Version 2 - effective 23 September 2026
Download PDFIn short. If you use the Mesh ID Platform, most of your personal data is handled on the instructions of the firm that invited you (the Customer). That firm is responsible for it, and questions and requests about it go to that firm. Mesh ID is responsible for a small set of data of its own: your account, sign-in and security records, the record of the terms you accepted, and any marketing preference you give us. This notice explains both, tells you who else sees your data, where it is processed, how long it is kept, and what your rights are.
Contents
This notice applies to anyone who uses the Mesh ID Platform following an invitation from a Customer or from someone acting for an entity the Customer is onboarding, whether or not you hold an account. It sits alongside the Mesh ID End User Terms at meshid.com/legal/end-user-terms and the Customer's own privacy notice. It does not cover the Mesh ID website, which has its own privacy policy at meshid.com/legal/privacy-policy.
Mesh ID B.V., Koningin Wilhelminaplein 1, 1062 HG Amsterdam, the Netherlands, Chamber of Commerce number 69878374. For anything in this notice, write to privacy@meshid.com.
Due diligence data. The Customer has to verify who you are, or who the entity you represent is, because the law requires it. The Customer decides what to ask for, which checks to run, and what happens with the results. In the language of the General Data Protection Regulation the Customer is the controller of that data and Mesh ID is its processor. We act on the Customer's written instructions, and the Customer's privacy notice explains its purposes and legal basis. Requests about this data go to the Customer (see section 10).
Our own data. For a narrow set of data we decide the purpose ourselves and are the controller. That set is described in section 5. Requests about it come to us.
Depending on how the Customer has configured its process, this may include:
We do not use any of this data for our own purposes. We keep it for as long as the Customer instructs us to, which is governed by the Customer's legal record-keeping obligations (see section 9).
| What | Why | Legal basis | How long |
|---|---|---|---|
| Account and sign-in data: email address, name shown on your account, authentication records | To create and secure your account and let you sign in | Performance of the End User Terms (GDPR art. 6(1)(b)) | While your account exists, then 12 months. |
| Security and audit logs: IP address, device and browser details, timestamps of actions on the platform, and records of suspected misuse of the platform | To keep the platform secure, detect and record misuse, and investigate incidents | Our legitimate interest in security (art. 6(1)(f)) | 12 months, longer if part of an incident investigation or where a record of suspected misuse is needed to protect the platform |
| Acceptance records: which version of the End User Terms you accepted, when, and confirmation that a storable copy was offered | To prove the terms were made available and accepted | Legitimate interest and legal obligation (art. 6(1)(c) and (f)) | For as long as we may need to prove acceptance, 7 years after your last use. |
| Support correspondence with support@meshid.com or privacy@meshid.com | To respond to you | Legitimate interest (art. 6(1)(f)) | 12 months after the matter is closed. |
| Marketing preference, if you opt in to hear from Mesh ID | To send you what you asked for | Consent (art. 6(1)(a)), withdrawable at any time | Until you withdraw |
| Aggregated usage statistics that do not identify you | To understand and improve the platform | Not personal data once aggregated | Indefinitely |
We do not sell personal data and we do not use due diligence data for marketing. We only contact you about Mesh ID if the Customer has agreed to that option being offered and you have separately opted in, and you can withdraw at any time using the link in any message or by writing to privacy@meshid.com.
The Customer. Everything you provide for the onboarding is visible to the Customer. Where you provided it at the request of someone acting for an entity, that person can also see it.
Our providers. We use the following companies to run the Mesh ID Platform. They process personal data on our instructions under written contracts, and only for the activity shown.
| Activity | Organisation | Location of processing |
|---|---|---|
| Hosting of the platform and storage of data | Amazon Web Services | Ireland (EU) |
| Sign-in and authentication | Auth0 (Okta) | Germany (EU) |
| Identity document verification, liveness detection and face comparison | Jumio Corporation | Austria (EU); manual review of some checks by Jumio staff in Colombia and India (applicable only to the human-assisted version) |
| Sanctions, politically exposed person and adverse media screening | ComplyAdvantage (IVXS UK Limited) | United Kingdom |
| Document reading and face matching software, where the Customer has chosen it instead of Jumio | Regula Forensics (software only) | Runs inside the Mesh ID environment in the EU; no data is sent to Regula. |
Others. We may disclose personal data to public authorities where the law requires it, to our professional advisers under confidentiality, and to a buyer of our business, in which case this notice continues to apply.
The Mesh ID Platform runs in the European Union. The United Kingdom is covered by a European Commission adequacy decision. Where a provider processes data outside the EU and the UK, as shown in section 6, we rely on the European Commission's standard contractual clauses and on the provider's additional safeguards. You can ask us for a copy of the relevant safeguards at privacy@meshid.com.
Verification Checks are automated: software reads your document, compares your face to the photograph, and runs Screening. The results are passed to the Customer. We do not make any decision about you. Whether the Customer accepts you, asks for more, or declines is decided by a person at the Customer. We do not profile you and we do not use your data to train any model.
Due diligence data is kept for as long as the Customer instructs us to keep it. Anti-money laundering law requires the Customer to keep records of its due diligence, typically for five years or more after its relationship with you ends; the exact period depends on the law that applies to the Customer. While that obligation applies, we cannot delete the data, and this remains true if you stop using the platform or your account is closed. Data that is not covered by such an obligation is deleted when the Customer instructs us to delete it, unless another firm that has verified you through the Mesh ID Platform is required to keep it.
Our own data is kept for the periods in section 5.
When a retention period ends the data is deleted from our systems and, after the normal backup cycle of 60 days, from our backups.
You have the right to ask for access to your personal data, to have it corrected or erased, to restrict or object to its processing, to receive a copy in a portable format, and to withdraw any consent you have given. These rights have limits; in particular, the right to erasure does not apply to data the Customer is legally required to keep.
For due diligence data, contact the Customer. It is the controller and holds the record, and we may only act on its instructions. Its contact details are in its privacy notice. If a request reaches us instead, we will pass it to the Customer and tell you we have done so.
For the data in section 5, contact us at privacy@meshid.com. We will need to confirm your identity and will respond within one month, or tell you if we need longer.
You can complain to a data protection supervisory authority, usually the one where you live or work. In the Netherlands this is the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl.
Data is encrypted in transit and at rest. Access inside Mesh ID is limited to staff who need it for their role and is logged. We operate an information security management system aligned with ISO 27001, run regular penetration tests, and publish our security documentation at trust.meshid.com. If a personal data breach affects you, we will inform the Customer without undue delay so that it can meet its obligations to you, and we will inform you directly where the data concerned is data we control.
We may update this notice. Each version is published at meshid.com/legal/platform-privacy-notice with its version number and date. Where a change matters to you, we will show it to you the next time you use the Mesh ID Platform.
This is the first published version of this notice.
Press Esc to close