Privacy Policy

Your privacy and data protection are our highest priorities. Reference No.: HELLOVERIFY /OM/POL/PP · Version 11.0 · Issue Date: 3 June 2026

I. Policy Scope

HelloVerify and its registered entities (collectively, "HelloVerify", "we", "us", or "our") are background screening organizations that provide services including, but not limited to, employment screening, background verification, occupational health screening, primary source verification, and reporting (collectively, the "Services") to clients who have a legitimate and lawful purpose for conducting such screening. This Privacy Policy applies to the website www.helloverify.com (the "Website") and to all services owned and operated by HelloVerify and its registered entities:

  • HelloVerify Inc.
  • HelloVerify India Pvt. Ltd.
  • HelloVerify Document Verification Follow- Up Services Co. L.L.C.
  • HelloVerify Ai Pte. Ltd.
  • HelloVerify Ai Company

HelloVerify is dedicated to protecting your personal information and will make every reasonable effort to handle collected information appropriately. This Privacy Policy ("Policy") describes how HelloVerify treats information collected or provided in connection with an end user's ("you", "user", or "client") use of HelloVerify products and background screening services (the "Services"). This privacy statement covers the data collected by HelloVerify. We are committed to protecting privacy and information provided by end users to enable HelloVerify to complete its Services.

Your use of and interaction with HelloVerify's online portals indicates your acknowledgement of this privacy policy. Where required by applicable law, we will obtain your explicit consent before collecting or processing your personal or sensitive personal data. By voluntarily providing your personal information, you consent to its collection, use, and disclosure for the purposes described in this Privacy Policy. If you do not agree with this Privacy Policy, you may choose not to use our online portals or provide personal information. Please note that certain services may not be available without the required information.

This Policy applies to individuals whose personal data (including sensitive personal data, where applicable) is processed by HelloVerify, including applicants, clients, employees, and business partners. HelloVerify generally acts as a data processor when processing personal data on behalf of its clients, in accordance with client instructions and applicable law. HelloVerify acts as a data controller (or equivalent under applicable law) with respect to personal data it processes for its own internal business operations, including human resources administration and employee management.

II. Policy Changes

We reserve the right to modify HelloVerify's privacy policy at any time, which will be published on our website. If we make material changes to this privacy policy, we will notify users by means of a notice on our home page. By continuing to use our websites and services after a revision takes effect, it is considered that users have read and understand the changes. You have the right to withdraw your consent at any time, subject to applicable legal or contractual obligations.

III. Policy Content

This policy seeks to answer questions you may have about the Services and HelloVerify's information practices:

  • What information we collect and why we collect it
  • How we share and use that information
  • General exceptions
  • Consent and update of records
  • Services regarding tracking, analytics and email communications
  • Security and compliance with regulatory authorities
  • Use of AI technologies
  • Data breach notification mechanism
  • How we protect your information
  • Where information is processed or stored
  • Onward transfer mechanisms
  • Information from minors
  • Grievance officer and contact details

IV. Information We Collect

Personally Identifiable Information

Personally Identifying Information ("PII") means such information that can potentially identify you, such as your name, date of birth and address. It does not include anonymized, aggregate or statistical information.

PII that we collect and hold about an individual will vary depending upon the background checks required by the client and the information the individual supplies to us. We process personal data based on applicable legal grounds, including consent, contractual necessity, legal obligations, and legitimate interests where permitted by law. Processing of sensitive personal data is conducted in accordance with applicable laws and subject to additional safeguards and consent requirements where applicable. Publicly available information is collected only from lawful and reliable sources and in accordance with applicable laws.

PII we may collect and hold

  • Contact information — name (including previous names or aliases), email address, telephone number, residential address, and location
  • Identity information — government-issued identification numbers (as permitted by law), passport number, driver's licence number, date of birth, place of birth, and other identifiers necessary for identity verification
  • Address history
  • Criminal records — arrests, charges, convictions, and related records, as permitted under applicable law
  • Credit information — credit history, payment records, judgments, or other financial characteristics, where legally permitted
  • Education history and qualifications — university accreditation, certification history
  • Employment history and professional experience
  • Professional licences and certifications
  • Right-to-work information — residency, sanctions, immigration status
  • Occupational health and drug screening results
  • References and opinions provided by third parties
  • Directorships, corporate affiliations, and governance information — claims, judgments, insolvency, current and previous directorships, character, personal reputation
  • Publicly available information — including information from social, print, or online media sources
  • Primary source verification — verification of educational, employment, or professional credentials as required by applicable legal or regulatory authorities
  • Any additional information — as requested by the client and permitted under applicable law

From clients and individuals, we may collect information related to conducting a background check and billing and payment details. From clients we may collect company address and the name, email and phone number of system users. From sources of our background checks we may collect the name and job title of the person who supplied us with the information.

HelloVerify applicants and employees

For individuals applying for employment with HelloVerify, we may collect the same categories of information described for candidates to assess suitability for employment and, where applicable, to conduct background verification. You may choose to provide further information during recruitment, including interview-related disclosures or supporting documentation.

For individuals employed by HelloVerify, we may collect and process personal information necessary for employment administration, including personal interests and voluntarily provided information; professional background and employment history; identity information (date of birth, identification documents, nationality, citizenship, immigration status, and work authorization); diversity information (such as gender, ethnicity, disability, veteran status, or similar data for statistical and compliance purposes, processed in accordance with applicable laws and, where required, maintained separately from identifying information); employment records; and compensation and benefits information (including payroll, tax, banking, insurance, benefits enrolment, and, where necessary, limited medical information required for administering employee benefits).

For employees located in Singapore, KSA, and UAE, HelloVerify complies with applicable employment data protection obligations in each jurisdiction, including rules on monitoring, records retention, and cross-border HR data transfers.

Website and cookies

When you visit our Website, we may collect technical and usage-related information, including IP address, device identifiers, domain name, approximate location, referring webpage, pages visited, time spent on each page, browsing behaviour (including interactions with third-party links), and other analytical or diagnostic data. This information is collected through cookies and similar tracking technologies.

We may also collect personal information you voluntarily provide for business or sales inquiries, including name, job title, organization, email address, telephone number, and mailing address.

You can use the Cookie Manager to learn more about the online tracking technologies we use and to review or set your preferences. The Cookie Manager is presented when you first visit a webpage or opened by selecting Cookie Preferences in the website footer. Blocking, disabling, or rejecting cookies may cause services to not function properly. Disabling cookies does not disable other online tracking technologies, but prevents those technologies from accessing details stored in cookies.

We recognize the importance of privacy issues and respect the confidentiality of PII individuals or clients provide to us. We collect and deal with PII in accordance with local laws and this Privacy Policy (as amended from time to time).

How do we collect information?

  • Information you provide directly, such as application forms, onboarding documents, and other materials submitted during the verification process
  • Information collected through your interactions with us, our systems, or authorized third parties during the course of providing our services
  • Information provided by our clients through client portals or by applicants through our applicant portal, where applicant details are uploaded and accessed by authorized HelloVerify users

In connection with a client's request for background verification services, HelloVerify and/or its clients may collect personal data directly from the individual or from authorized sources, in accordance with applicable law. We collect and process this information solely for legitimate business purposes, including the delivery and improvement of our services.

V. Information Used by HelloVerify

HelloVerify collects and uses personal information to perform services requested by our clients or applicants. This information may be collected through online portals, electronic communications (including email), or other authorized means, and may include:

  • Verification of applicant identity
  • Conducting background checks based on information provided by clients or applicants
  • Performing quality assurance and audit checks
  • Investigating discrepancies or disputes
  • Issuing necessary communications, including adverse action notices
  • Communicating with clients regarding their use of the Services
  • Providing updates, alerts, or changes related to our Services

We may also collect limited system or usage-related information (such as log information) to support service delivery, system security, and performance monitoring. Any such use will be proportionate and, where required, based on appropriate consent.

HelloVerify processes personal data only for specified and lawful purposes and ensures that appropriate consent is obtained where required under applicable data protection laws. Personal information may be stored, processed, and retained only for as long as necessary to fulfill these purposes or to comply with legal and regulatory requirements.

VI. Information We Share

We do not share personally identifiable information with companies, organizations and individuals outside HelloVerify unless one of the following circumstances applies:

With client and applicant consent

We may share an applicant's personal information with clients, employers, or other authorized parties for employment verification and related services. Where required by applicable law, such sharing will be based on the explicit consent of the individual.

For external processing

HelloVerify may engage trusted third-party service providers and partners, including background verification agencies, data processors, identity verification providers, IT service providers, auditors, legal advisors, and accounting professionals. Such third parties are granted access only to information necessary to perform their designated functions and are contractually obligated to maintain confidentiality, implement appropriate security measures, and process personal data only in accordance with our instructions and applicable law.

For legal reasons

We may disclose personal information, including personal and sensitive personal data, if we believe in good faith that such disclosure is necessary to:

  • Comply with any applicable law, regulation, legal process or enforceable governmental request
  • Enforce applicable Terms of Service, including investigation of potential violations
  • Detect, prevent, or otherwise address fraud, security or technical issues
  • Protect against harm to the rights, property or safety of HelloVerify, our clients, applicants, users or the public as required or permitted by law

For business transfers

In the event of a merger, acquisition, restructuring, or sale of assets, personal information may be transferred as part of the transaction. HelloVerify India will ensure that the confidentiality of such information is maintained and that affected individuals are provided with appropriate notice, where required.

Data retention

HelloVerify retains personal data only for as long as necessary to fulfill the purposes for which it was collected, including providing services, responding to inquiries, complying with contractual obligations, or meeting legal and regulatory requirements.

Unless otherwise required by jurisdiction-specific law or agreed with the client, personal data is retained for an active use period of up to one (1) year. Exceptions may be applied based on documented client requirements or applicable legal obligations. Personal data may be stored in electronic or physical formats, including secure servers, backup systems, and paper records. Access is restricted to authorized personnel on a need-to-know basis.

After the active retention period, data may be securely archived for a limited duration and subsequently deleted, anonymized, or destroyed in accordance with internal data retention and disposal policies. Data used in testing or development environments is retained only for as long as necessary and is subject to appropriate safeguards. Each internal function within HelloVerify is responsible for ensuring that data it creates, processes, stores, or manages is handled and disposed of in accordance with this policy.

VII. General Exceptions

HelloVerify may collect, use, monitor, store, or disclose personal information where necessary under the following circumstances:

  • To comply with applicable laws, regulations, legal processes, or enforceable governmental requests
  • To operate, maintain, and improve our business and services
  • To protect the security, integrity, and functionality of our systems and platforms
  • To enforce our Terms of Use or other contractual rights, and to investigate potential violations

Any such activities will be carried out in accordance with applicable law and with appropriate safeguards in place. To ensure compliance with our Terms of Use and to maintain the security of our services, HelloVerify may monitor information processed through its systems. Such monitoring is limited to what is necessary and proportionate and may include automated filtering of electronic communications to identify and prevent spam, malicious code, unauthorized access, or unlawful content.

HelloVerify may engage third-party service providers to deliver certain aspects of its services. Where necessary, personal information may be shared with such service providers solely for the purpose of delivering the services, and subject to appropriate contractual, confidentiality, and data protection obligations. Where required under applicable law, we will obtain appropriate consent prior to processing or sharing personal information. All disclosures will be made in accordance with this Privacy Policy and applicable legal requirements.

VIII. Withdraw Consent

Clients and candidates may at any time withdraw their consent for personal data stored with HelloVerify by providing written notice to privacy@helloverify.com.

Withdrawal of consent will be processed as soon as reasonably practicable and within applicable legal timelines from the date of receipt, subject to verification and applicable legal or contractual obligations. Withdrawal may impact our ability to continue providing certain services, including background verification activities, where processing of personal data is necessary for service delivery.

HelloVerify will process such requests in accordance with applicable data protection laws and will take appropriate steps to cease processing and, where applicable, delete or anonymize personal data, unless retention is required for legal, regulatory, or contractual purposes.

Requests relating to withdrawal of consent and other data subject rights (DSRs) will be addressed within the timelines prescribed under applicable data protection laws, or where no specific timeline is prescribed, within fifteen (15) business days of receiving a valid request.

IX. Update Records

Clients are responsible for ensuring that their contact and related information is accurate and up to date. In the event of any change or inaccuracy, clients should promptly update such information with their employer or client, or may request HelloVerify to assist in updating the same.

Applicants may review, access, and change certain account information (such as email address, phone number and mailing address) via the applicant portal. Requests to change certain other information, such as identity numbers, may require verification before the change is accepted. Applicants can request deletion of certain information in HelloVerify's control by contacting us through the details provided at the end of this Privacy Policy, subject to applicable legal and contractual requirements. Individuals may also have the right to restrict or object to processing and to request data portability, where applicable.

Applicants can dispute background check reports through the applicant portal or by directly contacting their employer/client (requestor). Once a client, such as an employer, has received a background check report, HelloVerify does not control the client's use, storage, or retention of such information. Clients are independently responsible for complying with applicable data protection laws in their handling of such data.

HelloVerify retains personal data only for as long as necessary to fulfill the purposes for which it was collected, including providing services, complying with legal obligations, preventing fraud, resolving disputes, enforcing agreements, and supporting investigations. Retention may continue even after closure of accounts or completion of services, where required for legal, regulatory, or legitimate business purposes. Where deletion is requested, HelloVerify will take reasonable steps to delete or anonymize personal data, unless retention is required under applicable law or contractual obligation.

HelloVerify will be unable to proceed with the provision of services to clients in the absence of necessary permissions or consent from the individual subject to the background verification.

X. Online Tracking, Analytics & Email Communications

HelloVerify may send periodic informational, service-related, or promotional communications to its clients. Clients may opt out of such communications by connecting with their concerned account manager or sending an email to HelloVerify (see Section XIX for contact details).

It may take up to 15 business days to process opt-out requests. We send service-related communications as necessary to fulfill contractual obligations, while promotional communications are sent based on consent or legitimate business interests, where permitted by law. We use cookies and similar technologies, and where required, obtain consent prior to their use. Users may manage preferences through cookie settings.

XI. Security & Confidentiality

HelloVerify implements appropriate administrative, technical, and physical safeguards to protect personal data that we collect, process, and store. These safeguards are designed to protect against unauthorized access, use, alteration, disclosure, or destruction of personal data, and to ensure the confidentiality, integrity, and availability of such information. Security measures include, but are not limited to:

  • Secure transmission of data using industry-standard encryption protocols (such as SSL/TLS)
  • Network security controls, including firewalls and intrusion protection mechanisms
  • Access controls, including role-based access and password protection
  • Physical security measures at facilities where data is stored or processed
  • Periodic monitoring and assessment of security controls

We take reasonable steps to ensure that personal information, including sensitive identifiers (such as government-issued identity numbers), is protected from foreseeable risks. While we strive to use commercially acceptable means to protect personal information, no method of transmission over the internet or electronic storage is completely secure. Accordingly, we cannot guarantee absolute security. If you have any questions regarding our security practices, please contact us using the details provided in this Privacy Policy.

XII. Use of Artificial Intelligence Technologies

HelloVerify is committed to the ethical, secure, and transparent use of artificial intelligence ("AI") technologies in the delivery of its background verification services. HelloVerify utilises AI technologies to assist in the processing, analysis, and quality assurance of personal information submitted as part of background verification.

The AI capabilities currently deployed include Optical Character Recognition ("OCR") for automated extraction of text from identity documents, qualification certificates, and other verification documents; Document Forensics for AI-assisted analysis to detect indicators of document tampering, forgery, digital manipulation, and metadata or pixel-level anomalies; and Document Blurriness Detection for automated quality assessment of uploaded document images to ensure legibility prior to processing.

All AI processing is conducted on enterprise-tier infrastructure where candidate data remains encrypted within HelloVerify's isolated processing environment. HelloVerify does not permit any AI vendor to use candidate or client data for model training, fine-tuning, or any purpose beyond the delivery of HelloVerify's services.

HelloVerify does not use AI tools to make any automated decisions that produce legal effects or similarly significant impacts on candidates. All AI outputs are advisory in nature and are subject to mandatory review by a trained human operator before any finding is acted upon or any verification report is finalised. No verification report is published without human sign-off.

Data controllers retain the right to request that their candidates' documents be processed without the use of AI tools. Where such a request is made as part of the written agreement, HelloVerify will accommodate manual processing as an alternative, which may affect processing timelines. Any use of AI processing is conducted in accordance with applicable data protection laws across HelloVerify's operating jurisdictions. HelloVerify's clients retain ultimate responsibility for employment, engagement, or other decisions made on the basis of verification reports; HelloVerify provides verification outputs and findings, and the client makes all final decisions relating to the individual candidate.

XIII. Data Breach Notification

HelloVerify maintains a data breach response procedure. In the event of a personal data breach, HelloVerify will promptly assess the nature and scope of the breach and take appropriate remedial measures. Where required by applicable law, HelloVerify will notify the relevant data protection authority and/or affected individuals within the timeframe prescribed by law, and in no event later than 72 hours from becoming aware of the breach where such notification is legally mandated.

Breach notifications will include the nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken or proposed to address the breach.

XIV. Compliance & Regulatory Cooperation

HelloVerify regularly reviews and updates its practices to ensure compliance with this Privacy Policy and applicable data protection laws. We comply with applicable legal and regulatory requirements, including information technology, privacy, and data protection laws. We may disclose personal data to regulatory authorities, law enforcement agencies, or government bodies where such disclosure is necessary to comply with applicable law or valid legal processes.

XV. Protection of Information

HelloVerify provides adequate safeguards to protect and secure information we maintain about clients. We maintain a comprehensive information security program aligned with ISO/IEC 27001 standards and applicable client-specific security requirements. These safeguards include encryption, secure network architecture, system hardening, access controls, physical security measures and continuous monitoring to ensure the protection of personal data.

We periodically review and update our security controls to address evolving threats, risks, and regulatory requirements.

XVI. Information Processing & Storage

HelloVerify processes and stores personal data using secure systems and infrastructure. Depending on client requirements and the nature of services, such data may be stored and processed in appropriate jurisdictions in accordance with applicable laws and contractual obligations.

Our systems operate in secure environments designed to protect personal data against unauthorized access, accidental loss, natural disasters, and other potential risks. Where necessary, HelloVerify may engage authorized service providers or partners to process or store personal data for purposes such as service delivery, backup, or retention, subject to appropriate contractual, confidentiality, and security safeguards.

In the course of providing services, personal data may be transmitted to authorized sources or recipients across different jurisdictions for verification purposes, subject to applicable cross-border transfer requirements. Such transfers will be conducted in accordance with applicable data protection laws and contractual commitments.

XVII. International — Onward Transfer

HelloVerify may transfer or disclose personal data (including sensitive personal data) to recipients located in different jurisdictions where necessary to provide its services. Such transfers may occur in connection with background verification activities—for example, where an individual has lived, studied, or worked in another country, it may be necessary to share personal data with relevant overseas entities, including employers, educational institutions, references, or verification agencies, in order to validate the information provided.

The jurisdictions to which personal data may be transferred will depend on the nature and scope of the services and may include countries with differing levels of data protection. HelloVerify ensures that such cross-border transfers are conducted in accordance with applicable data protection laws and contractual obligations, and that appropriate safeguards are implemented. Cross-border transfers may use Standard Contractual Clauses, adequacy decisions, binding corporate rules, or other mechanisms approved by the applicable data protection authority.

HelloVerify may also disclose personal data to affiliates, service providers, regulatory authorities, or law enforcement agencies, including those located in different jurisdictions, where such disclosure is necessary to provide services, comply with applicable law, or respond to valid legal requests.

XVIII. Information from Minor

HelloVerify's services are not directed to minors (children as defined under applicable law), and we do not knowingly collect personal data from individuals who are considered minors in the relevant jurisdiction.

In the event that personal data relating to a minor is required to be processed as part of our services, HelloVerify will ensure that appropriate consent or authorization is obtained from a parent or legal guardian, in accordance with applicable legal requirements. If we become aware that personal data has been collected from a minor without the required parental or legal guardian consent, we will take reasonable steps to delete such information as soon as practicable, unless retention is required to comply with applicable legal or regulatory obligations. We may implement additional safeguards where required under applicable laws when processing personal data relating to children.

XIX. Grievance Officer / Privacy Protection Officer

HelloVerify has established a grievance redressal mechanism to address concerns, complaints, or requests related to the processing of personal data. HelloVerify has designated appropriate personnel responsible for handling such requests in accordance with applicable laws.

In jurisdictions where applicable laws require the appointment of a Grievance Officer, Data Protection Officer, or similar designated authority, such responsibilities are fulfilled through the contact details provided below:

Group Data Protection Officer (DPO)

Email: privacy@helloverify.com

This contact point is designated exclusively for privacy-related queries, data protection concerns, and grievances regarding the processing of personal data. Requests will be addressed within the timelines prescribed under applicable data protection laws.

Please note that this contact should not be used for technical support or login-related issues concerning HelloVerify platforms.

XX. United States — Privacy Supplement

This United States Privacy Supplement ("Supplement") applies to the extent that HelloVerify processes personal data in connection with individuals located in the United States, including where data is received from clients, data sources, or other authorized parties. Where such processing occurs, HelloVerify is committed to handling personal data in a manner consistent with applicable U.S. legal and regulatory frameworks and recognized data protection standards. This Supplement should be read in conjunction with the Global Privacy Policy. In the event of any inconsistency, this Supplement will govern with respect to U.S.-related data processing.

Applicability of U.S. laws

To the extent applicable, HelloVerify aligns its practices with relevant U.S. federal and state laws governing personal data, including:

  • Fair Credit Reporting Act (FCRA)
  • Driver's Privacy Protection Act (DPPA)
  • Gramm-Leach-Bliley Act (GLBA)
  • Applicable U.S. state privacy laws (e.g., California Consumer Privacy Act (CCPA), as amended by CPRA, and other state-level privacy laws)

Where HelloVerify operates as a Consumer Reporting Agency (CRA) or provides services that fall within the scope of FCRA, it aligns with FCRA obligations, including permissible purpose requirements, consumer disclosure rights, dispute resolution and reinvestigation obligations, accuracy and data minimization standards, and user certification and monitoring. HelloVerify applies these principles where relevant to the nature of the service being delivered and the role it performs (e.g., service provider, processor, or contractor), even where it is not directly subject to jurisdiction.

Role in background screening

HelloVerify generally acts as a service provider to its clients and does not independently determine the purpose of processing U.S. personal data in most cases. Where services provided by HelloVerify fall within the scope of consumer reporting activities under U.S. law, HelloVerify supports its clients in meeting applicable obligations, including processing data only for legitimate and authorized purposes, supporting accuracy and data quality measures, enabling dispute resolution workflows where applicable, and implementing appropriate safeguards for sensitive personal data. Clients remain responsible for ensuring compliance with their specific regulatory obligations, including providing notices, obtaining authorizations, and managing consumer rights where required.

Distribution of personally identifiable information

HelloVerify seeks to limit the distribution of personally identifiable information consistent with the nature and sensitivity of the information. HelloVerify strives to make available personally identifiable information from sources other than public records or publicly available information only to its authorized users or clients. Similarly, where applicable, HelloVerify strives to restrict access to information in accordance with privacy laws such as the FCRA, the GLBA, and the DPPA and comparable state statutes. In the case of public record information available to the general public (such as bankruptcy, liens, judgments, criminal records and Uniform Commercial Code filings) and publicly available information, we may limit disclosure to authorized parties.

If, upon investigation, HelloVerify finds that personally identifiable information has been used or accessed inappropriately or unlawfully, HelloVerify strives to take reasonable steps to stop the misuse or access, educate the user concerning the appropriate use of the information, and prevent similar future misuses. Such steps may include discontinuation of the user's access to HelloVerify information products and services, pursuit of other legal remedies, and referral of misuse to the appropriate authorities.

Data accuracy and rights

HelloVerify strives to accurately report information in its products and information received from its data sources. HelloVerify takes reasonable steps to maintain data accuracy and encourages individuals to report inaccuracies through the appropriate client or designated contact channels. HelloVerify recognizes that reporting errors may occur and, where applicable, provides consumers with the opportunity to dispute and correct information we report, as described further in Access & correction below.

Sensitive information safeguards

HelloVerify strives to provide additional safeguards for sensitive personally identifiable information, such as Social Security numbers and driver's licence numbers. HelloVerify strives to limit the availability and access to full Social Security Numbers ("SSNs"), Driver's License Numbers and State Identification Numbers, and to protect the confidentiality of SSNs by limiting access to certain legitimate and authorized users. A limited number of public records may contain SSNs already available to the public; if such public records are accessed through HelloVerify services, our services may provide access to such SSNs. HelloVerify prohibits the unlawful disclosure of SSNs and takes steps to limit the availability of DLNs and state identification card numbers.

Education

HelloVerify is committed to promoting responsible data handling practices and raising awareness among its employees, clients, and users regarding the appropriate use of its products and services. HelloVerify provides guidance on privacy and security considerations associated with HelloVerify information products and services, and on the responsible use of personally identifiable information. HelloVerify also seeks to make information available to the public, where appropriate, regarding responsible use of personally identifiable information, measures HelloVerify has undertaken to enhance consumer privacy, and choices available to consumers regarding information access and the ability to opt out of certain products and services which utilize personally identifiable information.

Reputable sources

HelloVerify strives to acquire personally identifiable information from established, reputable sources in the government and private sectors. HelloVerify takes reasonable steps to assess the reputation and reliability of its private sector data sources before incorporating personally identifiable information from the source into its products and services. HelloVerify also strives to obtain assurances from its data suppliers that they have the legal right to license or sell the data to HelloVerify.

Cross-border processing

Where U.S.-origin personal data is transferred outside the United States, such transfers are conducted in accordance with contractual obligations with clients, applicable data protection requirements, and appropriate safeguards to ensure data protection standards are maintained.

Access & correction

HelloVerify provides a central point of contact for individuals seeking information about its privacy practices and the processing of personal information. HelloVerify strives to inform individuals about the nature of the public records, non-public information, and publicly available information that HelloVerify makes available in its information products and services. HelloVerify also strives, whenever practicable, to provide consumers, upon request, with meaningful opportunities to review personally identifiable information we maintain about them, and to provide opportunities for consumers to dispute and correct information by assisting them in identifying potential information sources at which corrections should be made.

Accountability

HelloVerify maintains internal policies, procedures, and controls designed to support compliance with applicable data protection requirements. It promotes responsible data handling practices across its operations and engages with relevant stakeholders to maintain appropriate privacy and security standards.

Online privacy

HelloVerify strives to protect the privacy of personally identifiable information obtained over the Internet and strives to apply our data privacy principles and evolving standards to the online environment.

Identity theft

HelloVerify strives to prevent the acquisition of information from its products and services for improper purposes, such as identity theft. Where a state law requires notice, HelloVerify complies with the law. In those states where notification laws do not exist, HelloVerify follows its Information Security Breach Response and Notification Policy, which provides that affected individuals will be notified when sensitive personally identifiable information owned or licensed by HelloVerify is acquired by an unauthorized individual and whenever HelloVerify has a reasonable basis to believe the breach has resulted in, or there is a significant risk that it will result in, identity theft to the consumer to whom the information relates.

Compliance

HelloVerify maintains a comprehensive information security and privacy program, which may be subject to periodic internal and external assessments. Such measures are designed to evaluate the effectiveness of administrative, technical, and physical safeguards and to support ongoing compliance with applicable standards and contractual obligations.

Consumer reporting activities (where applicable)

In limited circumstances, the services provided by HelloVerify may align with activities regulated under the U.S. Fair Credit Reporting Act ("FCRA"). HelloVerify primarily operates as a service provider to its clients and typically processes personal information on their behalf. To the extent applicable, HelloVerify supports its clients in complying with relevant legal requirements, including use of personal information for legitimate and authorized purposes, data accuracy and quality, and processes for dispute resolution and correction of information. Clients are responsible for ensuring compliance with applicable legal obligations, including establishing permissible purpose, providing required notices, and managing consumer rights.

Regulatory framework

Where relevant, HelloVerify aligns its practices with applicable U.S. laws, including the FCRA, the California Investigative Consumer Reporting Agencies Act (ICRAA), where applicable, and other relevant federal and state privacy laws. Regulatory oversight of such frameworks may involve authorities such as the Federal Trade Commission (FTC) and the Consumer Financial Protection Bureau (CFPB).

Investigative consumer reports (California)

Under California law, an investigative consumer report may include information regarding an individual's character, general reputation, personal characteristics, or mode of living. To the extent HelloVerify supports the preparation or processing of such reports on behalf of clients, such activities are conducted in accordance with client instructions, applicable law, and appropriate safeguards.

Contact us

To obtain additional information about the privacy practices and policies of HelloVerify in connection with its preparation and processing of investigative consumer reports, please contact: Email: privacy@helloverify.com

XXI. EEA & UK — Privacy Supplement

This European Economic Area (EEA) and United Kingdom (UK) Privacy Supplement applies to the processing of personal data relating to individuals located in the EEA and the UK by HelloVerify, in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR. This Supplement should be read in conjunction with the Global Privacy Policy. In the event of any inconsistency, this Supplement shall prevail with respect to personal data originating from the EEA and the UK.

Scope of processing

HelloVerify may process personal data originating from the EEA or UK in connection with the provision of its global background verification and related services, on behalf of clients and in accordance with their instructions, contractual obligations, and applicable data protection laws. Personal data may be processed for purposes including identity verification, employment and credential verification, fraud prevention, and compliance with legal or regulatory requirements. HelloVerify may obtain personal data from individuals, clients, or authorized third-party sources. The personal data processed is limited to what is necessary and proportionate for the specified purposes. HelloVerify primarily acts as a service provider or processor on behalf of its clients.

Legal basis for processing

  • Consent of the individual, where required
  • Performance of a contract
  • Compliance with legal or regulatory obligations
  • Legitimate interests pursued by HelloVerify or its clients, where such interests are not overridden by the rights and freedoms of the individual

Purpose of processing

  • Identity verification and background screening
  • Verification of education, employment, and professional credentials
  • Compliance with legal, regulatory, and client requirements
  • Fraud prevention, risk management, and security monitoring
  • Service delivery, quality assurance, and audit activities

Data sharing and onward transfers

HelloVerify may share personal data with clients, affiliates, and authorized service providers for the purposes described in this Policy. Where personal data is transferred outside the EEA or UK, HelloVerify ensures that appropriate safeguards are implemented, including Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms, and contractual, organizational, and technical safeguards designed to protect personal data. Such transfers are carried out in accordance with applicable data protection laws.

Data subject rights

  • Right to access personal data
  • Right to rectify inaccurate or incomplete data
  • Right to request erasure of personal data (subject to legal and contractual limitations)
  • Right to restrict processing
  • Right to object to processing, where applicable
  • Right to data portability, where applicable

Requests may be submitted using the contact details below. Where HelloVerify processes personal data on behalf of a client, such requests may be directed to or coordinated with the relevant client.

Security and data integrity

HelloVerify implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or alteration. Personal data is processed in a manner that ensures its accuracy, integrity, and confidentiality, and is limited to what is necessary for the purposes for which it is processed.

Data retention

Personal data is retained only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required to comply with applicable legal, regulatory, or contractual obligations.

Complaints

Individuals have the right to lodge a complaint with the relevant data protection authority in their country of residence, place of work, or place of the alleged infringement. HelloVerify encourages individuals to contact us first so that we may address any concerns directly.

Contact us

For any questions, requests, or concerns relating to this Supplement, please contact: Email: privacy@helloverify.com

XXII. Switzerland — Privacy Supplement

This Switzerland Privacy Supplement applies to the processing of personal data relating to individuals located in Switzerland in accordance with the Swiss Federal Act on Data Protection, as revised in 2023 ("revFADP"). This Supplement should be read in conjunction with the Global Privacy Policy and, where applicable, the EEA and UK Privacy Supplement. In the event of any inconsistency, this Supplement shall prevail with respect to personal data originating from Switzerland.

Scope of processing

HelloVerify may process personal data originating from Switzerland in connection with the provision of background verification and related services. HelloVerify primarily acts as a service provider and processes personal data on behalf of its clients in accordance with their instructions, contractual obligations, and applicable laws.

Purpose of processing

  • Identity verification and background screening
  • Verification of employment, education, and professional credentials
  • Compliance with legal or regulatory requirements
  • Fraud prevention and risk management
  • Service delivery, audit, and quality assurance

Personal data processed is limited to what is necessary and proportionate for these purposes.

Data sharing and onward transfers

  • Standard Contractual Clauses or equivalent contractual safeguards
  • Transfers to jurisdictions recognized as providing adequate protection
  • Other legally recognized transfer mechanisms

Data subject rights

  • Access their personal data
  • Request correction of inaccurate or incomplete data
  • Object to certain processing, where applicable
  • Request deletion, subject to legal and contractual limitations

Requests may be submitted using the contact details below. Where HelloVerify processes personal data on behalf of a client, such requests may be directed to or coordinated with the relevant client.

Security and retention

HelloVerify implements appropriate technical and organizational measures to protect personal data and to ensure its confidentiality, integrity, and availability. Personal data is retained only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by applicable law.

Contact us

For any questions, requests, or concerns relating to this Supplement, please contact: Email: privacy@helloverify.com

XXIII. India — Privacy Supplement

This India Privacy Supplement applies to the processing of personal data by HelloVerify in India and should be read in conjunction with the Global Privacy Policy. HelloVerify processes personal data in India in connection with the provision of its Services, including background verification, identity verification, and related activities, as well as for its internal business operations and services offered to clients and individuals within India. This Supplement is to be read in light of the Digital Personal Data Protection Act, 2023 ("DPDP Act") and any rules notified thereunder.

Scope and role of processing

  • On behalf of clients, where HelloVerify acts as a service provider and processes data in accordance with client instructions
  • For its own legitimate business purposes, where HelloVerify determines the purpose and means of processing in accordance with applicable law

In all cases, personal data is processed only for lawful purposes and in compliance with applicable data protection requirements.

Purpose of processing

  • Conducting background verification and identity checks
  • Verifying employment, education, and professional credentials
  • Complying with legal, regulatory, and client requirements
  • Preventing fraud, misconduct, and unauthorized activities
  • Delivering and improving services, including quality assurance and audits
  • Managing client relationships and internal operations

Lawful processing

HelloVerify processes personal data based on consent and other lawful grounds as permitted under applicable law. Where consent is required, HelloVerify will ensure that such consent is obtained in a clear and informed manner. Individuals may withdraw their consent at any time, subject to applicable legal or contractual requirements. Withdrawal of consent may affect the ability of HelloVerify to provide certain services where such processing is necessary.

Notice and transparency

HelloVerify provides individuals with appropriate notice regarding the collection and use of personal data, including the purpose of processing, categories of data processed, and available rights, in accordance with applicable legal requirements. Where HelloVerify processes personal data on behalf of clients, such notice may be provided by the relevant client.

Data sharing

  • Clients and authorized parties for the purpose of service delivery
  • Affiliates and group entities
  • Third-party service providers engaged to support the Services

Cross-border transfers

Personal data may be processed or transferred outside India where necessary for the provision of Services. HelloVerify ensures that such transfers are carried out in accordance with applicable legal requirements and subject to appropriate safeguards.

Individual rights

  • Access information about the personal data being processed
  • Request correction or updating of personal data
  • Request deletion of personal data, subject to applicable limitations
  • Withdraw consent
  • Raise concerns or grievances regarding processing

Data security and retention

HelloVerify implements appropriate technical and organizational measures to protect personal data and ensure its confidentiality, integrity, and availability. Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable law or contractual obligations.

Grievance redressal

HelloVerify has established a grievance redressal mechanism to address concerns relating to the processing of personal data. Requests or complaints may be submitted using the contact details below and will be addressed within the timelines prescribed under applicable law.

Contact us

For any questions, requests, or concerns relating to this Supplement, please contact: Email: privacy@helloverify.com

XXIV. Kingdom of Saudi Arabia — Privacy Supplement

This Kingdom of Saudi Arabia Privacy Supplement applies to the processing of personal data by HelloVerify in connection with individuals located in the Kingdom of Saudi Arabia ("KSA"), in accordance with the Saudi Personal Data Protection Law ("PDPL") and its implementing regulations. This Supplement should be read in conjunction with the Global Privacy Policy. In the event of any inconsistency, this Supplement shall prevail with respect to personal data processed in KSA.

Scope and role of processing

HelloVerify may process personal data in KSA in connection with the provision of its Services, including background verification and related activities. Depending on the nature of the engagement, HelloVerify may process personal data on behalf of clients or for its own legitimate business purposes, where permitted by applicable law. All processing is carried out in accordance with applicable legal and regulatory requirements.

Where processing involves sensitive personal data as defined under the PDPL, HelloVerify will ensure prior explicit consent and compliance with the PDPL Implementing Regulations. Cross-border transfers shall be subject to a Data Transfer Impact Assessment where required by SDAIA.

Purpose of processing

  • Identity verification and background screening
  • Verification of employment, education, and professional credentials
  • Compliance with legal, regulatory, and client requirements
  • Fraud prevention and risk management
  • Service delivery, audit, and quality assurance activities
  • Business operations and client relationship management

Lawful processing and consent

HelloVerify processes personal data in accordance with lawful bases recognized under the PDPL. Where required, personal data is processed based on the consent of the individual in a clear and informed manner. Consent may be withdrawn at any time, subject to applicable legal or contractual obligations. Processing may also be carried out without consent where permitted under applicable law.

Notice and transparency

HelloVerify provides appropriate notice to individuals regarding the collection and use of personal data. Where HelloVerify processes personal data on behalf of clients, such notice may be provided by the relevant client.

Data sharing

  • Clients and authorized parties for the purpose of providing Services
  • Affiliates and group entities
  • Third-party service providers engaged to support service delivery

Cross-border transfers

  • Implementation of appropriate safeguards
  • Compliance with regulatory approvals or conditions
  • Ensuring that the level of protection for personal data is maintained

Data subject rights

  • Be informed about the collection and processing of their personal data
  • Access their personal data
  • Request correction or updating of personal data
  • Request deletion of personal data, where applicable

Data security and retention

HelloVerify implements appropriate technical, administrative, and organizational measures to protect personal data. Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, or as required under applicable legal or contractual obligations.

Regulatory compliance

HelloVerify complies with applicable regulatory requirements and may disclose personal data to competent authorities where required by law or pursuant to valid legal processes.

Contact us

For any questions, requests, or concerns relating to this Supplement, please contact: Email: privacy@helloverify.com

XXV. United Arab Emirates — Privacy Supplement

This United Arab Emirates ("UAE") Privacy Supplement applies to the processing of personal data by HelloVerify in connection with individuals located in the UAE, in accordance with UAE Federal Decree Law No. 45 of 2021 on the Protection of Personal Data ("UAE PDPL"). Where HelloVerify's operations extend to the DIFC or ADGM free zones, the applicable free zone data protection laws shall govern in addition to or in lieu of the UAE Federal PDPL to the extent applicable. This Supplement should be read in conjunction with the Global Privacy Policy. In the event of any inconsistency, this Supplement shall prevail with respect to personal data processed in the UAE.

Scope and role of processing

HelloVerify may process personal data in the UAE in connection with the provision of its Services. Depending on the nature of the engagement, HelloVerify may process personal data on behalf of clients or for its own legitimate business purposes, where permitted by applicable law.

Purpose of processing

  • Identity verification and background screening
  • Verification of employment, education, and professional credentials
  • Compliance with legal, regulatory, and client requirements
  • Fraud prevention, risk management, and due diligence
  • Service delivery, audit, and quality assurance
  • Business operations and client relationship management

Lawful processing

HelloVerify processes personal data in accordance with lawful grounds recognized under applicable law. Where required, personal data is processed based on consent obtained in a clear and informed manner. Consent may be withdrawn at any time, subject to applicable legal or contractual obligations. Processing may also occur without consent where permitted under applicable law.

Notice and transparency

HelloVerify provides appropriate notice regarding the collection and use of personal data. Where HelloVerify processes personal data on behalf of clients, such notice may be provided by the relevant client.

Data sharing

  • Clients and authorized parties for the purpose of providing Services
  • Affiliates and group entities
  • Third-party service providers engaged to support the Services

Cross-border transfers

Personal data may be transferred outside the UAE where necessary for the provision of Services. HelloVerify ensures that such transfers are carried out in accordance with applicable legal requirements, including implementing appropriate safeguards.

Data subject rights

  • Access personal data
  • Request correction or updating of personal data
  • Request deletion of personal data, where applicable
  • Restrict or object to certain processing activities, where permitted

Data security and retention

HelloVerify implements appropriate administrative, technical, and organizational measures to protect personal data. Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required under applicable legal or contractual obligations.

Regulatory compliance

HelloVerify complies with applicable regulatory requirements and may disclose personal data to competent authorities where required by law or pursuant to valid legal processes.

Contact us

For any questions, requests, or concerns relating to this Supplement, please contact: Email: privacy@helloverify.com

XXVI. Singapore — Privacy Supplement

This Singapore Privacy Supplement applies to the processing of personal data by HelloVerify in connection with individuals located in Singapore, in accordance with the Singapore Personal Data Protection Act 2012 ("PDPA"). This Supplement should be read in conjunction with the Global Privacy Policy. In the event of any inconsistency, this Supplement shall prevail with respect to personal data processed in Singapore.

Scope and role of processing

HelloVerify may process personal data in Singapore in connection with the provision of its Services. Depending on the nature of the engagement, HelloVerify may process personal data on behalf of clients or for its own legitimate business purposes, where permitted by applicable law.

Purpose of processing

  • Identity verification and background screening
  • Verification of employment, education, and professional credentials
  • Compliance with legal, regulatory, and client requirements
  • Fraud prevention, risk management, and due diligence
  • Service delivery, quality assurance, and audit activities
  • Business operations and client relationship management

Lawful processing

HelloVerify collects, uses, and discloses personal data with consent where required under the PDPA or where otherwise permitted by law. Individuals are provided with appropriate notice regarding the purposes for which their personal data is collected, used, or disclosed. Consent may be withdrawn at any time, subject to applicable legal or contractual obligations. Where HelloVerify processes personal data on behalf of clients, such notice and consent may be obtained by the relevant client.

Data sharing

  • Clients and authorized parties for the purpose of providing Services
  • Affiliates and group entities
  • Third-party service providers engaged to support the Services

Cross-border transfers

Personal data may be transferred outside Singapore where necessary for the provision of Services. HelloVerify takes appropriate measures to ensure that any such transfers are conducted in accordance with applicable legal requirements and that the personal data continues to receive a standard of protection comparable to that required under the PDPA.

Access and correction

Individuals may have the right to request access to personal data and request correction of inaccuracies, subject to applicable legal requirements. Where HelloVerify processes personal data on behalf of a client, such requests may be directed to or coordinated with the relevant client.

Data security and retention

HelloVerify implements appropriate administrative, technical, and organizational measures to protect personal data. Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required under applicable legal or contractual obligations.

Accountability & compliance

HelloVerify maintains policies and procedures to support compliance with the PDPA. In the event of a data breach affecting individuals in Singapore, HelloVerify will notify the Personal Data Protection Commission and affected individuals in accordance with Section 26C of the PDPA.

Contact us

For any questions, requests, or concerns relating to this Supplement, please contact: Email: privacy@helloverify.com

XXVII. Australia & New Zealand — Privacy Supplement

This Australia and New Zealand Privacy Supplement applies to the processing of personal information by HelloVerify in connection with individuals located in Australia and New Zealand. This Supplement should be read in conjunction with the Global Privacy Policy. For the purposes of this Supplement, "Privacy Legislation" refers to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the Privacy Act 2020 (New Zealand) and the Information Privacy Principles (IPPs). "Personal Information" has the meaning given under the applicable Privacy Legislation.

Scope of services

HelloVerify provides background screening and verification services to its clients to assist them in assessing individuals for employment, changes in responsibility, or other circumstances where background verification is required, including regulatory, compliance, and risk management purposes.

Information we collect

  • Identification and contact details (e.g., name, date of birth, address)
  • Employment history, references, and professional qualifications
  • Educational background and certifications
  • Residency, immigration, and right-to-work information
  • Publicly available records (e.g., court records, insolvency data)
  • Other information necessary to verify the information provided by the individual

HelloVerify may also collect limited information from clients and from sources used during verification. In certain circumstances, HelloVerify may process sensitive information (e.g., criminal records), which is handled in accordance with applicable legal requirements and subject to additional safeguards.

Purpose of processing

  • Verifying information provided by individuals
  • Conducting background screening and due diligence checks
  • Preparing verification or investigative reports for clients
  • Supporting compliance with legal and regulatory requirements
  • Assisting clients in making employment or business decisions

How we collect information

  • Directly from individuals
  • From clients and authorized representatives
  • From third-party sources identified by the individual
  • From public records and other lawful sources

By providing third-party references or information, the individual is expected to have obtained appropriate authorization for such disclosure.

Use and disclosure of personal information

  • To clients for the purposes of providing Services
  • To authorized verification sources (e.g., employers, educational institutions, public authorities)
  • To third-party service providers engaged to support service delivery
  • Where required or permitted by applicable law

Storage and security

HelloVerify stores personal information in secure systems, which may include electronic databases and, where applicable, physical records. We implement appropriate administrative, technical, and physical safeguards. Access is restricted to authorized personnel on a need-to-know basis.

Retention

Personal information is retained only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal, regulatory, or contractual obligations. When personal information is no longer required, it is securely deleted, anonymized, or destroyed.

Identifiers

HelloVerify does not adopt, use, or disclose government-issued identifiers (such as tax file numbers or similar identifiers) except as permitted under applicable law.

Overseas disclosure

  • Verification sources located overseas
  • Clients and affiliates in other jurisdictions
  • Authorized service providers supporting global service delivery

Such disclosures are carried out in accordance with applicable Privacy Legislation and subject to appropriate safeguards.

Access and correction

Individuals may request access to personal information held about them and request correction of inaccurate or incomplete information. Requests may be submitted using the contact details below and will be handled in accordance with applicable Privacy Legislation. Verification of identity may be required. In certain circumstances, access may be restricted where permitted under applicable law.

Contact us

For any questions, requests, or concerns relating to this Supplement, please contact: Email: privacy@helloverify.com

XXVIII. Canada — Privacy Supplement

This Canada Privacy Supplement applies to the processing of personal information by HelloVerify in connection with individuals located in Canada, in accordance with the Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy laws. This Supplement should be read in conjunction with the Global Privacy Policy. In the event of any inconsistency, this Supplement shall prevail with respect to personal information processed in Canada.

Scope and role of processing

HelloVerify may process personal information in Canada in connection with the provision of its Services. Depending on the nature of the engagement, HelloVerify may process personal information on behalf of clients or for its own legitimate business purposes, where permitted by applicable law.

Purpose of processing

  • Identity verification and background screening
  • Verification of employment, education, and professional credentials
  • Compliance with legal, regulatory, and client requirements
  • Fraud prevention, risk management, and due diligence
  • Service delivery, quality assurance, and audit activities
  • Business operations and client relationship management

Consent

HelloVerify collects, uses, and discloses personal information with consent where required under applicable law, or where otherwise permitted. Consent may be express or implied, depending on the nature and sensitivity of the information and the reasonable expectations of the individual. Individuals may withdraw consent at any time, subject to legal or contractual restrictions. Where HelloVerify processes personal information on behalf of clients, consent may be obtained by the relevant client.

Limiting collection, use, and disclosure

  • To clients and authorized parties for the purpose of providing Services
  • To verification sources and third parties as required to complete background checks
  • To service providers supporting HelloVerify operations
  • Where required or permitted by law

Accuracy

HelloVerify takes reasonable steps to ensure that personal information is as accurate, complete, and up to date as necessary for the purposes for which it is used. Individuals are encouraged to report inaccuracies through the appropriate channels.

Safeguards

HelloVerify implements appropriate administrative, technical, and physical safeguards to protect personal information. Access is restricted to authorized personnel on a need-to-know basis.

Retention

Personal information is retained only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal, regulatory, or contractual obligations. When personal information is no longer required, it is securely deleted, anonymized, or destroyed.

Openness and transparency

HelloVerify makes information available regarding its privacy practices through this Privacy Policy and applicable supplements. Additional information may be requested using the contact details below.

Access and correction

Individuals may request access to personal information held about them and request correction of inaccurate or incomplete information. Requests will be handled in accordance with applicable law. Identity verification may be required. In certain circumstances, access may be restricted where permitted by law.

Accountability

HelloVerify is responsible for personal information under its control and has implemented policies and procedures to ensure compliance with applicable privacy laws. Where third-party service providers are engaged, they are required to protect personal information in a manner consistent with this Policy.

Cross-border transfers

Personal information may be processed or transferred outside Canada where necessary for the provision of Services. HelloVerify takes reasonable steps to ensure that such information receives an appropriate level of protection and is handled in accordance with applicable legal requirements.

Contact us

For any questions, requests, or concerns relating to this Supplement, please contact: Email: privacy@helloverify.com