Veri5 Passport

Privacy Policy

Last updated: 27 June 2026

This Privacy Policy explains how Hefes LLC ("Hefes", "we", "us", or "our") collects, uses, protects, and shares personal information when you use Veri5 Passport, the single sign-on and identity service for the Veri5 ecosystem. We act as the controller of the personal information described here. By using the service, you agree to the practices in this Policy.

1. Information We Collect

We collect the following categories of personal information:

2. How We Use Information

We use personal information to:

3. Consent and Legal Bases

We process personal information on the legal bases of performing our contract with you, your consent (in particular for sharing identity claims with connected applications), our legitimate interests in operating and securing the service, and compliance with legal obligations. You may withdraw consent for sharing with a connected application at any time by revoking its authorization, though this will not affect processing already carried out.

4. How We Protect Information

We apply technical and organisational safeguards designed to protect your information. Passwords are stored only as salted hashes. Your recovery code and managed-account secrets are encrypted at rest. Identity-verification and KYB documents are encrypted, and access is restricted to authorised personnel and processes on a need-to-know basis. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

5. How We Share Information

We share personal information only as follows:

We do not sell your personal information.

6. International Data Transfers

Your information may be processed in countries other than the one in which you reside. Where we transfer personal information across borders, we use appropriate safeguards — such as standard contractual clauses or equivalent mechanisms — to protect it in accordance with applicable data-protection law.

7. Data Retention

We retain personal information for as long as your account is active and as needed to provide the service. We retain verification and KYB documents and consent records for the period required to meet legal, regulatory, and fraud-prevention obligations, after which we delete or anonymise them. When you close your account, we delete or anonymise your information except where retention is required by law.

8. Your Rights

Subject to applicable law (including the EU General Data Protection Regulation and applicable Personal Data Protection Acts), you have the right to access, correct, update, or delete your personal information, to object to or restrict certain processing, to data portability, and to withdraw consent. To exercise these rights, contact us at [email protected]. You also have the right to lodge a complaint with your local supervisory authority.

9. Cookies and Sessions

We use strictly necessary cookies and similar technologies to keep you signed in, maintain session security, and prevent fraud. These are essential to the operation of an identity service and cannot be disabled without affecting sign-in functionality.

10. Children's Privacy

The service is not directed to children under 18, and we do not knowingly collect personal information from them. If we learn that we have collected such information, we will delete it.

11. Changes to This Policy

We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, provide additional notice. Your continued use of the service after changes take effect constitutes acceptance of the revised Policy.

12. Contact Us

For questions or requests regarding this Policy or your personal information, contact our privacy team at [email protected].