Privacy Policy
How WeVerify B.V. collects, uses and protects your personal data in accordance with the GDPR and the eIDAS Regulation.
1. Who are we?
These principles of processing personal data describe how WeVerify B.V. as a data controller ensures the protection of personal data in accordance with applicable laws while offering KYC services. The aim of these principles is to provide information for the subscribers on the relevant topics related to personal data processing and to introduce principles that WeVerify B.V. follows while processing personal data.
These principles do not concern the storage and processing of data of legal persons or other institutions. Should you have any questions relating to the processing of personal data we kindly ask you to contact us using the following contacts:
Data controller: WeVerify B.V.
Address: Otto Reuchlinweg 1142, 3072 MD Rotterdam, The Netherlands
Phone: +31 10 257 99 99
E-mail: info@weverify.com
Data Protection Officer e-mail: dpo@weverify.com
2. Applicable Regulations for Processing Personal Data
2.1 The General Data Protection Regulation
The General Data Protection Regulation 2016 (GDPR) is one of the most significant pieces of legislation affecting the way that WeVerify B.V. carries out its information processing activities. Significant fines are applicable if a breach is deemed to have occurred under the GDPR, which is designed to protect the personal data of citizens of the European Union. It is WeVerify B.V.'s policy to ensure that our compliance with the GDPR and other relevant legislation is clear and demonstrable at all times.
2.2 eIDAS Regulation
Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market, as amended up to 18 October 2024. WeVerify B.V. is guided by the eIDAS Regulation in its document signing activities and service provision. The regulation is directly applicable in the European Union, containing requirements and conditions for providing different trust services, including specific requirements for personal data processing.
3. Which information we collect and process, and why
| Data category | Specific data collected | Purpose | Legal basis |
|---|---|---|---|
| Personal details | First name, last name, middle name (if applicable); street address, city, postal code, country | Document signing, managing your account, communicating about service requests, providing KYC solutions | Contractual necessity; legal obligation |
| Contact information | Email address; phone number (including country code) | Communicating about service requests, managing your account, updates and offers | Contractual necessity; consent (marketing) |
| Identification | National identification number and issuing country; type of identity document, document number, expiry date, issuing authority, scanned copy (if collected) | Document signing, providing KYC solutions | Contractual necessity; legal obligation (KYC) |
| Technical data | Device model, OS version, browser type and version, IP address, device ID; timestamp of access, pages visited, actions taken | Fraud prevention, service optimisation, monitoring usage, security | Legitimate interest; legal obligation |
| Biometric data | Type of biometric data (e.g. facial image), method of collection, purpose (identity verification), storage method (encrypted) | Identity verification, preventing fraud during KYC and digital signing | Explicit consent |
| NFC data | NFC data collected during identity verification | Verifying identity documents (ePassports, national ID cards) containing NFC chips, preventing fraud | Legal obligation; explicit consent |
| Account information | Username, hashed password, account creation date, last login date, account status | Managing your account, providing and securing access | Contractual necessity; legitimate interest (security) |
| Communication data | Content of communications with support (emails, chat, call recordings), date/time and channel | Customer support, improving services, training | Contractual necessity; legitimate interest |
| Payment information | Payment method, card type, expiry, last four digits, billing address, transaction history, amount, date, status (full card details handled by a third-party processor) | Processing payments, managing subscriptions, preventing fraud | Contractual necessity; legal obligation |
| Marketing preferences | Opt-in status, preferred channels, topics of interest | Sending and personalising marketing communications | Explicit consent |
| Location data | General location derived from IP (city, country); precise location data | Personalising content, fraud prevention, location-based services | Legitimate interest; consent (precise location) |
| Usage data | Device information, unique identifiers, diagnostic data (error logs, performance) | Analysing usage, improving experience, troubleshooting, security, monitoring performance | Legitimate interest; contractual necessity; legal obligation |
| KYC data | Proof of identity and address documents, source of funds, PEP status, sanctions screening results | Complying with KYC/AML regulations, preventing fraud and money laundering | Legal obligation |
Legal bases summary:
- Legal obligations — to comply with applicable laws and regulations.
- Consent — where you have provided explicit consent for us to process your data.
- Contractual necessity — to fulfil our obligations under a contract with you.
4. When we collect
- When you create an account.
- When you use our KYC services.
- When you sign contracts or agreements with us.
- When you apply for a job.
- When you interact with our customer support team.
- When you submit forms or request information via our website.
- When you visit our website and consent to cookies.
5. Data retention
WeVerify B.V. processes personal data only as long as necessary for fulfilling the purposes for which the personal data was collected or for fulfilling the obligations arising from applicable legislation. To provide digital signing and KYC services, we are guided by the GDPR for the storage of personal data.
WeVerify B.V. is required to retain evidence used for identifying you during the provision of digital signing services, and logs related to the procedures performed, for at least 10 years. This retention is necessary to investigate any potential misuse of your identity and to demonstrate the appropriateness of WeVerify B.V.'s operations, if required. Retention of data and evidence is required under law and verified by independent auditors and supervisory bodies.
6. Data transfer and disclosure
Your information, including personal data, is processed at the Company's operational offices and any other locations where parties involved in the processing are situated. This means your information may be transferred to and stored on computers located outside of your jurisdiction, where data protection laws may differ. By consenting to this Privacy Policy and providing your information, you agree to such a transfer.
The Company will take all reasonable measures to ensure that your data is handled securely and in accordance with this Privacy Policy. No transfer of your personal data will occur to any organisation or country unless adequate safeguards are in place. If the Company participates in a merger, acquisition, or asset sale, your personal data may be transferred, and we will notify you beforehand. The Company may disclose your personal data when it believes in good faith that such action is necessary to: comply with a legal obligation; protect and defend the rights or property of the Company; prevent or investigate possible wrongdoing in connection with the Service; protect the personal safety of users or the public; or protect against legal liability.
7. Your rights
You have the right to access your personal data, request rectification, deletion, transmission of data and restriction of processing. To exercise these rights, send an electronically signed request to info@weverify.com. We will respond within 30 days.
A request cannot be met where: the identity of the applicant cannot be identified; the applicant is not legally connected with the data; it would be contrary to special laws; it would conflict with WeVerify B.V.'s legal obligations; it may harm the rights and freedoms of another person; it may hinder the provision of the service; or it is not technically possible. Where processing is based on consent, you may withdraw consent at any time. If you believe your rights have been infringed, you may send an electronically signed complaint to info@weverify.com, or file a complaint with your national data protection authority.
8. Consent
Consent must be obtained from a data subject to collect and process their personal data in accordance with the GDPR, with parental consent required for children under 18 (or a lower age defined by individual EU member states). Clear and accessible information regarding the use of personal data and rights, including the right to withdraw consent, is provided at the time of consent. Special categories of personal data, such as biometric data, require explicit consent; WeVerify B.V. asks for this during registration, specifically for the facial image extracted from a video you provide for identity verification. We process personal data within the EU or EEA, and where authorised processors are located outside this area we apply legal safeguards, including adequacy decisions and standard contractual clauses.
9. Breach notification
It is WeVerify B.V.'s policy to be fair and proportionate when considering the actions to inform affected parties regarding breaches of personal data. In line with the GDPR, where a breach is known to have occurred which is likely to result in a risk to the rights and freedoms of individuals, the relevant supervisory authority will be informed within 24 hours.
10. Cookies
WeVerify B.V. uses cookies on its websites. For further information, please read our Cookie Policy.
Questions about your data?
Contact our Data Protection Officer at dpo@weverify.com or our team at info@weverify.com.
