Last updated: Sep 9, 2026
This privacy notice explains how 247 IQ Industries (“247 IQ”, “we”, “us”) collects, uses, and protects information when you visit this website or when our identity-verification products process a document on behalf of a customer. Because our products read identity documents, we have written this notice to be explicit about two very different roles we play — and about what happens to a document image after it has been checked.
Two roles, two sets of rules
As a controller, we decide how information is used: this covers our website, demo requests, and our dealings with customers and candidates. This notice describes that role in full.
As a processor, we only act on the documented instructions of a customer — a bank, a hotel group, a car-rental company, a border authority — when their end users’ documents pass through our scanners or our API. In that case the customer is the controller, their own privacy notice applies, and the terms between us govern what we may do. If you are an end user and want to exercise your rights over such a check, contact the organisation that scanned your document first; we will support them, and you can always reach us at the address below.
Questions or concerns?
If anything here is unclear, write to us at privacy@247iq.ai. If you do not agree with this notice, please do not use this website or our services.
01What information do we collect?
Information you give us
When you request a demo, write to us, or become a customer, you provide contact and professional details — typically your name, work email, company, role, and whatever you choose to put in a message. We use this to answer you and to run the commercial relationship.
Information collected automatically
When you browse this website, some data is collected by the site and by the services that keep it running:
- Connection data: IP address, approximate region, and the time of the request.
- Device and browser data: browser and operating system, screen size, and language.
- Usage data: pages viewed, links followed, and how long a page was open.
Identity documents processed by our products
When an organisation uses a 247 IQ scanner, station, or API, the following may pass through our systems on their behalf: the images of the document (visible light, ultraviolet, and infrared), the data read from it — including the machine-readable zone and the chip, where present —, the authenticity checks performed, and the resulting verdict. Depending on the document and the customer’s configuration, this can include a facial image and other biometric data, which the GDPR treats as a special category of personal data and which we only ever process on that customer’s instructions and legal basis.
02How do we process your information?
As a controller, we process information to reply to your enquiries, provide and administer our services, keep our systems secure, detect and prevent fraud and abuse, improve our products, and comply with the law. We process it only where we have a valid legal basis to do so.
We do not train models on customer documents by default. Where a customer wants to contribute material to improve detection, that is a separate, written agreement, and the material is handled under it.
We do not sell personal information, and we do not use documents processed for one customer to serve another.
03Legal bases for processing
For visitors in the EU, the UK, and Switzerland, the GDPR requires us to state the legal bases we rely on. As a controller, these are:
- Consent — for non-essential cookies and for marketing messages, which you may withdraw at any time.
- Contract — to provide the services a customer has asked for and to manage the relationship.
- Legitimate interests — to secure our systems, prevent abuse, and understand how our website is used, where those interests are not overridden by your rights.
- Legal obligation — where accounting, tax, or other law requires us to keep or disclose information.
Where we act as a processor, the legal basis is the customer’s to determine, not ours.
04How long do we keep information?
We keep information only as long as needed for the purpose it was collected for, or as long as the law requires.
- Document images and extracted data: kept only for as long as the verification requires, then deleted according to the customer’s configured retention period. Where a deployment runs on the customer’s own infrastructure, the images may never reach us at all.
A CONFIRMAR: os prazos padrão por produto. - Verification logs — the fact that a check happened, its result, and its metadata — are kept longer, because customers need them for audit.
A CONFIRMAR: o prazo. - Website and contact data: kept while the relationship is live and for a reasonable period afterwards.
A CONFIRMAR: o prazo.
When information is no longer needed, we delete it or irreversibly anonymise it.
06International transfers
Information may be processed in a country other than yours. Where personal data leaves the European Economic Area, we rely on an adequacy decision or on the European Commission’s standard contractual clauses, together with the technical measures needed to make them effective. A CONFIRMAR: as regiões de hospedagem oferecidas e quais transferências existem hoje.
07Security
We protect information with encryption in transit and at rest, access control on a need-to-know basis, logging of access to production systems, and regular testing. No system is perfectly secure, but where we control the risk we treat it as our own. Security questions and vulnerability reports are welcome at the address below.
09Your privacy rights
Depending on where you live, you may have the right to access the information we hold about you, to correct it, to delete it, to restrict or object to how it is used, to receive it in a portable form, and to withdraw consent you have given. Where we act as a processor, we will pass your request to the customer responsible and support them in answering it.
To exercise a right, write to us at the address below. You also have the right to complain to your local data-protection authority.
10Minors
This website is not directed at children, and we do not knowingly collect their information through it. Identity documents belonging to minors may be processed by our products where a customer’s own legal basis allows it — for example at a border — and always under that customer’s instructions.
11Updates to this notice
We may update this notice. The current version is always the one published here, marked with the “Last updated” date at the top of the page. Where a change materially affects how we handle your information, we will take reasonable steps to tell you.
12Contact us
Questions, requests, and complaints about this notice go to privacy@247iq.ai.
A CONFIRMAR: a razão social completa, o endereço registrado e, se houver, o encarregado de proteção de dados (DPO) e o representante na União Europeia.