data retention · Privacy Policy
Didit policy finding
“ Didit retains personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to: provide and support the relevant services; follow customer instructions in processor relationships; comply with contractual, legal, tax, accounting, and regulatory obligations; maintain security and fraud-prevention records; resolve disputes; and establish, exercise, or defend legal claims. Retention periods vary by service, workflow configuration, applicable law, and the role Didit plays in the processing: Business relationship data is typically retained for the duration of the relationship and for lawful post-termination recordkeeping periods. Support and audit records may be retained for operational, security, and compliance purposes. Recruitment data is retained for the recruitment process and any lawful follow-up period, or longer if you separately consent. Verification data , the default retention is indefinite ("unlimited"), unless the customer configures a shorter period . Customers configure retention per application in the Business Console between 30 days and 10 years , or trigger a per-session delete at any time via the API endpoint `POST /v3/sessions/:session_id/delete/`. End users may also exercise deletion rights as described in Section 9. Biometric data retention is in every case subject to, and capped by, applicable biometric-privacy laws and regulations , including the EU General Data Protection Regulation (GDPR) Article 9, the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington H.B. ”
- Document
- Privacy Policy
- Captured
- 2026-07-20
- Location
- § 8 (Retention)
- Snapshot SHA-256
- c76647e4473d37e9d292a8df885eb195d38b83057b5950d7acde9825f2e04663
Informational only, not legal advice. Terms change; verify the source and capture date.