Privacy Policy

Last updated: July 2026 · Version 1.2

Our core principle: VerifyBlind enables identity verification without requiring your Turkish national ID number (TCKN), full name, or date of birth to be shared in plain text with anyone — including us or our partners. This data is processed in encrypted form only inside a hardware-secured isolated environment (AWS Nitro Enclave) and immediately deleted.

1. Data Controller

Name
VerifyBlind LLC
Email
kvkk@verifyblind.com
Request
In-app "Data Request" or kvkk@verifyblind.com
VERBİS Status
Exempt — Board Decision 2025/1572

The VERBİS registration exemption under Board Decision 2025/1572 covers only the registry filing obligation; disclosure, explicit consent, data security, and all other KVKK obligations remain fully in effect.

2. What Data Do We Process and Why?

Mobile App — Identity Verification

Temporarily processed inside the secure Enclave — then deleted

National ID number (TCKN), full name, date of birth, gender, NFC chip contents, facial image and biometric vector

Stored in our system (does not reveal your identity)

Cryptographic hash (HMAC) values — cannot be reversed to TCKN.
Verification result: only true/false.
Consent record (scope and date).

Never stored

TCKN, full name, date of birth, actual age value, biometric data, facial photo

Partner Portal

DataPurposeRetention
Company name, emailAccount and communicationContract + 10 years
Hashed passwordAuthenticationUntil account deletion
Public key, Callback URLAPI integrationDuration of contract

Mobile App — Support and Feedback

DataPurposeRetention
Name, email address, message content (+ device/OS info for diagnostics)Responding to your support/feedback requestSupport tickets anonymised after 365 days

This information is collected only when you yourself use the in-app Feedback or Support (chat) screen; it is not required for identity verification. Your support tickets are stored in our system and, after 365 days, your email address and IP are irreversibly anonymised (SHA-256); feedback messages are delivered to our support team by email. This data is processed solely to respond to your request and is never used for advertising or marketing.

3. Parties We Share Data With

PartySharedCondition
Partner OrganisationsVerification result (true/false) and — if requested — partner-specific recognition codes (user_id, nsbd_id, doc_id). Raw identity data (national ID, name, biometrics) is never shared; the codes cannot be reversed to the ID number nor linked across partners.With your explicit consent
Amazon Web ServicesEncrypted processing (AWS Nitro Enclave cannot access content)Service infrastructure
Cloudflare Web AnalyticsAnonymous page view statistics (no cookies, no IP storage, no personal data)Service quality monitoring
Sentry (Crash Diagnostics)App crash/error reports only. TCKN, MRZ, facial and biometric data are redacted before sending. Not linked to your identity; never used for advertising or tracking.App stability / error monitoring
Postmark (Email Delivery)Only if you send support/feedback: your email address and message are used to deliver your request to our team and to send you a reply. Identity verification data (national ID, name, biometrics) is never sent.Support/feedback communication
Dropbox / Google Drive (optional backup)Only if you initiate it: your end-to-end encrypted identity backup is written to your OWN cloud account. Only your device can decrypt it; we cannot access it.At your choice
Competent AuthoritiesMinimum data when legally requiredKVKK Art. 8/2-a

4. Retention Periods

Identity data (TCKN etc.)Processing onlyImmediately deleted by Enclave
Biometric dataProcessing onlyImmediately deleted by Enclave
Verification pseudonyms (HMAC)10 yearsAnonymised (Turkish Commercial Code Art. 82)
Technical logs (masked IP)365 daysAnonymised
Application logs90 daysDeleted

5. Security

  • AWS Nitro Enclave — Hardware isolation; no operator, including Amazon, can look inside
  • End-to-end encryption — AES-256-GCM + RSA-OAEP-SHA256
  • Android Keystore (TEE) / iOS Secure Enclave & Keychain — Keys stored in the device secure hardware zone
  • Nonce-based protection — Every operation is unique and non-replayable
  • Data minimisation — Only the minimum necessary data is written to the system

6. Your Rights

RightHow to Exercise
View my dataApp → Settings → Data Request
Delete my dataApp → Settings → Delete My Data
Withdraw consentApp → History → Select operation → Withdraw
Data portabilityApp → Settings → Download My Data
Object / Complainkvkk@verifyblind.com or kvkk.gov.tr
Important note: Since our identity verification records contain neither TCKN nor email, requests relating to your verification operations require you to prove ownership using your in-app nonce value. (Email you provide for support/feedback is outside this scope; you may submit such requests directly to kvkk@verifyblind.com.) Response time: within 30 days.

7. Contact

For questions about our privacy policy or your personal data: kvkk@verifyblind.com