v11 (current)

Sumsub Notice of Personal Data Processing

This Sumsub Notice of Personal Data Processing (“Notice”) is designed to inform users, regardless of their residence, about how their personal data may be processed by Sumsub. Except where the applicable law specifically requires active opt-in consent, this notice is informational and does not itself constitute or request such consent.

1. Who processes your personal data. Your personal data will be processed by Raritex Trade Ltd., HE 369578, 153 Agiou Andreou, 3036, Limassol, Cyprus, together with its relevant affiliates and independent authorized distributors, including without limitation:

  • Sum and Substance Ltd. (UK);
  • Sumsub Tech Ltd. (Cyprus);
  • Sumsub Ltd. (Cyprus);
  • Sumsub Inc. (US);
  • Sumsub GmbH (Germany);
  • Sumsub APAC Pte. Ltd. (Singapore);
  • Sumsub Technology LLC (UAE);
  • Sumsub Brasil LTDA (Brazil);
  • Lexory Technologies OPC (Philippines)

(cumulatively “Sumsub”), as may be involved in providing identification, identity verification, authentication, transaction monitoring, fraud prevention, and other services (“Services”) to the Company. The Company is not part of Sumsub; it is the organization with which you are seeking to establish, maintain, or continue a business relationship in connection with your interaction with Sumsub and is generally the data controller responsible for deciding why your personal data is processed in the context of its onboarding and due diligence procedures. Sumsub typically processes personal data on the Company’s behalf to provide it with the Services. For certain limited purposes described below, Sumsub may also process your personal data as an independent data controller.

2. Categories of personal data that may be processed. Depending on which Services are selected by the Company and whether you have a direct contractual relationship with Sumsub, the following categories of personal data may be processed by Sumsub and its subprocessors: identifiers and profile data (such as full name, date of birth, nationality, citizenship, sex, residential address, and other identifying details); government-issued document data (such as document type, issuing country, document number, expiration date, machine-readable zone data, barcode data, and security features); contact details (such as email address, telephone number, and correspondence details); visual, audio, and biometric data (such as scans of face geometry) extracted from your selfies, video selfies, or photographs appearing on identity documents; financial and source-of-funds information; screening and compliance data (such as sanctions, watchlist, politically exposed person, adverse media, and fraud risk check results); technical, device, and network data (such as IP address, timestamps, browser attributes, device identifiers, operating system data, and general geolocation inferred from the device); communications data (such as information you provide in support requests, appeals, complaints, or fraud investigations); and inferences or risk indicators derived from the data above for identity verification, fraud prevention, and compliance purposes.

3. Sources of personal data. Personal data may be collected directly from you; from the Company; automatically from your device or browser when you use Sumsub’s or the Company’s interface; from government registries, databases, sanctions and watchlist providers, identity verification vendors, fraud prevention sources, telecommunications or document validation providers, and public sources such as corporate, judicial, or regulatory records; and, where permitted by law, from previous verification or authentication events linked to the same account or verification program.

4. Purposes of processing and Sumsub’s legal bases for processing.

For the following purposes, Sumsub processes your personal data solely on the Company’s behalf and in accordance with its instructions. For questions about these purposes, or to exercise your data subject rights in relation to them, you should contact the Company directly.

  • Identity verification: to verify your identity and assess the authenticity, validity, and integrity of your identity documents and other submitted information as part of the Company’s due diligence procedures.
  • Liveness and authentication checks: to perform liveness detection, anti-spoofing, reverification, and authentication checks during onboarding and at subsequent access points as part of the Company’s due diligence procedures.
  • Regulatory compliance (AML/CFT and sanctions): to assist the Company in fulfilling its obligations under applicable anti-money laundering, counter-terrorist financing, and sanctions laws, including customer due diligence and ongoing monitoring.
  • Underage access prevention: to detect and prevent access by individuals who do not meet the minimum age requirements set by the Company as part of the Company’s due diligence procedures.
  • Fraud prevention – client-level: to detect and prevent fraud, account misuse, and identity theft within the Company’s own user base, carried out on the Company’s instructions and using only data relating to that Company’s users.

For the following purposes, Sumsub determines how and why your personal data is used, independently of the Company, thereby acting as a data controller. For questions about these purposes, or to exercise your data subject rights in relation to them, you should contact Sumsub directly.

  • Handling data subject requests (Legal basis: legal obligation – GDPR Articles 12-22): to receive and respond to requests from individuals seeking to exercise their data protection rights in relation to processing activities for which Sumsub acts as data controller.
  • Service security and integrity (Legal basis: legitimate interests): to maintain the security, resilience, and operational integrity of our platform, including detecting and responding to threats and vulnerabilities.
  • Sumsub’s own legal and regulatory compliance (Legal basis: legal obligation): to comply with legal, regulatory, audit, and recordkeeping obligations applicable to Sumsub, and to respond to lawful requests from courts, regulators, and authorities.
  • Legal claims and enforcement (Legal basis: legitimate interests): to establish, exercise, or defend Sumsub's legal claims and enforce our contractual rights.
  • Fraud detection and prevention – network-level (Legal basis: legitimate interests; for biometric data, substantial public interest under applicable law): to detect, investigate, and prevent fraud and identity abuse across Sumsub's platform by identifying patterns, signals, or matches that span multiple clients' verification data.
  • Analytics and performance monitoring (Legal basis: legitimate interests): aggregated analysis of service usage, verification outcomes, and system performance.
  • Quality control / Service quality assurance (Legal basis: legitimate interest): samples of personal data of applicants such as document images, selfies/videos, or video identification interview recordings may be reviewed and analysed by authorised personnel of Sumsub for quality assurance purposes, including verification of adherence to client identification policies, regulatory requirements and Sumsub procedures.
  • Service development, including AI model training (Legal basis: legitimate interests): to improve, test, calibrate, and develop our verification, fraud detection, and security systems, including through AI model training and testing vendor services.

5. How the processing works, including automated decision-making. Processing may include automated text extraction; document authenticity and validity checks; facial image comparison; liveness and anti-spoofing analysis; duplicate identity detection; screening against sanctions lists, politically exposed person lists, adverse media, and other compliance databases; device and network analysis; risk and fraud scoring; and related logging and audit trails. Human review may be used to review edge cases, investigate suspected fraud, provide support, or satisfy legal and compliance requirements.

Sumsub’s systems may generate verification results, alerts, or risk labels, but the final decision whether to approve an onboarding request, maintain an account, or allow access to the Company’s services is made by the Company and is not based solely on the basis of automated outputs provided by Sumsub.

6. Disclosure of personal data. Personal data may be disclosed by Sumsub to: (a) the Company and its corporate affiliates involved in the relevant customer relationship; (b) Sumsub entities and approved subprocessors or service providers that support the Services, hosting, storage, communications, analytics, support, fraud prevention, or screening functions; (c) external data sources, registries, and screening providers used for identity verification or compliance checks; (d) professional advisers, auditors, insurers, or transaction counterparties where reasonably necessary; and (e) courts, regulators, supervisory authorities, law enforcement agencies, or other public bodies where disclosure is required or permitted by law.

7. International data transfers. Your personal data may be transferred to, or accessed from, the United Kingdom, the United States of America, Germany, Singapore, Brazil, and the United Arab Emirates, as well as any other countries in which Sumsub or the Company operate. Where required by applicable law, such transfers are protected by appropriate safeguards, which may include adequacy decisions, standard contractual clauses, binding corporate rules, the EU-U.S. Data Privacy Framework where applicable, or another lawful transfer mechanism. More detail is available in the Sumsub Privacy Notice.

8. Retention and deletion. How long your personal data is retained depends on who is responsible for the retention decision.

Data processed on the Company's behalf. Where Sumsub processes your data as a processor acting on the Company's instructions, the data is retained for the duration of the contract between the respective Sumsub entity and the Company, and deleted or returned in accordance with the Company's documented instructions. The Company determines how long your data must be kept, including to meet its AML/CFT or other regulatory obligations. For questions about those retention periods, please contact the Company directly.

Data retained by Sumsub for its own purposes. Where Sumsub processes your data as an independent controller, the periods set out below apply.

  • Handling data subject requests: records of requests and our responses are retained for 3 years from the date the request is closed, to demonstrate compliance with applicable data protection laws.
  • Service security and integrity: data is retained in accordance with Sumsub's internal security and data retention policies, and in any event no longer than necessary to maintain the security and integrity of our platform.
  • Our own legal and regulatory compliance (audit trails and compliance records): data is retained for the time specified in the applicable legislation.
  • Legal claims and enforcement: logs from applicants KYC verification for the purpose of defense from claims may be kept for the applicable limitation of claims periods.
  • Fraud prevention – network-level: data can be used for this purpose for the duration of Sumsub’s business relationship with the Company.
  • Analytics and performance monitoring: data for analytics can be aggregated and de-identified; where underlying data remains identifiable, it is retained for no longer than 5 years from the date of collection.
  • Quality control / Service quality assurance: samples of personal data of applicants such as document images, selfies/videos or video identification recordings may be reviewed for quality assurance purposes during the period of Sumsub’s business relationship with the Company.
  • Service development, including AI model training: your data may be used for this purpose for up to 5 years from the date of collection.

9. Your privacy rights. Depending on your location and the laws that apply, you may have rights to request access to your personal data; correction of inaccurate data; deletion of data; portability of certain data; restriction of processing; objection to certain processing, including certain profiling; withdrawal of consent where processing relies on consent; appeal of certain refusals to act on a request; and the right not to be discriminated against for exercising privacy rights. You may also have the right to complain to a competent supervisory authority, attorney general, or other regulator. Requests relating to the Company’s use of your personal data should generally be directed to the Company. Requests relating to Sumsub’s own processing may be directed to [email protected].

10. U.S. State Privacy Disclosures

10.1 Notice at Collection. This Notice serves as Sumsub's notice at collection under U.S. state privacy laws, including the CCPA (as amended by the CPRA) and comprehensive privacy laws in other U.S. states. Categories of personal information collected, sources, purposes, recipients, retention, and your rights are described in Sections 2, 3, 4, 7, 9, and 10.

10.2 No Sale or Share. Sumsub does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. Fraud signals or risk scores Sumsub provides to the Company concern the Company’s own users and do not disclose personal information about any other client's users.

10.3 Roles of the Parties. When providing the Services to the Company, Sumsub acts as a “service provider” or “contractor” under the CCPA, and as a “processor” under other state privacy laws, on the Company's behalf. The Company is responsible for its own notices and consents required by applicable law. Where Sumsub processes personal information for the purposes identified in Section 4, Sumsub acts as a “business” or “controller.”

10.4 California Residents. Additional disclosures required by California law, including the treatment of sensitive personal information, are set out in Sumsub's California Privacy Notice, which together with this Notice serves as Sumsub's notice at collection for purposes of California law.

10.5 Biometric Information. Sumsub's collection and use of biometric information is also subject to the Illinois Biometric Information Privacy Act, Washington's RCW 19.375 and the Texas Capture or Use of Biometric Identifier Act and other similar laws regulating processing of biometric information. The additional disclosures are set out in Sumsub's Biometric Privacy Notice.

10.6 Non-Discrimination. You will not receive discriminatory treatment for exercising your privacy rights.

11. Further information. This Notice should be read together with the Sumsub Privacy Notice. If there is a conflict between this Notice and a jurisdiction-specific notice that applies to you, the jurisdiction-specific notice will control to the extent of the conflict.

Sumsub Privacy Notice (Service Delivery): https://sumsub.com/privacy-notice-service/
Sumsub privacy-related contact: [email protected]