Legal

Privacy Policy

Effective Date: 21 May 2026 Last Updated: 21 May 2026 GDPR & CCPA Compliant ISO 27001:2022 Certified
01

Overview

Pixl ("Pixl", "we", "us", or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect information in connection with our identity verification platform, website at pixl.ai, and all associated services (collectively, the "Services").

Please read this policy carefully. By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the terms described here, please do not use our Services.

For business clients: If you are a business using Pixl's API or platform to verify your end users, you act as the Data Controller for your users' personal data. Pixl acts as the Data Processor on your behalf. Your end users' rights are governed by your own privacy policy as well as this document.

02

Who We Are

Pixl is an intelligent identity infrastructure company providing AI-powered identity verification, biometric authentication, KYC/KYB compliance, and fraud prevention solutions to regulated enterprises globally.

Data Controller:

  • Company: Pixl (PixDynamics Pvt. Ltd.)
  • Registered Address: Unit No. III A-2, 3rd Floor, Phase II, Carnival Infopark, Kakkanad, Kochi - 682 042, Kerala, India
  • Privacy Email: privacy@pixl.ai
  • General Contact: connect@pixl.ai
  • Phone: +91 79944 31839
03

Data We Collect

Depending on how you interact with our Services - whether as a website visitor, API integration partner, or an end user being verified - we may collect the following categories of data:

Identity Data

Full name, date of birth, nationality, government-issued ID numbers, and other identity attributes.

Document Data

Images of passports, national IDs, driving licences, and other identity documents submitted for verification.

Biometric Data

Facial images and liveness-check data captured during biometric verification, including facial geometry measurements.

Contact Data

Email address, phone number, and postal address collected from business clients and direct enquiries.

Usage & Technical Data

IP address, browser type, device identifiers, pages visited, timestamps, API call logs, and error reports.

Business Data (KYB)

Company registration details, UBO information, beneficial ownership documents, and business licences for KYB checks.

AML & Compliance Data

Sanctions screening results, PEP status, adverse media checks, and risk scores generated during compliance workflows.

Communication Data

Messages and records from support requests, sales conversations, and any other direct communications with us.

Biometric data is treated as Special Category Data under GDPR Article 9 and receives the highest level of protection. We process biometric data only with explicit consent or where required by law.

04

How We Use Your Data

We use personal data only for the purposes described below and only to the extent necessary for those purposes:

Purpose Description
Identity VerificationVerifying the identity of end users on behalf of our business clients via document checks, biometric matching, and liveness detection.
Fraud Detection & PreventionAnalysing patterns and signals to detect fraudulent documents, synthetic identities, and suspicious activity in real time.
KYC/KYB ComplianceSupporting regulated enterprises in meeting their legal obligations under AML, KYC, and KYB regulations across global jurisdictions.
Service ProvisionDelivering, maintaining, and improving the Pixl platform, APIs, and dashboard for our business clients.
Platform SecurityMonitoring for abuse, security threats, and technical issues to maintain platform integrity and uptime.
Analytics & ImprovementAggregated, anonymised analysis of service usage to improve accuracy, performance, and user experience.
Legal ObligationsComplying with applicable laws, regulations, court orders, and regulatory requests.
Business CommunicationsResponding to enquiries, providing customer support, and sending service-related notifications.

We do not sell your personal data to third parties. We do not use personal data for automated decision-making that produces legal or similarly significant effects without human oversight.

06

Data Sharing & Disclosure

We do not sell, rent, or trade your personal data. We may share data with the following categories of recipients under strict contractual obligations:

  • Business Clients (Data Controllers): Verification results and associated data are shared with the business client that initiated the verification request.
  • Technology Sub-Processors: Trusted cloud infrastructure providers who process data solely on our instructions and under Data Processing Agreements (DPAs).
  • Regulatory & Law Enforcement Authorities: Where we are legally compelled to disclose data by applicable law, court order, or regulatory mandate.
  • Professional Advisors: Lawyers, auditors, and accountants bound by confidentiality obligations.
  • Business Transfers: In a merger, acquisition, or sale of assets, data may be transferred to the acquiring entity subject to the same protections.

All sub-processors are contractually bound to process data only as directed by Pixl and maintain security standards equivalent to or exceeding our own. A full list is available on request to privacy@pixl.ai.

07

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal or regulatory requirements.

Data Category Retention Period Reason
Identity & document dataTypically 1-7 years (per client contract)Regulatory AML/KYC requirements
Biometric data (facial images)Deleted within 90 days of verificationMinimisation - special category data
API & audit logs13 monthsSecurity monitoring & incident response
Usage & analytics dataUp to 26 monthsProduct improvement
Contact / enquiry data3 years from last interactionBusiness relationship management

When data reaches its retention limit, it is permanently deleted or anonymised so it can no longer be linked to an individual.

08

International Data Transfers

Pixl is headquartered in India and operates globally. Personal data may be transferred to and processed in countries outside your country of residence, including India, the EEA, the United Kingdom, and the United States.

When transferring personal data across borders, we ensure adequate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to countries without an adequacy decision.
  • UK International Data Transfer Agreements (IDTAs) for transfers from the United Kingdom.
  • Adequacy Decisions issued by the European Commission or the UK Secretary of State where applicable.
  • Compliance with India's Digital Personal Data Protection Act, 2023 (DPDPA) for processing personal data of Indian residents.
09

Your Privacy Rights

Depending on your jurisdiction, you may have some or all of the following rights. Contact us at privacy@pixl.ai to exercise them.

Right to Access

Request a copy of the personal data we hold about you and information on how it is used.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data where there is no compelling reason for continued processing.

Right to Restrict

Request that we limit how we use your data in certain circumstances.

Data Portability

Receive your data in a structured, machine-readable format and transfer it to another service.

Right to Object

Object to processing based on legitimate interests or for direct marketing purposes at any time.

Withdraw Consent

Withdraw previously given consent at any time without affecting the lawfulness of prior processing.

Lodge a Complaint

Lodge a complaint with your local data protection authority if you believe we have mishandled your data.

We will respond to all legitimate requests within 30 days. We may need to verify your identity before processing your request.

If you are an end user verified through one of our business clients, please direct your request to that client in the first instance, as they are the Data Controller.

10

Security

Pixl is ISO 27001:2022 certified and implements a comprehensive Information Security Management System (ISMS). Our technical and organisational security measures include:

  • AES-256 encryption for data at rest; TLS 1.2+ for all data in transit.
  • Role-based access control (RBAC) and multi-factor authentication (MFA) for all internal systems.
  • Continuous security monitoring, intrusion detection, and automated threat response.
  • Regular penetration testing and independent third-party security audits.
  • Strict data minimisation - we collect only what is necessary for the stated purpose.
  • Employee security training and background checks for personnel with access to sensitive data.
  • Documented incident response and breach notification procedures aligned with GDPR Article 33.

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by applicable law.

11

Cookies & Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience and analyse site usage. Cookies are small text files stored on your device.

Cookie Type Purpose Duration
Strictly NecessaryEssential for the website to function. Enable navigation, security checks, and access to secure areas.Session
FunctionalRemember your preferences such as cookie consent choices and language settings.Up to 1 year
AnalyticsCollect anonymised data on how visitors use our website to help us improve its performance.Up to 2 years
MarketingDeliver relevant advertisements and track the effectiveness of our campaigns. Only set with your consent.Up to 1 year

You can manage your cookie preferences at any time using our Cookie Settings panel accessible from the cookie icon on this page.

12

Children's Privacy

Pixl's Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take immediate steps to delete that information.

If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately at privacy@pixl.ai.

Where our business clients use our platform for age verification purposes, the collection of data from minors is governed by the business client's own legal basis and consent framework.

13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will:

  • Update the Last Updated date at the top of this page.
  • Notify active business clients via email or in-dashboard notification at least 30 days before the changes take effect.
  • Where required by law, seek renewed consent for any new processing activities.

Your continued use of our Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

14

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please reach out. We are committed to resolving any privacy concerns promptly and transparently.

Data Privacy Team

For privacy-specific enquiries, data subject requests, and DPA matters:

privacy@pixl.ai

Registered Office

Unit No. III A-2, 3rd Floor, Phase II, Carnival Infopark,

Kakkanad, Kochi - 682 042, Kerala, India

+91 79944 31839  ·  connect@pixl.ai

You also have the right to lodge a complaint with your local supervisory authority. In India, this is the Data Protection Board of India. In the EU/EEA, this is your national Data Protection Authority (DPA).