Policy on the Processing of Personal and Biometric Data During KYC
Last updated: August 2, 2026
1. General
This policy describes the processing of personal and biometric data during identity verification (KYC) on the AdaptGroup platform (hereinafter, the "Platform").
The data controller and the party determining the purposes of verification is AdaptGroup LLC, a limited liability company registered in the State of Wyoming, USA (hereinafter, the "Company").
This policy supplements the AdaptGroup Privacy Policy. If the mandatory laws applicable at the user's location provide additional rights or safeguards, those requirements apply.
2. When KYC Is Required
As a general rule, KYC is not required to register or use the basic functionality of the Platform. After successful verification, additional features may become available in organizations owned by the user. If a specific feature requires KYC, this is indicated in the Platform interface.
The Company may require a user to complete an initial or repeat identity verification. If KYC is made mandatory for an account, access to the dashboard is temporarily restricted until verification is completed successfully.
The user may decline voluntary KYC or stop an ongoing verification. In that case, features requiring a verified status will remain unavailable. If the Company has required KYC, the access restriction remains in place until verification is completed successfully or the matter is resolved with support.
3. Purposes of Processing
The Company conducts KYC for the following purposes:
- verifying the user's identity;
- checking the authenticity and validity of an identity document;
- confirming that the user is the person shown in the document;
- confirming the presence of a live person and preventing image substitution;
- matching document information against available government and permitted commercial sources;
- detecting risk signals related to the user's device, connection, and location;
- preventing fraud, abuse, and circumvention of Platform restrictions;
- providing access to features that require identity verification;
- reviewing disputed cases and user requests;
- protecting the security of the Platform and the legitimate interests of the Company;
- complying with applicable law and lawful requests from competent authorities.
4. Didit Verification Provider
The Company uses the Didit service, provided by Didit Identity, Inc., a Delaware corporation, to conduct KYC.
Didit generally acts as a data processor on behalf of the Company. The Company determines whether verification is required, which checks are included, and the consequences of the result, while Didit provides the verification technology.
For limited purposes, including service security, abuse prevention, audit logging, compliance with its own legal obligations, and defense against claims, Didit may act as an independent data controller. Didit also states that, where permitted by law, it may use anonymized or pseudonymized data for testing, quality control, improving verification models, and fraud detection.
Before completing KYC, users are encouraged to review the following Didit documents:
5. Data Processed
The Company and Didit process the following categories of data as part of the configured verification workflow.
5.1 Account and Session Data
- the user's internal identifier on the Platform;
- interface language;
- KYC session identifier and status;
- dates when verification was created, updated, and completed successfully;
- whether KYC is mandatory for the account;
- the URL used to return the user to the Platform after verification.
5.2 Document Data
- an image of the identity document;
- the document holder's photograph;
- first name, last name, date of birth, nationality, and sex;
- document type, number, issuing country, and expiration date;
- machine-readable zone, barcodes, and other information contained in the document;
- results of document authenticity, integrity, and quality checks.
5.3 Images and Biometric Data
- selfies, facial images, and video obtained during the active check;
- movements and actions performed by the user in front of the camera;
- the result of the liveness and anti-spoofing check;
- features and templates derived from facial geometry;
- the result of matching the user's face against the photograph in the document;
- confidence, quality, anti-spoofing, and other verification signals.
An image or video may not itself constitute a biometric identifier under the laws of a particular jurisdiction. Features derived from facial geometry and used to identify or verify a person may constitute biometric data.
5.4 Technical Data
- IP address;
- browser, operating system, hardware, and device characteristics;
- language, time zone, time, and session parameters;
- persistent device identifiers, device fingerprints, and technical device signals;
- Canvas, WebGL, media capabilities, and other available browser signals;
- approximate location, country, region, city, and coordinates derived from network data;
- network, carrier, and autonomous system (ASN) information;
- indicators of VPN, proxy, Tor, data center, emulator, or spoofing tool usage;
- device or IP address matches with other sessions;
- discrepancies between the connection location and the country or address in the document;
- warnings and other technical risk signals.
5.5 Database Validation
- information extracted from the identity document;
- results of matching information against sources available for the relevant country and document type;
- information about matches, mismatches, or unavailable checks;
- responses and risk signals obtained from government, public, or permitted commercial sources.
The specific source depends on the user's country, document type, and availability of the check. Didit may use national identity registries, civil, immigration, and tax registries, as well as other permitted sources. Database Validation is not an AML or sanctions screening check.
5.6 Verification Results
- final status and status transitions;
- results of document, liveness, face match, database, device, and IP address checks;
- confidence indicators, warnings, and risk signals;
- requests to resubmit information;
- verification notes and supporting materials if included in the Didit response.
6. Data Transfer and Storage of Results
When creating a KYC session, the Platform sends Didit the user's internal identifier, selected language, and return URL. The user provides the document, facial image, and other verification materials directly on Didit's secure page.
Didit sends the Platform notifications when the status changes. A notification may contain results of individual checks, extracted data, and links to verification materials. The Platform processes the notification to determine the user's status but does not store the complete Didit response in its own database.
In its own database, the Company stores whether KYC is mandatory, the Didit session identifier, the current status, and the dates when the status changed or verification was completed successfully. The Company does not upload or store copies of documents, selfies, videos, or biometric templates in its own information systems.
Didit stores the source materials and verification results in accordance with the retention period set by the Company, Didit's terms, and applicable law.
7. Access to Data
Regular Platform staff receive only the KYC status required for the relevant Platform features.
A limited number of authorized Company representatives may access verification materials through the secure Didit console. Such access is permitted only to review a disputed result, respond to a user request, prevent fraud, verify compliance with Platform rules, or comply with a legal obligation.
Didit and its service providers may access data to the extent necessary to perform verification, provide security and technical support, and comply with applicable requirements. Access is restricted by the organizational and technical measures of the relevant party.
8. Verification Results and Decision-Making
Didit uses automated systems and, in certain cases, manual review to analyze the document, liveness, face match, available databases, device, connection, and risk signals.
The Platform receives the session status and displays it automatically in the user's account. Didit provides the technical verification result, while the Company determines how that result affects access to Platform features.
The Company does not guarantee successful KYC completion. The result may depend on the quality of the submitted materials, availability of data sources, data matches, and identified risk signals. An individual signal, including VPN use or a device match, may be considered together with other results and lead to additional review, repeat verification, or rejection.
After a rejection, the user may start a new KYC session and complete verification again. Support does not manually assign a successful status but may assist with technical issues, explain the available next steps, or arrange a review of a disputed case by an authorized representative.
A successful KYC status remains valid indefinitely. The Company may require repeat verification where necessary for security, abuse prevention, review of a disputed case, or access to specific features.
9. Legal Bases and Consent
Data is processed to provide the verification requested by the user, perform the Platform terms, maintain security, prevent fraud, and comply with applicable legal obligations. Documents, facial images, and biometric data are processed on the basis of the user's express consent unless applicable law provides another lawful basis.
Before document, facial image, or biometric data collection begins, the user is given an opportunity to review this policy and the Didit documents. Consent is provided by selecting a separate checkbox in the Platform interface before proceeding to verification. KYC cannot be started without selecting this checkbox.
Browser or device permission to use the camera is a technical permission and does not by itself replace consent to data processing. Consent is requested again whenever a new KYC session is created, including after a rejection or at the Company's request.
10. Retention and Destruction
| Category | Storage location | Retention period |
|---|---|---|
| Documents, facial images, videos, and biometric data | Didit | No more than 30 days after the final result or the last activity in an incomplete session |
| Results, verification data, and supporting materials | Didit | No more than 30 days after the final result or the last activity in an incomplete session |
| Didit User entity associated with verification | Didit | Deleted together with associated data no later than the applicable 30-day deadline |
| Session identifier, KYC status, and dates | AdaptGroup | While the account exists, then deleted no later than 30 days after account deletion |
| Didit operation audit logs | Didit | 365 days according to Didit's documentation |
The Company sets Didit's retention period to one month and ensures deletion of the KYC session and associated User entity. Deletion covers documents, images, videos, biometric data, extracted information, Database Validation and Device/IP Analysis results, and other related materials. AdaptGroup retains only the minimum status and verification dates required to provide KYC-dependent features without retaining the source materials.
Under the current workflow, the Company does not create separate face, document, or device blocklist entries from KYC materials. If such processing is enabled in the future, the Company will update this policy before it begins.
The Company and Didit delete, anonymize, or securely destroy data after the retention period expires, upon receipt of a valid deletion request, or upon an earlier deadline required by applicable law. Didit audit logs are retained for 365 days. Didit may separately retain limited security records or other data that it processes as an independent controller in the circumstances and for the periods specified in Didit's documents or required by law.
For users in jurisdictions with specific biometric privacy laws, the shorter applicable period applies. In particular:
- for users in Illinois, biometric identifiers and biometric information are destroyed when the original purpose has been satisfied or no later than three years after the user's last interaction, whichever occurs first;
- for users in Texas, biometric identifiers are destroyed within a reasonable period, generally no later than one year after the purpose for collection ends, unless longer retention is required by law;
- for users in Washington, data is not retained longer than reasonably necessary to provide verification, prevent fraud, maintain security, or comply with a legal obligation.
11. International Data Transfers
The Company is registered in the United States, and Didit states that production data is processed and stored in the European Union by default using Amazon Web Services infrastructure. The actual processing location may depend on settings, service providers, and contractual terms.
Data may be processed outside the user's country. Where required, Didit applies legally recognized transfer mechanisms, including adequacy decisions, standard contractual clauses, and other recognized safeguards.
12. Sale of Biometric Data
The Company does not sell, lease, trade, or otherwise profit from the transfer of users' biometric identifiers or biometric information.
Didit also states that it does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information.
13. User Rights
Depending on applicable law, users may have the right to:
- obtain information about the processing of their data;
- request access to or a copy of their data;
- request correction of inaccurate data;
- request deletion of data;
- withdraw consent to further processing;
- request restriction of or object to processing;
- request review of a disputed result;
- lodge a complaint with a competent data protection authority.
To exercise these rights, contact AdaptGroup through Telegram or at [email protected]. Do not send a copy of an identity document or a selfie with the request. To locate the relevant session, support may request the user's account identifier and additional information necessary to verify the requester's identity.
If a request concerns processing performed by Didit as an independent controller, the user may also contact [email protected] or [email protected].
14. Withdrawal of Consent and Data Deletion
Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal. After receiving a request, the Company stops processing based on consent unless another lawful basis applies.
The Company may instruct Didit to delete the relevant KYC sessions and associated User entity. If the request concerns data processed by Didit as an independent controller, the user may also contact Didit using the contact details in Section 13.
Some information may be retained to a limited extent where necessary to comply with law, defend against claims, or prevent fraud.
Deletion of a KYC session or withdrawal of consent may result in loss of the verified status and restriction of features that require KYC. Where permitted by law, the Company informs the user of these consequences before completing the request.
15. Users Under 18
KYC is available only to persons who are at least 18 years old. The user confirms that they meet this age requirement before starting verification.
Users under 18 must not provide Didit with documents, facial images, or other data for KYC. Subject to the Platform's general age restrictions, they may use Platform features that do not require identity verification.
16. Changes to This Policy
The Company may update this policy to reflect changes to the KYC process, Didit settings, or applicable law. The current version is published in the Platform documentation with the date of the latest update.
If a change requires new consent, the Company will request it before continuing the relevant processing.
17. Contact and Company Details
For questions about data processing during KYC, contact:
- Telegram: @adapt_support
- Email: [email protected]
Company Details
AdaptGroup LLC
30 N Gould St Ste R
Sheridan, WY 82801, USA