Polyguard गोपनीयता नीति

अंतिम अपडेट: 2 अगस्त, 2026

1. Introduction

Polyguard brokers secure identity verification to authorize participants joining voice and video calls, ensuring that the people on your calls are who they claim to be. We work alongside your existing communication platforms, including Zoom, Microsoft Teams, and WebRTC-based applications, and are fully compatible with end-to-end encrypted calls.

The Polyguard Verification System is also available via SDK for identity verification in other contexts, including financial transactions, step-up authentication for remote workers, and other applications where authenticity matters, including dating, voting, commerce and telemedicine. This Privacy Policy applies to all uses of Polyguard services.

t-zero security, Inc. dba Polyguard, Inc., a Delaware corporation headquartered in New York, NY, is the data controller responsible for the personal data described in this Privacy Policy. This Privacy Policy describes how we collect, use, and handle your information when you use our services. Your privacy is foundational to our business. We do not monetize your data, and we have designed our systems to minimize data collection and retention. We do not have access to the content of your calls.

2. Our Core Privacy Commitments

We do not store your credentials or biometric data outside of your mobile phone, where it is encrypted and uses the secure hardware enclave to manage the encryption key. All biometric matching, including face-to-document matching, happens on your device. When you verify your identity through Polyguard, we facilitate verification but do not capture, store, or retain the underlying biometric data or credentials. Where possible, we verify identity directly via NFC scanning of your identity document on your own device, with no third-party involvement. When NFC verification is unavailable, we use trusted document-proofing providers (see Section 4), and images of your identity document are retained for up to 90 days for document authenticity checks and fraud prevention before deletion. Document images are never used for biometric matching by Polyguard servers or our providers.

Your explicit consent comes first. Before any biometric processing begins, we ask for your explicit, specific consent within the Polyguard app, separate from your acceptance of our Terms of Service. You can withdraw consent at any time in the app, as easily as you gave it, and related processing stops.

We do not use your data to train AI models. Your personal information, verification history, and usage patterns are never used to train, fine-tune, or improve machine learning or artificial intelligence models, whether our own or those of any third party.

We do not sell or share your data for commercial purposes. We will never sell your personal information. We do not share your data with advertisers, data brokers, or other third parties for marketing or commercial purposes.

We do not access your call content. Polyguard operates at the access and authorization layer only. We do not receive, process, record, or store the audio or video content of your calls. Our service is fully compatible with end-to-end encrypted communications.

3. Information Collection and Use

Personal Information: When you register for Polyguard, we collect your name, email address, and other relevant details necessary to create and manage your account.

Verification Records: When you verify your identity for a call or other transaction, we retain a record of that verification. These records contain only the identity details you chose to share with other call participants (such as your verified name), not the underlying identity documents, biometric data, or credentials used during verification. Verification records are available to all participants of the relevant call.

Consent Records: We keep a record of each consent you give or withdraw, including the time and the version of the consent language you saw, so that we and you can demonstrate what was agreed.

Call Metadata: We collect metadata about calls protected by Polyguard, including participant identities and entry/exit times. We do not collect or have access to call content.

Analytics and Usage Data: We may collect data pertaining to your use of our services, device types, and preferences to improve our application functionality. This data is used solely to operate and improve Polyguard and is not shared externally except as described in Section 4.

Legal bases (EEA, UK and Swiss users): We process your account and verification data to perform our contract with you (our Terms of Service); biometric data on the basis of your explicit consent; and verification outcomes shared with the organization that requested your verification on the basis of legitimate interests in preventing fraud and impersonation, interests shared by that organization and by you.

4. Data Sharing and Disclosure

We do not share your personal information with third parties, except in the following limited circumstances:

Organizations that request your verification: When you verify at the request of an organization (for example, a prospective employer or your company's help desk), that organization receives the verification outcome: the result, timestamp, and identity details you chose to share. It never receives your biometric data, identity documents, or credentials.

Identity verification providers: When NFC-based verification is not available, we use third-party document-proofing services to verify your identity. These providers are:

These providers receive only the information necessary to complete verification and are contractually and legally prohibited from using your data for other purposes. We encourage you to review their privacy policies. Polyguard remains responsible under the Data Privacy Framework Principles if a third party processing personal data on our behalf does so in a manner inconsistent with those Principles, unless we prove we are not responsible for the event giving rise to the damage.

EU Representative: Prighter GmbH acts as our representative in the European Union under Article 27 GDPR (see Section 9). If you contact us through Prighter, Prighter receives the data you provide about yourself (such as name, identification, and contact details) and the details of your request, and transfers that data to us so we can respond. Prighter hosts its request-management tool with Hetzner Online GmbH.

Legal compliance and law enforcement: We may disclose information when required by law, subpoena, or court order, or when we have a good-faith belief that disclosure is necessary to comply with legal obligations or cooperate with law enforcement investigations. This includes disclosing personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Protection of rights: To protect and defend the rights, property, or safety of Polyguard, our users, or the public.

Business transfers: In connection with a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control.

We do not share data with any third parties for advertising, analytics partnerships, or AI/ML training purposes.

5. Data Storage and Security

We employ industry-standard security measures to protect against unauthorized access, alteration, disclosure, or destruction of data. Polyguard has completed a SOC 2 Type II audit with an unqualified report, available upon request through our Trust Center at trust.polyguard.ai. However, no method of transmission over the Internet or electronic storage is 100% secure.

Data minimization and retention: We retain only the minimum information necessary to provide our services. Verification records, including call metadata, are retained for 179 days. These records contain only shared identity details, not underlying credentials or biometric data. Identity document images collected via our document-proofing providers are retained for up to 90 days. We do not maintain any record of call content.

6. User Rights and Regulatory Compliance

You may request access to, correction of, or deletion of your personal information by contacting us at support@polyguard.ai.

For users in the European Economic Area (GDPR): You have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing and to withdraw consent where processing is based on consent, including your biometric consent, which you can withdraw at any time in the Polyguard app. To exercise these rights, contact us at support@polyguard.ai, or contact our EU Representative (see Section 9). You also have the right to lodge a complaint with your local data protection authority.

For California residents (CCPA/CPRA): You have the right to know what personal information we collect, disclose, or sell; the right to request deletion of your personal information; and the right to opt out of the sale or sharing of your personal information. Polyguard does not sell your personal information. To exercise your rights, contact us at support@polyguard.ai. We will not discriminate against you for exercising these rights.

For healthcare and telemedicine use cases (HIPAA): When Polyguard services are used in contexts where the Health Insurance Portability and Accountability Act applies, we address HIPAA requirements through Business Associate Agreements (BAAs) with covered entities. Contact us at support@polyguard.ai for more information.

Depending on your location, you may have additional rights related to your data under applicable law.

7. International Data Transfers

Polyguard is headquartered in the United States, and your information may be stored and processed in the United States and in other countries where we or our service providers operate. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to the United States, we rely on the EU-U.S. Data Privacy Framework as described in Section 8 and, where applicable, on the European Commission's Standard Contractual Clauses and equivalent UK and Swiss mechanisms. You may contact us at privacy@polyguard.ai for more information about the safeguards applied to a specific transfer.

8. EU-U.S. Data Privacy Framework

t-zero security, Inc. dba Polyguard, Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. We have certified to the U.S. Department of Commerce that we adhere to the EU-U.S. DPF Principles with regard to the processing of personal data received from the European Union and the United Kingdom, and to the Swiss-U.S. DPF Principles with regard to personal data received from Switzerland. If there is any conflict between the terms in this Privacy Policy and the DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework program, and to view our certification, please visit dataprivacyframework.gov.

Recourse. In compliance with the DPF Principles, Polyguard commits to resolve complaints about our collection or use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints should first contact us at privacy@polyguard.ai or through our privacy portal. Polyguard has further committed to cooperate and comply with the advice of the panel established by the EU data protection authorities (DPAs), the UK Information Commissioner's Office (ICO), and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the DPF, including human resources data received in the context of the employment relationship. This independent dispute resolution is provided at no cost to you.

Binding arbitration. If your complaint is not resolved through these channels, under certain conditions you may invoke binding arbitration as described in Annex I of the DPF Principles.

Enforcement. Polyguard is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).

Onward transfer liability. As described in Section 4, Polyguard remains liable under the DPF Principles for onward transfers to third parties acting on our behalf.

9. EU Representative

We have appointed Prighter GmbH as our representative in the European Union under Article 27 of the GDPR. Prighter is the point of contact for data protection authorities and for data subjects in the EU on all matters relating to our processing of personal data.

Prighter GmbH
Schellinggasse 3
1010 Vienna, Austria

GDPR Certification: Art 27 representation by Prighter

powered by Prighter

You may contact Prighter in place of, or in addition to, contacting us directly at privacy@polyguard.ai. Requests can be submitted through our privacy portal at app.prighter.com/portal/polyguard. Prighter operates a request-management tool that channels, filters, and structures data subject requests, and forwards the relevant personal data to us so that we can respond. Prighter processes the data you provide about yourself (such as name, identification, and contact details) together with the details of your request, and hosts that data with Hetzner Online GmbH. Prighter acts as our processor when providing the request-management tool and infrastructure, and as an independent controller when providing advice and support.

Appointing an EU Representative does not limit your rights under Section 6, including your right to lodge a complaint with your local data protection authority.

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically. Any changes will be posted on our website with an updated revision date. If we make material changes to how we handle your data, we will notify you by email or through a prominent notice on our service.

11. Contact Us

If you have any questions or concerns about our Privacy Policy or data handling practices, please contact us at:

t-zero security, Inc. dba Polyguard, Inc.