DocuVerified scenic privacy background
GDPR & Global Privacy Compliant

Privacy Policy & Data Protection

DocuVerified is architected around a fundamental principle: official business documents can be permanently verifiable without compromising personal privacy, exposing confidential payroll records, or indexing private identity documents.

Effective Date: September 14, 2026Version: 3.4 (Global Edition)Jurisdiction: International & EU/EEA Aligned
Section 1

Privacy by Design & Zero-Knowledge Verification

DocuVerified operates as an authoritative cryptographic trust layer for official business documents. Traditional verification workflows force organizations to email unredacted PDF files or photocopies containing sensitive employee details—such as passport numbers, national ID numbers, and confidential compensation figures—to third parties such as commercial banks, embassy visa officers, landlords, and background-check agencies.

Our platform replaces this vulnerability with Privacy-by-Design architecture. When an organization issues a document through DocuVerified, our cryptographic engine binds the document to an opaque verification token (e.g. DV-26-X7M9KP) and a mathematical SHA-256 checksum. Third-party verifiers can confirm whether the document was legitimately issued, whether it remains valid, and whether the file has been tampered with—without seeing confidential data points that the issuer has chosen to mask.

Section 2

Information We Collect

We collect and process only the minimal data required to issue, manage, and verify official corporate documents:

  • Account & Organization Information: Corporate legal entity name, commercial trade registration or tax registration number (TRN), registered business address, authorized signatory name, corporate email address, and billing contact.
  • Cryptographic Document Metadata: Document category (e.g. Salary Certificate, NOC Letter, Offer Letter), issuance timestamp, unique alphanumeric verification ID, document status (Valid, Revoked, Expired), and the SHA-256 cryptographic hash of the generated PDF document.
  • Authorized Recipient Identifiers: Recipient name and professional designation as specified by the issuing company.
  • Verification Activity Logs: When a verifier scans an embedded QR code or enters a token on the public portal, we record the verification timestamp, IP address (truncated and anonymized for fraud prevention), and browser user-agent string to maintain an audit trail for the issuer.
Section 3

Field-Level Privacy & Redaction Controls

DocuVerified provides granular Field-Level Privacy Controls. Issuing organizations can configure exactly which fields are visible on the public verification portal when an external third party scans the document’s QR code:

Publicly Confirmed

Issuer corporate identity, employee active status, document title, date of issuance, and SHA-256 fingerprint matching status.

Protected / Redacted

Exact monthly salary amounts, basic/allowance breakdown, personal passport numbers, and private residential addresses.

When a field is flagged as masked, the raw value is never stored in plain text on the public-facing verification lookup service.

Section 4

How We Use Document Data

DocuVerified uses collected information strictly for operational and verification purposes:

  • To render and generate official corporate documents formatted according to enterprise standards.
  • To maintain the authoritative cryptographic ledger that powers instantaneous QR code verification for third-party verifiers (banks, embassies, universities, immigration authorities).
  • To notify issuers when a revoked or expired document is queried or flagged for suspicious activity.
  • To generate administrative analytics for enterprise account holders (e.g. issuance volume, document lifecycles, verification counts).
Important: DocuVerified will never sell, monetize, rent, or trade your corporate documents, employee lists, or recipient data. We do not use your customer documents to train artificial intelligence or public machine-learning models.
Section 6

Encryption & Storage Security

We enforce rigorous technical and organizational security controls across our infrastructure:

Data in Transit

All API communications, web interactions, and verification requests are encrypted using Transport Layer Security (TLS 1.3) with mandatory HTTP Strict Transport Security (HSTS).

Data at Rest

All database records, cryptographic keys, and token mappings are encrypted with military-grade AES-256 encryption. Hardware security modules (HSM) manage root cryptographic signing keys.

Cryptographic Hashing

Document files are fingerprinted using SHA-256. A cryptographic hash is a one-way mathematical function; the original document contents cannot be reverse-engineered from the hash alone.

Section 7

Data Retention & Lifecycle Revocation

We retain document metadata for as long as the issuing organization maintains an active subscription or until the issuer explicitly marks a document as Revoked or Purged:

  • Active Documents: Verifiable indefinitely or until an optional expiration date configured by the issuer.
  • Revoked Documents: If an employee leaves or a certificate is cancelled, the issuer marks the record Revoked. Any subsequent scan of the QR code immediately displays a prominent "Revoked" status.
  • Account Deletion / Data Purge: When an enterprise closes its account, all corresponding document templates and metadata are scheduled for permanent, irreversible cryptographic purging within 30 days.
Section 8

Data Subject Rights (GDPR, CCPA & International)

Depending on your geographical jurisdiction, you possess statutory rights regarding personal data held about you:

Right of Access: Request a copy of all document records associated with your identity.
Right to Rectification: Request correction of inaccurate or incomplete corporate data.
Right to Erasure: Request permanent deletion ("Right to be Forgotten") of personal identifiers.
Right to Portability: Export document metadata and audit logs in structured JSON/CSV format.

To exercise any of these rights, contact our Data Protection Officer at privacy@docuverified.com. We respond to all verified requests within 30 days.

Section 9

Sub-Processors & Infrastructure

DocuVerified engages select Tier-4 infrastructure providers who comply with SOC 2 Type II, ISO 27001, and GDPR Data Processing Addendums:

Sub-ProcessorService ProvidedData Location
Amazon Web Services (AWS)Cloud Hosting, Encrypted Storage, HSM KMSEU (Frankfurt) / US / Global Edge
Cloudflare, Inc.DDoS Protection, WAF, Global DNS RoutingGlobal Edge Network (300+ Cities)
Stripe, Inc.Payment Processing (PCI-DSS Level 1)United States / Global
Section 10

Data Protection Officer & Inquiries

If you have questions, regulatory inquiries, or concerns regarding our privacy policies or data processing practices, please contact our Data Protection Officer:

DocuVerified Inc. — Data Protection Office

Email: privacy@docuverified.com

Security Team: security@docuverified.com

Response time: within 1 business day for security/privacy inquiries.