At 1Kosmos, data privacy is important to us. This Privacy Policy explains how OneKosmos Inc. (“1Kosmos”, “OneKosmos”, “us” or “we”) collects, uses, discloses, stores, safeguards and retains your Personal Information. Please take the time to read this Privacy Policy carefully in order to understand how we collect, share, and otherwise process information relating to individuals (“Personal Data”).

Personal Information

Personal Information” means information, other than business contact information, about an identifiable individual.

If any of your Personal Information collected or stored by us or our service providers is not accurate, complete or up-to-date, please contact our Chief Privacy Officer so that we can correct the information or direct you to the third party responsible for correcting the information.

This Privacy Policy applies to Personal Information that we collect when you use our website or services, and to public Personal Information that we may collect from third party websites. This Privacy Policy does not apply to the practices of companies or other entities that we do not own or control, or to people that we do not employ or manage. Any Personal Information that you supply, or authorize us to supply to any third parties is governed by the privacy policies of those third parties.

Security

We have implemented reasonable technology and security features appropriate to the sensitivity of the information, including the use of encryption, to safeguard the privacy of your Personal Information from unauthorized access or improper use.

Accuracy

If any of your Personal Information collected or stored by us or our service providers is not accurate, complete or up-to-date, please contact our Chief Privacy Officer so that we can correct the information or direct you to the third party responsible for correcting the information.

Collection and use

Some examples of the types of information that we may collect include:

  1. contact information, such as your name, address, telephone number, email address;
  2. usage information and history, such as your usernames, internet protocol (IP) addresses, support ticket history, and website usage information;
  3. meaningless but unique numbers (MBUN); and
  4. persistent anonymous identifiers (PAI).

We will collect and use your Personal Information in connection with the provision of products and services from our website including: (i) delivery of our services, such as our authentication service(s) or our identity service(s), (ii) carrying out transactions that you have requested, (iii) for billing purposes, (iv) in order to communicate with you about new products and services, and promotional offers, (v) to prevent fraud and other prohibited or illegal activities, and (vi) managing recruitment and employment relationships. We may use your Personal Information, in conjunction with information available from third parties, to provide the complete functionality of our services.

TrueDepth API

Our app makes use of automatically collected information using the device camera and the TrueDepth API provided by Apple. This information is used to track the user’s head and face so that we can detect any kind of image or video spoofing thus making LiveID scan feature more robust. None of the information collected by the TrueDepth API ever leaves the user’s device nor is it persistently stored on the device.

Data retention

Your Personal Information will be retained only as long as necessary for the purposes for which it was collected, or until you request that we delete it, in which case it will be deleted in accordance with (and subject to) our data retention policy and our legal obligations.

You should exercise discretion when disclosing your Personal Information to us, and should not disclose sensitive or confidential information that you wish to remain private.

Disclosure

We may share your Personal Information with our corporate affiliates to carry out transactions that you request or to make our business, or that of our corporate affiliates, more responsive to your needs. We will not sell, trade, or disclose to third parties any Personal Information — including customer names and addresses — without the consent of the customer.

We may share your Personal Information with third parties that we engage to provide products and services on our behalf, or to third parties on whose behalf we collect your Personal Information. We will also not disclose your Personal Information to third parties for the purposes of the third party marketing products to you.

We may disclose your Personal Information:

  1. to any governmental authority as part of an investigation to determine our compliance with any applicable law, rule or regulation (including privacy laws, rules and regulations);
  2. in response to a court order, subpoena, discovery request or other lawful judicial or administrative proceeding;
  3. in order to comply with an applicable law, rule or regulation; and
  4. in good faith, to protect or defend our rights or property, or the rights or property of other customers or users.

Security posture & measures taken

Security is a critical priority for 1Kosmos. We maintain a comprehensive, written information security program that contains industry-standard administrative, technical, and physical safeguards designed to prevent unauthorized access to Personal Data.

However, no security system is perfect, and due to the inherent nature of the Internet, we cannot guarantee that data, including Personal Data, is absolutely safe from intrusion or other unauthorized access by others. You are responsible for protecting your credential(s) and maintaining the security of your devices.

If you use the 1Kosmos online service via a subscription purchased for you by a 1Kosmos customer, then that customer is responsible for configuring your instance appropriately. Additional information about security settings and configurations can be found in the documentation related to our online service, including the Trust & Compliance documentation.


Privacy Rights

Your European Privacy Rights

Under the General Data Protection Regulation, if you are a European Union data subject, you have rights to understand and request how we collect, use, and disclose Personal Data in our capacity as a data controller to the extent permitted by applicable law.

Right to Access. You have the right to access your Personal Data held by us.

Please note that we do not have access to, or the ability to share, information about you.  For information about fraudulent activities, you may contact the relevant fraud prevention agency for further information.

Right to Rectification. You have the right to rectify inaccurate Personal Data and, taking into account the purpose of processing, to ensure it is complete.

Right to Erasure (or “Right to be Forgotten”). You have the right to have your Personal Data erased or deleted, and that is under your complete control.

Right to Restrict Processing. You have the right to restrict our processing of your Personal Data where applicable.

You can ask us to do this if:

  • you dispute the accuracy of your personal information;
  • our processing is unlawful but you prefer restriction to deletion;
  • we no longer need the information but you need it for legal reasons; or
  • you have objected to our processing and we are still dealing with this objection.

If you would like to contact us about your restriction rights, please complete our online form.

Right to Data Portability. You have the right to transfer your digital Personal Data when requested, when possible, through the digital wallet.

Right to Object. You have the right to object to the processing of your Personal Data that is carried out on the basis of legitimate interests, such as direct marketing.

There are unlikely to be any circumstances when this right applies to 1Kosmos Identity Verification service personal information. If you want to contact us about your objection rights, please complete our online form.

Right Not to be Subject to Automated Decision-Making. You have the right not to be subject to automated decision-making, including profiling, which produces legal effects. 1Kosmos does not currently engage in the foregoing on our websites or in our products and services.

If you would like to make a request and exercise your rights described above, please complete our online form.

Your California Privacy Rights

Under the California Consumer Privacy Act of 2018 (“CCPA”), effective January 1, 2020, if you are a California resident, you have rights to understand and request that we disclose how we collect, use, disclose, and sell your Personal Data to the extent permitted by applicable law. If you would like to learn about our verification process, including the details that you must provide to us to verify your request, click here.

Right to Know About Personal Data Collected, Disclosed, or Sold. You have the right to request that we disclose what Personal Data we collect, use, disclose, and sell.

Right to Request Deletion of Personal Data. You have the right to request the deletion of your Personal Data collected or maintained by us as a business.

Right to Opt-Out of the Sale of Personal Data. You have the right to opt-out of the sale of your Personal Data by us as a business, in the event we sell Personal Data.

Right to Non-Discrimination for the Exercise of Your Privacy Rights. You have the right not to receive discriminatory treatment by us for the exercise of your privacy rights conferred by the CCPA.

Authorized Agent. You may designate an authorized agent to make a request under the CCPA on your behalf by us with a copy of your power-of-attorney document granting that right.

Financial Incentives. We do not provide any financial incentives tied to the collection, sale, or deletion of your Personal Data.

If you would like to make a request and exercise your rights described above, please complete our online form, or contact us via the telephone number listed in the contact us page. If you would like to opt-out of Personal Data sharing with marketing and advertising third parties through the use of cookies, please see the section above on Your Privacy Choices. Since there is no reasonable way for us to verify information for which we are a service provider to our customers, we will not respond to any requests in relation to data we hold on behalf of our customers.

Withdrawal of consent

You may withdraw your consent to the collection, use and disclosure of your Personal Information at any time. To do this, please contact our Chief Privacy Officer. Withdrawal of your consent to the collection, use and disclosure of your Personal Information will result in you being unable to continue to use our website or services.

Ready to go Passwordless?

Indisputable identity-proofing, advanced biometrics-powered passwordless authentication and fraud detection in a single application.