Privacy Policy

Effective 6 September 2026

This policy explains what personal data the Kiedo Kompliance platform handles, why, who it is shared with, and what you can ask us to do about it.

1.Who is responsible

The platform is operated by Ephelia Swisstech SA, Via Nassa 3a, 6900 Lugano, Switzerland, registered in the Commercial Register of the Canton of Ticino under CHE-179.848.999. Data protection contact: privacy@kiedo.ai.

Our role differs by the data in question. For our own business relationships — Client accounts, billing, the people who administer a Client’s workspace — we are the controller. For the identity and compliance data an Applicant submits through a verification flow, the business that sent you to that flow is the controller and decides what is collected and why; we process it on that business’s documented instructions. If you are an Applicant and want to know why a particular piece of information was asked for, that business is the first place to ask — and we will help you reach them.

2.What we collect

  • Account data — name, work email, role and sign-in activity for the people who use a Client workspace.
  • Applicant contact data — email address and, where the flow uses it, mobile number.
  • Identity data — the information and documents a flow asks for: name, date of birth, nationality, address, identity-document images and, where the flow includes a liveness or document check, a facial image and the data derived from it. Identity-document and biometric data are treated as sensitive personal data.
  • Compliance answers — the responses given to questionnaire steps (source of funds, ownership structure, declarations) and any files uploaded with them.
  • Evidence of consent and signature — timestamps, the version of a document accepted, and the fact that a one-time code was issued and used.
  • Technical data — IP address, user agent, and event timestamps, recorded for security, abuse prevention and audit.

We do not use tracking or advertising cookies. The cookies we set are strictly necessary: a session cookie to keep you signed in, and a short-lived token that carries a verification session.

3.Why we use it, and on what basis

  • To run the verification a business asked for — performance of a contract, and the Client’s compliance with its own legal obligations under anti-money-laundering and know-your-customer law.
  • To confirm that a contact detail belongs to you — one-time codes by email and SMS. Legitimate interest in preventing impersonation and fraud, and, for signature codes, evidence that the person who signed was the person contacted.
  • To keep the platform secure and available — legitimate interest.
  • To bill Clients and keep accounting records — contract and legal obligation.

Sensitive data — identity documents and any biometric data derived from them — is processed because it is necessary for the Client to meet a legal obligation, and, where the applicable law requires it, on your explicit consent given in the flow.

4.Mobile numbers and text messages

No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are not shared with any third party.

A mobile number you enter in a verification form is used for one purpose: to send you the one-time codes described in section 7 of our Terms of Service. We do not send marketing by SMS, we do not build marketing profiles from your number, and we do not sell or rent it.

The number is passed to our messaging provider, Twilio Inc., solely so it can deliver the message, and to your own mobile operator as part of delivery. That is the whole of the sharing.

How it is stored. The one-time-code record itself never holds your number in the clear: it stores a cryptographic hash of the number and a hash of the code. The number in readable form is held only as the answer to the form field you entered it in, as part of the Client’s verification record.

You can opt out at any time by replying STOP. See the Terms for what that means for a verification in progress.

5.Who we share data with

We do not sell personal data, and we do not share it for anyone’s marketing. We use a small number of service providers, each under a written processing agreement and each limited to what its function requires:

  • Messaging — Twilio Inc. (United States), for SMS delivery.
  • Email delivery — our transactional email provider, for sign-in links, resume links and notifications.
  • Identity verification — our identity-verification provider, which performs the document, liveness and watchlist checks.
  • Hosting, storage and network — our infrastructure is operated in Switzerland; uploaded documents are held in encrypted object storage and traffic is served through a content-delivery and DDoS-protection provider.
  • Automated review assistance and document reading — Anthropic PBC (United States), whose models help review questionnaire answers and, where the business you are applying to has switched it on, read the machine-readable zone of an identity document you upload so that your name, date of birth, nationality, document number and expiry date can be pre-filled for you to check (see section 8). Data sent for either purpose is not used to train models and is not retained by the provider beyond the request.
  • Payments — our payment processor, for Client billing only. Applicant data is never sent to it.

We also disclose data to the Client whose flow you completed — that is the point of the service — and to authorities, auditors or advisers where we are legally required to, or to establish or defend legal claims.

6.International transfers

Our infrastructure is in Switzerland. Some providers above are in the United States. We transfer personal data to them on the basis of the European Commission’s standard contractual clauses together with the Swiss addendum recognised by the Federal Data Protection and Information Commissioner, or on an adequacy decision where one applies. A copy of the safeguards is available from privacy@kiedo.ai.

7.How long we keep it

  • One-time codes and their challenge records: minutes — a code expires 5 minutes after it is sent, and the record is retained only as evidence that a verification took place.
  • Applicant verification records, including documents and answers: for the period the Client instructs, which is normally the retention period its own anti-money-laundering law imposes (commonly ten years after the business relationship ends).
  • Client account and billing records: for the term of the agreement and the statutory accounting period afterwards.
  • Security and audit logs: up to 24 months.

When a Client’s agreement ends we delete or return its data in line with that agreement, except where we must keep a copy by law.

8.Automated review

Some questionnaire answers are reviewed with automated assistance, which flags whether an answer appears complete and consistent and proposes an outcome. It does not, by itself, approve or reject a person: the Client’s own reviewer decides, and the platform routes anything the automated step is unsure about to a human. If a decision was taken about you and you want it looked at again by a person, contact the business you applied to, or write to us and we will pass it on.

Where a Client has enabled it, an identity document you upload may be read automatically so that the details printed in its machine-readable zone are pre-filled into the form. The read is checked against the document’s own check digits and is used only where every one of them passes; the pre-filled values are shown to you to confirm or correct before anything is signed. Reading a document in this way does not verify it or you: identity verification is a separate step performed by the identity-verification provider.

9.Security

Data is encrypted in transit, and uploaded documents are encrypted at rest in object storage. Access is restricted to the people who need it, workspaces are isolated from one another, credentials and provider secrets are held encrypted, and one-time codes are stored only as keyed hashes and compared in constant time. We log administrative access. No system is perfectly secure, and we will notify affected parties and the competent authority where a breach requires it.

10.Your rights

Subject to the applicable law, you may ask for access to your personal data, its correction or deletion, restriction of or objection to processing, and a copy in a portable format; and you may withdraw a consent you gave, without affecting what was done before you withdrew it.

Because most Applicant data is processed for a Client, we will normally forward your request to that Client and support them in answering it — tell us who you applied to and we will route it. Write to privacy@kiedo.ai.

You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), or to your local supervisory authority if you are in the EU or the UK.

11.Children

The platform is not directed at children, and a verification flow is not intended to be completed by anyone under 18 except where a Client’s own regulated process provides for it with a guardian’s involvement.

12.Changes

We may update this policy. The effective date at the top always reflects the current version, and we will tell Clients about material changes in advance.

13.Contact

Ephelia Swisstech SA, Via Nassa 3a, 6900 Lugano, Switzerland — CHE-179.848.999
Data protection: privacy@kiedo.ai
Service and HELP requests: support@kiedo.ai