Privacy Policy
Effective date: April 1, 2026
Last updated: August 11, 2026
1. Who we are
Verifex is a real-time sanctions, PEP, and business-verification (KYB) screening service. Verifex is operated by ALKITAB LLC, a company registered in the Republic of Azerbaijan ("Verifex," "we," "us," or "our").
For privacy questions or to exercise your rights, contact us at hello@verifex.dev. This policy explains what personal data we process, why, on what legal basis, who we share it with, how long we keep it, and the rights available to you.
2. Our roles: controller and processor
Verifex acts in two different capacities depending on the data:
- Controller. For data relating to your account, billing, the operation of the service, security, and support, Verifex determines the purposes and means of processing and is the controller.
- Processor. When you submit names, entities, or other inputs to our screening or KYB features for your own compliance purposes, you (the customer) are the controller and Verifex processes that data on your behalf and on your instructions. The data you screen may include personal data of third parties; it is not simply "public data."
3. Data we process
- Account data: name, email address, hashed password, and optional company name, website, role, country, and timezone.
- Authentication and signup data: signup IP address, user-agent, referrer, and UTM/campaign parameters, together with password-reset and verification tokens.
- API usage metadata: API keys (stored as hashes), the endpoints called, timestamps, request IP addresses, and whether a match was found.
- Screening inputs and results: the names and entity details you submit for screening, plus match results, confidence scores, and decisions. Screened names may be personal data.
- Screening watches: entities you place under ongoing monitoring, and the associated risk information.
- Batch data: uploaded files, requester email, company name, and per-row names and matches.
- KYB data: company officers, persons with significant control (PSCs), and ultimate beneficial owners (UBOs) — including names and, where provided by the source, dates of birth — plus sanctions and adverse-media findings.
- Billing data: customer email and subscription details held by our payment provider; we do not store your card details.
- Transactional email data: recipient email and message content for verification, reset, receipt, and notification emails.
- Support communications: the content of messages you send us.
- Security and operational logs: authentication events, error logs, uptime checks, and rate-limiting data.
4. Purposes and legal bases
Where data-protection law such as the GDPR applies to our processing as a controller, we rely on the following legal bases:
- Contract: to create and administer your account, authenticate API requests, deliver screening and KYB results, and manage billing and subscriptions.
- Legitimate interests: to secure the service, prevent fraud and abuse, apply rate limiting, monitor and improve reliability, and provide support — balanced against your interests and rights.
- Legal obligation: to keep certain records and to respond to lawful requests where the law requires it.
- Consent: where we specifically ask for it; you may withdraw consent at any time.
Where Verifex acts as a processor for the screening and KYB data you submit, we process it only on your documented instructions and for the purpose of providing results to you. We do not build profiles of the people or entities you screen, and we do not use your screening inputs to train models for other customers.
5. AI-assisted processing
Some features may optionally use a third-party AI provider (Anthropic) to support entity resolution and adverse-media analysis. This is only active when explicitly enabled; when it is not configured, the feature is a graceful no-op. When enabled, only limited data — names, entity context, and article text — is sent to Anthropic via its commercial API, under a data-processing and standard-contractual-clause transfer framework, subject to the applicable account terms. Under those commercial terms, this data is not used for general model training by default. Your account email, API keys, and payment data are never sent for AI processing.
We do not use DeepSeek to process your screening or KYB inputs. DeepSeek is not a subprocessor of customer data.
6. Recipients and subprocessors
We share personal data with a limited set of service providers who process it on our behalf — for hosting, payments, email, optional AI features, error monitoring, and operational alerting. The current, canonical list is maintained at /subprocessors. We do not sell, rent, or trade personal data.
7. International transfers
Our primary infrastructure is hosted in the European Union (Hetzner, Germany/Finland). Some subprocessors are located in the United States or elsewhere. Where personal data is transferred outside the EU/EEA and a transfer mechanism is required, we rely on the European Commission's Standard Contractual Clauses (SCCs) or an equivalent mechanism. Some vendor transfer arrangements are still under review; see /subprocessors for the per-vendor status.
8. Data retention
| Data | Retention |
|---|---|
| Account data | Retained while the account is active; deletion schedule under review. |
| Authentication / security logs | Operational logs retained approximately 90 days. |
| API usage metadata | Retained per plan; schedule under review. |
| Screening records | Retained per plan — approximately 30 to 365 days depending on plan tier — then removed by a scheduled cleanup. You can export your evidence at any time for your own recordkeeping, and longer or fixed retention can be arranged under an Enterprise or pilot agreement. Retention periods are under legal and contractual review and are not presented as a universal, automatic OFAC requirement. |
| Screening watches | Retained until removed by the customer. |
| Batch files / results | Under review. |
| KYB data | Under review. |
| Billing records | Retained per the payment provider and applicable legal/tax requirements. |
| Support communications | Under review. |
| Backups | Daily database backups are taken. Off-site and encrypted backup handling is being improved and is not claimed as complete. |
9. Your rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data, subject to legal retention requirements.
- Port your data in a machine-readable format.
- Restrict or object to processing in certain circumstances.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email hello@verifex.dev. Where the screening or KYB data is submitted by a customer, requests from the underlying data subjects are generally directed to that customer as controller; we will assist them as processor.
Complaints. Where the GDPR or a comparable law applies, you have the right to lodge a complaint with your local data-protection supervisory authority.
10. Cookies
We use only strictly necessary cookies. See our Cookie Policy for details.
11. Security
We apply technical and organizational measures to protect personal data, described on our Security page. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. Data Processing Agreement
If you process personal data of individuals and require a Data Processing Agreement, a draft is available for contractual review — see /dpa or contact hello@verifex.dev.
13. Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you by email.
14. Contact
Questions or requests about this policy or our data practices: hello@verifex.dev.