Draft — to be reviewed by counsel
Privacy Policy
Last updated: 24 September 2026
1. Who we are
SeenPact ("we", "us") provides identity verification (KYC) and electronic signing services to business customers through an API and dashboards. This policy explains what personal data we process, why, and the choices you have. Contact: admin@seenpact.com.
2. Data we process
- Verification data submitted by a customer's end user: email address, identity document fields and images, selfie and liveness video, device and timing signals.
- Signing data: documents uploaded for signature, signer email addresses, signature placements, certificate and PIN metadata, event logs.
- Account data for customer staff: name, work email, role, authentication factors, audit entries.
- Website data: what you type into the contact form and standard server logs.
3. Roles and lawful basis
For verification and signing we act as a processor on behalf of the business customer that integrates SeenPact; the customer is the controller and determines the lawful basis. For customer accounts and this website we act as a controller and rely on contract performance and legitimate interests.
4. How we protect data
Personal fields are encrypted at rest (AES-GCM), public identifiers are opaque, admin actions are hash-chained in an audit log, access is role-based with two-factor authentication, and the platform runs in single-tenant containers.
5. Retention
Retention periods are configured per customer (backups, purge policies and exports). Sandbox data is isolated and purged on a short schedule. Contact-form messages are kept for as long as needed to answer them.
6. Your rights
Depending on where you live you may have rights to access, correct, delete or export your data, or to object to processing. If SeenPact processed your data on behalf of a business, please contact that business first; we will support their response. Otherwise write to admin@seenpact.com.
7. Changes
We will post any changes on this page and update the date above.