Privacy Policy
Last updated: 28 July 2026
1. Who we are
Zanyara Ltd ("Zanyara", "we", "us") provides an identity-verification platform. Businesses ("clients") use Zanyara to verify the identity of their customers and applicants ("applicants") using identity documents, facial biometrics, and related risk signals.
For most verification data we act as a processor: we process applicant data on the documented instructions of the client that asked you to verify. That client is the controller, and their privacy notice governs why you are being verified. We act as a controller for a smaller set of data: operator console accounts, billing records, our website, and correspondence with us.
2. Data we process
- Identity document data. Images of passports, national ID cards, driving licences and similar documents, and the data extracted from them (name, date of birth, document numbers, MRZ, NFC chip data, barcodes).
- Biometric data. Selfie photographs, short liveness-challenge video frames, and the facial templates derived from them for face matching and liveness detection. This is special-category data and is only processed with your explicit consent (see section 4).
- Contact and applicant details. Name, phone number (for cross-device links sent by SMS), email address, and address where a proof-of-address check is part of the flow.
- Screening data. The results of checks against publicly available sanctions, politically exposed persons (PEP), and adverse-media datasets.
- Device and session data. IP address, device characteristics, and capture-session telemetry (for example, how many capture attempts were needed) used for fraud prevention and service quality.
- Console account data. For client operators: name, work email, role, login and security events (including two-factor authentication status), and the actions taken in the console (audit trail).
3. Why we process it, and the lawful bases
- Verifying identity on the instructions of the client (performance of the client's contract with us; the client establishes its own lawful basis, commonly compliance with anti-money-laundering law or legitimate interests).
- Biometric face matching and liveness: your explicit consent, captured before any camera opens.
- Fraud prevention and platform security: legitimate interests in keeping the service safe and reliable.
- Billing, support, and account administration: performance of our contract with the client.
- Legal obligations: where retention or disclosure is required by applicable law.
4. Biometric data and consent
Before any document or selfie capture begins, the verification flow presents a consent step that explains what will be processed and why. If you do not consent, no biometric processing takes place; you can instead contact the business that requested your verification about alternative ways to prove your identity. Consent can be withdrawn by contacting privacy@zanyara.com or the requesting business; withdrawal does not affect processing that happened before it.
5. How long we keep data
- Verification data is retained according to the controller client's configured retention period, after which it is deleted by automated purge jobs.
- Liveness challenge frames are short-lived evidence: they are automatically purged within 30 days of capture.
- Audit trails and billing records are kept for as long as we are required to for legal, accounting, and dispute-resolution purposes.
- Console account data is kept for the life of the account and deleted or anonymised after closure, subject to legal retention duties.
6. Who we share data with (subprocessors)
We do not sell personal data. We share it only with the parties needed to run the service:
- Google Cloud Platform: hosting and storage. Data residency is configurable: clients choose the region where their data is hosted.
- SMSPortal: delivery of cross-device verification links sent by SMS.
- OpenSanctions: the sanctions/PEP/adverse-media datasets we screen against. Screening queries are performed against this data; screening results are stored with the check.
- The controller client: the business that requested your verification receives the results and evidence of the check.
Where a subprocessor processes data outside the UK/EEA, we rely on appropriate safeguards such as adequacy regulations or standard contractual clauses.
7. Your rights
Under applicable data-protection laws (including the EU GDPR, UK GDPR, POPIA, the CCPA/CPRA and similar regional frameworks) you have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent for consent-based processing. Where Zanyara is the processor, we will route your request to the controller client and support them in answering it; our platform exposes right-to-erasure APIs so clients can execute deletion programmatically.
To exercise a right, contact privacy@zanyara.com. You also have the right to complain to a supervisory authority; in the UK that is the Information Commissioner's Office (ICO).
8. Security
Data is encrypted in transit and at rest. Access is role-based and logged; console sessions are single-session and can be IP-locked, with optional two-factor authentication. Every check carries a tamper-evident audit trail of who did what, when.
9. Cookies and local storage
Zanyara's web applications use only strictly necessary storage: session tokens to keep operators signed in and short-lived state needed to run a verification (for example, which capture step you are on). We do not use advertising or cross-site tracking cookies, and we do not load third-party analytics on applicant-facing pages.
10. Changes and contact
We will update this policy as the service evolves and change the date at the top when we do. Material changes affecting applicants are also communicated to our clients. Questions: privacy@zanyara.com (privacy) or hello@zanyara.com (general).