Policies
Privacy
This page tells you what exists, where it lives, who can read it, and how long it is kept — with the actual figures, not adjectives.
The binding documents — the VirtEngine Privacy Policy, Biometric Data Addendum and Consent Framework — are versioned in the open-source repository. This page summarises them faithfully; where they differ, the repository documents govern.
Design commitments; service not live
The Identity Wallet and VEID verification service are not live. This page explains the published privacy design and policy; it is not a claim that every described control has been deployed or independently verified. Before launch, the actual client, network, recipients, retention and deletion behavior must be checked against these commitments.
This website collects nothing
identity.org.au is a static informational site. It has no accounts, no login, no forms, no analytics trackers and no advertising. The privacy questions that matter concern the wallet and the VEID network — which is what the rest of this page covers.
The life of your data, in five stages
Original document images stay on your device and never enter the network. The client processes the document locally; only minimum, user-approved derived data may leave, encrypted before transmission and processed under the relevant VEID scope.
- Stage 1 Captured On your phone: document scan, selfie, liveness.
- Stage 2 Original stays local The document image never leaves your device. OCR and checks run locally.
- Stage 3 Derived data, if approved Only minimum user-approved fields may leave, encrypted for VEID processing.
- Stage 4 Transient data cleared Temporary processing data is cleared under the scope lifecycle; source images remain local.
- Stage 5 Selective result The network records the verification result and required encrypted references, never source images.
What exists, where it lives, who can read it
| Data | Where it lives | Who can read it | Kept for |
|---|---|---|---|
| Original document images (licence, passport) | On your device only; not uploaded to the network | You, through the local wallet client | Under your device's controls; VirtEngine does not retain a copy |
| Biometric templates (face, fingerprint, iris) | Encrypted on-device before transmission (X25519-XSalsa20-Poly1305); never unencrypted on-chain | Never shared with services; never sold — prohibited regardless of consent | Active account + 3 years after closure; absolute maximum 7 years from last use |
| OCR-extracted details (name, date of birth) | Only if you approve submission: minimum derived fields in an encrypted, consent-scoped payload | You; services only per explicitly consented claim | According to the approved scope's lifecycle notice; original document images are not included |
| Verification results (level, pass/fail) | On the network — tamper-proof records | Services you consent to, per request | Permanent (results, not evidence) |
| Consent records | Auditable history, timestamped | You in full; services see their own grants | Permanent audit trail |
| Verification session metadata (device fingerprint, IP during verification) | Off-chain verification systems | Fraud-prevention processing only | Security logs 12 months; error logs 90 days |
| Wallet address and transactions | The public blockchain | Public — but not linked to your personal details | Permanent (blockchain immutability) |
The biometric commitments
Biometric data is special-category data, and the published Biometric Data Addendum binds the system to commitments stronger than general privacy law requires:
- Never sold, leased or traded — an absolute prohibition that applies regardless of consent. Biometric data is never monetised.
- Never disclosed raw. Services receive verification results, not biometric data. Sub-processors are contractually prohibited from retaining or using it.
- Separate, informed consent — biometric consent is unbundled from terms acceptance, logged with a timestamp, and withdrawable at any time.
- Deletion on request: 30 days from request or account closure, plus backup rotation (typically 90 days). Encryption keys are destroyed, rendering encrypted copies permanently unreadable.
- Breach notification within 72 hours of discovery, with plain-language disclosure and identity-theft protection support where biometric data is involved.
- Access rights: request a copy of your biometric data at any time (dpo@virtengine.com, subject “Biometric Data Access Request”); responses within 30 days.
Retention, in one table
| Data type | Retention period | Why |
|---|---|---|
| Blockchain records | May be permanent | Immutable history can include public metadata and encrypted references; deletion of submitted records cannot be promised |
| Biometric data submitted for an approved scope | As described by the scope notice and Biometric Data Addendum; the published schedule allows up to 7 years from last use, subject to applicable law | The stated scope purpose and retention schedule; no universal KYC/AML basis is assumed |
| Original document images | Not received or retained by the protocol | Remain on your device under your control |
| Derived document fields, if submitted | As stated in the scope notice | Only the minimum fields needed for the approved purpose |
| Usage metrics | 3 years | Billing and audit |
| Support communications | 3 years | Customer service |
| Security logs | 12 months | Incident investigation |
| Error logs | 90 days | Debugging |
At the end of retention
The applicable scope notice describes deletion timing and backup handling for data the service controls. Consent withdrawal stops future authorized processing or sharing where applicable, but does not erase immutable blockchain history or independent copies. This policy does not promise cryptographic erasure unless the deployed key lifecycle supports it.
Your rights
- Access — a copy of your data, within 30 days of request.
- Correction — re-verify with corrected evidence; you review every extracted field before submission.
- Withdrawal of consent — per scope, per service, any time. See revoking consent.
- Deletion — see deleting your identity for the full process and its honest limits.
- Portability — export your data in a structured format.
Contact for all privacy matters: dpo@virtengine.com. The system is designed to comply with the Australian Privacy Principles, GDPR (including Article 9 explicit consent for biometric data), and biometric-specific laws such as Illinois BIPA.
Read the governing documents
The full Privacy Policy, Biometric Data Addendum, Consent Framework and GDPR compliance documentation are versioned alongside the code in the open-source repository — you can read the exact text this page summarises.