Identity Verification Privacy Notice
This notice explains identity verification in 2Help using Didit. It applies when you start that verification, including within the mobile app, and supplements the 2Help Privacy Policy.
Before you begin: verification involves an identity document and a selfie or liveness capture. Facial analysis may create biometric information. Didit processes the verification materials; 2Help keeps a limited verification record, not copies of your document or biometric templates. Our retention period for verification materials is up to one year, subject to the earlier-deletion rules in Section 8.
1. Who is responsible
2HELP, INC., 262 Chapman Road, Ste 240, Newark, DE 19702, US, is the controller or business responsible for deciding why verification is offered in 2Help and how its result affects your account. Contact us at support@2help.app.
Didit supplies the verification technology as our processor or service provider. Its service is provided by Didit Identity, Inc. and/or Didit Identity Spain, S.L., as applicable. Didit also identifies limited processing for which it acts independently; see Section 6. Our responsibilities for your 2Help account are not transferred to Didit.
2. Why verification is used
2Help connects people who request or offer help, for free or for payment. Identity verification helps us associate a genuine verification result with the right account and reduce impersonation. We use the outcome to maintain verification status, investigate errors or suspected misuse, and respond to support or privacy requests.
A verified status means that the required checks were confirmed for a particular attempt. It is not a criminal-record check, professional qualification, financial assessment, endorsement, or guarantee of another person's conduct or safety. Continue to follow the Safety Center guidance.
3. Information used in the verification
Materials processed by Didit
The flow uses the document and capture steps presented to you. These can include:
- Identity-document information: document images and extracted information such as your name, date of birth, document number, issuing country, expiry date, photograph, and other fields present on the submitted document.
- Selfie and liveness information: photographs or video captures, facial characteristics, comparison results, and signals used to assess whether a live person is present and matches the document photograph.
- Session information: IP address, device and browser details, language, timestamps, capture events, consent records, and information used to protect the verification session.
Facial characteristics processed to identify you can be biometric identifiers, biometric information, or special-category personal data under applicable law. An ordinary photograph and a derived facial template are not necessarily treated the same way by every law.
Information exchanged with 2Help
To start an attempt, 2Help sends a non-readable account reference, an attempt identifier, the selected verification workflow, and, where supplied, your language. The session-creation request does not include your registration email address or telephone number. Didit can still receive information you submit in its flow and technical information directly from your device.
Our server obtains the provider's response, validates it, and keeps only the account linkage, service and attempt identifiers, status, document/liveness/face-match pass results, relevant dates, limited failure information, and an audit trail. The verification database does not retain raw provider responses, document copies, extracted identity attributes, selfies, liveness video, biometric templates, or comparison scores.
Authorized 2Help support and safety personnel can access a limited verification history when needed for their role. This is separate from any tightly controlled access to records held in the provider's service. Do not send identity documents, selfies, verification links, or one-time codes through public posts, ordinary chat, or email support.
4. Your choices, consent, and legal bases
You can leave the verification flow before submitting the requested materials. Without successful verification, you will not receive the corresponding verified status. If a particular feature requires verification, you may be unable to use that feature; any such requirement must be explained in the relevant flow. Contact support if you cannot complete the process or need an accessible alternative. An alternative method is not guaranteed to be available.
Where the GDPR, UK GDPR, or a similar law applies, ordinary session and result information is processed to provide the verification you request and, where applicable, for our legitimate interests in account integrity, fraud prevention, and resolving disputes, subject to your rights. A legal obligation is relied on only where an applicable requirement actually exists; this notice does not assert that all 2Help users must undergo a statutory KYC check.
For biometric identification covered by Article 9 of the GDPR or UK GDPR, explicit consent is normally the applicable special-category condition, in addition to an Article 6 basis. Where another biometric privacy law requires prior written or electronic consent, that consent must be obtained before capture or collection. Reading this notice, accepting general terms, or granting camera permission is not, by itself, that consent.
You may withdraw consent by contacting support@2help.app. Withdrawal does not invalidate earlier lawful processing. We will stop processing that depends on the withdrawn consent and assess deletion and any independently justified retention. Verification status or a feature dependent on it may no longer be available.
5. Automated checks and disputed results
Document checks assess the submitted document; liveness checks look for a real person rather than a replay or artificial capture; facial comparison assesses whether the captured face matches the document photograph. The technology can make mistakes, including when lighting, image quality, accessibility needs, or document characteristics affect a capture.
2Help accepts verified status only after its server confirms the provider result and the required document, liveness, and face-match checks have passed. Missing evidence, incomplete checks, or a rejected attempt do not establish verified status. A session may require another submission or review.
If you believe a result is incorrect, contact support@2help.app to request human review, explain your circumstances, and contest the result. Where applicable law restricts decisions made solely by automated means that have legal or similarly significant effects, you retain those protections, including applicable rights to human intervention and to express your view.
6. Didit's separate processing and your choices
Didit's Privacy Policy describes independent processing for security, abuse prevention, legal compliance, audit and legal claims. It also describes the use of anonymized or pseudonymized verification-derived data for improving verification and fraud models and for cross-customer fraud prevention, where lawful. Pseudonymized data is not necessarily anonymous.
Didit offers an opt-out from that model-improvement and fraud-processing use through privacy@didit.me. You can ask 2Help to help identify the relevant session and submit the request. Didit describes the opt-out as prospective, with reasonable efforts to remove eligible records from active training datasets; it is not a promise to reverse an already trained model.
This disclosure is not blanket consent to additional processing. Any purpose requiring separate consent or another legal condition must satisfy that requirement. Our own verification integration does not place identity documents or biometric evidence into 2Help matching, marketing analytics, or general-purpose AI prompts.
8. Retention and destruction
Verification materials: up to one year
Our retention period for identity-document images and extracted information, selfies, liveness recordings, and associated biometric verification materials held for 2Help by Didit is no longer than one year after the verification attempt is completed. For an abandoned, cancelled, or incomplete attempt, the period runs from the last activity in that attempt. Each attempt has its own period; starting another attempt does not restart the period for older materials.
This is a maximum, not a minimum. Materials must be removed sooner when the collection purpose has ended and no lawful ground remains, when a valid erasure or consent-withdrawal request requires it, or when a shorter statutory period applies. Completing a check or closing the app does not itself perform deletion. We instruct the provider to implement the applicable retention and destruction requirements.
Limited records held by 2Help
We keep the minimal status and audit record described in Section 3 while needed to maintain an accurate account status, address a disputed result, or protect account integrity. Its duration is determined by account status, the continuing relevance of the result, unresolved complaints, and applicable recordkeeping or claims requirements. This limited record is distinct from the underlying document and biometric materials and does not extend their one-year maximum.
Biometric destruction rules
Where the Illinois Biometric Information Privacy Act applies, biometric identifiers and biometric information must be permanently destroyed when their initial collection purpose is satisfied or within three years of your last interaction with the responsible entity, whichever is earlier. Our shorter one-year maximum also applies. A valid court warrant or subpoena is handled as that law requires; a general desire to retain records does not override the destruction rule.
Any separately retained biometric template remains subject to the same applicable maximum and earlier-deletion rules, even if a provider's ordinary session-deletion operation does not remove it. A privacy-erasure request must address all attributable biometric data within its scope, not only the visible session. Deletion is not described as complete until the required provider action is confirmed. Any legally compelled preservation is limited to the information and period actually required and is not used as authority for unrelated processing.
9. Privacy requests and account deletion
To request access, correction, erasure, restriction, portability where applicable, consent withdrawal, or an objection to processing, email support@2help.app with the subject “Identity verification privacy request.” Identify your 2Help account and, if known, the approximate date of the attempt. Do not attach an identity document or selfie. We may verify the requester's identity proportionately and will explain any lawful exception or available appeal.
Uninstalling 2Help does not delete your account. Deleting a local account record is also not confirmation of provider-side erasure. We assess verification-data requests separately and coordinate the required action with Didit. You may ask us to include the provider-held materials in an account-deletion request without repeating your verification captures.
For processing that Didit controls independently, you may also contact privacy@didit.me or dpo@didit.me. Rights and response deadlines depend on applicable law. You may complain to your local data-protection or consumer-protection authority and exercise rights without unlawful discrimination.
10. Security and international processing
Access to 2Help verification records is restricted by role. We minimize retained information and use protected server-to-server communications. Didit describes encryption for data in transit and at rest and access controls for verification materials in its security documentation. These safeguards reduce risk but cannot guarantee absolute security.
Verification information may be processed outside your country, including in the European Union and the United States, depending on the service and provider arrangements. Where a transfer requires safeguards, these may include an adequacy decision, the European Commission's Standard Contractual Clauses with the relevant UK or Swiss provisions, and supplementary protections as needed. Contact support for information about the arrangements applicable to your data.
11. Age requirement and changes
2Help is intended for adults aged 18 or older. Do not submit a child's identity documents or captures for a 2Help account. Contact support if information has been submitted without proper authorization.
We may revise this notice when the verification process or applicable requirements change. The date above identifies this version. Material changes will be communicated and any newly required consent obtained before the relevant processing.
12. Contact and related notices
2HELP, INC. — Privacy
262 Chapman Road, Ste 240
Newark, DE 19702, US