Skip to content
IDtta
ProductsHow it worksPricingSecurityDevelopers
TREN
Sign inBook a demo
ProductsHow it worksPricingSecurityDevelopersAboutChangelogContactSign in

On this page

Automatic retention periodWhat gets deletedWhat is retainedEarly deletion request (right to erasure)Incomplete sessionsLegal basis

Data Retention & Destruction · Last updated: July 24, 2026

Data Retention and Destruction Policy

IDotta stores and destroys the identity verification data it collects from a tenant's end users (applicants) as described in this policy. The tenant acts as Data Controller; IDotta acts as the Data Processor handling this data on the tenant's behalf.

Personal data is retained only for as long as its processing purpose requires, and is automatically and irreversibly deleted once that period ends.

Scope

This policy covers identity document images, NFC chip data, liveness and face biometric records, and identity fields extracted via OCR/MRZ (name, ID/passport number, date of birth, etc.).

  1. 01Automatic retention period

    For sessions in a terminal state (approved, rejected, or expired), personal data is automatically deleted 90 days (default) after the status becomes final. This runs via a daily background job.

  2. 02What gets deleted

    All files tied to the session (document images, raw NFC data, attempt archives), OCR text, MRZ fields, extracted identity fields, NFC details, and the face biometric record are permanently deleted.

  3. 03What is retained

    Verification scores, the final decision, and the status history contain no personal data and are kept for audit and dispute-resolution purposes.

  4. 04Early deletion request (right to erasure)

    A tenant can request immediate deletion of personal data for a session in a terminal state, without waiting out the retention period. A full-deletion request removes every row including the audit record, leaving only a single-line deletion log of who deleted it and when.

  5. 05Incomplete sessions

    Sessions that expire before completion (60 minutes by default) move to an 'expired' state and enter the same automatic retention/destruction cycle.

  6. 06Legal basis

    Under KVKK Art. 7 and GDPR Art. 5(1)(e), personal data is not kept longer than its processing purpose requires; the deletion obligation is enforced automatically once that period elapses.

Important note

Retention periods follow the defaults above unless otherwise agreed in your data processing agreement. Reach out to us with deletion requests or questions.

IDtta

Identity verification infrastructure.
İstanbul · Berlin

© 2026 IDotta Teknoloji A.Ş.

PRODUCTDocument verificationNFC chip readingLivenessFace matchAML screeningHow it works
COMPANYAboutChangelog & blogContactDevelopers
LEGALData retentionSecurity
STATUSAll systems operationalstatus.idotta.cominfo@idotta.com