Scope
This statement applies to visitors to docinvault.com, people who contact us, business representatives, and individuals invited to complete a DocinVault verification flow. A customer-specific notice presented in a verification flow may provide additional information and will control for that workflow where it is more specific.
Controller and processor roles
DocinVault acts as a controller for business-contact information, website inquiries, account administration, and its own security and legal records.
When a customer uses DocinVault to verify a guest, applicant, representative, or other person, the customer generally determines why the data is processed and the workflow requirements. In that context, the customer is normally the controller and DocinVault acts as a processor or service provider under the customer's documented instructions. The applicable agreement and in-flow notice determine the exact roles.
Personal data we may process
DocinVault processes only the categories needed for the selected interaction or configured workflow. Not every workflow uses every category.
- Business-contact data, including name, work email, company, role, message content, and requested service scope.
- Identity attributes, such as name, date of birth, nationality, address, document number, issuing information, and document validity fields.
- Identity evidence, such as document images, proof-of-address files, selfie images, video, audio where a video workflow requires it, and NFC-derived document data when configured and supported.
- Biometric comparison and liveness signals used to evaluate whether the person is present and whether submitted facial images correspond.
- A transient biometric vector map generated for facial comparison. The vector map is deleted immediately after the configured similarity level is established and is not retained as a reusable biometric template.
- Screening, questionnaire, KYB, or transaction-monitoring information when the customer configures those modules.
- Technical and audit data, including session identifiers, timestamps, device and browser information, IP address, workflow events, access records, and result status.
Sources of personal data
We receive data directly from you, from the DocinVault customer that created the session, from documents or evidence you submit, and from configured authoritative, screening, or fraud-prevention sources where the customer has enabled them and has a lawful basis to do so.
Purposes and legal bases
Depending on our role and the applicable law, data may be processed to respond to inquiries, provide and secure the Service, verify identity evidence, perform configured checks, deliver results to the customer, prevent misuse, maintain audit records, comply with legal obligations, establish or defend legal claims, and improve reliability using appropriately controlled information.
Legal bases may include performance of a contract, compliance with legal obligations, legitimate interests in secure service delivery and fraud prevention, and consent where the controller determines that consent is appropriate. For special-category or biometric data, the controller must identify an additional lawful condition required by applicable law. DocinVault does not choose a customer's legal basis on the customer's behalf.
Customer responsibilities
Customers must provide a lawful and transparent notice, configure only necessary checks and fields, identify an appropriate legal basis, respond to data-subject requests, and set access and retention rules consistent with their obligations. DocinVault processes customer-controlled data according to the contract and documented instructions, unless law requires otherwise.
Infrastructure and service providers
DocinVault uses Amazon Web Services EMEA SARL for primary cloud infrastructure and data processing in the European Economic Area. AWS EMEA is located at 38 Avenue John F. Kennedy, L-1855 Luxembourg, and its processing is governed by an applicable data processing agreement incorporating current transfer safeguards.
Google Cloud EMEA Limited provides backup and restoration services for the AWS-hosted environment, with relevant servers located in Frankfurt, Germany. Google Cloud EMEA is located at 70 Sir John Rogerson's Quay, Dublin 2, Ireland, and is governed by its applicable data processing terms and transfer safeguards.
Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, supports network delivery, traffic routing, availability, and security. It may process IP addresses, routing data, system configuration information, and information about traffic to and from DocinVault services under its contractual privacy and transfer terms.
International transfers
Where personal data is transferred across borders, DocinVault uses lawful transfer mechanisms and appropriate safeguards required by the applicable jurisdiction. Relevant provider agreements incorporate the European Commission's Standard Contractual Clauses where required. The specific hosting and transfer arrangement for a customer deployment is also governed by the applicable customer agreement and configuration.
Retention and deletion
Website inquiries and business records are kept only as long as reasonably needed to respond, maintain the relationship, protect the Service, and meet legal obligations.
Verification evidence, including permitted document images and video, is retained according to the customer's documented instructions, configured retention period, contractual requirements, and applicable law. The transient biometric vector map used for facial similarity is deleted immediately after the similarity result is established. Anonymized technical and security logs are retained for three years to support audit, security, reliability, and legal obligations.
When an applicable retention period ends or a lawful customer instruction requires deletion, personal data is securely deleted or de-identified unless continued retention is required by law or necessary for a documented legal claim.
Security
DocinVault protects data in transit using TLS or SSL and encrypts stored protected data using AES-256. Cryptographic keys are generated, stored, rotated, and access-controlled through managed key-management processes designed to protect against unauthorized disclosure or loss.
Access is limited through unique user identification, role-based access control, least privilege, strong authentication, periodic access review, automated session controls, and timely offboarding. Pseudonymization or anonymization is applied where feasible and consistent with the verification purpose.
Security measures also include environment separation, audit history, secure software-development practices, asset and media controls, annual vulnerability scans and penetration testing, tracked remediation, incident response, employee training, and annually tested business-continuity and disaster-recovery procedures. Critical or high security findings block production release unless a documented exception and compensating controls are approved.
No system can guarantee absolute security. Customers and authorized users must protect credentials, follow access rules, and report suspected misuse promptly.
Incident notification
DocinVault maintains a documented incident-response process covering detection, containment, investigation, risk assessment, preservation of relevant evidence, remediation, and communication. Personnel and contractors must report suspected security incidents within 24 hours.
Where an incident affects a customer's use of DocinVault services, DocinVault will notify the affected customer without undue delay and no later than 24 hours after detection. The notice will include available information about the nature and scope of the incident, its likely impact, and mitigation measures. DocinVault will also support notifications to competent authorities and data subjects where required by applicable law or contract.
Your rights
Depending on the applicable law, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, and review of certain automated decisions. Rights may be limited where an exemption or overriding legal obligation applies.
For a customer-initiated verification, contact that customer first because it normally controls the workflow. You may also contact legal@docinvault.com, and we will assist the customer or respond directly where DocinVault is the controller.
Questions and complaints
You may contact the DocinVault Data Protection Officer at legal@docinvault.com or by writing to DocinVault LLC, 43 Meskheti St., Borjomi, Georgia. You may also complain to the competent data-protection supervisory authority in Georgia or in the jurisdiction where you live or where the relevant processing occurred.
Updates to this statement
We may update this statement to reflect legal, operational, security, or product changes. The current version and effective date will remain available on this page. Material changes will be communicated where required by law or contract.
Reference texts
These links are provided for convenience. The official text in force at the relevant time controls.