TosiName

Privacy Policy

Last updated: June 27, 2026

TosiName provides verified digital identity services. This policy explains what we collect, why we collect it, and how we handle your information.

1. Data We Process

We process the following categories of data to provide the service:

2. Why We Process Data

3. Service Providers

We use trusted processors to deliver the service:

4. Identity Verification

TosiName provides verified identity links. To create or publish a verified identity link, we may require you to complete an identity verification process.

We use Didit as our identity verification provider. During this process, Didit may collect and process information such as your identity document, document data, selfie or liveness image, face match result, extracted legal name, country, IP address, device information, and other technical or fraud-prevention data.

TosiName does not store copies of your identity document, selfie, video, or biometric template. After a successful verification, TosiName stores only limited verification metadata needed to operate the service, such as your verification status, verified legal name, country, verification timestamp, identity verification provider, and provider session identifier.

Didit stores identity verification session data according to the retention setting configured by TosiName. We currently configure Didit's retention period to 6 months. After that period, Didit should delete the verification session data unless it is legally required to retain it for longer.

Identity verification may involve biometric data, such as facial data used for liveness detection and face matching. Where required by law, we ask for your explicit consent before this processing takes place.

Didit processes verification data on our behalf as a data processor. Didit may also process anonymized or pseudonymized data as an independent controller for fraud prevention, security, and improvement of its verification systems. You may request deletion of your TosiName account or verification data by contacting us.

5. International Data Transfers

Some of our service providers process data outside the European Economic Area. Didit states that identity verification data is primarily hosted within the EEA. Where non-EEA transfers do occur, they are governed by Standard Contractual Clauses approved by the European Commission or other recognized GDPR transfer mechanisms, which provide appropriate safeguards for your personal data.

6. Data Retention

We retain data only as long as needed for service operation, security, and legal compliance. Reveal Links are time-limited. When you close your account, access is immediately disabled and account data is scheduled for deletion after a 90-day retention period. During that period, processing is restricted to security, abuse prevention, fraud investigation, dispute handling, legal claims, accounting, and compliance purposes. We may retain limited records for longer where required by law or where necessary for the establishment, exercise, or defence of legal claims. We currently configure our identity verification provider (Didit) to retain verification session data for 6 months, after which Didit should delete the data unless legally required to retain it longer.

7. Your Rights

Depending on your jurisdiction, you may have rights to:

8. Cookies and Analytics Consent

We use an analytics consent banner. If you accept, we store a consent cookie and collect limited product analytics through PostHog (such as visited pages, time spent, and key product events) to improve the service. We configure these analytics to reduce personal data exposure. If you reject, PostHog analytics collection is disabled.

We remember an accepted analytics choice for 6 months and a rejected analytics choice for 3 months. You can reopen cookie settings at any time here: .

We also use Sentry to monitor application reliability and diagnose technical failures (for example, crash and error reports). Sentry data is used for security and service operation.

9. Account Closure

You can close your account directly from the dashboard. When you close your account, we immediately disable access to the account and deactivate published proof URLs and Reveal Links. We then schedule account data for deletion after 90 days. During this retention period, we restrict processing to security, abuse prevention, fraud investigation, dispute handling, legal claims, accounting, and compliance. We may retain limited records for longer where required by law or where necessary for the establishment, exercise, or defence of legal claims.

We currently configure our identity verification provider (Didit) to retain verification session data for 6 months. After that period, Didit should delete the verification session data unless it is legally required to retain it for longer; TosiName does not control this retention.

10. Security

We use technical and organizational safeguards, including signature verification for identity verification callbacks, security headers, and abuse rate limiting. No system is perfectly secure, but we continuously improve controls.

11. Contact

For privacy requests, contact: privacy@tosiname.com

For security reports, contact: security@tosiname.com