RESILIANT ID / IdNFT APP PRIVACY POLICY
Effective Date: 1st August 2025
This Privacy Policy explains how Resiliant (“we”, “our”, or “us”) collects, processes, and protects personal data through the Resiliant ID™ mobile application and the IdNFT™ mobile application . We are committed to ensuring the privacy, integrity, and security of all user data.
User Overview
Resiliant ID™ and IdNFT™ empowers users with full and personal control over their digital identity. All biometric data and identity documentation uploaded to Resiliant ID™ is encrypted and stored only on the user’s device.
Only the user can access, view, edit, share, or delete this data. Biometric checks are conducted solely by our artificial intelligence engine, without human review or intervention.
Resiliant ID™ and IdNFT™ provides a simple ‘Yes’ or ‘No’ identity verification response to authorised third parties, without revealing personal data. If a third party requests access to a user’s photo ID or additional data, explicit consent from the user is always required before any information is shared.
Since all data is stored locally, deleting the Resiliant ID™ app from the device deletes all associated data from the system.
Data Protection Commitment
Resiliant™ and IdNFT™ complies with the UK GDPR, EU GDPR, and relevant data protection laws in the regions in which it operates.
We act primarily as a data processor under Article 28 of the GDPR and may act as a data controller under Article 24 in certain cases, depending on the service and context. In both roles, Resiliant™ and IdNFT™ adheres to the highest standards of data privacy and security.
No personal or biometric data is uploaded to external servers or cloud systems. All identity data remains securely stored on the user’s mobile device and under the user’s exclusive control.
Scope of This Policy
This Privacy Policy applies to:
-
Users of the Resiliant ID™ and IdNFT™ mobile applications
-
Personal data processed solely on the user’s device
-
Any data shared with third parties with user consent
Although Resiliant does not generally process personal data on its servers, this policy ensures our systems, procedures, and staff comply with applicable UK, EU, and regional data protection regulations if processing ever becomes necessary.
Responsibilities
a) Resiliant’s Responsibilities
Resiliant ID™ and IdNFT™ is responsible for implementing and maintaining appropriate policies, procedures, and technical safeguards in compliance with applicable data protection laws.
b) Data Protection Officer (DPO)
Our DPO oversees compliance, manages data requests, handles breach notifications, and responds to privacy complaints.
Contact: info@resiliant.com
c) Staff Responsibilities
All Resiliant ID™ and IdNFT™ personnel must comply with this policy, protect data confidentiality, and report any data incidents immediately.
d) Third-Party Processors
Where external processors are used (e.g. for verification services), Resiliant™ and IdNFT™ ensures they meet required legal, contractual, and security standards.
Data Security Measures
Resiliant™ and IdNFT™ implements the following to protect user data:
-
Device-based encryption and secure storage
-
Biometric and facial data processed locally
-
No external transmission of sensitive data
-
Strict access controls, hardware protection, and monitoring for any authorised backend functions
-
Ongoing vulnerability testing, audits, and employee training
Physical and Network Security
We maintain robust physical security including restricted access, CCTV, secure hardware, and media control. Network and software infrastructure are regularly tested for vulnerabilities, with malicious activity monitored via machine learning.
Data Breach Protocol
Any suspected or confirmed data breach must be reported immediately to the DPO and/or CEO, with full details logged and assessed. Although user data is stored on-device, we maintain internal procedures for breach response where applicable.
Data Subjects’ Rights
Where applicable under GDPR and regional laws, users may have rights to:
-
Access their personal data
-
Request rectification or erasure
-
Restrict or object to processing
-
Exercise data portability
-
Avoid automated decision-making without oversight
Users may exercise these rights by contacting info@resiliant.com
Data Collected
Data collected and stored exclusively on the user’s device may include:
-
Full name
- Email Address
- Phone Number
-
Photo ID (passport or driving licence etc, or whatever document provided by the user)
- Documents signed by the user using the IdNFT/Resiliant ID App
-
Address
-
Facial biometrics
-
Phone IMEI
-
GPS location (if permitted)
- Voice
- Palm (Vein) Print
- Retina Scan
- Or any other identifying data after the user has provided explicit consent beforehand
This data is encrypted on the users phone and never transmitted unless the user consents explicitly.
Purpose of Data Collection
Personal data is used solely for identification and compliance checks, such as Know Your Customer (KYC) or Anti-Money Laundering (AML) verification.
Automated validation may be performed against approved datasets or databases, where applicable and with user consent.
Legal Basis for Processing
Data is processed solely on the basis of informed and explicit consent provided by the user. No processing takes place without consent, and no data is retained by Resiliant once the app is deleted.
Data Storage and Deletion
Resiliant does not store or access user data centrally. All user data is encrypted and stored on the user’s phone. Deleting the app removes all personal and biometric data.
Contact Us
For questions, data requests, or complaints related to this policy or your data, please contact:
Data Protection Officer
Email: info@resiliant.com