Skip to main content
Platform Review
PricingSign in
← All platforms
Workflow & Automation · didit.me

Didit

Graded against 811 verified platforms, from its own policy text. Automated assessment against a published rubric — not legal advice.

Overall riskLOWReviewed 2026-07-20
Creator: low · GRC: low · Counsel: low
Benchmark

No lens is bandable yet — banding requires fully verified documents with on-criteria findings. The gap is shown honestly, never estimated.

Exhibit A · Privacy Policy · verbatim

Didit trains, evaluates, and improves its identity-verification, biometric, and fraud-detection models, and operates cross-customer fraud-prevention safeguards, using anonymized or pseudonymized data derived from verification activity (for example: document features, fraud signals, attack patterns, model-error samples). Didit applies anonymization,

highest-risk verified finding on training use — tap for the citation
20 verified findings5 policy surfaces1/1 core docs verified

Partially verified: Privacy Policy assessed. Everything below comes only from what was read in full.

Risk triage

Watch: Data retention

Start here. These are the highest-risk verified clauses AIRIN found in the platform's own policy text.

0
high
1
medium
4
low
1/1
docs
Trains on your data?
No training on your content by default
from 1 cited finding
Who owns outputs?
Not yet assessed
no verified finding covers this surface yet
Commercial use?
Not yet assessed
no verified finding covers this surface yet
Every rating:verbatim-citedsnapshot-datedchange-loggedHow we keep ratings honest →

How to read this page: Overall risk rates what Didit's own policy terms mean for your prompts, outputs, and data. The benchmark bands below grade those same verified terms relative to peers — a platform in a risky-by-default category can rate HIGH risk and still grade STRONG against its peer set. Both trace to the cited findings.

Partially verifiedWorkflow & Automation

Partially verified — Privacy Policy — Verified (read in full, 20 findings). Findings below are from fully-read, verified documents only; remaining core documents are pending capture.

Why partial?

Terms not yet captured

AIRIN has not yet captured a gate-verified Terms of Service document for this platform.

Document status
  • Privacy Policy
    Verified - read in full - 20 citationsLast captured 2026-07-20
Tier conditions

Only citation-backed plan differences are shown here; absent cells mean AIRIN has not verified a tier-specific claim.

plan language
Training on your content

Describes Didit's practice of training, evaluating, and improving identity-verification, biometric, and fraud-detection models using anonymized or pseudonymized data derived from verification activity, and states that Didit applies anonymization, pseudonymization, aggregation, and access controls so that training data cannot reasonably be linked back to an identifiable individual — a user-favorable restriction on how training data may be used — and notes the legitimate-interest legal basis for this processing.

" Didit trains, evaluates, and improves its identity-verification, biometric, and fraud-detection models, and operates cross-customer fraud-prevention safeguards, using anonymized or pseudonymized data derived from verification activity (for..."
📍 § 11 (Anonymized model training and fraud detection, your opt-out)Jump to exact text →
plan language
Privacy & data use

Defines the scope and purpose of the Privacy Policy, identifies the processor/controller relationship between Didit and its customers in verification flows, and introduces the roles of 'controller,' 'processor,' and 'service provider' that govern downstream data-processing obligations throughout the document.

" This Privacy Policy explains how Didit processes personal data when you visit our websites, contact us, use our products and services, or complete an identity or fraud verification flow powered by Didit. If you are verifying your identity..."
📍 Privacy Policy › “On this page +”Jump to exact text →
plan language
Privacy & data use

Defines the scope of the Privacy Policy by enumerating the specific activities and relationships to which it applies, establishing the basis for which processing activities are covered by the document.

" This Privacy Policy applies when you: visit `didit.me` or any Didit-operated website; request information, a demo, or support; create or manage a Didit business relationship, account, or integration; apply for a role with Didit; or us..."
📍 § 2 (Scope and our role)Jump to exact text →
plan language
Privacy & data use

Defines three distinct roles Didit plays (controller, processor/service provider, and independent controller) depending on the processing context, including an explicit reference to training fraud-detection models on anonymized or pseudonymized data as an independent controller activity, thereby allocating processing responsibilities.

" Website visitors, marketing, recruiting, sales, support, and direct business relationships Controller Didit decides why and how the data is processed for those direct interactions. Verification flows requested by a Didit customer Process..."
📍 Privacy Policy › “Context Didit's role What that means”Jump to exact text →
plan language
Privacy & data use

Enumerates the categories of personal data Didit may process, including identifiers, business data, verification data (including identity document images and biometric-adjacent inputs), and other data types, defining the scope of personal data subject to the policy's obligations and restrictions.

" The categories of data we process depend on the service, workflow configuration, and your relationship with Didit. They may include: Identifiers and contact data , name, email address, phone number, mailing address, date of birth, and sim..."
📍 § 3 (Categories of personal data we process)Jump to exact text →
plan language
Privacy & data use

Enumerates the specific purposes for which Didit may use personal data, including operating services, providing identity and fraud infrastructure, securing the platform, and training and evaluating fraud-detection models, establishing the permissible scope of processing as an obligation of purpose limitation.

" We may use personal data for the following purposes: To operate our websites and services , account access, product delivery, customer support, billing, and communications. To provide identity and fraud infrastructure services , User Ver..."
📍 § 4 (How we use personal data)Jump to exact text →
plan language
Privacy & data use

Identifies the legal bases Didit relies upon to process personal data under applicable data protection laws, including contract performance, legitimate interests (expressly covering fraud-detection model training on anonymized or pseudonymized data), and consent, defining the lawful grounds for each category of processing.

" Where the General Data Protection Regulation (GDPR), United Kingdom GDPR, Swiss data protection law, or similar laws apply, Didit relies on one or more of the following legal bases: Performance of a contract or steps taken at your request..."
📍 § 5 (Legal bases for processing)Jump to exact text →
plan language
Privacy & data use

Defines the scope of the California-specific addendum, specifying when Didit is a 'business' versus 'service provider' or 'contractor' under applicable state consumer privacy law, and enumerates the categories of personal information collected in the preceding 12 months as defined under that law.

" This section supplements this Privacy Policy for California residents and applies whenever Didit is a "business" under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). When Didit is a "ser..."
Conflicting provisions (1)
  • Clause A states that personal data may be used for fraud model training, while Clause B specifies that only anonymized or pseudonymized data is used for this purpose when Didit acts as an independent controller.

    " We may use personal data for the following purposes: To operate our websites and services , account access, product delivery, customer support, billing, and communications. To provide identity and fraud infrastructure services , User Verification (Know Your Customer / KYC), Business Verification (Know Your Business / KYB), Transaction Monitoring, Wallet Screening (Know Your Transaction / KYT), and other configured checks. To secure the platform , prevent abuse, detect spoofing, prevent fraud, monitor suspicious activity, and maintain service integrity. To train, evaluate, and improve fraud-detection and verification models using anonymized or pseudonymized data derived from verification activity, where permitted by law. See Section 11 for the opt-out. To respond to requests , demo requests, support questions, due diligence requests, and business communications. To manage recruiting and hiring , review applications and communicate with candidates. To comply with legal and regulatory obligations , maintain records, respond to lawful requests, enforce contracts, and carry out internal or external audits. To establish, exercise, or defend legal claims and protect the rights, safety, and security of Didit, our customers, and affected individuals."
    " Website visitors, marketing, recruiting, sales, support, and direct business relationships Controller Didit decides why and how the data is processed for those direct interactions. Verification flows requested by a Didit customer Processor / Service Provider The customer decides why the verification happens and what checks are enabled. Didit processes data on the customer's behalf. Security, abuse prevention, service integrity, audit logging, legal compliance, fraud-model training and validation on anonymized or pseudonymized data, and legal claims Independent controller for that specific purpose Didit may process limited data to secure the platform, train and improve fraud-detection and verification models, comply with law, and establish, exercise, or defend legal claims. "
    Within one document

Evidence appendix

Showing priority citations first. The full appendix is available for audit trails; not every citation is a severe risk.

High - 0
Medium - 1
Tier-specific - 0
Total citations - 20
Severity
Surface
Document
Tier
Data retention
High
" Didit retains personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to: provide and support the relevant services; follow customer instructions in processor relationships; comply with contractual, legal, tax, accounting, and regulatory obligations; maintain security and fraud-prevention records; resolve disputes; and establish, exercise, or defend legal claims. Retention periods vary by service, workflow configuration, applicable law, and the role Didit plays in the processing: Business relationship data is typically retained for the duration of the relationship and for lawful post-termination recordkeeping periods. Support and audit records may be retained for operational, security, and compliance purposes. Recruitment data is retained for the recruitment process and any lawful follow-up period, or longer if you separately consent. Verification data , the default retention is indefinite ("unlimited"), unless the customer configures a shorter period . Customers configure retention per application in the Business Console between 30 days and 10 years , or trigger a per-session delete at any time via the API endpoint `POST /v3/sessions/:session_id/delete/`. End users may also exercise deletion rights as described in Section 9. Biometric data retention is in every case subject to, and capped by, applicable biometric-privacy laws and regulations , including the EU General Data Protection Regulation (GDPR) Article 9, the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington H.B. "
§ 8 (Retention)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Establishes Didit's data retention obligations, specifying that personal data is retained for as long as reasonably necessary for enumerated purposes including service provision, legal compliance, fraud prevention, dispute resolution, and legal claims, and notes that retention periods vary by service, configuration, applicable law, and Didit's processing role.

AI-generated interpretation, not legal advice.

Training on your content
High
" Didit trains, evaluates, and improves its identity-verification, biometric, and fraud-detection models, and operates cross-customer fraud-prevention safeguards, using anonymized or pseudonymized data derived from verification activity (for example: document features, fraud signals, attack patterns, model-error samples). Didit applies anonymization, pseudonymization, aggregation, and access controls so that the data used for training and fraud detection cannot reasonably be linked back to an identifiable individual outside the underlying verification record. This processing is grounded in Didit's legitimate interest in: improving the accuracy and safety of identity and fraud infrastructure used by all customers; detecting and preventing fraud, identity-theft attacks, deepfakes, and known-attacker repeat attempts; and meeting regulatory expectations around model performance, fairness, and security. Opt-out. A customer or end user may opt their data out of model training and fraud-detection processing by: deleting the underlying verification record via the API or the Business Console (the deletion removes the record from training pipelines on the next refresh cycle), or emailing privacy@didit.me with the relevant session identifier or account, requesting an opt-out. Opt-outs apply prospectively from the date of the request; Didit will also use commercially reasonable efforts to purge eligible records from active training datasets."
§ 11 (Anonymized model training and fraud detection, your opt-out)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes Didit's practice of training, evaluating, and improving identity-verification, biometric, and fraud-detection models using anonymized or pseudonymized data derived from verification activity, and states that Didit applies anonymization, pseudonymization, aggregation, and access controls so that training data cannot reasonably be linked back to an identifiable individual — a user-favorable restriction on how training data may be used — and notes the legitimate-interest legal basis for this processing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This section supplements this Privacy Policy for California residents and applies whenever Didit is a "business" under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). When Didit is a "service provider" or "contractor" to a Didit customer (a "business" under the CCPA), the customer's privacy notice governs the relevant verification flow and Didit processes personal information under the relevant Data Processing Agreement. Categories of personal information collected in the last 12 months (CCPA categories): Identifiers (name, email, phone, IP address, device identifiers). Customer records (billing, contact, account). Internet or network activity (browsing, interactions, telemetry). Geolocation data (inferred from IP). Sensory data (selfies, face images, liveness video, document images). Professional or employment data (for candidates). Sensitive personal information (SPI), including biometric information used to uniquely identify a consumer, government identifiers contained in identity documents, and account log-in credentials. Inferences drawn from any of the above (risk scores, fraud signals, decision outcomes). Purposes , the purposes listed in Section 4. Sale or sharing of personal information. Didit does not sell or share (as those terms are defined under the CCPA/CPRA) personal information, including biometric information. Use and disclosure of sensitive personal information. "
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the scope of the California-specific addendum, specifying when Didit is a 'business' versus 'service provider' or 'contractor' under applicable state consumer privacy law, and enumerates the categories of personal information collected in the preceding 12 months as defined under that law.

AI-generated interpretation, not legal advice.

Privacy & data use
High
"Didit uses sensitive personal information only for the purposes permitted under California Civil Code § 1798.121(a) and the implementing regulations , to provide and secure the verification service, prevent fraud and security incidents, comply with legal obligations, and other purposes permitted without a separate consumer right to limit. Your California rights: right to know what personal information is collected, used, disclosed, and sold/shared; right to delete personal information; right to correct inaccurate personal information; right to opt out of sale or sharing (Didit does neither); right to limit use and disclosure of sensitive personal information (Didit's processing is already limited to purposes that do not trigger the right); right to data portability; and right to non-discrimination for exercising any of the above. Submit California requests to privacy@didit.me . Verification of your identity may be required before responding. Authorized agents may submit requests with proof of authorization. Global Privacy Control (GPC) and Do Not Track (DNT). Didit honors browser-based Global Privacy Control signals on the marketing site as an opt-out of sale or sharing, even though Didit does not sell or share personal information, GPC signals are recorded so that no advertising or analytics cookie that could be construed as sharing is set for that browser. Didit does not currently respond to legacy Do Not Track (DNT) headers because there is no industry consensus on how to interpret them; the GPC signal supersedes DNT for Didit's purposes."
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts Didit's use of sensitive personal information to enumerated permitted purposes only and enumerates California consumers' privacy rights, including the right to know, delete, correct, opt out of sale or sharing (expressly stating Didit does neither), and limit use of sensitive personal information, establishing both obligations on Didit and rights for California residents.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Didit's public websites and standard business services are not directed to children. Some customers may lawfully use Didit for age-related or identity-related checks involving younger users, but that use must be supported by an appropriate legal basis and the customer's own notices. If you believe personal data was submitted to Didit without proper authorization, contact privacy@didit.me ."
§ 14 (Children)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Restricts Didit's general services from being directed to children, while recognizing an exception where customers may lawfully conduct age- or identity-related checks involving younger users provided those uses are supported by an appropriate legal basis and the customer's own notices; also provides a contact address for reporting unauthorized submissions of personal data involving minors.

AI-generated interpretation, not legal advice.

Subprocessors & data sharing
High
" We may disclose personal data to: The customer that asked us to perform the verification , so the customer can complete onboarding, fraud review, compliance checks, or related business processes. Didit group entities , where necessary to operate, support, secure, or provide the relevant services. Service providers and sub-processors , providers of cloud hosting, storage, infrastructure, communications, support, analytics, fraud prevention, document processing, security, audit, and professional services. A current sub-processor list is available to customers and prospective customers under a signed Non-Disclosure Agreement (NDA) on request to security@didit.me . Professional advisers , lawyers, auditors, insurers, and consultants, where needed for legitimate business, compliance, or legal purposes. Public authorities, regulators, courts, law enforcement, or other third parties , when required by law, legal process, or enforceable governmental request. Successors and transaction counterparties , if Didit is involved in a merger, acquisition, financing, insolvency process, or sale of assets, subject to confidentiality and legal safeguards. Didit does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information."
§ 6 (How we disclose personal data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Discloses the categories of third parties to whom Didit may share personal data, including customers, group entities, and service providers/sub-processors, and states that a current sub-processor list is available to customers under a specified access condition, establishing disclosure obligations and data-sharing scope.

AI-generated interpretation, not legal advice.

Audit rights / DPA / residency
High
" Didit may process data in multiple countries. When personal data is transferred outside the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, Didit uses appropriate safeguards where required, including: adequacy decisions; the European Commission's 2021 Standard Contractual Clauses (SCCs) and any equivalent UK or Swiss addenda; intra-group transfer arrangements; or another lawful transfer mechanism recognized by applicable law."
§ 7 (International transfers)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes the safeguards Didit uses when transferring personal data internationally, including adequacy decisions, Standard Contractual Clauses and equivalent addenda, and other recognized transfer mechanisms, establishing Didit's obligation to implement appropriate cross-border transfer protections.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This Privacy Policy explains how Didit processes personal data when you visit our websites, contact us, use our products and services, or complete an identity or fraud verification flow powered by Didit. If you are verifying your identity for a bank, fintech, crypto platform, marketplace, employer, or another organization that uses Didit, that organization is the party that decides why the verification is required. In those cases, it is the controller or business , and Didit acts as its processor or service provider . For verification-specific processing, biometric data, and white-label flows, read our Verification Privacy Notice and End User Terms for Identity Verification ."
Privacy Policy › “On this page +”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the scope and purpose of the Privacy Policy, identifies the processor/controller relationship between Didit and its customers in verification flows, and introduces the roles of 'controller,' 'processor,' and 'service provider' that govern downstream data-processing obligations throughout the document.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Depending on the service and geography, your data may be processed by one or both of the following Didit entities: Didit Identity Spain, S.L. , CIF B22929327, Calle Nápoles 227, P. 1, 08013 Barcelona, Spain. Contracting entity for European Union, United Kingdom, European Economic Area, and Switzerland customers and the establishment that operates the European data plane. Didit Identity, Inc. , EIN 39-2860573, 1111B S Governors Ave STE 34855, Dover, Delaware 19904, United States. Contracting entity for United States, Canada, Latin America, Asia-Pacific, Middle East, and global customers. When we say "Didit" , "we" , "us" , or "our" , we mean the Didit entity or entities providing the applicable service. Privacy contact: privacy@didit.me Data Protection Officer: dpo@didit.me Security contact: security@didit.me General contact: hello@didit.me "
§ 1 (Who we are)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Identifies the two Didit legal entities that may process personal data, specifying their registered details and the geographic customer bases each entity serves, thereby defining which contracting party bears processing obligations depending on the user's geography.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" This Privacy Policy applies when you: visit `didit.me` or any Didit-operated website; request information, a demo, or support; create or manage a Didit business relationship, account, or integration; apply for a role with Didit; or use a verification, fraud-prevention, authentication, or compliance flow operated by or through Didit. Our role changes depending on the context:"
§ 2 (Scope and our role)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines the scope of the Privacy Policy by enumerating the specific activities and relationships to which it applies, establishing the basis for which processing activities are covered by the document.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Website visitors, marketing, recruiting, sales, support, and direct business relationships Controller Didit decides why and how the data is processed for those direct interactions. Verification flows requested by a Didit customer Processor / Service Provider The customer decides why the verification happens and what checks are enabled. Didit processes data on the customer's behalf. Security, abuse prevention, service integrity, audit logging, legal compliance, fraud-model training and validation on anonymized or pseudonymized data, and legal claims Independent controller for that specific purpose Didit may process limited data to secure the platform, train and improve fraud-detection and verification models, comply with law, and establish, exercise, or defend legal claims. "
Privacy Policy › “Context Didit's role What that means”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Defines three distinct roles Didit plays (controller, processor/service provider, and independent controller) depending on the processing context, including an explicit reference to training fraud-detection models on anonymized or pseudonymized data as an independent controller activity, thereby allocating processing responsibilities.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" If you are in a white-label verification flow or on a custom domain, custom branding does not necessarily mean only the branded company processes your data. Didit may still provide the underlying verification technology and related processing."
Privacy Policy › “Context Didit's role What that means”Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Clarifies that white-label or custom-branded verification flows do not eliminate Didit's role as an underlying data processor, ensuring users understand that Didit may still process their data even when the interface is branded by another organization.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" The categories of data we process depend on the service, workflow configuration, and your relationship with Didit. They may include: Identifiers and contact data , name, email address, phone number, mailing address, date of birth, and similar identifying information. Business and account data , company name, billing information, account credentials, API usage details, and records of your relationship with Didit. Verification data , identity document images, extracted document data, proof-of-address files, questionnaire answers, sanctions or watchlist screening inputs, and verification outcomes. Biometric and liveness data , where the workflow includes face verification or similar checks, selfies, face images, videos, liveness captures, anti-spoofing signals, and data derived from scans of facial geometry. Device, network, and technical data , IP address, browser type, operating system, language, device identifiers, timestamps, geolocation inferred from network data, and other security or anti-fraud telemetry. Communications and support data , messages, support tickets, call records, email exchanges, and operational logs. Third-party and public-source data , information provided by our customers, identity or fraud-prevention partners, public authorities, telecom providers, and publicly available sources where permitted by law. Recruitment data , CVs, employment history, and other materials submitted during hiring. We do not need every category listed above for every interaction. The exact data used depends on the services requested and the configuration selected by the relevant customer."
§ 3 (Categories of personal data we process)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates the categories of personal data Didit may process, including identifiers, business data, verification data (including identity document images and biometric-adjacent inputs), and other data types, defining the scope of personal data subject to the policy's obligations and restrictions.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" We may use personal data for the following purposes: To operate our websites and services , account access, product delivery, customer support, billing, and communications. To provide identity and fraud infrastructure services , User Verification (Know Your Customer / KYC), Business Verification (Know Your Business / KYB), Transaction Monitoring, Wallet Screening (Know Your Transaction / KYT), and other configured checks. To secure the platform , prevent abuse, detect spoofing, prevent fraud, monitor suspicious activity, and maintain service integrity. To train, evaluate, and improve fraud-detection and verification models using anonymized or pseudonymized data derived from verification activity, where permitted by law. See Section 11 for the opt-out. To respond to requests , demo requests, support questions, due diligence requests, and business communications. To manage recruiting and hiring , review applications and communicate with candidates. To comply with legal and regulatory obligations , maintain records, respond to lawful requests, enforce contracts, and carry out internal or external audits. To establish, exercise, or defend legal claims and protect the rights, safety, and security of Didit, our customers, and affected individuals."
§ 4 (How we use personal data)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates the specific purposes for which Didit may use personal data, including operating services, providing identity and fraud infrastructure, securing the platform, and training and evaluating fraud-detection models, establishing the permissible scope of processing as an obligation of purpose limitation.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Where the General Data Protection Regulation (GDPR), United Kingdom GDPR, Swiss data protection law, or similar laws apply, Didit relies on one or more of the following legal bases: Performance of a contract or steps taken at your request before entering into a contract. Legitimate interests , securing our platform, supporting customers, preventing fraud, maintaining records, training and improving fraud-detection and verification models on anonymized or pseudonymized data, and communicating with business contacts, provided those interests are not overridden by your rights. Consent , including where consent is required for marketing communications, certain cookies, or biometric processing in a particular jurisdiction or workflow. Legal obligation , where processing is required to comply with applicable law, regulation, court order, or lawful request from authorities. Establishment, exercise, or defense of legal claims . Where special-category or sensitive data is processed, including biometric data used to uniquely identify you, Didit processes that data only where permitted by applicable law. In verification flows, the relevant customer is responsible for determining and documenting the primary legal basis for the verification itself, including whether explicit consent is required."
§ 5 (Legal bases for processing)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Identifies the legal bases Didit relies upon to process personal data under applicable data protection laws, including contract performance, legitimate interests (expressly covering fraud-detection model training on anonymized or pseudonymized data), and consent, defining the lawful grounds for each category of processing.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Depending on your location and the applicable law, you may have the right to: access your personal data; request correction of inaccurate or incomplete data; request deletion or erasure; request restriction of processing; object to certain processing, including processing on the basis of legitimate interests (see Section 11 for the model-training and fraud-detection opt-out); withdraw consent where processing is based on consent; request portability of the data you provided; not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, subject to the conditions and exceptions in Article 22 GDPR; and lodge a complaint with a supervisory authority. Didit's lead supervisory authority is the Spanish Data Protection Agency (Agencia Española de Protección de Datos / AEPD) at `aepd.es`. When Didit acts as controller, submit privacy requests to privacy@didit.me or dpo@didit.me . When Didit acts as processor or service provider for a customer verification flow, direct your request to the organization that asked you to verify. That customer controls the purpose of the verification and is best positioned to respond. If Didit receives such a request directly, we may forward it to the relevant customer."
§ 9 (Your rights)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Enumerates the individual rights available to users depending on their location and applicable law, including access, correction, deletion, restriction, objection (including an opt-out for model training and fraud detection referenced in Section 11), consent withdrawal, data portability, and freedom from solely automated decision-making, and instructs users how to exercise these rights.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Didit uses cookies and similar technologies on its websites for functionality, security, analytics, and attribution. Read our Cookies Policy for the full inventory, the consent banner controls, and our Global Privacy Control (GPC) and Do Not Track (DNT) posture."
§ 10 (Cookies and similar technologies)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Describes Didit's use of cookies and similar technologies for functionality, security, analytics, and attribution, and incorporates by reference a separate Cookies Policy for the full inventory and consent controls including GPC and DNT posture.

AI-generated interpretation, not legal advice.

Privacy & data use
High
" Didit uses administrative, technical, and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, and unlawful destruction, including encryption at rest with AES-256, encryption in transit with TLS 1.3, key management in AWS KMS, role-based access control, environment separation, continuous monitoring, vendor oversight, and incident response procedures. See the Information Security Policy for the full posture and certifications. No security measure is perfect. You should also protect your own devices, credentials, and communications."
§ 13 (Security)Jump to exact text →
Source: Privacy Policy- Snapshot 2026-07-20- View source
Permalink to this finding →
Automated analysis

Imposes an obligation on Didit to implement specified administrative, technical, and organizational safeguards (including enumerated controls such as encryption at rest, encryption in transit, key management, role-based access control, environment separation, continuous monitoring, vendor oversight, and incident response) to protect personal data against unauthorized access, loss, misuse, alteration, and unlawful destruction; also includes a disclaimer that no security measure is perfect and an advisory that users should protect their own devices and credentials.

AI-generated interpretation, not legal advice.

Common questions about Didit's policies

Does Didit train its AI models on your data?
No training on your content by default — based on 1 verified finding from Didit's published policy. Informational only, not legal advice.

Clause detail — protections, your obligations, and coverage

Every clause below is a verbatim quote from Didit's own published policy, read in full and linked to its exact location. Protections and user obligations are reported separately from risk because they are different kinds of clause — an obligation on you is not a risk to your data. Informational only, not legal advice.

✅ Protections found

0 verified clauses

Clauses in Didit's policies that work in your favour — commitments the platform made to you.

No protective clause has been verified in Didit's published policies yet. That means we did not find one in the documents we read — not that the platform offers nothing.

📋 Rules you must follow

0 verified clauses

What Didit requires of YOU. These are your obligations, not risks to your data or IP, so they are cited here and excluded from this platform's risk rating.

No user-conduct rule has been verified in Didit's published policies yet.

What the policies actually cover

0 topics

None of Didit's verified clauses has been assigned a topic yet. The clause-trust review has not reached this platform's findings.

Cross-clause notes

Cross-reference

Two verified clauses intersect on the same subject matter: the Privacy Policy, § 8 (Retention) addresses how long content is retained, and the Privacy Policy, § 11 (Anonymized model training and fraud detection, your opt-out) addresses use of content in connection with model training or service improvement. Both clauses are in force at the same time — read them together.

Automated cross-reference against the published rubric — not legal advice.

Clause intelligence

Canonical clauses and stance patterns extracted from the same gate-verified citations shown on this page.

21
clauses
4
patterns
4
stances
privacy sharing · 3data retention · 1
data retentionMEDIUM§ 8 (Retention)

The clause allows indefinite, perpetual, or necessity-based retention.

Didit retains personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to: provide and support the relevant services; follow customer instructions in processor relationships; comply with contractual, legal, tax, accounting, and regulatory obligations; maintain security and fraud-prevention records; resolve disputes; and establish, exercise, or defend legal clai...
Open source citation
privacy sharingHIGH§ 6 (How we disclose personal data)

The clause permits sale of personal data or information.

We may disclose personal data to: The customer that asked us to perform the verification , so the customer can complete onboarding, fraud review, compliance checks, or related business processes. Didit group entities , where necessary to operate, support, secure, or provide the relevant services. Service providers and sub-processors , providers of cloud hosting, storage, infrastructure, communications, support, an...
Open source citation
privacy sharingHIGH§ 12

The clause permits sale of personal data or information.

This section supplements this Privacy Policy for California residents and applies whenever Didit is a "business" under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). When Didit is a "service provider" or "contractor" to a Didit customer (a "business" under the CCPA), the customer's privacy notice governs the relevant verification flow and Didit processes pe...
Open source citation
privacy sharingHIGH§ 12

The clause permits sale of personal data or information.

Didit uses sensitive personal information only for the purposes permitted under California Civil Code § 1798.121(a) and the implementing regulations , to provide and secure the verification service, prevent fraud and security incidents, comply with legal obligations, and other purposes permitted without a separate consumer right to limit. Your California rights: right to know what personal information is collected...
Open source citation

Tier matrix

Plan-level conditions detected from citation-backed clauses. Empty tiers mean AIRIN has not captured decisive tier language yet.

TierSurfaceVerdictRiskCitations
All applicable tiersprivacy data useworsensHIGH1
Team / Businessdata retentionconditionalMEDIUM1
Team / Businessprivacy data useworsensHIGH1
Team / Businesssubprocessors data sharingworsensHIGH1

Policy evolution

Open full timeline

Before/after stance changes across captured policy versions. When no material delta exists yet, AIRIN shows the latest citation-backed stance events instead.

Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on subprocessors data sharing

We may disclose personal data to: The customer that asked us to perform the verification , so the customer can complete onboarding, fraud review, compliance checks, or related business processes. Didit group entities , where necessary to operate, support, secure, or provide the relevant services. Service providers and sub-processors , providers of cloud hosting, storage, infrastructure, communications, support, analytics, fraud prevention, document processing, security, audit, and professional services. A current sub-processor list is available to customers and prospective customers under a signed Non-Disclosure Agreement (NDA) on request to security@didit.me . Professional advisers , lawyers, auditors, insurers, and consultants, where needed for legitimate business, compliance, or legal purposes. Public authorities, regulators, courts, law enforcement, or other third parties , when required by law, legal process, or enforceable governmental request. Successors and transaction counterparties , if Didit is involved in a merger, acquisition, financing, insolvency process, or sale of assets, subject to confidentiality and legal safeguards. Didit does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
Open timeline citation
Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

This section supplements this Privacy Policy for California residents and applies whenever Didit is a "business" under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). When Didit is a "service provider" or "contractor" to a Didit customer (a "business" under the CCPA), the customer's privacy notice governs the relevant verification flow and Didit processes personal information under the relevant Data Processing Agreement. Categories of personal information collected in the last 12 months (CCPA categories): Identifiers (name, email, phone, IP address, device identifiers). Customer records (billing, contact, account). Internet or network activity (browsing, interactions, telemetry). Geolocation data (inferred from IP). Sensory data (selfies, face images, liveness video, document images). Professional or employment data (for candidates). Sensitive personal information (SPI), including biometric information used to uniquely identify a consumer, government identifiers contained in identity documents, and account log-in credentials. Inferences drawn from any of the above (risk scores, fraud signals, decision outcomes). Purposes , the purposes listed in Section 4. Sale or sharing of personal information. Didit does not sell or share (as those terms are defined under the CCPA/CPRA) personal information, including biometric information. Use and disclosure of sensitive personal information.
Open timeline citation
Jul 20, 2026data sharingHIGH

Latest stance: sale or sell on privacy data use

Didit uses sensitive personal information only for the purposes permitted under California Civil Code § 1798.121(a) and the implementing regulations , to provide and secure the verification service, prevent fraud and security incidents, comply with legal obligations, and other purposes permitted without a separate consumer right to limit. Your California rights: right to know what personal information is collected, used, disclosed, and sold/shared; right to delete personal information; right to correct inaccurate personal information; right to opt out of sale or sharing (Didit does neither); right to limit use and disclosure of sensitive personal information (Didit's processing is already limited to purposes that do not trigger the right); right to data portability; and right to non-discrimination for exercising any of the above. Submit California requests to privacy@didit.me . Verification of your identity may be required before responding. Authorized agents may submit requests with proof of authorization. Global Privacy Control (GPC) and Do Not Track (DNT). Didit honors browser-based Global Privacy Control signals on the marketing site as an opt-out of sale or sharing, even though Didit does not sell or share personal information, GPC signals are recorded so that no advertising or analytics cookie that could be construed as sharing is set for that browser. Didit does not currently respond to legacy Do Not Track (DNT) headers because there is no industry consensus on how to interpret them; the GPC signal supersedes DNT for Didit's purposes.
Open timeline citation
Jul 20, 2026retentionMEDIUM

Latest stance: indefinite or necessity based on data retention

Didit retains personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to: provide and support the relevant services; follow customer instructions in processor relationships; comply with contractual, legal, tax, accounting, and regulatory obligations; maintain security and fraud-prevention records; resolve disputes; and establish, exercise, or defend legal claims. Retention periods vary by service, workflow configuration, applicable law, and the role Didit plays in the processing: Business relationship data is typically retained for the duration of the relationship and for lawful post-termination recordkeeping periods. Support and audit records may be retained for operational, security, and compliance purposes. Recruitment data is retained for the recruitment process and any lawful follow-up period, or longer if you separately consent. Verification data , the default retention is indefinite ("unlimited"), unless the customer configures a shorter period . Customers configure retention per application in the Business Console between 30 days and 10 years , or trigger a per-session delete at any time via the API endpoint `POST /v3/sessions/:session_id/delete/`. End users may also exercise deletion rights as described in Section 9. Biometric data retention is in every case subject to, and capped by, applicable biometric-privacy laws and regulations , including the EU General Data Protection Regulation (GDPR) Article 9, the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington H.B.
Open timeline citation

Capture recency

  • Privacy Policy:Last captured 2026-07-20· verified 2026-07-20verified once — not yet re-verified

Dates state when our pipeline captured and verified each document — not when the vendor last changed it. Documents are re-scanned on a recurring cadence; a document verified once says so until a re-scan confirms it again.

21 findings first captured First scan: July 2026.

Claim this profile

Compare and stack are saved in your browser. Open compare · View your stack. A correction triggers an automated re-read of Didit's policies — no human edits the data.

Need this for procurement or legal diligence?

Free shows today's risk. A Stack Audit gives you a citable, verbatim-sourced PDF across your whole AI stack — and flags the moment a vendor's terms change.

Know where the missing document lives?

We haven't yet verified Didit's Terms of Service. Point us at the official page and our pipeline will attempt to capture and read it in full. Submissions are candidates only — nothing is published until it passes the same verification gates as every other document on this site.

Every finding above is a verbatim quote from Didit's own published policy, captured to an immutable snapshot and read in full through a two-gate verification pipeline. Confidence labels and any analysis are AI-generated and informational only — not legal advice.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.