Legal

Privacy Policy

How Persona Grata handles personal data and information.

Effective date: [DATE]

01

Introduction

Persona Grata respects your privacy. This Privacy Policy explains how personal data is handled when you use the Persona Grata website and services.

Persona Grata processes personal data only for defined purposes connected with providing identity verification, authenticity, account, security, and related services, as described below.

02

Data Controller

The controller responsible for the processing of personal data described in this policy is:

Data Controller[LEGAL ENTITY NAME][BUSINESS ADDRESS]Email: [PRIVACY CONTACT EMAIL]
03

Information We Collect

The information processed depends on how you use Persona Grata. It falls into the following categories.

Information you provide directly

  • Account information, such as your name and sign-in credentials.
  • Contact information, such as your email address.
  • Information you submit when requesting access or during verification.
  • Information about content you choose to register.
  • Communications you send to Persona Grata.

Information obtained through service providers or connected platforms

  • Identity-verification information, verification results, and verification status returned by verification providers.
  • Connected-account information returned by third-party platforms you choose to connect.
  • Payment and transaction information, such as payment status, returned by payment providers.

Information generated when you use the service

  • Technical and security information, such as log data, device and browser information, and IP address.
  • Information required to operate, maintain, and protect the service.
04

Identity Verification

Persona Grata verifies whether an individual is a real person and whether submitted identity information is consistent with the verification process.

Depending on the verification process and service configuration, identity verification may be performed with the assistance of specialized third-party verification providers. Those providers may process identity documents and related information on behalf of, or in connection with, Persona Grata. Persona Grata receives the verification results and status needed to provide the service.

05

Connected Accounts

You may voluntarily connect supported third-party accounts, such as social-media or professional accounts (for example TikTok or LinkedIn), to your Persona Grata record. Connecting an account is optional.

When you connect an account, you authorise the connection on the third-party platform's own sign-in page. Persona Grata may process the information necessary to establish the connection and to verify your ownership of, or association with, that account. This is typically basic profile information, such as the account identifier, username or display name, and profile image, together with the access credentials issued by the platform for that connection.

Persona Grata requests only basic profile access for this purpose. It does not request permission to post on your behalf. You can disconnect a connected account at any time from your account settings.

06

Registered Content and Authenticity

You may register digital content or authenticity-related information with Persona Grata.

Where applicable, Persona Grata may process technical identifiers, hashes, timestamps, URLs, metadata, provenance credentials, or similar information associated with that content in order to create and display authenticity records.

07

Payments

Payments may be processed by third-party payment providers. Payment-card information may be processed directly by our payment service providers. Persona Grata does not need to store complete payment-card details to provide the service.

08

Service Providers

Persona Grata currently uses the following third-party service providers to operate the service:

  • Sumsub — identity document and liveness verification.
  • Stripe — payment processing for the verification fee.
  • Resend — delivery of transactional emails, such as application and incident confirmations.
  • Vercel — website hosting, infrastructure and file storage (Vercel Blob) for uploaded evidence and registered content.
  • Neon — database hosting for account, verification, trust-record and incident data.
  • Trufo — C2PA content-credential signing for registered content.
  • Instagram (Meta) and TikTok — only when you choose to connect an account, to confirm account ownership.

These providers process information only as needed to perform their services for Persona Grata. [OWNER TODO: confirm data processing agreements and provider locations after legal review]

09

Identity Incident Reports

When you submit an identity incident report, Persona Grata stores the information you provide: incident type, who is affected, platform or location, URL, description, optional PG ID, contact email and any evidence files you upload. A technical fingerprint derived from your connection is stored in hashed form to limit abuse and duplicate submissions.

This information is used to document and review the report, to contact you about it, and to send you a confirmation email. The public incident status page shows only the Incident ID, status, incident type, platform and dates — never your email, description, evidence or internal review notes.

10

Purposes of Processing

Personal data is processed for the following purposes:

  • Providing the service.
  • Identity verification.
  • Account management.
  • Connected-account verification.
  • Content and authenticity functions.
  • Payment processing.
  • Security and fraud prevention.
  • Customer support.
  • Service improvement.
  • Compliance with legal obligations.
12

Data Retention

Personal data is retained only for as long as reasonably necessary for the relevant purpose, the contractual relationship, legal obligations, dispute resolution, security, and legitimate business needs. When information is no longer needed for these purposes, it is deleted or anonymised in accordance with applicable requirements. [OWNER TODO: define concrete retention periods — no automated deletion schedule is currently implemented]

13

Data Security

Persona Grata uses reasonable technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure, and absolute security cannot be guaranteed.

14

International Processing

Service providers or infrastructure may process information in jurisdictions outside your country of residence, where legally permitted and subject to applicable safeguards.

15

Your Rights

If you are located in the EU/EEA, or in another jurisdiction where such rights apply, you may have the right to:

  • Access the personal data held about you.
  • Correct inaccurate personal data.
  • Request deletion of personal data.
  • Restrict processing.
  • Object to processing.
  • Receive your personal data in a portable format.
  • Withdraw consent at any time, where consent is the legal basis, without affecting processing carried out before withdrawal.

These rights depend on applicable law and may be subject to limitations. You may also have the right to lodge a complaint with a competent data-protection authority. To exercise your rights, contact [PRIVACY CONTACT EMAIL].

16

Cookies and Similar Technologies

The website uses technically necessary cookies and similar technologies, for example to keep you signed in and to protect the service. Where additional technologies are used that require consent under applicable law, they will only be used in accordance with those requirements.

17

Third-Party Services

The service may contain links to, or integrations with, third-party platforms. Those platforms are governed by their own privacy policies, and Persona Grata is not responsible for their practices. Please review the privacy policies of any third-party services you use or connect.

18

Children

Persona Grata is not intended for children. Users must meet the age requirements applicable to them under the law of their jurisdiction and under these services' terms.

19

Changes to this Privacy Policy

This Privacy Policy may be updated from time to time. The effective date below indicates when it was last revised. Material changes may be communicated through appropriate channels, such as a notice on the website or by email.

20

Contact

For questions about this Privacy Policy or the handling of personal data, contact [PRIVACY CONTACT EMAIL]. See also the Terms of Service.

21

Effective Date

Effective date: [DATE]