Skip to main content
AIRIN
PricingSign in

Didit policy evolution

Before/after stance changes across captured policy versions, with exact citations. If no before/after delta is available yet, AIRIN shows the latest citation-backed stance events instead.

Diffs
0
Improved
0
Worsened
0
Changed
0
No before/after stance delta is available for this filter yet. Latest citation-backed stance events are shown below.
Jul 20, 2026subprocessors / sharinghigh

data sharing

Latest stance: sale or sell

We may disclose personal data to: The customer that asked us to perform the verification , so the customer can complete onboarding, fraud review, compliance checks, or related business processes. Didit group entities , where necessary to operate, support, secure, or provide the relevant services. Service providers and sub-processors , providers of cloud hosting, storage, infrastructure, communications, support, analytics, fraud prevention, document processing, security, audit, and professional services. A current sub-processor list is available to customers and prospective customers under a signed Non-Disclosure Agreement (NDA) on request to security@didit.me . Professional advisers , lawyers, auditors, insurers, and consultants, where needed for legitimate business, compliance, or legal purposes. Public authorities, regulators, courts, law enforcement, or other third parties , when required by law, legal process, or enforceable governmental request. Successors and transaction counterparties , if Didit is involved in a merger, acquisition, financing, insolvency process, or sale of assets, subject to confidentiality and legal safeguards. Didit does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
Open citation
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

This section supplements this Privacy Policy for California residents and applies whenever Didit is a "business" under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). When Didit is a "service provider" or "contractor" to a Didit customer (a "business" under the CCPA), the customer's privacy notice governs the relevant verification flow and Didit processes personal information under the relevant Data Processing Agreement. Categories of personal information collected in the last 12 months (CCPA categories): Identifiers (name, email, phone, IP address, device identifiers). Customer records (billing, contact, account). Internet or network activity (browsing, interactions, telemetry). Geolocation data (inferred from IP). Sensory data (selfies, face images, liveness video, document images). Professional or employment data (for candidates). Sensitive personal information (SPI), including biometric information used to uniquely identify a consumer, government identifiers contained in identity documents, and account log-in credentials. Inferences drawn from any of the above (risk scores, fraud signals, decision outcomes). Purposes , the purposes listed in Section 4. Sale or sharing of personal information. Didit does not sell or share (as those terms are defined under the CCPA/CPRA) personal information, including biometric information. Use and disclosure of sensitive personal information.
Open citation
Jul 20, 2026privacyhigh

data sharing

Latest stance: sale or sell

Didit uses sensitive personal information only for the purposes permitted under California Civil Code § 1798.121(a) and the implementing regulations , to provide and secure the verification service, prevent fraud and security incidents, comply with legal obligations, and other purposes permitted without a separate consumer right to limit. Your California rights: right to know what personal information is collected, used, disclosed, and sold/shared; right to delete personal information; right to correct inaccurate personal information; right to opt out of sale or sharing (Didit does neither); right to limit use and disclosure of sensitive personal information (Didit's processing is already limited to purposes that do not trigger the right); right to data portability; and right to non-discrimination for exercising any of the above. Submit California requests to privacy@didit.me . Verification of your identity may be required before responding. Authorized agents may submit requests with proof of authorization. Global Privacy Control (GPC) and Do Not Track (DNT). Didit honors browser-based Global Privacy Control signals on the marketing site as an opt-out of sale or sharing, even though Didit does not sell or share personal information, GPC signals are recorded so that no advertising or analytics cookie that could be construed as sharing is set for that browser. Didit does not currently respond to legacy Do Not Track (DNT) headers because there is no industry consensus on how to interpret them; the GPC signal supersedes DNT for Didit's purposes.
Open citation
Jul 20, 2026retentionmedium

retention

Latest stance: indefinite or necessity based

Didit retains personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to: provide and support the relevant services; follow customer instructions in processor relationships; comply with contractual, legal, tax, accounting, and regulatory obligations; maintain security and fraud-prevention records; resolve disputes; and establish, exercise, or defend legal claims. Retention periods vary by service, workflow configuration, applicable law, and the role Didit plays in the processing: Business relationship data is typically retained for the duration of the relationship and for lawful post-termination recordkeeping periods. Support and audit records may be retained for operational, security, and compliance purposes. Recruitment data is retained for the recruitment process and any lawful follow-up period, or longer if you separately consent. Verification data , the default retention is indefinite ("unlimited"), unless the customer configures a shorter period . Customers configure retention per application in the Business Console between 30 days and 10 years , or trigger a per-session delete at any time via the API endpoint `POST /v3/sessions/:session_id/delete/`. End users may also exercise deletion rights as described in Section 9. Biometric data retention is in every case subject to, and capped by, applicable biometric-privacy laws and regulations , including the EU General Data Protection Regulation (GDPR) Article 9, the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington H.B.
Open citation

Generated from live stance events. Informational only, not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.