Data Subject Requests
This page is for individuals who completed an identity verification powered by OKIAS — you photographed your ID document and took a selfie inside another company’s app or website, and that verification was processed by us. It explains how to see the data we hold about you (GDPR Article 15) or have it deleted (Article 17), and who is responsible for answering.
1. Who actually holds your data
The company that asked you to verify is legally in charge of your data (the “controller”). OKIAS processed it on their behalf. The fastest route is to ask them — but you can also contact us, and we will act directly where the law requires.
When you verified your identity, you did so for a specific business — a marketplace, exchange, employer or similar. Under the GDPR, that business is the data controller for your verification data, and OKIAS is its processor: we analysed your document and selfie on that business’s instructions and reported a result back to it. Because we act on the controller’s instructions, requests are normally routed through the business you verified with — they can view and delete your verification directly in their OKIAS dashboard. That said, if you contact us we will not turn you away: we will forward your request to the controller without undue delay, and we will act on it directly ourselves where applicable law requires a processor to do so.
2. What data we may hold about you
- Images of your identity document, your selfie and liveness frames.
- Identity fields extracted from the document (name, date of birth, document number, nationality, expiry), stored encrypted.
- The verification decision, confidence scores and reason codes.
Note the automatic clock already running in your favour: an hourly purge job permanently deletes document/selfie media and extracted identity data once your verification passes the retention window — 90 days by default (the business you verified with may configure a different window). After that, only the anonymised decision record remains. So depending on when you verified, some or all of your media may already be gone. Details are in our Privacy Policy and Data Processing Agreement.
3. How to make a request
Email the business you verified with, or email us at security@okias.io. Tell us who you are, roughly when you verified, and with which company. No form to fill — a plain email is a valid GDPR request.
- Preferred: contact the business you verified with. They are the controller, they can identify your record fastest, and they can delete it themselves. Reference “identity verification data” in your message.
- Or contact OKIAS directly: email security@okias.io (data-protection function) or support@okias.io with the subject “Data subject request”.
Honest caveat: our @okias.io mailboxes are still being provisioned and delivery is not yet reliable. If your email bounces or you receive no acknowledgement within 5 business days, please use route 1 — the business you verified with can reach us through their account channel and instruct us directly. We publish this rather than let a request silently disappear.
4. What to include (identity proof)
We must be sure we are giving data to — or deleting data for — the right person. Include in your request:
- Your full name exactly as it appears on the document you used.
- The name of the business whose verification you completed.
- The approximate date of the verification.
- If you have it, any reference or verification ID shown during the flow.
Please do not email us fresh copies of your identity document — email is not a secure channel and we do not need another copy. We verify requesters by matching the details above against the record and, where necessary, by confirming through the controller. If we cannot locate a matching record or cannot verify your identity, we will tell you so rather than guess.
5. Response timeline
We acknowledge verified requests and respond within 30 days, as GDPR Article 12(3) requires. For complex requests this can be extended by up to two further months — if so, we tell you within the first month and explain why. Erasure requests are subject to legal exceptions (for example, the anonymised decision record retained for audit and the controller’s own legal retention duties); where we refuse any part of a request we will say which part and on what ground.
6. Your full set of rights
Beyond access (Art. 15) and erasure (Art. 17), you may also request rectification of inaccurate data (Art. 16), restriction of processing (Art. 18), a portable copy (Art. 20), or object to processing (Art. 21). If a verification decision significantly affected you, the business you verified with is required to offer human review and appeal (Art. 22); OKIAS supplies the reason codes that make that review possible. You always retain the right to lodge a complaint with your local data-protection supervisory authority.