[
Legal
]
Data Retention and Deletion Policy
Last updated September 30, 2026 · Effective September 30, 2026 · Version 1.0
This policy states how long Krede, Inc. and its technology provider keep the data processed through the Krede verification services on behalf of our customers, and how it is deleted. It forms part of each customer's Data Processing Agreement. Where a customer agreement states a different period in writing, that period applies.
1. Retention periods
Data
Kept for
Then
Identity document images, selfie images and video submitted for verification
Five years after the check is created
Permanently deleted
Verification results, extracted data fields, screening results, reports, decision records, logs and consent records
Five years after the check is created
Permanently deleted
Biometric data (a scan of face geometry created from images or video to compare a selfie with an identification document or to confirm liveness)
Until the purpose for which it was collected is satisfied, and in any case no later than three years after the individual's last interaction with our customer
Permanently destroyed
Dashboard user account data
The term of the customer agreement plus 90 days
Deleted
Sandbox (test) data
No real personal data is permitted in the sandbox
Purged on reset
2. Biometric data
Biometric data is collected only to verify an applicant's identity and to prevent fraud in connection with the applicant's application to, and relationship with, our customer, including re-verification of the same applicant. It is not sold, leased, traded or used for marketing. It is disclosed only to the customer that requested the verification, to service providers bound by this policy, as required by law, or with the individual's consent. Photographs and video from which a scan is derived are kept as document and selfie images under section 1.
3. Deletion on request
A customer may instruct deletion of the data for a named applicant or check at any time. Deletion is completed within 30 days of the written instruction, except where law requires the data to be kept, in which case only the data required is kept for as long as the requirement lasts. Backup copies are overwritten in the ordinary course.
4. End of a customer agreement
Within 30 days after a customer agreement ends, the customer's data is returned or deleted, at the customer's written election, subject to the legal-hold exception above.
5. Method
Deletion uses methods that make the data non-recoverable. Deletion is confirmed in writing on request.
6. Changes
We may update this policy. Customers are notified at least 30 days before a change takes effect. A retention period for a customer's data is never lengthened without that customer's written agreement.
Questions
privacy@krede.ai