Policies
Privacy
This page tells you what exists, where it lives, who can read it, and how long it is kept — with the actual figures, not adjectives.
The binding documents — the VirtEngine Privacy Policy, Biometric Data Addendum and Consent Framework — are versioned in the open-source repository. This page summarises them faithfully; where they differ, the repository documents govern.
This website collects nothing
identity.org.au is a static informational site. It has no accounts, no login, no forms, no analytics trackers and no advertising. The privacy questions that matter concern the wallet and the VEID network — which is what the rest of this page covers.
The life of your data, in five stages
Captured on your phone, encrypted before it moves, processed only inside hardware-sealed trusted processing units, destroyed when scoring ends — leaving only the result.
- Stage 1 Captured On your phone: document scan, selfie, liveness.
- Stage 2 Encrypted on your device Sealed before anything moves. Keys stay in your phone.
- Stage 3 Processed in a sealed enclave Hardware-attested. No operator can look inside.
- Stage 4 Raw data destroyed The enclave keeps nothing after scoring ends.
- Stage 5 Only the result remains A score and tier — never documents or biometrics.
What exists, where it lives, who can read it
| Data | Where it lives | Who can read it | Kept for |
|---|---|---|---|
| Document scans (licence, passport) | Encrypted on your device; encrypted payloads in the network vault | You. Processing happens only inside sealed, attested enclaves — no operator can look in; results, not images, are recorded | 7 years (know-your-customer law), then destroyed |
| Biometric templates (face, fingerprint, iris) | Encrypted on-device before transmission (X25519-XSalsa20-Poly1305); never unencrypted on-chain | Never shared with services; never sold — prohibited regardless of consent | Active account + 3 years after closure; absolute maximum 7 years from last use |
| OCR-extracted details (name, date of birth) | Encrypted identity scopes on the network | You; services only per explicitly consented claim | With your account, subject to the document retention rule |
| Verification results (level, pass/fail) | On the network — tamper-proof records | Services you consent to, per request | Permanent (results, not evidence) |
| Consent records | Auditable history, timestamped | You in full; services see their own grants | Permanent audit trail |
| Verification session metadata (device fingerprint, IP during verification) | Off-chain verification systems | Fraud-prevention processing only | Security logs 12 months; error logs 90 days |
| Wallet address and transactions | The public blockchain | Public — but not linked to your personal details | Permanent (blockchain immutability) |
The biometric commitments
Biometric data is special-category data, and the published Biometric Data Addendum binds the system to commitments stronger than general privacy law requires:
- Never sold, leased or traded — an absolute prohibition that applies regardless of consent. Biometric data is never monetised.
- Never disclosed raw. Services receive verification results, not biometric data. Sub-processors are contractually prohibited from retaining or using it.
- Separate, informed consent — biometric consent is unbundled from terms acceptance, logged with a timestamp, and withdrawable at any time.
- Deletion on request: 30 days from request or account closure, plus backup rotation (typically 90 days). Encryption keys are destroyed, rendering encrypted copies permanently unreadable.
- Breach notification within 72 hours of discovery, with plain-language disclosure and identity-theft protection support where biometric data is involved.
- Access rights: request a copy of your biometric data at any time (dpo@virtengine.com, subject “Biometric Data Access Request”); responses within 30 days.
Retention, in one table
| Data type | Retention period | Why |
|---|---|---|
| Blockchain records | Permanent | Immutability — but never readable personal data |
| Biometric templates | Active account + 3 years | Fraud and re-registration prevention, KYC/AML |
| Identity documents | 7 years | Regulatory (KYC/AML) requirements |
| Usage metrics | 3 years | Billing and audit |
| Support communications | 3 years | Customer service |
| Security logs | 12 months | Incident investigation |
| Error logs | 90 days | Debugging |
At the end of retention
Destruction is automatic: deletion from active systems, removal from backups within the rotation schedule, and destruction of encryption keys — which makes any on-chain encrypted material permanently unreadable.
Your rights
- Access — a copy of your data, within 30 days of request.
- Correction — re-verify with corrected evidence; you review every extracted field before submission.
- Withdrawal of consent — per scope, per service, any time. See revoking consent.
- Deletion — see deleting your identity for the full process and its honest limits.
- Portability — export your data in a structured format.
Contact for all privacy matters: dpo@virtengine.com. The system is designed to comply with the Australian Privacy Principles, GDPR (including Article 9 explicit consent for biometric data), and biometric-specific laws such as Illinois BIPA.
Read the governing documents
The full Privacy Policy, Biometric Data Addendum, Consent Framework and GDPR compliance documentation are versioned alongside the code in the open-source repository — you can read the exact text this page summarises.