WebinarShufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle18th Sep | 02:00 PM UTCREGISTER NOW Shufti x AML IntelligenceHow AMLR Extends KYC Across the Customer Lifecycle18th Sep | 02:00 PM UTCREGISTER NOW How AMLR Extends KYC Across the LifecycleRegister One sign-up screen. One rulebook behind it;  AMLR, eIDAS 2.0, EUDI wallet.Read the GUIDE One sign-up screen. One rulebook behind it;  AMLR, eIDAS 2.0, EUDI wallet.Read the GUIDE AMLR, eIDAS 2.0 & EUDI walletRead the guide Shufti x FTAHKWebinarThe Lifecycle of a Compliant Crypto TransferTravel Rule, Wallet Verification & Counterparty Risk05:00 PM HKT9th September, 2026Register Now Shufti x FTAHKTravel Rule, Wallet Verification & Counterparty Risk9th September, 2026Register Now Compliant Crypto Transfer — Travel Rule & moreRegister Shufti x ACFEWebinarAI has changed fraud. Now we need to change how we fight it.Microphone icon for Shufti and ACFE fraud webinar5th October, 2026Register Now Shufti x ACFEAI has changed fraud. Now we need to change how we fight it.5th October, 2026Register Now AI has changed fraud — change how we fight itRegister INNOVATION DROPSUMMER
EDITION
20
26
Qualified Electronic Signature
WATCH NOW
INNOVATION DROP - Qualified Electronic SignatureWatch Now Innovation Drop — Qualified Electronic SignatureWatch
INNOVATION DROPSUMMER
EDITION
20
26
Transaction Trust Monitoring
WATCH NOW
INNOVATION DROP - Transaction Trust MonitoringWatch Now Innovation Drop — Transaction Trust MonitoringWatch
INNOVATION DROPSUMMER
EDITION
20
26
Travel Rule Compliance
WATCH NOW
INNOVATION DROP - Travel Rule ComplianceWatch Now Innovation Drop — Travel Rule ComplianceWatch
G2 badgesShufti - The #1 Identity Verification Solution on G240+ Badges | Fall 2026 ReportExplore More Shufti - The #1 Identity Verification Solution on G2Explore more Shufti — #1 Identity Verification on G2Explore

de

35.198.113.100

Shufti Pro Limited · Washington Consumer Health Data Policy

Washington Consumer Health Data Policy

Washington My Health My Data Act. This is a separate, standalone policy. It is not part of our Services Privacy Notice and is not replaced by it.

Version 1.2 Last updated September 2026 Contact [email protected]
Version1.2
Last UpdatedSeptember 2026
Applies ToPeople in Washington State, other than in an employment context
Required ByWashington My Health My Data Act

1.Who We Are and When This Applies

Shufti Pro Limited, registered in England and Wales, provides identity verification, biometric and fraud prevention services to businesses. We call those businesses Clients. This policy covers people in Washington State.

It does not apply to you if you are dealing with us in an employment context. Washington law excludes employees from this Act, so workforce and candidate checks are outside it.

Our two roles

Most of the time, a Client decides that you should be verified and tells us what checks to run. In that situation the Client is the regulated entity under Washington law and we act on its instructions. The Client's own policy governs, and requests about that data should go to the Client. We will not process your data in any way that conflicts with the Client's policy.

We decide the purpose ourselves for a small number of things: preventing fraud across our platform, keeping our systems secure, and testing that our checks work accurately. For those, we are a regulated entity in our own right, and this policy is ours.

This policy describes both, so that you can see the whole picture.

2.What Consumer Health Data We Collect, and Why

What we collect Why we collect it, and how we use it
Face images and video — a selfie, a short video, or the photo page of your identity document To check that your document is genuine and belongs to you, and to check that a real, live person is present rather than a photograph, a mask or a deepfake. Used to run the check the Client asked for and to return a result.
Face templates — a mathematical representation calculated from those images To compare one face to another. Used only for the comparison, and deleted on the schedule in section 6.
Liveness and deepfake signals, and the scores behind them To detect attempts to fool the check. Used to return a result and to detect fraud against our platform.
Precise location, where a Client turns on a location feature To tell the Client whether a session came from a permitted area. We never use location to work out anything about your health.
Conclusions we draw from the above — match confidence, liveness confidence, fraud and risk signals To return a result to the Client, and to detect patterns of fraud across our platform.

We do not create voiceprints. Where a Client uses video identification, the recording may contain audio, but we do not extract a voice template from it or use it to identify anyone.

We collect nothing about your health conditions, treatment, diagnoses, medication or use of health services. Washington law treats biometric data as health data whatever it is used for, which is why this policy exists, but the purpose of our checks is to confirm identity, not to learn anything about your health.

We do not use consumer health data of people in Washington to train or improve our systems. Where a Client is a health care provider, we do not record or infer anything from the fact that you were verified for that Client.

3.Where It Comes From

  • Directly from you, when you complete a verification screen that we host or that uses our capture software.
  • From the Client, when the Client collects your images or details itself and sends them to us.
  • From your device or browser during the session.

We do not buy consumer health data, and we do not take it from public sources or social media.

4.What We Share, and With Whom

We share the categories in section 2 only as set out below. We do not share consumer health data for advertising, analytics or any purpose of the recipient's own.

Who receives it What they receive, and why
The Client who asked for the check The verification result and the images and signals behind it, so the Client can decide whether to accept you. This is what you initiated when you started the check.
Our group companies — Shufti LLC (Delaware), Shufti AB (Sweden), Shufti Pro Limited (Cyprus), Shufti Digital ID Verification Services Limited (Dubai), Shufti PTE Limited (Singapore) Access for the engineering, support and security teams that keep the platform running. Bound by intra-group agreements to the same terms as this policy.
Hosting and storage providers Storage and processing of the data on our behalf. They act only on our instructions and may not use it for anything of their own.
Communications providers Where a Client uses video identification, the platform carrying that session.
Law enforcement, regulators and courts Only where the law requires it, or on a valid warrant, subpoena or court order.

If you ask, we will give you a list of every third party and affiliate we have actually shared or sold your consumer health data with, together with a way of contacting each of them. See section 7.

5.We Do Not Sell It

We do not sell consumer health data, and we have never done so. Washington law would require us to obtain a written authorisation from you first, signed, separate from anything else, naming the buyer and the purpose, and expiring after a year. We do not seek those authorisations because we do not sell this data.

We also do not set up a geofence around any hospital, clinic, pharmacy or other place providing in-person health care, and we do not allow our location features to be used that way. Our contracts with Clients prohibit it.

6.Consent, and How Long We Keep It

We collect and share consumer health data only where it is necessary to deliver the verification you started with the Client, or where you have given separate consent.

For the check itself, no separate consent is needed under this Act, because the collection is necessary to provide the service you asked for. You will still be told before your face is captured and asked to agree, because our biometric commitments require it.

For anything beyond that, we ask for your clear, opt-in consent first, and we ask separately again before sharing. We tell you what data, what purpose, who receives it, and how to withdraw.

You can withdraw consent at any time, and we will stop. Withdrawing does not undo what was lawfully done beforehand.

We destroy biometric data when the check is complete and any retention period the Client has instructed has run out, or three years after you last dealt with us, whichever comes first. That three-year limit is absolute and no Client can extend it. Destruction covers our live systems, our backups and our archives, and cannot be reversed.

7.Your Rights

If you are in Washington, you can ask us to:

  • Confirm and show you. Tell you whether we are collecting, sharing or selling consumer health data about you, and give you a copy, along with a list of every third party and affiliate we have shared or sold it to and a way to contact each of them.
  • Withdraw your consent. Stop collecting or sharing your consumer health data.
  • Delete it. Remove it from all of our systems, including backups and archives. We will also tell every processor, affiliate and third party we shared it with to delete it, and we will pass on your request to them.
How to ask https://shuftipro.com/shuftipro-data-rights-request-form-v4/ or email [email protected]
Timing We acknowledge within 10 business days and answer within 45 days. We may take one further 45 days where the request is complex, and we will tell you within the first 45.
Cost Free.
Proving it is you We ask for enough information to match you to what we hold, and we use it only for that.
If we refuse We explain why and tell you how to appeal. We decide appeals within 45 days. If we still refuse, we give you a link to submit a complaint to the Washington Attorney General. You can also complain to us at https://shuftipro.com/shuftipro-complaint-form-v2/
Going to court A breach of this Act is treated as an unfair or deceptive practice under the Washington Consumer Protection Act, and you may bring a claim directly. Nothing here limits that.

8.How We Protect It

We protect consumer health data at least as carefully as any other confidential information we hold: encryption while it moves and while it sits, access restricted to the people who need it and logged every time, biometric stores kept separate from other data, staff training and background checks, supplier due diligence, and independent assessment against ISO 27001 and SOC 2. Access is limited to what each person needs to do their job.

9.Changes to This Policy

We will not collect, use or share consumer health data for any purpose that is not described here without telling you first and obtaining your clear, opt-in consent. If we add a new category or a new purpose, we will update this policy and seek that consent before we start.

Questions: [email protected].

Version 1.2 · Last updated: September 2026 · Shufti Pro Limited · SP-PRV-PN-WA-001