Legal
Privacy policy
Draft — pending legal review
This policy explains what personal information Delphi Verify processes, why, and what control you have over it. Delphi handles photographs of real places and precise capture locations. We treat both as highly privacy-sensitive information.
Not yet legally reviewed
5 sections on this page still need completion or legal review, and are marked below. This page must not go live in this state — either port the existing published policy or have counsel complete it.
Who we are
Delphi Verify provides an evidence-certificate platform. The company responsible is Delphi Verify Inc., a corporation incorporated in the State of Delaware, United States.
Registered address: 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States.
Privacy enquiries: contact@delphiverify.com.
Reviewer note — this section requires completion or confirmation before publication.
Our role as controller or processor
Our data protection role depends on which processing is in question, and it is not the same throughout the service.
Where an organisation uses Delphi Verify to commission evidence — deciding what is captured, why, who may access it and how long it is kept — that organisation is generally the controller for the evidence, and we act as its processor. Our processing is then governed by the data processing agreement with that organisation, and by its instructions.
We are an independent controller for processing where we determine the purposes ourselves: administering accounts, securing and operating the platform, detecting and preventing fraud and misuse, providing support, and meeting our own legal obligations.
Where you use Delphi Verify as an individual rather than through an organisation, we are the controller for that processing.
One organisation can be controller for some processing and processor for other processing at the same time. Which applies turns on who determines the purposes and means, not on who holds the data.
What information we process
- Account data: the email address associated with your account, and the identity provider used to sign in (Apple, Google, or email and password).
- Evidence data: photographs and video captured through the Delphi Verify app, the capture time reported by the device, the device location at the moment of capture, and the accuracy of that location.
- Integrity data: device and application attestation records, media hashes, and the proof material required to verify a certificate.
- Certificate content: the title, description and other details supplied when publishing.
- Organisation data: the jobs, assets, workflows and user roles configured by an organisation using the platform.
- Support data: correspondence with us, and the records needed to answer it.
- Operational data: logs necessary to run, secure and support the service.
Evidence data may contain information about people other than the person capturing it. Section 05 deals with that specifically.
Why we process it, and our lawful bases
Where we act as controller, we rely on the following lawful bases. Where we act as processor for an organisation, that organisation determines the basis for its own processing.
| Purpose | Information | Proposed lawful basis |
|---|---|---|
| Providing the service | Account data, evidence data, certificate content, organisation data | Performance of a contract |
| Verification and attestation | Integrity data, evidence data | Performance of a contract; legitimate interests in the reliability of certificates |
| Security, fraud and misuse prevention | Operational data, integrity data, account data | Legitimate interests in protecting the service and the people who rely on it |
| Support | Support data, account data | Performance of a contract; legitimate interests in answering enquiries |
| Legal and regulatory compliance | As required in the circumstances | Legal obligation |
| Website analytics | Limited usage data, only if analytics are enabled | Consent |
Where we rely on legitimate interests, you may object — see section 11. Where we rely on consent, you may withdraw it at any time, and withdrawal does not affect processing already carried out.
Reviewer note — this section requires completion or confirmation before publication.
Evidence and people appearing in captures
Evidence captured through Delphi Verify records real places, and can contain information about people who have never used the service — a tenant, a family member, an employee, a contractor, a visitor, a vehicle registration, or personal possessions visible in a room.
This policy applies to those people as well as to account holders. If you are identifiable in evidence held by Delphi Verify, the rights in section 11 are available to you.
Where the evidence was captured for an organisation, that organisation is generally the controller and decides what is captured and why. We will usually need to refer a request to it, and will tell you when we do.
Whoever captures evidence is responsible for doing so lawfully, including obtaining any permission needed to photograph a property, asset or location and respecting the rights of people who may appear. Our terms of service and data processing agreements place that responsibility on the capturing party.
Location privacy
Location is central to what Delphi proves, and among the most privacy-sensitive information we handle.
When publishing a certificate you choose a location privacy level. At 'exact', precise coordinates appear on the certificate. At 'nearby' and 'area', published coordinates are snapped to a coarser grid and the displayed address is generalised.
Reducing published precision does not change the integrity protection applied to the location evidence. It reduces the precision of the location disclosed to certificate viewers: a certificate published at 'nearby' or 'area' establishes an area rather than an exact coordinate, and establishes it just as robustly.
Where the available accuracy cannot support the level requested, the privacy level is automatically restricted rather than published misleadingly.
Blockchain and permanent integrity records
When an evidence record is sealed, a cryptographic commitment is published to the Ethereum Attestation Service on Base mainnet.
The blockchain record contains cryptographic commitments rather than copies of the photographs or plaintext location data. These commitments are designed to allow integrity verification without publishing the underlying evidence to the blockchain.
The on-chain record is permanent. Deleting a certificate removes the media and certificate data we hold, but does not delete or alter the attestation already published. We do not control that record and cannot revise or withdraw it.
This is worth understanding before publishing, because it is the one part of the process that cannot be undone.
Service providers and international transfers
We rely on the following providers to operate the service. Each processes information only as needed for the purpose shown.
| Provider | Purpose | Processing location and transfer basis |
|---|---|---|
| Google Cloud | Managed database and asynchronous task processing | To be confirmed |
| Firebase (Google) | Identity, media storage and API surface | To be confirmed |
| Apple | Device and application attestation for captures made on iOS | To be confirmed |
| Base / Ethereum Attestation Service | Public attestation of cryptographic commitments | Public distributed network, not a single location |
Where information is transferred outside the UK or EEA, we put in place an appropriate transfer mechanism. The mechanism applicable to each provider is shown above once confirmed.
Reviewer note — this section requires completion or confirmation before publication.
Retention and deletion
You may delete a certificate. Deletion is irreversible: media and certificate data are removed, an audit record of the deletion is retained, and the public code subsequently returns a removed state rather than silently disappearing.
Deletion is asynchronous. Data is removed from live systems first and cycles out of backups afterwards.
You may delete your account, which anonymises or removes the associated profile. Where evidence was created for an organisation, deleting your individual account does not delete that organisation's records.
| Information | Retained | Determined by |
|---|---|---|
| Evidence and media | Until deleted, or as agreed with the organisation | Customer instruction; enterprise agreement |
| Account data | For the life of the account | Contract; deleted or anonymised on closure |
| Deletion audit records | Retained after the evidence is deleted | Integrity of the record that a deletion occurred |
| Security and operational logs | To be confirmed | Security need; legal obligation |
| Support records | To be confirmed | Handling the enquiry and any follow-up |
| Backups | Maximum cycle to be confirmed | Backup rotation schedule |
Blockchain attestations are not subject to these periods. As section 08 explains, they are permanent and outside our control.
Reviewer note — this section requires completion or confirmation before publication.
Your rights
Under UK and EU data protection law you have rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where we rely on it. Which rights apply in a given case depends on the circumstances and on the lawful basis for the processing.
You have the right to object to processing carried out on the basis of legitimate interests. We draw that to your attention specifically rather than leaving it in a list.
To exercise any right, contact contact@delphiverify.com. We will respond within the period the law allows and will tell you if we need to verify your identity first.
Where we act as processor for an organisation, we will refer your request to that organisation, which is responsible for answering it, and will tell you that we have done so.
You may complain to your local supervisory authority at any time. In the United Kingdom that is the Information Commissioner's Office.
Rectification of sealed evidence works differently, because altering a sealed record would destroy the integrity it exists to provide. Our intended approach is to preserve the original record and to correct, annotate, revoke or supersede it, so that the correction is visible rather than the history being silently rewritten.
Reviewer note — this section requires completion or confirmation before publication.
Contact and complaints
Delphi Verify Inc., 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, United States.
Privacy enquiries and rights requests: contact@delphiverify.com.
If you are not satisfied with our response, you may complain to your local data protection supervisory authority.