Rillis Network Privacy Policy
Version 2026-07-11 · Effective July 11, 2026
Rillis Network Privacy Policy
Version: 2026-07-11 · Effective as of: July 11, 2026 Who this applies to: individuals whose identity data is processed through the Rillis Platform, including the Single Verification Network. For processing that Rillis carries out on behalf of its corporate clients, the client (the company requesting your verification) is the primary controller; this policy explains Rillis’s role and practices.
Courtesy translation. This English version is provided for convenience. The Spanish version is the legally binding text and prevails in case of any discrepancy.
Note on roles. In most processing, Rillis acts as a processor (processing on behalf of the client, which is the controller). Rillis acts as an independent controller only with respect to (a) operation of the Network infrastructure (matching by verified identifier, consent logging, immutable audit trail, integrity attestation), and (b) data it processes for its own operations, security, billing, compliance, and service improvement using de-identified data. Where Rillis is a processor, you may exercise your rights by contacting either the controller client or Rillis, which will direct you accordingly.
1. What data we process
Depending on the service contracted by the client, we may process: declared identity data (name, ID document, date of birth, contact details); images of the identity document; facial image/selfie and facial biometric template (biometric/sensitive data); voice and voice template when voice verification is used (biometric/sensitive data); technical capture metadata; transaction data (where applicable); and, for the Network, a verified network identifier (your email).
We do not record plaintext personal data on any blockchain. When we anchor an integrity attestation, we record only a cryptographic digest (hash) together with a random value (“salt”) stored off-chain.
2. Why we process it (purposes) and legal basis
We process your data to: verify your identity; carry out fraud, sanctions, PEP, and adverse media prevention checks (which are run by the client, not Rillis, as its own decision); enable you, if you consent, to reuse your verification with another Network client; retain records in accordance with regulatory obligations (e.g., AML/CFT); and operate and secure the service.
The legal basis for processing is determined by the controller client and varies by jurisdiction. For biometric data, we rely, as a universal basis, on your explicit consent; and — where the law permits — the basis of fraud prevention and security in identification and authentication processes may also apply (e.g., under Brazil’s LGPD) or another public-interest basis with legal support. You are informed of the applicable basis at the time of capture.
3. The Single Verification Network (reuse)
If you have already verified with a Rillis client (the “Donor”), you may choose to reuse your verification with another client (the “Recipient”) without repeating the process. How it works and how it protects your privacy:
- Only your identity evidence travels (declared data, document images, and selfie). The results, scores, or decisions from the prior process never travel.
- We authenticate before moving a single piece of data. The order is: email → verification code (OTP) → your consent → a brief selfie. Only after your explicit, specific consent for that particular Recipient is the evidence communicated.
- Consent for each reuse and each recipient. We do not use a “network-wide, forever” consent. You may decline and verify from scratch at no disadvantage, and you may withdraw your consent for future reuses at any time.
- The Recipient decides independently. The Recipient runs its own checks and makes its own decision; reuse does not replace its due diligence.
- Anti-enumeration. We design the flow so as not to reveal whether a match exists before authenticating you.
4. Who we share data with
We share data with: the controller client requesting your verification; the Recipient you authorize in a reuse; and our sub-processors (OCR/biometrics providers, OTP code delivery providers, and cloud providers), under contract and solely to provide the service. Screening sources (sanctions/PEP/adverse media) are third parties; the client, not Rillis, decides their use.
5. International transfers
When a reuse or the service involves transferring your data to another country, we do so under a valid mechanism under applicable law (adequacy decisions; standard contractual clauses — including the EU SCCs, the Brazilian SCCs, or local model clauses; or, exceptionally, your explicit consent to the transfer). If the reuse crosses a border, you are informed of the destination country before you accept.
6. How long we retain data
We retain your data for as long as necessary for the purpose and, where the law requires (e.g., KYC records under AML/CFT rules), for the applicable regulatory period (by default 5 years under the FATF standard, or the longer local period). Raw biometric samples (images/audio) are deleted after verification, retaining only protected templates where applicable, with destruction upon fulfillment of the purpose and within applicable maximum limits. The on-chain hash cannot be deleted; but once your data and the off-chain salt are deleted, that hash can no longer be linked back to you.
7. Your rights
Depending on your jurisdiction, you have the right to: access, rectify, delete, object to, restrict processing of, port your data, withdraw consent, and not be subject to decisions based solely on automated processing with significant effects without safeguards (including the right to human intervention, to express your point of view, and to challenge the decision). If a legal obligation requires us to retain your data, we may block it rather than delete it until the retention period expires.
To exercise them, contact the controller client or Rillis at privacidad@rillis.io. Where available, you may also contact your country’s data protection authority.
8. Security
We apply encryption in transit and at rest, role-based access control, strong authentication, and protection of biometric templates in accordance with recognized standards (irreversibility, unlinkability, and renewability; presentation-attack detection for facial biometrics). No measure eliminates risk entirely, but we work to minimize it.
9. Minors
The Services are directed at verification on behalf of corporate clients. Where a client verifies a minor, processing and consent are governed by the capacity and parental consent rules of the applicable jurisdiction.
10. Changes and contact
We may update this policy; we will publish the current version with its date. For privacy inquiries: privacidad@rillis.io. Entity responsible for the Network infrastructure: the Rillis group entity identified as the contracting party in the Master Terms and Conditions (per the applicable Order Form).