Trustd Privacy Notice

1. What is Trustd IDV under the UK DVS?

Trustd’s Identity Verification service allows one time verification of a living person’s identity. This identity verification is conducted under the rules set out in the Department for Science, Innovation and Technology’s UK digital identity and attributes trust framework (known as the “UK DVS”).

Trustd uses its Identity Verification service, certified against the UK DVS, to assist its Clients conduct digital ID and Right to Work checks. You do not have to pay Trustd for this service, but Trustd will charge its Clients. If you do not want to complete a digital check, you should contact the organisation (the Trustd Client) that asked you to complete the check and ask for an alternative way of proving your identity.

2. Who we are

Managed Identities Limited (Company No. 12044881), trading as Trustd, of Newstead House, Pelham Road, Nottingham, United Kingdom NG5 1AP (“we”, “us”, “our”) provides the Trustd identity verification service.

In this notice, “Client” means the organisation that asked you to complete an identity check using Trustd, and with which we have a contract. “You” means the individual whose identity is being checked.

3. Our role, and the Client’s role

Data protection law distinguishes between a controller, who decides why and how personal data is used, and a processor, who acts on the controller’s instructions.

ProcessingRoleWho to contact
Identity verification carried out because a Client asked you to complete a checkThe Client is the controller. We act as processor on the Client’s instructions.The Client, for questions about why the check was required, the result, and how long the result is kept
Our own limited purposes described at section 7 — securing and operating the service, detecting fraud against it, meeting our own legal and certification obligations, and our websiteWe are the controllerUs, using the contact details at section 14

Where we act as processor, the Client is responsible for telling you why your identity is being checked, on what lawful basis, and what it does with the result. If you have questions about those matters, or you want to be verified another way, you should contact the Client.

4. Information we collect from you

We collect and process some or all of the following, depending on the check the Client has asked you to complete:

  • Information needed to verify your identity, which may include biometric data where you choose to provide it.
  • Personal details such as name, date of birth, address, and details taken from your identity document.
  • Driving licence details, driver’s insurance and vehicle details, and other licences, qualifications and registrations relevant to your position with the Client.
  • A record of your progress through the verification, and the result of each check carried out.
  • A record of any correspondence, if you contact us.
  • Technical information about your use of the Trustd platform, including traffic data, weblogs and other communication data.

5. Information we collect from other sources

To carry out a check we may send your details to third-party providers and use their response. The providers we use are:

ProviderWhat it is used for
GBG — ID ScanBiometric checks: liveness detection and matching your selfie to the photograph in your identity document
GBG — ID3 GlobalVerifying identity details including date of birth, driving licence details and entitlement to drive, and checking that the identity has existed over time. GBG may search records held by the UK credit reference agencies to do this. This is a soft credit search
GBG — TrustIdentity fraud checking
DVLA — MOT HistoryMOT history of a vehicle
DVLA — Access to Driver DataDriving licence endorsements

We may also receive information about you from the Client.

6. Automated processing

The matching of your information against third-party records is carried out automatically. The result is provided to the Client. Decisions about what to do with the result — for example whether to engage you — are taken by the Client, not by us. No applicant is denied onboarding to our platform as a result of automated processing.

7. Why we process your information, and on what basis

7.1 Where we act as processor

We process your information on the Client’s documented instructions, to carry out the identity check the Client has asked you to complete and to return the result to it. The lawful basis for that processing is the Client’s to determine and to explain to you.

7.2 Where we act as controller

There is a limited set of processing that we carry out for our own purposes. For this we are the controller.

PurposeLawful basis
Collecting biometric data to verify that you are a real person and that you match your identity documentExplicit consent, which you give before each biometric capture. If you do not want to give it, contact the Client and ask to be verified another way.
Keeping records of how each verification was carried out, to meet our obligations under the UK digital verification services trust framework and to evidence them to our auditor and the regulatorLegal obligation, and our legitimate interest in maintaining certification
Detecting and preventing fraud against the service, including sharing information with fraud prevention agencies and the authorities where we suspect an offenceLegitimate interest, and substantial public interest for any special category data
Securing and operating the platform, including access control and monitoringLegitimate interest
Responding to your questions and to any complaint or rights requestLegitimate interest, and legal obligation where the request is one the law requires us to answer
Improving the accuracy of the service and reducing bias in how it performsLegitimate interest. See section 7.3

8. Who we share your information with

  • The Client that asked you to complete the check. We provide the result of the verification and a record of how it was carried out.
  • The third-party providers listed at section 5, so that they can carry out the checks we have asked them to perform.
  • Fraud prevention agencies and the authorities, where we suspect identity fraud or another offence.
  • Law enforcement or another public body where we receive a valid legal order. We satisfy ourselves that the request is valid and that no more information is provided than is necessary, and we tell the Client where we are able to.
  • Our auditor and the regulator of the digital verification services trust framework, for the purpose of certification and supervision.
  • A buyer or seller, if we sell or buy a business or assets, or if our business is acquired.

We do not sell your information, and we do not share it with advertisers.

9. Where your information is stored, and international transfers

  • The Trustd platform operates on Amazon Web Services (AWS) located in the United States of America. AWS is party to the US-EU Data Privacy Framework. Details of which can be found in the following link.

10. How long we keep your information

  • We hold your information in-line with our tenant contracts which could be up to 6 years.

Where we are under a legal obligation to keep information for longer, for example following a valid request from law enforcement, we will do so.

11. How we protect your information

  • Personal data is encrypted in transit and at rest.
  • Access is restricted to those with a genuine business need, is subject to a duty of confidentiality, and is protected by multi-factor authentication.
  • We operate an information security management system certified to ISO/IEC 27001, and a risk management framework aligned to ISO/IEC 27005.
  • We have a documented procedure for responding to a personal data breach, and we will notify you and the regulator where the law requires it.

The transmission of information over the internet is never completely secure. We protect your information as far as we are able, but any transmission is at your own risk.

12. Your rights

You have the following rights in relation to your personal data: to be told how it is used and to have a copy of it; to have inaccurate information corrected; to have information erased in certain circumstances; to receive information you provided in a portable format; to object to processing in certain circumstances, including at any time to direct marketing; to have processing restricted in certain circumstances; and to complain to the Information Commissioner’s Office.

Where we act as processor, the Client is responsible for answering your request. If you contact us we will pass your request to the Client and tell you that we have done so. Where the request concerns processing for which we are the controller, as described at section 7.2, we will answer it ourselves.

To make a request, contact us using the details at section 14, tell us enough to identify you, and tell us what your request relates to. We may ask you to confirm your identity before we act, so that we do not disclose your information to someone else.

We do not have to disclose information about fraud indicators. Where that applies you should contact the relevant fraud prevention agency.

13. Cookies and similar technologies

A cookie is a small file of letters and numbers stored on your browser or device. Cookies contain information that is transferred to your device and allow the Trustd platform to recognise it.

Cookies that are strictly necessary for the platform to work are enabled by default and are set automatically at the point you access the Trustd platform. Any cookie that is not strictly necessary is set only where you expressly consent to it through the cookie banner. You can change your choice at any time.

Type of cookieWhat it does
Strictly necessaryRequired for the operation of the Trustd platform. These include cookies that let you sign in to secure areas of the platform, and cookies that record that you have accepted this notice.
AnalyticalAllow us to recognise and count visitors and to see how visitors move around the Trustd platform. This helps us improve the way the platform works, for example by making sure people can find what they are looking for.
FunctionalityRecognise you when you return to the Trustd platform. These allow us to personalise content, greet you by name, and remember your preferences such as your choice of language or region.
TargetingRecord your visit to the Trustd platform, the pages you visit and the links you follow. We use this to make the platform, and any offers we send you, more relevant to your interests. We use this information ourselves only.

We do not share cookie information with third parties. Cookie information collected through the Trustd platform is used by Managed Identities Limited only, and is not sold, passed to advertisers, or shared with any other organisation for their own purposes.

Further information about the cookies used by Managed Identities Limited, and how to manage them, is published in the Trustd cookie policy on our help centre. The Trustd cookie policy covers both the Trustd platform and our marketing website, and is maintained by Managed Identities Limited.

13.1 Device and usage information

We may collect information about the mobile phone, computer or other device from which you access the Trustd platform, including where available your IP address, operating system, screen size and resolution, and browser type. We use this for systems administration and to understand how the service is used.

This is statistical information about how the platform is used and does not by itself identify you. We may, however, use it together with other information we hold about you in order to understand your use of the service.

14. How to contact us, and how to complain

We hope we can resolve any concern you raise about how your information is used.

PurposeContact
Questions about why you were asked to complete a check, the result, or how long the result is keptThe Client that asked you to complete the check
Questions about this notice or about how we handle personal data[email protected]
Data protection officer[email protected]
Postal addressManaged Identities Limited, Newstead House, Pelham Road, Nottingham, United Kingdom NG5 1AP

You may also complain to the Information Commissioner’s Office, which regulates the handling of personal information in the United Kingdom, at ico.org.uk/make-a-complaint or on 0303 123 1113. You do not have to complain to us first, although we would prefer the chance to put things right.