it with

Sections 6, 7 and 11 of this notice cover this. In short, it comes from you, from the Client, from your device, and from the databases a Client asks us to check you against. We use it to run the check, to stop fraud, to keep the platform secure, to test that our systems work accurately, and to comply with law.

In the last twelve months we have disclosed every category listed above, for business purposes only, to: the Client who asked for the check; our own group companies; our hosting, storage and communications suppliers; the data sources a Client has turned on; our advisers, auditors and insurers; and law enforcement, regulators or courts where the law required it.

We do not give personal information to data brokers, advertising networks or analytics companies.

19.5 We do not sell or share your information

We have not sold personal information, or shared it for cross-context behavioural advertising, at any point in the last twelve months, and we do not do so now. That includes information about anyone we know to be under 16. Because we do not, there is no "Do Not Sell or Share" link on our site. If that ever changes we will publish one and give you the chance to opt out first.

We do not offer money, discounts or better service in exchange for your information.

19.6 Sensitive information

Some of what we handle counts as sensitive: government numbers, biometric information used to identify you, precise location, and anything about your race, ethnicity or immigration status readable from your documents.

We use sensitive information only to run the service, keep it secure, prevent and investigate fraud and illegal activity, check and improve the quality and safety of our own service, and comply with law. Those are all purposes US law permits without an opt-out, so the right to limit how we use sensitive information does not currently apply to us. We never use it to work out other things about you, and never for advertising. If we ever go beyond those purposes we will publish a "Limit the Use of My Sensitive Personal Information" link before we start.

Section 20 sets stricter rules again for biometric information in Illinois, Texas and Washington.

19.7 How long we keep things

Section 13 of this notice sets out the full schedule. Two limits are fixed by US law and cannot be extended by anything a Client asks for:

  • Biometric data about people in Illinois: destroyed when the purpose is met or three years after your last dealing with us, whichever comes first.
  • Biometric data about people in Texas: destroyed within a year of the purpose running out.

We apply the Illinois limit to biometric data everywhere in the US. Where a Client gives us no retention instruction for other verification data, we delete after twelve months.

19.8 Your rights

Depending on your state, you can ask us to confirm what we hold and give you a copy, correct anything wrong, delete what we hold, give you a portable copy, and stop selling your information, using it for targeted advertising, or profiling you in ways that significantly affect you. California residents can also ask for the categories we collect, where we got them, why we use them, who we gave them to, and the specific pieces we hold.

From January 2027, California residents will also be entitled to advance notice of automated decisions that significantly affect them, an explanation, and the ability to opt out.

How to askUse the form at https://shuftipro.com/shuftipro-data-rights-request-form-v4/ or email [email protected]. Tell us your state so we apply the right rules.
If we hold it for a ClientWe pass your request to that Client, act on their instruction, and tell you we have done so. This does not apply to biometric data — those duties are ours and we act on them ourselves.
Proving it is youWe ask for enough to match you to what we hold, and more if you are asking about biometric data or a copy of a document. We use it only to check it is you, then delete it. If we cannot verify you, we tell you why.
Someone acting for youAllowed, with your written permission. We may still ask you to confirm it is you.
TimingWe acknowledge within 10 business days and answer within 45 days. We can take up to 90 days in total if it is complicated, and we tell you within the first 45.
CostFree, up to twice a year. We may charge or decline if a request is clearly excessive or repetitive.
If we say noWe explain why and tell you how to appeal. We decide appeals within 45 days and, if we still say no, tell you how to complain to your state Attorney General. In California you can also complain to the California Privacy Protection Agency.
No penaltyWe will not treat you worse for asking.

Complaints about us: https://shuftipro.com/shuftipro-complaint-form-v2/ or [email protected].

19.9 Automated processing

Our checks are automated. Software compares your face to your document, scores whether you are really there, flags likely deepfakes, matches your name against lists, and produces a risk score. Depending on what the Client chose, a trained person may also review your case.

The decision that affects you — account opened, refused, more evidence needed, or reported — is the Client's, not ours. If the Client makes it automatically and it matters, the Client must tell you, offer a human review, and meet the bias-audit rules in places like Colorado, California and New York City.

The one significant decision we make ourselves is blocking a session for fraud across our platform. A person reviews it before it is final, we tell you, and you can challenge it at [email protected].

19.10 Children

Our services are not aimed at children, and Clients must not put children through them without whatever agreement their own law requires. We do not knowingly collect anything from a child under 13 without a parent's verified agreement. We do not sell or share the information of anyone under 16. New York and several other states restrict what may be done with the data of under-18s beyond what the service needs, and we keep to that.

Age checking is different, because the person may well be young. There we take only what is needed to give an age answer, we do not keep the image afterwards, and we never use any of it to improve our systems.

20.Biometric Notice for Illinois, Texas and Washington

It covers face images and video, and the face templates we calculate from them. We call that biometric data.

We do not create voiceprints. Where a Client uses video identification, the recording may contain audio, but we do not extract a voice template from it or use it to identify anyone.

20.1 How long we keep it, and how we destroy it

We destroy your biometric data as soon as the first of these happens:

  • the check is finished, the result has gone to the Client, and any retention period the Client has told us about in writing has run out; or
  • three years have passed since you last dealt with us.

Three years is an absolute limit. A Client cannot ask us to keep your biometric data longer, and if one asks, we say no. This applies whether we are holding it for a Client or for ourselves.

In Texas the limit is shorter: we destroy it within a year of the purpose for collecting it running out.

In Washington, where we store a face template in a database that matches it to a specific person, we keep it no longer than we need it to provide the service, prevent fraud or comply with a court order.

The only exception is a court order or a specific legal requirement to keep something. Then we keep only what is covered, only for as long as needed, and separately from everything else.

Destroying it means permanently deleting the face template and the original images or video from our live systems, our backups and our archives, so that it cannot be recovered. We do this within 30 days and we record it.

20.2 Telling you first, and asking you first

Before anyone collects your biometric data you must be told, in writing, that it is being collected, what it is for and how long it will be kept, and you must agree.

  • If we run the screen, we show you that notice before the camera starts and record your agreement. A tick box or on-screen signature counts.
  • If the Client runs the screen and sends us the result, our contract requires the Client to tell you and get your agreement first, and to prove it if we ask. That is an arrangement between us and the Client. It does not change what we owe you under this section.

Appearing in a photo or video that someone else put online is not agreement. We do not scrape public images or video to build face databases.

If you are in Illinois, Texas or Washington and you were never told or never agreed, email [email protected]. We will look into it, tell you what we hold, and delete it unless the law requires us to keep it.

20.3 We do not sell it or make money from it

We never sell, rent, trade or otherwise profit from your biometric data.

We also do not use the biometric data of people in Illinois or Washington to train, test or improve our face, liveness, deepfake or fraud systems, or anyone else's. We identify and remove sessions from those states before building any development data set. Where we do use biometric data elsewhere to improve our own systems, we keep it no more than 24 months, strip out what identifies you wherever we can, and never pass it to anyone else for that purpose.

20.4 When we pass it on

We pass biometric data on only where you have agreed, where it is needed to complete something you asked for, where the law requires it, or on a valid court order or subpoena.

Sending your result and images back to the Client who asked for the check falls into the first two. Our hosting and storage suppliers handle it on our behalf under contracts that stop them using it for anything of their own; they are not separate recipients.

20.5 How we protect it

We protect biometric data at least as carefully as any other confidential information we hold, and to the standard expected in our industry: encryption while it moves and while it sits, access limited to those who need it, biometric stores kept apart from everything else, every access logged, and independent testing.

20.6 Washington consumer health data

Washington's My Health My Data Act treats biometric data as consumer health data, whatever it is being used for. That Act requires a separate policy, and ours is our Consumer Health Data Privacy Policy, published on its own page with a link on our homepage. It sits alongside this notice and is not replaced by it.

In summary: you can ask what consumer health data we hold, ask for a list of everyone we shared it with, withdraw your agreement, and have it deleted from our systems, backups and archives. We do not sell consumer health data. We do not set up geofences around hospitals, clinics or anywhere else providing in-person health care, and our contracts forbid Clients from using our location features that way. The Act does not treat employees as consumers, so it does not apply to workforce or candidate checks. The separate policy has the detail.

20.7 Going to court

In Illinois and Washington you can take a company to court directly over how it handles biometric data. Nothing in this notice, and nothing in any contract we have with a Client, takes that right away. We would rather you came to us first, but you do not have to. In Texas, the Attorney General enforces the law and you can complain to that office.

21.Changes to This Notice

We may update this Services Privacy Notice. We will publish the current version and "Last updated" date, consistent with Shufti's existing privacy policy change notification pattern. Where changes are material, we will take reasonable steps to bring them to affected parties' attention.

Version 1.2 · Last updated: September 2026 · Shufti Pro Limited · Notice B