Privacy Policy
How Authvio handles account, authentication, verification, developer, support, and usage data across its global and regional services.
Last updated: July 18, 2026 · A brand of Bolrach Technologies Limited
On this page
1. Who we are and where this policy applies
Authvio is a brand of Bolrach Technologies Limited. Bolrach Technologies Limited controls the personal data used to provide Authvio accounts, authentication, fraud prevention, support, and the user-facing verification service.
Authvio serves people and developers in supported countries. Regional processing and storage operate behind the Authvio product identity and domain. A visitor's location never becomes a default audience, residence, nationality, or coverage setting.
2. What we collect
The data depends on the feature you use. It may include:
- Account and profile data: email, name, phone number if provided, date of birth, sex, country of origin, residence and address data when requested, a profile photo, username, and optional biography.
- Registration choices: the version and time of your Terms and Privacy acceptance, plus hashed network data and limited browser information used to prove the choice.
- Authentication data: password hashes or registered authentication methods, recovery and verification state, session identifiers, browser and device details, IP address, and sign-in timestamps.
- Verification data: the requested level, status, decisions, country and region routing, document images, extracted document fields, selfie or video frames, liveness results, face-match results, reviewer actions, and fraud signals when a verification requires them.
- Developer and business data: organization, application, domain, API-key, webhook, usage, verification-reference, billing-contact, and go-live review records.
- Support data: the details you enter in a support request, its reference and category, and account linkage when you are signed in.
A profile photo is required in the current account registration flow. It represents the account, but it does not by itself mean the identity has passed document, face, issuer, or attended verification.
3. Where the data comes from
Most data comes from you, your browser, or a developer using Authvio at your request. Verification may also use results from a configured document, liveness, issuer, sanctions, business-registry, or review provider when that capability is enabled for the requested country and level. The product should identify the check it is asking you to complete.
4. How we use personal data
- Create and manage accounts, sessions, recovery methods, connected apps, and developer workspaces.
- Run the identity check you or a relying party requested, detect duplicate or fraudulent use, and maintain the resulting status.
- Issue authentication tokens and share only the claims and fields approved through the relevant consent and scope controls.
- Operate support, privacy-rights requests, service monitoring, usage limits, audit trails, and incident response.
- Meet legal duties and enforce the Terms and Acceptable Use Policy.
5. Legal grounds
Depending on the feature and applicable law, we process data to perform our contract with you, follow your consent, comply with law, or pursue legitimate interests such as account protection, fraud prevention, abuse control, service reliability, and legal-claim handling. Where consent is the legal ground, you may withdraw it, but that does not undo processing already carried out lawfully.
6. Identity evidence and biometric processing
Document, selfie, liveness, and face-match material is sensitive. It is encrypted, access-controlled, logged, and routed to the data region assigned to the verification. Capture should stop if the required regional evidence store is unavailable.
Finished-session evidence is purged under the active retention policy. The current default is 30 days. An encrypted reference image or protected face template may remain after a successful check for duplicate detection, account recovery, fraud prevention, or later re-verification until the account is erased or another policy requires deletion. Connected apps do not receive raw documents, selfie frames, liveness media, face templates, or internal fraud signals.
issuer_match applies only when an approved issuer connector is configured and shown for the requested country. Authvio does not treat a document and face match as an issuer-database match.
8. Regions and international transfers
Verification evidence follows the regional route assigned from the declared residence and available storage policy. Account, authentication, fraud, support, audit, and control-plane data may be processed in other countries by contracted providers. Where law requires a transfer safeguard, we use the applicable contractual, adequacy, or other approved mechanism. A requested country may remain unavailable until its required storage or provider path is ready.
9. How long we keep data
Account data remains while the account is active. Session, verification evidence, audit, consent, fraud, legal-acceptance, support, developer, and billing records follow separate policies based on their purpose, sensitivity, contract, and legal duties. Finished verification-session evidence currently uses a 30-day default unless an enabled regional policy sets another period. Resolved or closed support requests normally age out after 365 days unless a legal duty or active dispute requires longer retention.
Account erasure revokes connected access and starts deletion of erasable profile and verification material. Erasure is not reported complete while an evidence object remains queued for deletion. Limited non-identifying audit, consent, transaction, or legal records may remain when law or the protection of legal claims requires them.
10. Your choices and rights
Depending on where you live, you may have rights to access, export, correct, delete, restrict, or object to processing, withdraw consent, and complain to a regulator. You can manage connected apps, download an account export, and start account erasure from Account Privacy.
For correction, portability, a representative request, or anything the account controls do not cover, use the privacy request form. We may need to verify identity before disclosing or deleting data.
11. Protection and incident response
We use encrypted transport and storage, role-based access, separate evidence storage, audit records, session controls, key rotation, and service monitoring. No system is risk-free. If a personal-data incident requires notice, we will notify affected people and regulators as required by applicable law.
12. Age requirement
Self-service Authvio accounts are for people aged 18 or older. Registration uses a server-side age gate. If we learn that an ineligible child created an account, we may close it and remove the data, subject to legal retention duties.
13. Changes to this policy
We will change the date on this page when the policy changes. If a change materially affects how an existing account is used, we will give notice through the service or a contact channel where required and may ask for a new acceptance.
14. Contact and complaints
Send privacy or data-protection questions through the encrypted legal and privacy form. Include your country so the request can be handled under the right law. You may also complain directly to the privacy regulator responsible for your jurisdiction.
Authvio is a brand of Bolrach Technologies Limited. Send a legal or privacy request through the encrypted support form.