Washington Consumer Health Data Policy
Washington My Health My Data Act. This is a separate, standalone policy. It is not part of our Services Privacy Notice and is not replaced by it.
| Version | 1.2 |
|---|---|
| Last Updated | September 2026 |
| Applies To | People in Washington State, other than in an employment context |
| Required By | Washington My Health My Data Act |
1.Who We Are and When This Applies
Shufti Pro Limited, registered in England and Wales, provides identity verification, biometric and fraud prevention services to businesses. We call those businesses Clients. This policy covers people in Washington State.
It does not apply to you if you are dealing with us in an employment context. Washington law excludes employees from this Act, so workforce and candidate checks are outside it.
Our two roles
Most of the time, a Client decides that you should be verified and tells us what checks to run. In that situation the Client is the regulated entity under Washington law and we act on its instructions. The Client's own policy governs, and requests about that data should go to the Client. We will not process your data in any way that conflicts with the Client's policy.
We decide the purpose ourselves for a small number of things: preventing fraud across our platform, keeping our systems secure, and testing that our checks work accurately. For those, we are a regulated entity in our own right, and this policy is ours.
This policy describes both, so that you can see the whole picture.
2.What Consumer Health Data We Collect, and Why
| What we collect | Why we collect it, and how we use it |
|---|---|
| Face images and video — a selfie, a short video, or the photo page of your identity document | To check that your document is genuine and belongs to you, and to check that a real, live person is present rather than a photograph, a mask or a deepfake. Used to run the check the Client asked for and to return a result. |
| Face templates — a mathematical representation calculated from those images | To compare one face to another. Used only for the comparison, and deleted on the schedule in section 6. |
| Liveness and deepfake signals, and the scores behind them | To detect attempts to fool the check. Used to return a result and to detect fraud against our platform. |
| Precise location, where a Client turns on a location feature | To tell the Client whether a session came from a permitted area. We never use location to work out anything about your health. |
| Conclusions we draw from the above — match confidence, liveness confidence, fraud and risk signals | To return a result to the Client, and to detect patterns of fraud across our platform. |
We do not create voiceprints. Where a Client uses video identification, the recording may contain audio, but we do not extract a voice template from it or use it to identify anyone.
We collect nothing about your health conditions, treatment, diagnoses, medication or use of health services. Washington law treats biometric data as health data whatever it is used for, which is why this policy exists, but the purpose of our checks is to confirm identity, not to learn anything about your health.
We do not use consumer health data of people in Washington to train or improve our systems. Where a Client is a health care provider, we do not record or infer anything from the fact that you were verified for that Client.
3.Where It Comes From
- Directly from you, when you complete a verification screen that we host or that uses our capture software.
- From the Client, when the Client collects your images or details itself and sends them to us.
- From your device or browser during the session.
We do not buy consumer health data, and we do not take it from public sources or social media.
4.What We Share, and With Whom
We share the categories in section 2 only as set out below. We do not share consumer health data for advertising, analytics or any purpose of the recipient's own.
| Who receives it | What they receive, and why |
|---|---|
| The Client who asked for the check | The verification result and the images and signals behind it, so the Client can decide whether to accept you. This is what you initiated when you started the check. |
| Our group companies — Shufti LLC (Delaware), Shufti AB (Sweden), Shufti Pro Limited (Cyprus), Shufti Digital ID Verification Services Limited (Dubai), Shufti PTE Limited (Singapore) | Access for the engineering, support and security teams that keep the platform running. Bound by intra-group agreements to the same terms as this policy. |
| Hosting and storage providers | Storage and processing of the data on our behalf. They act only on our instructions and may not use it for anything of their own. |
| Communications providers | Where a Client uses video identification, the platform carrying that session. |
| Law enforcement, regulators and courts | Only where the law requires it, or on a valid warrant, subpoena or court order. |
If you ask, we will give you a list of every third party and affiliate we have actually shared or sold your consumer health data with, together with a way of contacting each of them. See section 7.
5.We Do Not Sell It
We do not sell consumer health data, and we have never done so. Washington law would require us to obtain a written authorisation from you first, signed, separate from anything else, naming the buyer and the purpose, and expiring after a year. We do not seek those authorisations because we do not sell this data.
We also do not set up a geofence around any hospital, clinic, pharmacy or other place providing in-person health care, and we do not allow our location features to be used that way. Our contracts with Clients prohibit it.
6.Consent, and How Long We Keep It
We collect and share consumer health data only where it is necessary to deliver the verification you started with the Client, or where you have given separate consent.
For the check itself, no separate consent is needed under this Act, because the collection is necessary to provide the service you asked for. You will still be told before your face is captured and asked to agree, because our biometric commitments require it.
For anything beyond that, we ask for your clear, opt-in consent first, and we ask separately again before sharing. We tell you what data, what purpose, who receives it, and how to withdraw.
You can withdraw consent at any time, and we will stop. Withdrawing does not undo what was lawfully done beforehand.
7.Your Rights
If you are in Washington, you can ask us to:
- Confirm and show you. Tell you whether we are collecting, sharing or selling consumer health data about you, and give you a copy, along with a list of every third party and affiliate we have shared or sold it to and a way to contact each of them.
- Withdraw your consent. Stop collecting or sharing your consumer health data.
- Delete it. Remove it from all of our systems, including backups and archives. We will also tell every processor, affiliate and third party we shared it with to delete it, and we will pass on your request to them.
| How to ask | https://shuftipro.com/shuftipro-data-rights-request-form-v4/ or email [email protected] |
|---|---|
| Timing | We acknowledge within 10 business days and answer within 45 days. We may take one further 45 days where the request is complex, and we will tell you within the first 45. |
| Cost | Free. |
| Proving it is you | We ask for enough information to match you to what we hold, and we use it only for that. |
| If we refuse | We explain why and tell you how to appeal. We decide appeals within 45 days. If we still refuse, we give you a link to submit a complaint to the Washington Attorney General. You can also complain to us at https://shuftipro.com/shuftipro-complaint-form-v2/ |
| Going to court | A breach of this Act is treated as an unfair or deceptive practice under the Washington Consumer Protection Act, and you may bring a claim directly. Nothing here limits that. |
8.How We Protect It
We protect consumer health data at least as carefully as any other confidential information we hold: encryption while it moves and while it sits, access restricted to the people who need it and logged every time, biometric stores kept separate from other data, staff training and background checks, supplier due diligence, and independent assessment against ISO 27001 and SOC 2. Access is limited to what each person needs to do their job.
9.Changes to This Policy
We will not collect, use or share consumer health data for any purpose that is not described here without telling you first and obtaining your clear, opt-in consent. If we add a new category or a new purpose, we will update this policy and seek that consent before we start.
Questions: [email protected].
Version 1.2 · Last updated: September 2026 · Shufti Pro Limited · SP-PRV-PN-WA-001

