Trustform Wallet Privacy Notice
Effective 11.09.2026
This Privacy Notice explains how Trustform handles personal data when you use Trustform Wallet on the web or mobile, including identity verification, Partner Sign-In, organisation profiles, certifications and verifiable credentials.
In short
• You control what you put in your Wallet and what you choose to share.
• We use trusted service providers to run parts of the Wallet, including electronic identity verification and verifiable-credential infrastructure.
• We do not sell your personal data or use Wallet Content for third-party behavioural advertising.
• We do not use Wallet Content to train general-purpose AI models.
• You have rights under the UK GDPR, the Data Protection Act 2018 and, where applicable, the EU GDPR
Who we are
Trustform UK Ltd, company number 16485941, of Fourth Floor, 11 Berkeley Street, London, England, W1J 8DS, operates Trustform Wallet. For UK users, Trustform UK Ltd is the controller of personal data processed for the Wallet relationship unless this Notice or a separate enterprise arrangement says otherwise.
Where another Trustform entity is identified as the controller for your location or service, that entity is responsible for the processing it carries out.
You can contact us at privacy@trustform.io or our Data Protection Officer at dpo@trustform.io.
This Notice covers individual Wallet users, users invited to organisation or enterprise Wallets, people whose information is entered into a Wallet by an organisation, Certifiers where Trustform processes their account and vetting information, and people who receive or verify shared Wallet information.
When another organisation is responsible
If an organisation enters personal data about its directors, shareholders, beneficial owners, officers, employees or other people, that organisation normally decides why that information is used and is responsible for its own lawful basis and privacy information. Trustform processes that information to provide and secure the Wallet and, where applicable, as a processor on the organisation’s instructions.
If Wallet information is shared into a regulated institution’s compliance workflow, that institution may become the controller of the copy it receives and Trustform may act as its processor under a separate agreement. A Certifier is responsible for the professional certification decision they make, and a recipient is responsible for what it lawfully does with information it receives.
2. What personal data we use
Depending on how you use the Wallet, we may process:
• account and contact information, such as your name, email, telephone number, country, organisation, role and preferences;
• authentication and security data, including session identifiers, IP address, login history, device information and security events;
• identity and verification data, such as identity-document details and images, date of birth, nationality, address, verification results, and where electronic identity verification is used, facial images, liveness signals and biometric data;
• Wallet and organisation profile data, including documents you upload, structured profile fields, company details, ownership and control relationships, directors, officers and signatories;
• automated extraction data, including information proposed from uploaded documents using OCR or AI-assisted extraction and your confirmations or corrections;
• certification and credential data, including certification requests, supporting documents, Certifier details, certification statements, verifiable credentials, cryptographic proofs and related sharing or verification events;
• sharing and activity data, including what you shared, with whom, when, and the access settings you selected;
• Partner Sign-In data. If you use a branded sign-in option such as “Log in with Investors Europe”, we receive the authentication identifiers and identity claims needed to authenticate you and connect you to the correct Wallet; and
• technical, support and billing information, including app/browser/device information, diagnostics, support messages, invoices and payment tokens where relevant.
3. Why we use personal data
We use personal data only where we have a lawful basis. Depending on the activity, this may be because it is necessary to perform our contract with you, because we have a legitimate interest in operating and securing the Wallet, because we must comply with a legal obligation, or because you have given consent.
We use personal data to:
• provide and operate Wallet accounts, profiles, sharing, certification and credential features;
• authenticate users, including Partner Sign-In, secure accounts, prevent misuse and investigate security events;
• perform electronic identity verification;
• read documents and produce extraction or profile suggestions for your review;
• facilitate certification and create, hold, present, verify and delete verifiable credentials;
• keep security, audit and transaction records;
• comply with law, sanctions, court orders and regulatory requests;
• support, maintain, test and improve the Service;
• manage billing, accounting and tax; and
• send marketing where permitted by law. You can opt out at any time.
Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests, you may object and we will consider your objection against the reasons for the processing and the rights of others.
Identity verification and biometric data
The Wallet may offer electronic identity verification through a third-party eIDV provider that processes information on our behalf as a subprocessor. The provider may receive identity-document data and images, facial images or short video, liveness information, device signals and the verification result.
Where biometric data is processed to uniquely identify or verify you, it is special-category data. Where explicit consent is the applicable legal condition, we ask for that consent separately at the verification step. Accepting the Wallet Terms does not itself constitute biometric consent. You may withdraw consent, although this does not make processing already carried out unlawful.
Documents you choose to store may sometimes contain other sensitive information. We process this only as necessary to provide the feature you selected, comply with law or protect legal rights, and we apply safeguards required by applicable data-protection law.
5. Partner Sign-In
Trustform Wallet supports partner-branded authentication on both web and mobile. For example, eligible users may see “Log in with Investors Europe”. If you choose that option, the partner or its authentication infrastructure provides Trustform with the authentication result and identity claims needed to identify you, match you to the correct account or Wallet, and maintain secure access.
The partner may process personal data for its own authentication, customer or regulatory purposes under its own privacy notice. Trustform processes the information it receives to authenticate you and provide the Wallet.
Using Partner Sign-In does not by itself give the partner access to the contents of your Wallet. Wallet Content is shared with a partner only where you instruct us to share it, where the relevant organisation controls the enterprise workspace, where a separate enterprise arrangement requires the processing, or where law requires it.
6. Verifiable credentials and SSI infrastructure
A verifiable credential is a digital, machine-readable credential containing claims made by an issuer and protected by cryptographic proof so that its origin and integrity can be checked.
Trustform uses a third-party API and self-sovereign identity infrastructure provider as a subprocessor to support the creation, signing, storage, presentation, verification and deletion of credential resources.
Credentials stored through the Wallet may be deleted where the Service provides that functionality. Deleting a credential from your Wallet or from infrastructure we control does not delete a copy you previously shared, exported or otherwise provided to another person. That recipient is responsible for its own copy and any lawful retention of it.
Where a credential needs correcting, the usual approach is to issue a corrected credential rather than alter the cryptographically signed credential already issued. We do not describe credential revocation as a standard Wallet capability unless the relevant credential type or feature expressly provides it.
7. Automated processing and AI
We use automation to read documents, propose structured fields, support identity verification, and assist with organisation and ownership information. Unless we tell you otherwise in a specific feature, these tools produce information or suggestions for review and do not make a solely automated decision that produces legal effects or similarly significant effects on you.
We do not use Wallet Content to train or fine-tune general-purpose or foundation AI models, and we do not give Wallet Content to a model provider for that provider’s own training. We may use aggregated or de-identified information to improve extraction, classification, security and service quality.
8. Who we share personal data with
We disclose personal data only where necessary for the purposes described in this Notice. This may include:
• our eIDV provider, credential/SSI infrastructure provider, hosting, backup, communications, support, security, monitoring, analytics and payment service providers acting as processors or subprocessors;
• Certifiers you select and other professionals involved in a certification request;
• organisations or recipients you choose to share Wallet Content with;
• your organisation or enterprise administrator where you use a Business Wallet;
• partner identity or authentication providers where you use Partner Sign-In;
• regulators, courts, law-enforcement authorities and other public bodies where disclosure is required or permitted by law; and
• professional advisers, auditors, insurers, prospective buyers or investors where reasonably necessary and subject to confidentiality safeguards.
We do not sell personal data and we do not disclose Wallet Content for third-party behavioural advertising.
9. International transfers
Some service providers or support teams may process personal data outside the United Kingdom or the European Economic Area. Where a restricted transfer occurs, we use an appropriate lawful transfer mechanism, such as an applicable adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses. We use supplementary safeguards where appropriate.
You can contact privacy@trustform.io for information about safeguards used for a particular transfer.
10. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Wallet, maintain security and auditability, meet legal and accounting requirements, handle disputes and establish or defend legal claims.
In general:
• account, profile and Wallet Content is kept while the relevant account or Wallet is active, followed by a limited closure/export period and deletion or de-identification unless a legal or security reason requires longer retention;
• identity-verification evidence and biometric data is kept only for the period necessary for verification, fraud prevention, dispute handling and legal compliance;
• credentials are kept while held in the Wallet or until you delete them, subject to backup cycles and any lawfully retained audit or security metadata;
• audit, security and sharing records are kept for as long as reasonably necessary for security, integrity, accountability and evidence of relevant events; and
• billing, accounting, support and complaint records are kept for the periods required for those purposes and applicable law.
11. Security
We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include encryption, access controls, authentication controls, logging, monitoring, backup and incident-response procedures. No online service can guarantee absolute security.
12. Your privacy rights
Depending on the law that applies to you, you may have the right to access your personal data, correct inaccurate or incomplete data, request deletion, restrict processing, object to certain processing, receive certain data in a portable format, withdraw consent where processing is based on consent, and raise a concern about certain automated decisions where applicable.
To exercise a right, contact privacy@trustform.io. We may need to verify your identity. We normally respond within the period required by applicable law. Where the data is controlled by an organisation using the Wallet or by a receiving institution, we may direct or forward your request to that controller and will assist where required.
If you are in the United Kingdom, you may complain to the Information Commissioner. If the EU GDPR applies, you may complain to the supervisory authority in the EEA country where you live, work or consider the infringement occurred.
13. Children, marketing and tracking technologies
The Wallet is intended for adults and is not directed at children. We do not knowingly provide the Wallet to anyone under the minimum age stated in the Terms.
You can opt out of marketing communications at any time using the unsubscribe control in the message or by contacting us. Service and security messages are not marketing and may still be sent where necessary to operate your account.
Web and mobile versions of the Wallet may use cookies, local storage, SDKs or similar technologies for security, authentication, preferences, diagnostics and analytics. Where the Privacy and Electronic Communications Regulations 2003 or another applicable law requires consent for a non-essential technology, we request it before using that technology. Further detail may be provided in our Cookie & Tracker Notice or in-app privacy controls.
14. Legal framework
For UK processing, this Notice is intended to support compliance with the UK General Data Protection Regulation, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and the Data (Use and Access) Act 2025 as it amends the UK data-protection and privacy framework. Where the EU GDPR applies, we also apply its corresponding transparency, lawful-basis, rights, security and international-transfer requirements.
Mandatory rights under the law that applies to you are not reduced by this Notice.
15. Changes and contact
We may update this Notice when the Wallet, our providers or applicable law changes. We will post the updated version and, where a change materially affects how we use personal data, provide appropriate notice through the Service or by email.
Privacy enquiries and rights requests: privacy@trustform.io
Data Protection Officer: dpo@trustform.io
Trustform UK Ltd
Fourth Floor, 11 Berkeley Street
London, England W1J 8DS
United Kingdom