Legal
Privacy Policy
Last Updated: 20 August 2026
This policy explains how HELPAYMENTS LTD, trading as VerifyDirector, handles personal data when you visit verifydirectors.com, purchase a service, submit identity evidence, or communicate with us.
1. Controller and Contact Details
HELPAYMENTS LTD, trading as VerifyDirector, is the controller for the personal data we use to provide our ACSP identity- verification service, meet our legal obligations, manage orders, and operate the website.
Registered office: Initial Business Centre, Unit 7, Wilson Business Park, Manchester, England, M40 8WN.
Anti-Money Laundering supervision registration no.: XYML00000209849.
Privacy contact: support@verifydirectors.com
2. Scope and Our Role
This policy applies to the website, checkout, application form, customer-support communications, ACSP review, identity-verification workflow, and operational records connected with the service.
If an authorised representative submits information for another person, we remain an independent controller for our ACSP, AML/KYC, fraud-prevention, security, and legal obligations because we decide why and how those checks are carried out. The representative is responsible for having authority and giving the individual this policy.
Some providers, including Companies House and Stripe in certain activities, may act as separate controllers under their own privacy notices. Other providers process data for us under service and data- protection terms.
3. Identity and Verification Data
Depending on the route and evidence, we may process:
- Full legal name, former names, date of birth, nationality, place of birth, and residential address.
- Email address, phone number, preferred language, and other contact details.
- Passport, national identity card, driving licence, eVisa, or other accepted evidence, including document images and extracted fields.
- Proof-of-address documents, translations, supporting explanations, and document-quality information.
- Selfie, facial image, liveness result, face-match result, and related verification signals where the selected route requires them.
- Companies House role and company information, including director or PSC status and information needed for the verification statement.
- Verification status, error codes, review notes, decisions, timestamps, application identifiers, and audit records.
A facial image or biometric result is special-category data where it is processed for the purpose of uniquely identifying a person. Where that applies, we use an applicable UK GDPR Article 9 condition, which may include explicit consent or substantial public interest supported by law and appropriate safeguards.
Information about suspected fraud, sanctions, or criminal conduct may be criminal-offence data. We process it only where authorised by law and with appropriate safeguards.
4. Payment, Communications, and Technical Data
- Order, package, payment status, Stripe Checkout identifiers, billing details, refunds, disputes, and transaction metadata. We do not store full payment-card numbers.
- Emails, support requests, attachments, reminders, delivery status, complaints, and other correspondence.
- IP address, browser and device information, referring page, site activity, security events, and cookie or advertising identifiers.
- Fraud, sanctions, PEP, AML/KYC, source-of-funds, or other compliance information where a check or legal obligation requires it.
Full payment-card details are entered directly into Stripe's checkout environment. We normally receive payment status and limited transaction details rather than the complete card number.
5. Sources of Personal Data
We may receive information:
- Directly from the person being verified through the website, Stripe Identity, a secure application or document-management service, email, or support communication.
- From an authorised representative, company officer, professional adviser, or person purchasing on behalf of the applicant.
- From Stripe, Companies House, public registers, fraud-prevention sources, sanctions or PEP screening sources, and other lawful compliance sources.
- Automatically from browsers, devices, security systems, and consented analytics or advertising technologies.
Where information is required to provide the service or meet a legal obligation, we will identify it as mandatory at the relevant stage. If required information is not provided, we may be unable to begin, continue, or complete the identity verification or another requested service. Information requested only for an optional purpose does not have to be provided for the core service.
6. Why We Use Personal Data
- Provide the service, review evidence, make an ACSP decision, submit the verification statement, and support Personal Code delivery issues.
- Match payments, applications, verification sessions, and customer communications.
- Comply with Companies House ACSP standards, record-keeping duties, AML/KYC, sanctions, fraud-prevention, tax, accounting, and other legal obligations.
- Communicate about an order, request missing information, send status or reminder messages, and handle complaints.
- Protect customers, staff, providers, accounts, systems, and the integrity of the Companies House register.
- Establish, exercise, or defend legal claims and respond to regulators, courts, government bodies, or law-enforcement authorities.
- Measure and improve the website and understand advertising performance, subject to applicable privacy and electronic-communications rules.
We do not sell identity documents, facial data, customer lists, or other personal data.
7. Legal Bases
- Contract — processing needed to take payment, review an application, provide the purchased service, and communicate about it.
- Legal obligation — processing required by Companies House, ACSP, AML/KYC, sanctions, fraud-prevention, tax, accounting, or other applicable law.
- Legitimate interests — operating and securing the service, preventing misuse, maintaining audit records, improving support, and managing legal claims where those interests are not overridden by individual rights.
- Consent — optional analytics, advertising measurement, marketing, or another activity where consent is the appropriate legal basis.
More than one legal basis may apply to the same record. Withdrawing consent does not require deletion of information that must be retained under another lawful basis, such as ACSP or AML record-keeping.
8. Automated Checks and Human Review
Stripe Identity may use automated technology to assess document authenticity, image quality, liveness, face matching, and fraud signals. An automated result informs our process but does not by itself constitute our final ACSP decision.
Our authorised review process considers the available evidence and may request more information or decline to make a positive verification statement. You can contact us if you believe an automated result or personal detail is incorrect.
9. Who Receives Personal Data
Access is limited to recipients who need the information for a defined service, security, compliance, legal, or regulatory purpose. Current categories include:
- Stripe — payment processing and Stripe Identity document, selfie, liveness, face-match, verification, and fraud-prevention services.
- Secure application, document-management, and business-workspace providers — application intake, access-controlled records, supporting documents, and ACSP review administration.
- Companies House — receipt and processing of the ACSP verification statement and required personal details; Companies House acts under its own legal responsibilities.
- Website hosting, security, communications, and email providers — website delivery, server-side functions, domain protection, email automation, delivery events, and operational logs.
- Analytics and advertising providers — website measurement and advertising performance where those technologies are used.
- Professional advisers, auditors, insurers, or contractors who need information for a defined service and are subject to confidentiality and data-protection obligations.
- Courts, regulators, supervisory bodies, government departments, Companies House, HMRC, the National Crime Agency, police, or other authorities where disclosure is required or permitted by law.
A provider receives only the information reasonably needed for its role. Providers may also retain information where their own law or independent-controller obligations require it.
We select providers using proportionate privacy, security, and service due diligence. Where required, we use contractual terms that limit processing to the agreed purpose, require appropriate protection, and address confidentiality, security incidents, deletion, and lawful international transfers.
10. International Processing
Some of our service providers operate internationally, so personal data may be processed outside the United Kingdom. Internet routing, provider support, hosting, identity verification, document management, and communications may involve more than one jurisdiction.
Where UK data-protection law requires a transfer safeguard, we use an applicable mechanism such as a UK adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, or another lawful safeguard. You may contact us for further information about the recipient category, destination, and safeguard relevant to a particular transfer.
11. Retention
We apply the following general retention approach:
- Companies House ACSP identity-check records and evidence: 7 years from the date the identity check is completed, unless a longer legal hold applies.
- AML/KYC and related regulated-service records: for the period required by applicable law, normally measured from completion of the check or the end of the relevant relationship.
- Payment, refund, tax, accounting, and contract records: normally up to 6 years after the relevant transaction or relationship, unless law requires longer.
- Support correspondence, application records, reminder history, and email-delivery logs: retained for as long as needed for the regulated service, complaint handling, security, audit, and legal claims, and deleted or minimised when no longer required.
- Website analytics and advertising data: retained according to provider settings, legal requirements, and the purpose for which it was collected.
Failed or incomplete checks may still need to be retained where they form part of an AML, fraud, dispute, or regulated-service record. We may retain information longer for litigation, regulatory enquiries, law-enforcement preservation, sanctions, fraud, SAR, or another legal hold. When retention ends, we delete or anonymise the information where reasonably practicable.
We may retain and use information that has been irreversibly anonymised for statistical, security, audit, and service-improvement purposes. Information is treated as anonymised only where an individual can no longer be identified by reasonably available means; genuinely anonymised information is no longer personal data.
12. Security
We use administrative, technical, and organisational safeguards appropriate to the nature of the information. These include access restriction, authenticated provider accounts, encryption in transit, provider security controls, separation of secrets from public code, operational logging, staff confidentiality, and limiting access to authorised personnel with a service or compliance need.
Identity documents retained for ACSP review are kept through a secure, access-controlled document-management service rather than a public website database. Stripe Identity handles supported passport and live-selfie capture. Operational email and automation logs do not contain full payment-card details.
No transmission or storage system can be guaranteed completely secure. If you suspect unauthorised access, contact us immediately and do not send identity documents through an unverified channel.
13. Law-Enforcement and Government Requests
We may receive requests or legal demands from UK police, the National Crime Agency, HMRC, Companies House, courts, regulators, supervisory bodies, or other public authorities. We may also be required to make a disclosure under AML or other law.
We assess requests according to the applicable legal process and may seek clarification, narrow an overbroad request, or disclose only the information lawfully required. An overseas authority would normally need to use an applicable UK, treaty, court, or mutual-assistance process unless direct disclosure is otherwise lawful and required.
Where legally permitted and not harmful to an investigation, we may notify the affected person. We will not notify where notice is prohibited by law, a court or authority requires confidentiality, or notice could prejudice an investigation.
14. SARs, Tipping Off, and Legal Holds
If we know, suspect, or have reasonable grounds to suspect money laundering, terrorist financing, or criminal property, we may be required to submit a suspicious activity report (SAR) to the National Crime Agency or make another statutory disclosure.
We may be prohibited from confirming that a SAR, Defence Against Money Laundering request, investigation, preservation request, or legal hold exists. In those circumstances, we may restrict processing or retain records without explaining the reason where an explanation would be unlawful or could prejudice an investigation.
15. Your Rights
- Access — ask whether we process your data and request a copy, subject to lawful exemptions.
- Rectification — ask us to correct inaccurate or incomplete information.
- Erasure — ask us to delete information where no legal or regulatory reason requires continued retention.
- Restriction — ask us to limit certain processing while an issue is considered.
- Objection — object to processing based on legitimate interests or to direct marketing.
- Portability — receive eligible data in a structured, commonly used, machine-readable format.
- Withdraw consent — change a consent-based marketing choice without affecting processing already carried out lawfully.
- Complain — contact us first or complain to the UK Information Commissioner’s Office.
Rights are not absolute. We may withhold or retain information where a legal exemption applies, including ACSP or AML retention, legal privilege, the rights of another person, crime prevention, taxation, regulatory functions, or avoiding prejudice to an investigation. We will explain a refusal where legally permitted.
To exercise a right, email support@verifydirectors.com. We may request proportionate information to confirm identity before disclosing or changing a record.
16. Cookies and Marketing
The website uses cookies and similar technologies for security, language, payment, application continuity, analytics, and advertising measurement. These may include third-party website analytics and advertising tools. Browser settings can block or delete cookies, although doing so may affect secure website features.
Service messages are not marketing. Where we send optional marketing, you can unsubscribe or withdraw consent without affecting the service.
17. Children
The paid identity-verification service is intended for adults aged 18 or over. We do not knowingly offer it to children. Contact us if you believe a child's information has been submitted without a lawful reason or appropriate authority.
18. Personal Data Breaches
We investigate suspected breaches, take reasonable containment and remediation steps, and notify the Information Commissioner's Office and affected individuals where UK data-protection law requires it. Notification may be delayed or limited where law enforcement or another legal restriction applies.
19. Business Reorganisation or Transfer
If HELPAYMENTS LTD is reorganised, merged, sold, or transfers all or part of the VerifyDirector business, relevant personal data may be disclosed under confidentiality during due diligence and transferred to a successor organisation for the same lawful purposes described in this policy.
Any successor must handle the information in accordance with applicable data-protection law. We will provide notice where required by law and will not use a business transfer to remove your statutory rights.
20. Changes to This Policy
We may update this policy when our service, providers, data practices, or legal obligations change. The current version and last-updated date will be published here. Material changes will be brought to attention where reasonably practicable.
21. Complaints and Contact
HELPAYMENTS LTD, trading as VerifyDirector
Initial Business Centre, Unit 7, Wilson Business Park, Manchester, England, M40 8WN
Email: support@verifydirectors.com
Please give us the opportunity to investigate a privacy complaint. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.