Skip to main content
Platform Review
PricingSign in
Didit assessment

Didit procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Didit
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslow Didit may process data in multiple countries. When personal data is transferred outside the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with transfer restrictions, Didit uses appropriate safeguards where required, including: adequacy decisions; the European Commission's 2021 Standard Contractual Clauses (SCCs) and any equivalent UK or Swiss addenda; intra-group transfer arrangements; or another lawful transfer mechanism recognized by applicable law.Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersunknown1493, and any other applicable biometric-privacy law; where such law prescribes a shorter retention period or an earlier destruction obligation, that shorter or stricter rule prevails over any default or customer-configured retention period. When data is no longer needed, Didit deletes, redacts, anonymizes, de-identifies, or securely destroys it. For biometric data and verification media, see the Verification Privacy Notice .Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersmedium Didit retains personal data for as long as reasonably necessary for the purposes described in this Privacy Policy, including to: provide and support the relevant services; follow customer instructions in processor relationships; comply with contractual, legal, tax, accounting, and regulatory obligations; maintain security and fraud-prevention records; resolve disputes; and establish, exercise, or defend legal claims. Retention periods vary by service, workflow configuration, applicable law, and the role Didit plays in the processing: Business relationship data is typically retained for the duration of the relationship and for lawful post-termination recordkeeping periods. Support and audit records may be retained for operational, security, and compliance purposes. Recruitment data is retained for the recruitment process and any lawful follow-up period, or longer if you separately consent. Verification data , the default retention is indefinite ("unlimited"), unless the customer configures a shorter period . Customers configure retention per application in the Business Console between 30 days and 10 years , or trigger a per-session delete at any time via the API endpoint `POST /v3/sessions/:session_id/delete/`. End users may also exercise deletion rights as described in Section 9. Biometric data retention is in every case subject to, and capped by, applicable biometric-privacy laws and regulations , including the EU General Data Protection Regulation (GDPR) Article 9, the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), Washington H.B. Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tierslow We may disclose personal data to: The customer that asked us to perform the verification , so the customer can complete onboarding, fraud review, compliance checks, or related business processes. Didit group entities , where necessary to operate, support, secure, or provide the relevant services. Service providers and sub-processors , providers of cloud hosting, storage, infrastructure, communications, support, analytics, fraud prevention, document processing, security, audit, and professional services. A current sub-processor list is available to customers and prospective customers under a signed Non-Disclosure Agreement (NDA) on request to security@didit.me . Professional advisers , lawyers, auditors, insurers, and consultants, where needed for legitimate business, compliance, or legal purposes. Public authorities, regulators, courts, law enforcement, or other third parties , when required by law, legal process, or enforceable governmental request. Successors and transaction counterparties , if Didit is involved in a merger, acquisition, financing, insolvency process, or sale of assets, subject to confidentiality and legal safeguards. Didit does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.Captured 2026-07-20Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.