Digitrust
Log in

On this page

  • 1. Who we are
  • 2. Scope
  • 3. Roles
  • 4. Categories of personal data
  • 5. Purposes and lawful bases
  • 6. How verification works
  • 7. Sub-processors
  • 8. International transfers
  • 9. Retention
  • 10. Security
  • 11. Your rights
  • 12. Customer responsibilities
  • 13. Cookies and analytics
  • 14. Children
  • 15. Changes
  • 16. Contact

Privacy Policy

How Digitrust collects and uses personal data

Last updated: 2026-06-04 · Version 1.0

DIGITRUST TECHNOLOGIES - FZCO

Free Zone Company (FZCO) · IFZA (Dubai Integrated Economic Zones)

IFZA Business Park, DDP, P.O. Box 342001, Dubai, United Arab Emirates

Trade license no. 61834

Contact: legal@digitrust.ae

1. Who we are

DIGITRUST TECHNOLOGIES - FZCO ("Digitrust", "we", "us") provides a B2B identity verification platform. This Privacy Policy explains how we handle personal data when you use our website and application, when your organisation uses our Service, and when individuals complete verification at your request.

Registered office: IFZA Business Park, DDP, P.O. Box 342001, Dubai, United Arab Emirates. Contact: legal@digitrust.ae.

2. Scope

This policy applies to business users (Customer administrators and Authorized Users) and to visitors of our public pages.

When your organisation sends verification requests to individuals ("Subjects"), you are typically the data controller for Subject data and Digitrust acts as your processor. A separate notice is shown to Subjects at verification. See our Data Processing Agreement (/dpa).

3. Roles

Controller (Digitrust): account registration, billing, security, support, product analytics, and compliance for our own operations.

Processor (Digitrust): processing Subject personal data on documented instructions from Customers.

Controller (Customer): purposes and lawful basis for verifying Subjects; notices to Subjects; responding to Subject rights requests where applicable.

4. Categories of personal data

Customer users: name, email, role, company affiliation, authentication identifiers, activity logs.

Billing: company name, billing contact, payment metadata via Stripe (we do not store full card numbers).

Subjects (on Customer instruction): name, email, phone, government ID data, biometric/liveness images, verification scores, AML screening results, device/session metadata from IDV flows.

Technical: IP address, browser type, cookies and similar technologies (see /cookies).

5. Purposes and lawful bases

We process data to provide and secure the Service, process payments, support users, improve the product, comply with law, and prevent abuse.

Lawful bases may include contract performance, legitimate interests (security, analytics, service improvement), legal obligation, and consent where required (e.g. non-essential cookies when a consent mechanism is enabled).

Customers must establish their own lawful basis for Subject verification under applicable law.

6. How verification works

Subjects receive a link, verify contact ownership via OTP (email/SMS), and complete identity checks through our IDV Provider (Didit), which may include document capture, NFC, liveness, and face matching.

Results and images may be stored in our database and private storage bucket. Customers access results through the dashboard.

7. Sub-processors

We use trusted providers to operate the Service. A current list is in our DPA Annex II and summarised in our Terms Schedule C. Categories include hosting, database, IDV, email, SMS, payments, and analytics.

8. International transfers

Personal data may be processed in the UAE and other countries where our sub-processors operate. We implement appropriate safeguards as described in the DPA, including standard contractual clauses where required for transfers from the EEA/UK.

9. Retention

Verification records and related documents: typically twenty-four (24) months after completion, unless law or your agreement requires otherwise.

Account data: while your organisation maintains an active account and for up to twelve (12) months after termination unless deletion is requested earlier.

Billing records: as required for tax and accounting laws.

10. Security

We use access controls, encryption in transit, private storage for ID images, row-level security in our database, and least-privilege administrative access. No method is 100% secure; report concerns to legal@digitrust.ae.

11. Your rights

Depending on applicable law (including the UAE PDPL), you may have rights to access, rectify, erase, restrict, object, or port your personal data, and to withdraw consent where processing is consent-based.

Contact legal@digitrust.ae to exercise rights relating to data for which Digitrust is controller. For Subject data, contact the organisation that requested your verification in the first instance.

You may lodge a complaint with the UAE Data Office or your local supervisory authority where applicable.

12. Customer responsibilities

If you are a Customer, you are responsible for providing privacy notices to Subjects, responding to Subject requests, and ensuring your instructions to Digitrust comply with law.

13. Cookies and analytics

We use essential cookies for authentication and preferences, and analytics (Seline) to understand product usage. Details are in our Cookie Policy (/cookies).

14. Children

The Service is not directed to children under 18. Customers must not request verification of minors unless they have a lawful basis and appropriate safeguards.

15. Changes

We may update this policy. Material changes will be notified by email or in-app notice. The "Last updated" date shows the current version.

16. Contact

Privacy enquiries: legal@digitrust.ae. Support: support@digitrust.ae.

TermsPrivacyDPACookiesSupport