Privacy notice
DirectorIDVerify privacy notice
This notice explains how SB Business Consulting Limited, trading as DirectorIDVerify, uses personal data when you visit our website, contact us, buy or use our Companies House identity-verification service, or apply to have your identity verified through us.
1. Who is responsible for your personal data?
SB Business Consulting Limited is the controller of the personal data described in this notice. We trade as DirectorIDVerify. Our company number is 11369594 and our registered office is 28 Townsend Street, Cheltenham, England, GL51 9HD.
You can contact us about privacy or this notice at info@directoridverify.co.uk or 01242 350490.
2. Personal data we use
Depending on the service and what you provide, we may use the following categories of personal data:
- Contact and application details: your full name (and any former names), email address, telephone number, residential address and address history.
- Identity-verification data: date of birth, identity-document type, document number, issuing country, expiry date, document images, a selfie and liveness/face-match result, verification result, and the audit information needed to evidence our check.
- Proof-of-address data: the document you upload and the information it contains, together with the date and outcome of our review.
- Payment and service data: payment status, Stripe checkout/session references, price paid, correspondence, service status, reviewer decisions and review notes. We do not receive or store your full payment-card number.
- Technical and security data: limited log, device, browser, IP-address and cookie-preference information generated when you use the website or secure service.
3. Where we obtain your data
We obtain data directly from you, from the secure Stripe Identity journey that you complete, from our payment and website service providers, and from information generated by our reviewers while completing the verification. We may also receive information from Companies House when this is necessary to administer a verification or respond to a query.
4. Why we use your data and our legal bases
| Purpose | Ordinary personal-data basis |
|---|---|
| Taking payment, providing the service, answering service queries and administering your application. | Performance of a contract, or steps taken at your request before entering a contract. |
| Meeting Companies House authorised-agent obligations, keeping required evidence and responding to a lawful request from a regulator or authority. | Compliance with a legal obligation. |
| Preventing fraud, protecting the service, carrying out quality assurance, managing claims and defending our legal rights. | Our legitimate interests in operating a secure, lawful and accountable verification service, where these interests are not overridden by your rights. |
| Sending direct marketing that is not part of the service. | Your consent, where this is required. You can withdraw it at any time. |
5. Facial, biometric and other sensitive data
The Stripe Identity journey may use a selfie, liveness checks and facial comparison. Where this involves special-category or biometric data, we will identify both an Article 6 UK GDPR basis and an additional Article 9 condition before processing it. Our intended condition for fraud prevention and identity assurance is substantial public interest, including the relevant condition in the Data Protection Act 2018, supported by our appropriate policy document. We do not rely on acceptance of these terms as consent for this processing.
6. Who we share data with
We share only the data needed for the following purposes with:
- Stripe: to process payment and provide the secure identity-verification journey.
- WordPress, Forminator, our hosting and support suppliers: to operate the website, secure upload route, reviewer dashboard and service communications.
- IONOS HiDrive: to hold our encrypted long-term case archive.
- WP Mail SMTP and our email provider: to send operational messages. We do not intentionally email identity or proof-of-address documents as attachments.
- Companies House: when we tell Companies House that an identity has been verified, using the information it requires.
- Our authorised staff, professional advisers, insurers, auditors, regulators, law-enforcement bodies and courts: where necessary and lawful.
Our suppliers process data under written contractual terms where they act as processors. Some suppliers may process data outside the United Kingdom. Where they do, we will use an adequacy regulation or another lawful UK transfer safeguard.
7. How long we keep data
Companies House requires authorised corporate service providers to keep identity-check evidence and verification records for seven years from completion of the identity check. We therefore keep the authoritative case record, including required identity and proof-of-address evidence and review records, in our encrypted HiDrive archive for that period. We may retain data for longer where required by law, to deal with a complaint or claim, or to meet tax and accounting requirements.
WordPress is used as a temporary working environment only. Our operating policy is to delete the WordPress case record and uploaded working files after successful archival and no later than seven days after archival. Copies in disaster-recovery backups are retained only for the applicable backup cycle, are access-restricted and are not used for ordinary business purposes. If an archive or deletion control is not operating correctly, we will pause the affected workflow until it is corrected.
8. Security
We use technical and organisational measures designed for sensitive identity evidence. These include access controls, individual user accounts, least-privilege access, secure service-provider connections, encrypted long-term archive storage, audit records and staff procedures. You must use the secure links we provide and must not send identity documents, proof of address, date-of-birth information or a Companies House personal code by ordinary email.
9. Your rights
Subject to applicable law and exemptions, you may request access to your data, correction of inaccurate data, erasure, restriction, objection, and portability. You may also complain to the Information Commissioner’s Office. Retention and legal-obligation requirements may mean that we cannot delete verification records on request.
To exercise a right, contact us using the details above. You can complain to the Information Commissioner’s Office.
10. Cookies
Our use of cookies and similar technologies is described in our Cookie Policy. You can manage non-essential cookies through the cookie banner on our website.
11. Changes to this notice
We may update this notice when our service, suppliers or legal obligations change. The current version will always be published on this page with its last-updated date.