Privacy

Privacy notice

Draft pending counsel and DPO approval. This page sets out the structure and intended content of the privacy notice. It is not yet in force and must not be relied upon until it has been approved and this banner has been removed.

1. Who is responsible for your data

B Group acts in two different roles. When a business uses the platform to verify you, that business decides why and how your data is processed and is the controller; B Group processes your data on its instructions as a processor. If you choose to create a vault, B Group is the controller for the vault service, which exists only to let you hold and reuse your own verified identity. The legal entity, its address and registration details will be stated here once the entity decision has been confirmed by counsel.

2. What data is processed

  • Identity data: name, date of birth, nationality, identity document data and images.
  • Biometric data: a facial image and a template derived from it, used to compare your selfie with your document portrait and to confirm liveness. This is special-category data under the GDPR and is processed only with your explicit consent.
  • Address data: your address and the document or confirmation used as evidence.
  • Screening results: matches or non-matches against PEP, sanctions and adverse-media sources, and where the business requires it, wallet risk results.
  • Technical data: device and connection signals used to detect fraud and injection attacks.
  • Vault data: if you create a vault, the encrypted vault contents, your public key, and the minimum metadata needed to route a request you make.

3. Why it is processed and on what legal basis

  • Verifying your identity for a business that is legally required to do so: the business's legal obligation and legitimate interests; explicit consent for biometric comparison.
  • Screening and ongoing monitoring: the business's legal obligation under anti-money-laundering rules.
  • Fraud prevention and security: legitimate interests of the business and of B Group.
  • The vault service: your consent, and your right to data portability.
  • Keeping evidence packs: the legal obligation of the business to retain records.

4. How long data is kept

Evidence packs are the business's regulatory record and are kept for the period the law requires (five years after the end of the relationship under the EU AML Regulation, extendable on a supervisor's order) and then deleted automatically. Biometric templates are kept only as long as the verification flow needs them, unless you choose a vault, in which case the template lives inside the vault under your key. Your vault is kept until you erase it. Erasure is cryptographic.

5. Who receives data

The business that is verifying you; the sub-processors that perform specific steps (a document-authenticity provider, a liveness and face-match service processed in the EU, screening data providers, a crypto-asset analytics provider where required, and our cloud infrastructure provider); and public authorities where the law requires. When you reuse your vault, the data you select is sent only to the business you chose. The full list of sub-processors is available on request and on contract.

6. Where data is processed

In the European Union. UK and Swiss regions are planned. Where data is transferred outside the EU, appropriate safeguards will be described here once confirmed.

7. Your rights

You have the right to access, rectify, erase, restrict and port your data, to object to processing based on legitimate interests, to withdraw consent at any time, and to complain to a supervisory authority. Where a business must keep a record by law, that part cannot be erased until the retention period ends, and we will tell you the legal basis for what is kept. Requests about a verification should go to the business that verified you; requests about your vault can be made in the vault itself or to the Data Protection Officer.

8. Automated decisions

Verification flows use automated checks. Any adverse outcome is reviewed by a human before it is final, and you can ask for the reasons and contest the outcome through the business that verified you.

9. Contact

Data Protection Officer: dpo@bgroup.io. Postal address and supervisory-authority details will be added once the entity decision is confirmed.

Version: draft. This notice will be dated and versioned when approved.