Last updated: Sep 9, 2026

This privacy notice explains how 247 IQ Industries (“247 IQ”, “we”, “us”) collects, uses, and protects information when you visit this website or when our identity-verification products process a document on behalf of a customer. Because our products read identity documents, we have written this notice to be explicit about two very different roles we play — and about what happens to a document image after it has been checked.

Two roles, two sets of rules

As a controller, we decide how information is used: this covers our website, demo requests, and our dealings with customers and candidates. This notice describes that role in full.

As a processor, we only act on the documented instructions of a customer — a bank, a hotel group, a car-rental company, a border authority — when their end users’ documents pass through our scanners or our API. In that case the customer is the controller, their own privacy notice applies, and the terms between us govern what we may do. If you are an end user and want to exercise your rights over such a check, contact the organisation that scanned your document first; we will support them, and you can always reach us at the address below.

Questions or concerns?

If anything here is unclear, write to us at privacy@247iq.ai. If you do not agree with this notice, please do not use this website or our services.

01What information do we collect?

Information you give us

When you request a demo, write to us, or become a customer, you provide contact and professional details — typically your name, work email, company, role, and whatever you choose to put in a message. We use this to answer you and to run the commercial relationship.

Information collected automatically

When you browse this website, some data is collected by the site and by the services that keep it running:

  • Connection data: IP address, approximate region, and the time of the request.
  • Device and browser data: browser and operating system, screen size, and language.
  • Usage data: pages viewed, links followed, and how long a page was open.

Identity documents processed by our products

When an organisation uses a 247 IQ scanner, station, or API, the following may pass through our systems on their behalf: the images of the document (visible light, ultraviolet, and infrared), the data read from it — including the machine-readable zone and the chip, where present —, the authenticity checks performed, and the resulting verdict. Depending on the document and the customer’s configuration, this can include a facial image and other biometric data, which the GDPR treats as a special category of personal data and which we only ever process on that customer’s instructions and legal basis.

02How do we process your information?

As a controller, we process information to reply to your enquiries, provide and administer our services, keep our systems secure, detect and prevent fraud and abuse, improve our products, and comply with the law. We process it only where we have a valid legal basis to do so.

We do not train models on customer documents by default. Where a customer wants to contribute material to improve detection, that is a separate, written agreement, and the material is handled under it.

We do not sell personal information, and we do not use documents processed for one customer to serve another.

04How long do we keep information?

We keep information only as long as needed for the purpose it was collected for, or as long as the law requires.

  • Document images and extracted data: kept only for as long as the verification requires, then deleted according to the customer’s configured retention period. Where a deployment runs on the customer’s own infrastructure, the images may never reach us at all. A CONFIRMAR: os prazos padrão por produto.
  • Verification logs — the fact that a check happened, its result, and its metadata — are kept longer, because customers need them for audit. A CONFIRMAR: o prazo.
  • Website and contact data: kept while the relationship is live and for a reasonable period afterwards. A CONFIRMAR: o prazo.

When information is no longer needed, we delete it or irreversibly anonymise it.

05Sharing your information

We do not sell personal information. We share it only with:

  • Service providers who help us run the business — hosting, infrastructure, email, analytics, and support — bound by contract to process it only on our instructions. A CONFIRMAR: a lista de subencarregados e onde ela é publicada.
  • Our customers, where we processed information on their behalf.
  • Authorities, where the law compels us, and to the extent it compels us.
  • An acquirer, if the business or part of it is ever sold or reorganised — subject to this notice.

06International transfers

Information may be processed in a country other than yours. Where personal data leaves the European Economic Area, we rely on an adequacy decision or on the European Commission’s standard contractual clauses, together with the technical measures needed to make them effective. A CONFIRMAR: as regiões de hospedagem oferecidas e quais transferências existem hoje.

07Security

We protect information with encryption in transit and at rest, access control on a need-to-know basis, logging of access to production systems, and regular testing. No system is perfectly secure, but where we control the risk we treat it as our own. Security questions and vulnerability reports are welcome at the address below.

08Cookies and tracking

This site uses cookies and similar technologies to work correctly, remember your preferences, and understand how the site is used. Non-essential cookies are set only with your consent, and you can change your mind at any time. Most browsers also let you refuse or delete cookies; if you do, some parts of the site may not behave as intended.

Because no uniform standard for Do-Not-Track signals has been agreed, we do not currently respond to them.

09Your privacy rights

Depending on where you live, you may have the right to access the information we hold about you, to correct it, to delete it, to restrict or object to how it is used, to receive it in a portable form, and to withdraw consent you have given. Where we act as a processor, we will pass your request to the customer responsible and support them in answering it.

To exercise a right, write to us at the address below. You also have the right to complain to your local data-protection authority.

10Minors

This website is not directed at children, and we do not knowingly collect their information through it. Identity documents belonging to minors may be processed by our products where a customer’s own legal basis allows it — for example at a border — and always under that customer’s instructions.

11Updates to this notice

We may update this notice. The current version is always the one published here, marked with the “Last updated” date at the top of the page. Where a change materially affects how we handle your information, we will take reasonable steps to tell you.

12Contact us

Questions, requests, and complaints about this notice go to privacy@247iq.ai.

A CONFIRMAR: a razão social completa, o endereço registrado e, se houver, o encarregado de proteção de dados (DPO) e o representante na União Europeia.