Legal Terms
Privacy Policy
This notice applies to anyone who: (i) installs, opens or uses Vouch Verifier (the „App”) on a device they control or (ii) goes through attribute verification process using our products, as part of our business partner’s user or data verification procedure. It also applies to people who interact with vlayer directly — for example by emailing [email protected] or contacting our support team.
This notice does not cover the verification itself. When you start a verification through a vouch integration (for example, an employer's recruitment flow), the business that requested the verification is the controller of the personal data processed in that flow. That business will present you with its own privacy notice describing what is collected, why, on what legal basis, who receives it, how long it is kept and how to exercise your rights. Please refer to that notice for the verification-flow personal data.
1. Who we are
vlayer Labs Ltd — a company incorporated in England and Wales with company number 15480811, having its registered office at 101 New Cavendish Street, 1st Floor South, London W1W 6XH, United Kingdom.
Contact for privacy matters: [email protected].
We have not appointed a Data Protection Officer, but the contact above will route your message to the right person.
2. The two roles vlayer plays
Data-protection law distinguishes between the party that decides what to do with personal data (the "controller") and the party that processes personal data on the controller's instructions (the "processor"). For the vouch App, vlayer plays both roles, but for clearly separated purposes.
a) vlayer acting as a data processor on behalf of its customers:
In this scenario, we process personal data you generate by running a verification through Vouch (for example, the cryptographic proof produced as part of verification).
The third party that asked you to verify your identity is the controller of your personal data. vlayer processes that data only on that third party’s documented instructions, under a written processor agreement. For more information, please see privacy notice provided by the third party, for whom you undergo identity verification.
b) vlayer acting as a data controller
In very narrow circumstances, vlayer acts as a data controller. These include technical operation of the App, i.e.: crash reports, anonymous usage diagnostics, version-compatibility checks, abuse and fraud prevention, and direct communications you send us (for example, support enquiries or feedback).
For these limited purposes, vlayer is the controller, and the rest of this notice describes how we handle that data.
3. Personal data vlayer collects as a controller
3.1 Technical data from the App
- Crash reports and error diagnostics (including device model, operating-system version, App version, the function that failed and a technical error code). We use these to detect and fix bugs.
- Update and version-compatibility checks (App version, locale, broad geographical region of the request).
- Security and abuse-prevention signals (such as repeated install/uninstall patterns or anti-tampering indicators), used to detect and prevent fraudulent use of the App.
3.2 People who interact with us directly
- Contact details and content of your message when you email us at [email protected], our support address, or send us feedback.
- Limited account or profile data if you create an account on a vlayer dashboard (typically reserved for our business customers —not for App users who only run verifications).
3.3 What we do not collect for our own purposes
We do not collect or retain the attributes extracted in a verification (for example, the contents of a name field on a data source you log in to), the credentials you use to log in to those data sources (we never see or store them), the tokens or cookies of the data sources, or the cryptographic proofs you submit to a business — except as a processor on that business's behalf, governed by their privacy notice.
4. Why we process this data (controller-side legal bases)
Our legitimate interests (Article 6(1)(f) GDPR / UK GDPR) — in operating, securing, supporting and improving the App, and in preventing fraud and abuse. We have balanced these interests against your rights and freedoms and use the minimum data necessary.
Performance of a contract or pre-contractual steps (Article 6(1)(b)) — when you contact us, ask us a question, or use a vlayer dashboard account.
Compliance with legal obligations (Article 6(1)(c)) — for example, retaining records we are legally required to keep, or responding to lawful requests from authorities.
Your consent (Article 6(1)(a)) — only where we ask for it (for example, for any optional analytics we may introduce in the future). You can withdraw consent at any time.
5. Who we share data with
We share controller-side personal data only with the following categories of recipients, under appropriate contracts:
- Cloud infrastructure providers that host our systems.
- Security, anti-fraud and content-delivery providers.
- Software bug-tracking and crash-reporting providers.
- Professional advisors (lawyers, accountants, auditors) where they need access to give us advice.
- Public authorities and law-enforcement agencies, only where we are legally required to disclose.
We do not sell personal data, and we do not use personal data to serve targeted advertising.
6. Transfer of personal data
Acting as a data controller, we transfer your personal data to recipients outside the European Economic Area, i.e. to third countries, for the purpose of hosting our App. Any such additional transfers are made subject to the Controller having a legal basis, in a manner consistent with the provisions of Chapter V of the GDPR, i.e. on the basis of lawful data transfer mechanisms that ensure an adequate level of protection. For the purpose of hosting, we rely on Standard Contractual Clauses concluded with our trusted service providers and on the EU-US Data Privacy Framework. In the event that any additional transfers are to happen in the future, we shall also rely on adequate mechanisms to ensure their legality, in particular: the EU-US Data Privacy Framework, an adequacy decision issued by the European Commission (notably regarding transfers to the United Kingdom), Binding Corporate Rules (BCRs) or Standard Contractual Clauses (SCCs).
7. Personal data retention
We keep controller-side personal data only for as long as necessary for the purpose for which it was collected, and then delete or anonymise it. Indicative retention periods:
- Crash and diagnostic data — typically up to 90 days, then aggregated or deleted.
- Support and feedback correspondence — for the duration of the matter and for a reasonable archive period afterwards, not exceeding the applicable statute-of-limitation period.
- Security and abuse-prevention logs — typically up to 12 months.
For data we process as a processor in a verification flow, the relevant business's retention policy applies and our retention is governed by our processor agreement with them — typically only for the brief period needed to generate and deliver the verification.
8. Your rights
You have the right to:
a) to be informed whether your personal data is being processed by us and, if so, the right to access it and to receive a copy of it (Article 15 GDPR);
b) the right to rectification of personal data where the data is inaccurate and to completion of incomplete personal data (Article 16 GDPR);
c) the right to erasure of personal data, the so-called "right to be forgotten" (Article 17 GDPR);
d) the right to restrict the processing of personal data (Article 18 GDPR);
e) Othe right to receive the processed personal data in a structured, commonly used machine-readable format and to have it freely portable, including the right to request that we send it to another controller (Article 20 GDPR);
f) the right to object to the processing of your personal data on the basis of Article 6(1)(f) of the GDPR (Article 21 GDPR);
g) the right to lodge a complaint with the President of the Office for Personal Data Protection.
Your personal data will not be subject to automated decision-making, including profiling.
The provision of personal data within the scope indicated in point 4 above is voluntary, and always at the initiative of the data subject, but necessary in order to successfully complete the registration process, as well as to access and benefit from the Services. Failure to do so will result in the inability to register and to use the Services, notably the Dashboard and the Solution.
If any of the consents is given (i.e. as referred to in point 4 above) you have the right to withdraw your consent at any time without affecting the lawfulness of the processing carried out on the basis of your consent before its withdrawal. Withdrawal of consent will result in us not being able to process the personal data covered by the scope of the consent, for the purposes indicated therein. This item does not apply to the extent that the processing of personal data is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Last Updated: 30th June 2026