Version 1.2 - Last updated 8th April 2020
Keeping your data secure and maintaining your privacy is a significant responsibility and one that we take very seriously. We’ve written this policy to help you understand “what” personal information we collect, “how” we process it, “where” it is stored and how you can access or request deletion of your personal data.
By accessing, logging into or registering on the ML Verify website (or any of its sub-domains), you agree that it’s okay for us to process your information and personal data in accordance with the terms of this Privacy Policy. If you disagree with any of the terms in this policy, or wish to be no longer bound by these term, we kindly ask that you cease from entering information into the ML Verify website and cancel any temporary or rolling subscriptions.
When we refer to “Personal Data” we mean any data held on our system that directly or indirectly identifies an individual. This includes information that you have entered onto the system or have granted access to via a third-party integration.
We may also collect Personal Data about you in relation to how you use your account, i.e. where you are logging in from, how often you log in and what specific features you routinely use. This helps us to tailor your user experience and enhance security.
We comply with current UK Data Protection Legislation which implements the European Community’s Directive 95/46/EC and Directive 2002/58/EC, including, but not limited to, the DPA and the Privacy and Electronic Communications (EC Directive) Regulations 2003.
As of 25th May 2018 this incorporates Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (“GDPR”).
This includes the Personal Data you provide, or somebody else provides on your behalf when completing any of the following activities:
The information may include the following types of direct or indirect Personal Data:
Our service is not intended for anyone under the age of sixteen, and we do not knowingly collect or solicit personal data pertaining to children. In the event we have collected and identified data for anybody under the age of sixteen without parental consent, we will proceed to delete this information as quickly as possible.
ML Verify do not collect or process special categories of personal data, as defined under GDPR.
We also collect information about how you use your account, this helps us to deliver a more customised user experience, identify trends and improve security. Some of this data may be “Personal Data”, in cases where it can be used to identify a person. Here is the information we collect and how it is used:
In some cases we may receive Personal Data that has been passed to us by a third-party such as a payment processor or bank. This information is only received when you explicitly consent to share your information with us.
In addition to your Personal Data, you may also enter Personal Data of other individuals into the ML Verify website. This can include name, date of birth, address, nationality and personal documents.
The Personal Data you provide ML Verify is used as part of the service we offer you, in order to help you meet your AML obligations, including through document verification, electronic identity verification (eIDV), generate reports and deliver other functionality you would expect from us as a compliance software platform. We will not pass this information onto any third-party without your consent.
In order to safeguard your information we ask that you take great care to ensure your password remains private and take all reasonable steps to protect your account from unauthorised access. We also ask that when providing the Personal Data of others, that you do so with full consent and in accordance with current Data Protection Legislation.
In this section we explain how your Personal Data, and the Personal Data entered into your account, is used by ML Verify.
First and foremost your Personal Data and the Personal Data of others will be used to provide you with a stable and reliable service. We will use the data to provide you access to the ML Verify service and from time to time to contact you by email, SMS, post, phone or social media concerning your account or any related matters that may be of interest to you. We will not contact individuals who do not hold an account with us, unless requested (including, but not limited to, a request to supply documents).
You may elect to use a third-party Marketplace Application to provide additional functionality for your account. Your data will only be shared with your explicit consent, although we do ask that you carry out appropriate due diligence before granting any third-party access to your account.
We will use your Personal Data and the Personal Data of others that you’ve input, to improve our service to you. This can be through administering support, tracking feature usage, collaborating on beta development or resolving bugs. We may from time to time rely on trusted outsourcing partners to help with some of these tasks. In such cases, we will always perform thorough risk assessment and establish strong privacy controls for any outsourcing partner.
We collect anonymised data about how people use the ML Verify website. This includes collecting information on the number of visitors, what pages or features are accessed, which country visitors are connecting to the website from, browser types, display size and average viewing times. We may occasionally share this anonymised data with our community, although we will never include specific Personal Data here or any information that would identify you or your business.
We will occasionally contact you by email, SMS, post, telephone or social media to let you know about new features, forthcoming changes and relevant industry news. You reserve the right to opt-out from this type of correspondence at any time. You can either click the unsubscribe link or contact us and we will arrange that for you immediately.
We may also send you non-promotional notifications to update you on specific activity or events in your account. This may include when one of your clients uploads a documents or completes a KYC check that you have sent. It may also include reminders relating to your subscription or account status. If you prefer not to receive these types of notifications, we ask you to close your ML Verify account.
We rely on the use of internet cookies to track user sessions and to store particular preferences that facilitate the use of our website. By accessing the website and its sub-domains, you consent to the use of cookies for the aforementioned purposes. If you do not agree to this then we must advise you to cease using any of the services provided on our website.
Upon request, we can provide you with an export of your Personal Data and the Personal Data of others that you have entered, in a universal machine-readable format. These may be delivered instantly or emailed to the account administrator, depending on the file size and the time taken to generate the export. These exports may, upon request, include any documents and images uploaded to your account. Due to the multi-tenanted design of our software, we are unable to restore your account to a specific point-in-time from a previously issued data export.
Upon request, we will physically delete all Personal Data entered into your account. This can be instructed from the Account Settings section in your account, under the option “Close or Wipe your account”.
Under the provisions of Article 17 of the GDPR Legislation, you also have the right to request that any Personal Data (Notwithstanding those exemptions listed under Article 17, Paragraph 3) be permanently deleted. Upon receipt of such a request, we will take all reasonable steps to ensure that this is completed in an expeditious manner.
Depending on your jurisdiction you will likely be obligated to retain all business accounting records for a set period of time. We advise you to execute a backup of your account before instructing any deletion of your Data. Once we have received a request to delete your data we will be unable to reverse this process.
We use a third-party payment processor (Stripe, Inc) to collect credit and debit card payments for payments, subscriptions and related products and services. We never directly collect or store payment card information on our servers.
Our payment processor use a secure encrypted connection for collecting payment card information and implement all necessary controls to keep your payment data safe. Please click here to view Stripe’s privacy policy.
For monthly subscription we rely on Direct Debit mandates and payment request, processed by GoCardless Ltd. Please click here to view the GoCardless privacy policy.
In this section we explain a number of other circumstances in which we may share your Personal Data or the Personal Data entered into your account.
In some cases it will be necessary to share Personal Data with a third-party web service you have authorised to work with your ML Verify account. This may be something like passing Personal Data to a third-party payment processor for services such as electronic identity verification.
In these cases data will be shared only on the basis that you have provided explicit consent and that you have completed the necessary authorisation for us to pass data to each of these web services. When we work with a third-party web service in this way, we always make sure that your data is only sent over a secure encrypted connection.
In order to provide a robust and reliable service, we depend on a number of cloud service providers to carry out key operations within our business. This includes things like document storage, payment processing, email processing, marketing assistance, social media management and website security.
Whenever we entrust your data with an outsourcing partner, we always carry out thorough due diligence and ongoing monitoring to ensure that appropriate privacy controls are in place and maintained at all times.
The data we collect from you may be transferred to or stored at a destination outside of the European Economic Area (EEA). We may also hire staff or outsourcing partners who process your data outside of the EEA. In such cases, we will share only the minimum data required and ensure sufficient privacy controls are implemented to protect your privacy in accordance with this Privacy Policy.
We reserve the right to share Personal Data with a prospective buyer of business assets. This would be subject to the terms of a Non Disclosure Agreement.
We reserve the right to share Personal Data with law enforcement agencies, if the restriction of such information may prejudice an investigation into unlawful activity. Such exemptions will be sought under current Data Protection Legislation and ML Verify will have no legal liability for such disclosures.
We recognise the responsibility to ensure that your data is kept safe and secure at all times. We will ensure that whenever your Personal Data, or the Personal Data of others stored in your account, is passed to and from our servers, that it is done so on a secure, encrypted connection. This may be when you are accessing data on the Website or when we are required to exchange data with third-party services. You can read more about our data security policies here.
We also ask that you ensure your password remains private and take all reasonable steps to protect your account from unauthorised access. We highly recommend setting up 2-factor authentication to further increase the security on your account.
You own all of the Data you enter into ML Verify. More specifically we recognise the owner of an account and the data contained therein as the individual or entity that controls access to the email supplied as part of your login credentials.
In cases where a dispute arises between personnel within your organisation or a third-party, we will play no role in arbitrating such disputes and will acknowledge the email owner as the account holder.
Should a dispute over account ownership arise, we ask that you resolve this by establishing control over the ML Verify login email address via your hosting company or IT service provider. When you have relinquished control over the login email address, you may then proceed to initiate a password reset to regain access to an account.
You have the right to unsubscribe from any promotional materials that we may send from time to time, by way of email, SMS, post, phone or any other medium. You will also receive general notifications about account activity such as when an invoice is paid by your client or when a subscription is due for renewal. If you would also wish to cease receiving this type of correspondence we ask that you close your ML Verify account.
Right to Erasure - You have the right to request that your Personal Data is deleted (notwithstanding those exemptions allowed under GDPR and the current UK DPA). You will be able to request removal of all applicable Personal Data and Financial Data from the “Close or Wipe your Account” section within your account.
Right to Rectification - You have the right to request that any incorrect Personal Data we hold about you is corrected if that information is inaccurate or incomplete. If you are unable to make the necessary rectification from within your account please contact us.
Right to Data Portability - You have the right to request a machine-readable export of all Personal Data we hold about you. This will be delivered as a ZIP file containing multiple CSV files.
Right to Object - In certain circumstances, you may object to our processing of your personal data. If you wish to lodge an objection, then please contact us.
Right to restrict processing - You can request that we restrict the processing of personal data we hold about you in certain circumstances. If you wish to lodge such a request, then please contact us.
Right to lodge a complaint - You have the right to make a complaint about our data processing activities to a supervisory authority. In the UK this is the Information Commissioner’s Office (ICO). Further details can be found on their website at https://ico.org.uk. We do however ask that you first contact us with any concerns you may have before you escalate a complaint.
Where you, in turn, are acting as a Data Controller, we will endeavour to make all reasonable efforts to assist you in the identification, rectification, extraction, or deletion of any Personal Data you have provided to us in the capacity of a data processor.
We may from time to time make minor edits to this Privacy Policy. When we make more substantial changes to the terms in this Privacy Policy we will notify you accordingly.
For the purpose of current Data Protection Legislation, the Data Controller is ML Verify Ltd.