Skip to content
Authentity

Privacy Policy

Last updated: 9 August 2026

This policy explains how Authentity, Algiers, Algeria ("we", "us") handles personal data in connection with Authentity.

The short version: when our customers verify an identity document, the data inside its chip — including the holder's name, date of birth, document number and facial image — passes through our servers in memory, is returned to the customer, and is not stored by us. What we keep is a record that a verification happened, not what it contained.

1. Two different roles

We handle personal data in two distinct capacities, and it matters which one applies.

As a processor, for identity document data. Our customers are businesses that verify documents. They decide why a document is read and are the controller of the data inside it. We only carry out the verification on their instructions. If your document was scanned using Authentity, the organisation that scanned it is the one that decides what happens to your data, and your first point of contact should be them — although you may always contact us and we will help.

As a controller, for account data. When a business signs up, we decide how we handle their organisation, user and billing records. This policy governs that directly.

2. Identity document data — what we process and what we keep

When a document's chip is read, our servers process the contents of the data groups that the customer's application requests. Depending on the document, these may include:

  • DG1 — the machine readable zone: full name, date of birth, sex, nationality, document number, document type, issuing country and expiry date.
  • DG2 — the holder's facial image, which is biometric data.
  • DG7 — the holder's handwritten signature image, where present.
  • Security objects and the issuing country's certificates, used to verify the chip's authenticity and that its contents have not been altered.

3. We do not store document contents

This is the central design decision of the platform, so it is worth being exact about it.

Chip data exists only in the memory of the server process handling that one verification session. It is held for the seconds the read takes, returned to the customer's application over an encrypted connection, and discarded when the session ends. It is never written to our database, never written to disk, and never included in our logs — our logs record the size and format of an image, not the image.

We do not retain facial images. We do not build, hold or have access to any biometric template, face database or watchlist. We cannot search for a person across our customers' verifications, and neither can anyone else, because the underlying data does not exist on our systems after the session closes.

What we do keep for each verification is a metadata record: the document type, the nationality shown on the document, which data groups were read, whether the verification succeeded, how long it took, and any error message. This is what powers usage metering, billing and the diagnostics a customer sees in their dashboard. It contains no name, no date of birth, no document number and no image.

4. Account data we hold as controller

For businesses that hold an Authentity account, we store:

  • Account and user records: name, email address, role, the organisation's name and logo, and a password stored only as a salted hash — we never hold the password itself.
  • API keys: stored as a hash plus a short non-secret prefix so a key can be recognised in the dashboard. We cannot recover the full key after it is issued.
  • Usage records: monthly scan and API call counts per organisation.
  • Billing records: plan, subscription status and period, payment amount, currency, status, payment method type and the identifiers Paddle assigns. We do not receive or store card numbers.
  • Sales enquiries: if you use the contact form, the name, company, email, phone, country, expected volume and message you send, plus our notes on the conversation.
  • App downloads: where our mobile app is downloaded from our site, the IP address and browser user agent used, to measure distribution and prevent abuse.
  • Demo scans: where the public demo is used, a device identifier and date, to enforce the demo's daily limit.

5. Why we process it, and on what basis

Identity document data is processed solely to perform the verification our customer asked for, on their documented instructions, under our contract with them. The lawful basis for the underlying scan is the customer's responsibility, not ours — under our terms they must have one, and must tell the document holder that a processor performs the read on their behalf.

Account data is processed to provide the Service under our contract with the customer; to take payment and meet accounting and tax obligations; and, on the basis of our legitimate interests, to keep the platform secure, prevent abuse, meter usage and answer sales enquiries. Where we send anything beyond service and transactional messages, we rely on consent, which can be withdrawn at any time.

6. How long we keep things

Identity document contents: not retained. They exist only for the duration of the verification session.

Verification metadata, account, organisation and usage records: kept while the account is open, because customers rely on the history for reconciliation, and deleted when an account is closed and deletion is requested, subject to the retention below.

Billing and payment records: retained for as long as tax and accounting law requires, which is typically several years and is not something we can shorten on request.

Sales enquiries: kept while we are in contact and for a reasonable period afterwards, then deleted.

7. Who else is involved

We keep the number of third parties small, and none of them receives identity document contents, because we do not retain those to share.

  • Neon — managed PostgreSQL hosting for our database, located in Frankfurt, Germany (European Union).
  • Our server hosting provider, which runs the application servers that perform verifications.
  • Paddle.com — our Merchant of Record. Paddle handles checkout, takes payment, calculates tax and manages refunds and chargebacks. Paddle is the controller of the payment data you give it and applies its own privacy policy.
  • Our transactional email provider, used to send account and billing emails.
  • We do not sell personal data, do not share it for advertising, and do not use it to train machine learning models.

8. Where data is held and international transfers

Our database is hosted in Frankfurt, Germany (European Union). Some of our providers, including Paddle, operate internationally, so limited account and billing data may be processed outside your country.

Where such a transfer takes place from a jurisdiction that restricts it, we rely on the safeguards the law provides, such as standard contractual clauses or an adequacy decision covering the destination.

Because identity document contents are never stored, they are never transferred to any third party or jurisdiction; they travel only between the customer's application and our verification servers.

9. Security

All traffic to our API and dashboard is encrypted in transit with TLS. Chip data is relayed over an encrypted channel and processed only in memory.

Passwords are stored as salted hashes and API keys as hashes, so neither can be read from our database, by us or by anyone who obtained a copy of it. Access is scoped per organisation, API keys carry explicit permissions and rate limits, and administrative access to production is restricted to the people who need it.

No system is perfectly secure. If a breach occurs that is likely to present a risk to people, we will notify the affected customers and the relevant supervisory authority within the time limits the law sets.

10. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict or object to how it is processed, to receive it in a portable form, and to withdraw consent where processing relies on it.

To exercise these rights over account data, email privacy@authentity.io. We will respond within the period the law requires, and within one month at the latest.

If your identity document was scanned by an organisation using Authentity and you want to know what happened to that data, contact that organisation: they are the controller and hold the record of the scan. We can tell you that we did not retain the contents, but we cannot tell you who scanned you, because our metadata does not identify document holders.

11. Complaints

If you are unhappy with how we have handled your data, please tell us first at privacy@authentity.io — we would rather fix it directly.

We operate from Algeria and are subject to Law 18-07 of 10 June 2018 on the protection of natural persons in the processing of personal data, supervised by the National Authority for the Protection of Personal Data (ANPDP). You may lodge a complaint with the ANPDP, and if you are outside Algeria you may also complain to the data protection supervisory authority in your own country.

12. Children

Authentity is a business service and is not directed at children, and we do not knowingly create accounts for them. Identity documents belonging to minors may legitimately be verified by our customers — for example at a border — and the safeguards in this policy apply to that data in exactly the same way, including the fact that we do not retain it.

13. Changes to this policy

If we change this policy we will update the date at the top of this page, and for material changes we will notify account holders by email or in the dashboard before the change takes effect.

14. Contact

Data protection and privacy: privacy@authentity.io. Billing: billing@authentity.io.

Postal address: Algiers, Algeria.