Privacy Notice
This early-access notice describes the intended handling model for the ForgetID pilot. It must be reviewed by qualified privacy counsel before a public commercial launch.
Information used
ForgetID stores identity information submitted by the customer, declared or connected social profiles, authorization records, reference images, discovered exposure records, removal-request history, and verification results.
Purpose
The information is used only to operate the authorized privacy service: identify likely public records, document evidence, prepare or send approved privacy requests, verify removal, and provide the customer dashboard.
Security and minimization
Sensitive values are encrypted at rest. Access is restricted to the customer and authorized administrators. Reference photos and sensitive-site evidence should be retained only as long as needed for the authorized service.
Third-party services
When a customer explicitly connects a provider or authorizes an external search service, only the permitted data returned by that service should be imported. Provider tokens must be encrypted and revoked when the connection is removed.
Customer choices
Customers may disconnect social accounts, request correction, request an export, or request account closure. Some records may need to be retained temporarily for legal, fraud-prevention, or request-audit purposes.
Contact
The production notice must include the legal entity, privacy contact, physical or registered address, jurisdiction-specific rights, retention schedule, subprocessors, and appeal process before launch.