Security
GDPR & Privacy
Understand how the platform handles customer data and ensures GDPR compliance.
GDPR and Privacy
Kuata is committed to protecting your privacy. This document explains what data we collect, why we need it, your rights, and how to exercise them. Kuata's architecture is built on privacy-by-design principles — we collect only what is necessary, store it securely, and never use it for purposes you have not consented to.
Our Privacy Principles
Principle | What it means in practice |
Data minimisation | We collect only the data strictly necessary for each specific purpose |
Purpose limitation | Data collected for identity verification is never repurposed for marketing |
Zero-knowledge architecture | Third-party verifiers receive only a pass/fail result — never your personal data |
Transparency | You can see every piece of data we hold about you and every time it was accessed |
User control | You can export, correct, or delete your data at any time from within the app |
No advertising | Kuata is ad-free and will never sell your data to advertisers or data brokers |
Data We Collect and Why
Category | Examples | Why we need it |
Identity data | Name, date of birth, national ID number | Account creation and identity verification — required by law |
Contact data | Phone number, email address | Account access, security alerts, support |
Biometric data | Liveness check during onboarding only — stored on your device, not our servers | Confirms you are physically present; not retained by Kuata after verification |
Document data | Cryptographic hash of document content (not the image) | Powers the document wallet; enables verification |
Financial data | Transaction history, wallet balance, payment references | Processes your payments; detects fraud; meets regulatory requirements |
Usage data | App features used, device type, timestamps | Improves the service and detects unusual activity |
AI interaction (Pro only) | Queries sent to Akili — not stored after the session ends | Provides the AI assistant during your session only |
Legal Basis for Processing
Processing purpose | Legal basis (GDPR and equivalent laws) |
Providing identity wallet and payment services | Performance of contract with you |
Identity verification for third parties | Your explicit consent, given per-request in the app |
Fraud detection and AML compliance | Legal obligation and legitimate interests |
Service improvement | Legitimate interests (using anonymised, aggregated data only) |
Communicating with you | Contract performance and legitimate interests |
Retaining transaction records | Legal obligation (financial regulations in each market) |
Your Rights
Depending on your country of residence, you have the following rights regarding your personal data. To exercise any of them, go to Settings -> Privacy or email privacy@kuata.io:
Right | What it means | How to request |
Access | Receive a copy of all data Kuata holds about you | Settings -> Privacy -> Export my data |
Rectification | Correct inaccurate or incomplete data | Settings -> Profile, or email privacy@kuata.io |
Erasure | Request deletion of your data (subject to legal retention requirements) | Settings -> Account -> Delete account, or email privacy@kuata.io |
Portability | Download your data in a machine-readable format (JSON) | Settings -> Privacy -> Export my data |
Restriction | Pause processing while a dispute is resolved | Email privacy@kuata.io |
Objection | Object to processing based on legitimate interests | Email privacy@kuata.io |
Withdraw consent | Stop a specific consent-based processing activity at any time | Revoke in-app from the relevant consent record |
Note: We respond to all data rights requests within 30 days, or the shorter period required by your local data protection law. We never charge a fee for exercising your rights. |
Who We Share Data With
• Government identity registries — only the reference number needed to verify your document at onboarding; never your full profile.
• National payment networks — only the transaction data necessary to process your payment.
• B2B institutional partners — only a signed pass/fail verification result; never personal data. Partners are bound by a Data Processing Agreement.
• Amazon Web Services — our cloud infrastructure provider, processing data as a sub-processor under a Data Processing Agreement.
• Law enforcement and regulators — only when required by applicable law, and only the data legally required.
Security Alert: We never sell your data. We never share your data with advertisers. We never share your data with any party not listed above. |
Data Retention
Data category | How long we keep it |
Account and identity data | Duration of your account + 2 years after deletion |
Transaction records | 7 years (required by financial regulations in most markets) |
Verification audit log | 7 years |
Biometric data | On your device only; deleted when you disable biometrics or uninstall the app |
Akili AI conversations | Not retained beyond the session |
Usage and diagnostic logs | 90 days rolling |
Data from rejected onboarding | 5 years (regulatory requirement) |
International Data Transfers
If your data is transferred to a country outside your region, Kuata uses Standard Contractual Clauses (SCCs) or equivalent mechanisms approved by your local data protection authority to ensure adequate protection. You can request a copy of the applicable transfer mechanism from privacy@kuata.io.
Children
Kuata is not intended for users under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has registered an account, please contact privacy@kuata.io and we will delete the account promptly.
Changes to Our Privacy Practices
We will notify you of any material change to how we handle your personal data at least 30 days before the change takes effect, via in-app notification and email. You can always find the current Privacy Policy in Settings -> About -> Privacy Policy.
Contact
Purpose | Contact |
Data rights requests and privacy questions | privacy@kuata.io |
Urgent privacy concerns | privacy@kuata.io (mark subject: URGENT) |
Regulator complaints | Your national data protection supervisory authority |