Privacy Policy
Effective date: March 1, 2026
1. Data Controller
VerixID is a digital document integrity recording system operating under the laws of the Republic of Indonesia. Privacy-related inquiries may be directed through our Contact Page.
2. Core Privacy Guarantees
The structural integrity of VerixID relies on three non-negotiable architectural principles:
- 2.1 Zero Custody — All cryptographic fingerprint calculations (SHA-256) execute locally within your client environment. File payloads are never transmitted to our infrastructure—not merely as a matter of administrative policy, but because the underlying system architecture lacks any ingestion endpoint.
- 2.2 Anonymous by Default — Utilizing the platform requires no registration, identity disclosure, or personal credentials. Users on the free service tier remain completely anonymous.
- 2.3 Data Minimization — We restrict stored records exclusively to data points technically required to maintain ledger functionality.
3. Information Retained
3.1 Ledger Data — Integrity Records
When a document fingerprint is committed to the platform, the following record entries are preserved:
- a. The cryptographic SHA-256 hash derived from the file (never the file itself)
- b. An authoritative server timestamp marking the moment of registration
- c. A randomly generated unique Record ID
- d. A cryptographic hash of the designated Ownership Key (never the raw Key)
- e. A system-generated digital record signature
- f. Optional client-submitted metadata: filename and file size
This data payload contains no personal identifiable information (PII) and cannot be linked to a specific identity without the corresponding client-side Ownership Key held exclusively by you.
3.2 Billing Information — Paid Tiers Only
For accounts utilizing paid service tiers, we collect minimal operational data necessary for transaction processing and administrative servicing:
- a. Email address — utilized for transaction receipts and critical administrative notices
- b. Transaction telemetry — processed through authorized payment gateway partners
Provided email details are never deployed for promotional marketing, shared with unauthorized third parties, or converted into user profiling assets.
3.3 Excluded Data (What We Do Not Collect)
By architectural design, the VerixID platform does not process or store:
- a. Raw document contents or payload binaries in any format
- b. User IP addresses
- c. Geolocation signals
- d. Browser user-agent logs
- e. User real names, physical addresses, or government identification
- f. Tracking cookies or cross-session user identifiers
- g. Behavioral profiling or third-party telemetry data
4. Legal Basis for Processing
This platform operates as a registered Electronic System Operator (PSE) under registration number 022901.01/DJAI.PSE/04/2026.
Data processing complies with applicable privacy frameworks, including Law No. 27 of 2022 on Personal Data Protection (UU PDP), founded on the following legal grounds:
- 4.1 Contractual Performance & Core Service Provision — Ledger record processing is required to execute cryptographic document verification.
- 4.2 Financial Administration — Billing email processing is necessary to fulfill account servicing obligations for paid tiers.
We do not rely on legal grounds such as legitimate interest to perform processing activities that would allow user re-identification without explicit user consent.
5. Data Retention Parameters
- 5.1 Ledger Records — Maintained for a default period of 1 year* from initial registration in accordance with service retention terms. Ledger entries are mathematically immutable and cannot be altered or removed prior to policy expiry.
- 5.2 Billing Email Data — Retained for the active duration of the subscription term and purged following the closure of outstanding administrative obligations.
6. Third-Party Data Processing
We do not sell, rent, or trade user data. Data interactions involving third-party infrastructure are limited strictly to the following parameters:
- 6.1 Infrastructure Partners — Global edge infrastructure and cloud computing providers operating under strict security SLAs. Infrastructure operations do not receive identity records or personal user identifiers.
- 6.2 Payment Processing Gateway — Transaction data limited strictly to required parameters to process payments during premium tier checkouts.
- 6.3 Statutory Compliance & Legal Authorities — Disclosures executed solely in response to enforceable judicial orders or lawful police actions. Because our systems do not store user identity records, legal disclosures remain strictly limited to non-personal ledger metadata.
7. Data Subject Rights
Under applicable data protection law, you hold the right to:
- 7.1 Access personal billing records maintained within our systems
- 7.2 Rectify inaccurate or outdated billing contact records
- 7.3 Request Erasure of billing email records upon settlement of active servicing obligations
- 7.4 Obtain Transparency regarding operational data handling procedures
Architectural Note: Committed ledger entries (SHA-256 hashes and timestamp parameters) are cryptographic artifacts that remain immutable. Because ledger data contains no personal information or identity links, erasure requests do not apply to mathematical ledger hashes.
To exercise your data subject rights, please reach out via our Contact Page.
8. Cookies & Local Client Storage
8.1 VerixID does not deploy tracking cookies, third-party analytics scripts, advertising pixels, or cross-site fingerprinting frameworks.
8.2 The application utilizes standard browser sessionStorage exclusively to relay temporary state between pages within an active navigation flow (e.g., transferring parameters between verification and invoice request workflows). Session storage data remains restricted to your local client and terminates automatically upon tab closure.
9. Security Safeguards
We deploy robust technical safeguards across all infrastructure layers, including mandatory TLS encryption for in-transit communication, strict administrative access controls, and isolated domain boundaries separating public ledger records, forensic data, and billing components. By engineering our architecture to operate without collecting personal data, the risk of personal identity breach is systematically eliminated.
10. Policy Amendments
We reserve the right to modify this Privacy Policy to reflect evolving technical specifications or regulatory mandates. Revisions will be published directly on this page with an updated effective date. Continued system interaction following published updates signifies acceptance of the revised policy.
11. Contact Details
For inquiries or privacy-related communications, please contact us via our Contact Page.