Privacy Policy
Last updated: 1 March 2025
This Privacy Policy explains how ASTERIA KYC Ltd ("ASTERIA", "we", "our") collects, uses, and protects personal data in connection with the ASTERIA KYC platform and associated services. ASTERIA is certified under ISO/IEC 27701 (Privacy Information Management) and ISO/IEC 27018 (Cloud Privacy Protection).
1. Data Controller
ASTERIA KYC Ltd is the data controller for personal data collected through the website (asteriakyc.com), marketing communications, and account management. For personal data submitted by customers for identity verification processing, ASTERIA acts as a data processor and the customer is the data controller.
2. Data We Collect
Website and account data: name, email address, company name, job title, and usage data collected when you create an account or contact us. Verification data (as processor): document images, facial biometric data, and associated metadata submitted by customers for identity verification. This data is processed on behalf of the customer and governed by the applicable Data Processing Agreement.
3. How We Use Your Data
Account and contact data is used to provide and manage your access to the Services, send operational communications, and (with consent) marketing communications. Verification data submitted for processing is used solely to provide the verification services requested by the customer and is not used for ASTERIA's own purposes.
4. Legal Basis for Processing
We process account and contact data under Article 6(1)(b) GDPR (contract performance) and Article 6(1)(f) (legitimate interests) for security and fraud prevention. Marketing communications are sent under Article 6(1)(a) (consent) where required. Verification data is processed under Article 6(1)(c) (legal obligation) and Article 6(1)(b) as directed by the customer.
5. Data Retention
Account data is retained for the duration of the contractual relationship and for 7 years thereafter for legal compliance purposes. Verification session data is retained in accordance with the customer's configured retention period (default 7 years for AML-regulated customers). You may request deletion of account data by contacting privacy@asteriakyc.com.
6. Your Rights
Under GDPR, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing and to withdraw consent where processing is consent-based. To exercise these rights, contact privacy@asteriakyc.com. If you believe your rights have been violated, you have the right to lodge a complaint with your supervisory authority.
7. Data Transfers
ASTERIA processes data within the European Economic Area, the United Kingdom, and (for APAC customers) Singapore. International transfers are made under Standard Contractual Clauses or applicable adequacy decisions. A copy of the SCCs applicable to your processing can be requested from privacy@asteriakyc.com.
8. Cookies
The ASTERIA KYC website uses strictly necessary cookies for session management and security. Analytics cookies (used for platform performance monitoring) are only activated with your consent. You can manage cookie preferences via the cookie settings panel available on the website.
9. Security
ASTERIA KYC implements technical and organisational security measures in line with ISO/IEC 27001 and ISO/IEC 27017. These include encryption in transit and at rest, access controls, penetration testing, and continuous security monitoring. A copy of our current security statement is available upon request.
10. Contact
Data Protection Officer: privacy@asteriakyc.com ASTERIA KYC Ltd, 25 Cabot Square, London, E14 4QA, United Kingdom