TRUSTTICA maintains this Data Retention & Destruction Policy to explain how long categories of information may be retained and how information is securely deleted, destroyed, or de-identified when it is no longer required.
Biometric Information
TRUSTTICA retains biometric identifiers and biometric information only for the period necessary to fulfill the purpose for which the information was collected, subject to applicable law. The table below states the specific retention periods that apply.
| Data Category | Retention Period | Deletion Method |
|---|---|---|
| Raw facial selfie image (KYC capture) | 90 days from verification completion | Permanent deletion from Azure Blob Storage |
| Government ID document image | 90 days from verification completion | Permanent deletion from Azure Blob Storage |
| Biometric match confidence score | 3 years from verification date | Anonymized (de-linked from identity) at end of period |
| Verisefy provider session ID | 3 years from verification date | Permanent deletion from database |
| Verification outcome record (pass/fail/review) | 3 years from verification date or account closure + 3 years, whichever is longer | Permanent deletion (may be retained longer if required by law) |
| Audit log entries referencing biometric checks | 5 years (compliance requirement) | Permanent deletion |
Where a jurisdiction establishes a specific maximum retention or destruction requirement, TRUSTTICA will follow that requirement.
Biometric information will be securely deleted or destroyed when the applicable purpose has been fulfilled and the applicable retention period has expired, unless TRUSTTICA is legally required or permitted to retain the information because of:
- A valid legal obligation
- A legal hold
- Litigation or anticipated litigation
- A lawful government request
- A security or fraud investigation
- Another legally recognized preservation requirement
For more detail on how facial images and biometric data specifically are collected, processed, and shared with our identity verification provider, see our Biometric Consent Notice.
Identity Documents
Identity documents and source verification materials are retained only as long as reasonably necessary for verification, security, fraud prevention, compliance, dispute resolution, or other lawful purposes.
When no longer required, they will be securely deleted, destroyed, or de-identified.
Verification Results
Verification outcomes and related audit records may be retained separately from the underlying identity documents or biometric information where necessary to maintain an auditable record of a verification event.
Evidence Vault
Evidence Vault records may be retained for the period reasonably necessary to support trust, safety, accountability, dispute resolution, contractual obligations, security, or legal requirements.
Retention of an Evidence Vault record does not necessarily mean that the underlying identity document or biometric information is retained for the same period.
Security and Audit Logs
Security and administrative logs may be retained for a period reasonably necessary to investigate and prevent unauthorized access, fraud, abuse, or security incidents and to maintain appropriate security records.
Account Deletion
When a user deletes an account, TRUSTTICA will initiate deletion or de-identification of personal information that is not required to be retained.
Information subject to lawful retention may remain until the applicable legal or operational retention period expires.
To request deletion of your account, see the Delete Your Account page.
Secure Destruction
When information reaches the end of its applicable retention period, TRUSTTICA may use secure deletion, cryptographic erasure, destruction of storage media, de-identification, or another appropriate method designed to prevent unauthorized recovery.
Policy Changes
TRUSTTICA may update this policy when the platform, technology, retention practices, or legal requirements change.
Contact
Privacy Contact: support@trusttica.com
See also our full Privacy Policy.