Legal
Privacy policy
Last updated 28 July 2026.
This privacy policy explains how VeriLayer collects, uses, shares and protects personal data. VeriLayer provides identity and eligibility verification services — document and ID verification, affordability checks, anti-money-laundering (AML) screening, fraud detection and real-time decisioning — to businesses such as lenders, debt-solution providers and buy-now-pay-later firms.
In this policy, "VeriLayer", "we", "us" and "our" refer to [VeriLayer Ltd], a company registered in England and Wales (company number [00000000]) with its registered office at [registered address]. We are registered with the Information Commissioner's Office (ICO) under registration number [ZA000000].
Our role: controller and processor
The law treats us differently depending on whose data we are handling, and this affects your rights and who you should contact.
- As a controller. For personal data about visitors to our website, prospective clients, our business contacts and the people who work for our clients, VeriLayer decides how and why the data is used. This policy governs that processing.
- As a processor. When one of our clients uses VeriLayer to verify their own customers, that client is the controller. We process the end customer's identity and financial data only on the client's documented instructions, under a written data processing agreement. If your identity or eligibility was checked while dealing with one of our clients, please read that organisation's own privacy notice first — they are responsible for the decision to use our service and for handling your rights request, and we will assist them as required.
Information we collect
Website visitors, prospects and business contacts (we are controller)
When you visit our website or contact us — for example by requesting a demo — we may collect:
- Contact and business details you provide through our forms or by email, such as your name, company email address, company size, job title and any message you send us.
- Technical and usage data collected automatically, such as your IP address, device and browser type, and how you interact with the site. See our Cookie Policy for detail.
- Correspondence and records of any enquiries, support requests or contractual discussions.
Individuals verified through our services (we are usually processor)
When a client onboards their customers using VeriLayer, we process personal data about those individuals on the client's behalf. Depending on which checks the client has enabled, this can include:
- Identity data — full name, date of birth, nationality, address, and identity document details such as document type, number and expiry, captured from passports, driving licences and national ID cards.
- Document and image data — images of identity documents and a photograph or selfie used to confirm the document belongs to the person presenting it.
- Biometric data — where facial matching is used to compare a live image to the photo on an identity document, we process biometric data (a special category of personal data). See below.
- Financial data via open banking — where affordability or fraud checks are enabled, the individual connects their own bank account. We then read categorised transaction data, income, balances, existing credit and regular commitments to assess affordability and eligibility.
- Screening data — results of AML, sanctions, politically exposed person (PEP) and watchlist checks, which may indicate that an individual is the subject of, or connected to, financial-crime or criminal offence data.
- Decision and audit data — the verification and eligibility outcome we return to the client, together with the audit trail of how that result was reached.
Special category and criminal offence data
Biometric data used for identification is a "special category" of personal data under the UK GDPR, and AML and sanctions screening can involve data about criminal offences. Where we process this data as a processor, we act on our client's instructions and rely on the client's lawful basis and Article 9 / Article 10 condition. Where we determine any such processing ourselves, we rely on conditions including the prevention and detection of unlawful acts, compliance with regulatory requirements, and substantial public interest, and we keep an appropriate policy document as required by the Data Protection Act 2018.
How we use your information and our lawful bases
When we act as a controller, we rely on one or more of the following lawful bases under the UK GDPR:
- Legitimate interests — to respond to enquiries, run and secure our website, market our services to businesses, and manage our client relationships, where these interests are not overridden by your rights.
- Contract — to take steps at your request before entering a contract and to provide services to our clients.
- Legal obligation — to meet our own regulatory, tax, accounting and financial-crime obligations.
- Consent — for certain marketing communications and non-essential cookies, which you can withdraw at any time.
When we act as a processor, we process personal data only to deliver the verification, affordability, AML and fraud-detection services our client has asked for, strictly on that client's instructions.
Automated decision-making
Our service supports automated processing to return a real-time verification and eligibility outcome. Where this produces a decision with a legal or similarly significant effect on an individual, our client — as controller — is responsible for putting the appropriate safeguards in place, including ways to obtain human review, express a point of view and challenge the decision. VeriLayer designs its checks to be consistent and auditable and supports clients in meeting these obligations.
Open banking
Affordability and fraud checks use regulated open banking. The individual authenticates directly with their own bank and consents to share their data; we never see or store banking login credentials. Access is time-limited and used only for the purpose the individual agreed to.
Sharing and disclosure
We may share personal data with:
- Our clients, to whom we return verification and eligibility results for the individuals they ask us to check.
- Service providers and sub-processors who support our platform — for example cloud hosting, open banking providers, document and biometric verification partners, and AML and sanctions data providers — under contracts that require them to protect the data.
- Regulators, law enforcement and professional advisers where we are required or permitted to do so by law, including to prevent and detect fraud and financial crime.
- Parties to a corporate transaction, such as a merger, acquisition or reorganisation of our business.
We do not sell personal data.
International transfers
We aim to keep personal data within the UK and European Economic Area. Where data is transferred outside these areas — for example to a sub-processor — we put in place a lawful transfer mechanism, such as UK adequacy regulations or the International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), together with appropriate safeguards.
How long we keep data
When we act as a controller, we keep personal data only as long as necessary for the purposes set out above and to meet our legal and regulatory obligations, after which it is securely deleted or anonymised. When we act as a processor, retention is governed by our agreement with the client, and we delete or return the data at the end of the service unless we are required to keep it by law.
How we protect your data
We use appropriate technical and organisational measures — including encryption in transit and at rest, access controls, monitoring and staff training — to protect personal data against unauthorised access, loss or misuse.
Your rights
Under UK data protection law you have rights over your personal data, including the right to access it, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. You also have rights in relation to solely automated decisions.
If VeriLayer is the controller, contact us using the details below to exercise these rights. If your data was processed as part of a check carried out for one of our clients, that client is the controller — please contact them, and we will support them in responding.
Cookies
We use cookies and similar technologies on our website. For details of what we use and how to manage your choices, see our Cookie Policy.
Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above and, where changes are significant, take reasonable steps to bring them to your attention.
Contact us and complaints
For any questions about this policy or to exercise your rights, contact us at enquiries@VeriLayer.com, or write to our Data Protection lead at [registered address].
If you are unhappy with how we have handled your personal data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we would welcome the chance to resolve your concern first.