Legal
Overview
Pixl ("Pixl", "we", "us", or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, share, and protect information in connection with our identity verification platform, website at pixl.ai, and all associated services (collectively, the "Services").
Please read this policy carefully. By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the terms described here, please do not use our Services.
For business clients: If you are a business using Pixl's API or platform to verify your end users, you act as the Data Controller for your users' personal data. Pixl acts as the Data Processor on your behalf. Your end users' rights are governed by your own privacy policy as well as this document.
Who We Are
Pixl is an intelligent identity infrastructure company providing AI-powered identity verification, biometric authentication, KYC/KYB compliance, and fraud prevention solutions to regulated enterprises globally.
Data Controller:
- Company: Pixl (PixDynamics Pvt. Ltd.)
- Registered Address: Unit No. III A-2, 3rd Floor, Phase II, Carnival Infopark, Kakkanad, Kochi - 682 042, Kerala, India
- Privacy Email: privacy@pixl.ai
- General Contact: connect@pixl.ai
- Phone: +91 79944 31839
Data We Collect
Depending on how you interact with our Services - whether as a website visitor, API integration partner, or an end user being verified - we may collect the following categories of data:
Identity Data
Full name, date of birth, nationality, government-issued ID numbers, and other identity attributes.
Document Data
Images of passports, national IDs, driving licences, and other identity documents submitted for verification.
Biometric Data
Facial images and liveness-check data captured during biometric verification, including facial geometry measurements.
Contact Data
Email address, phone number, and postal address collected from business clients and direct enquiries.
Usage & Technical Data
IP address, browser type, device identifiers, pages visited, timestamps, API call logs, and error reports.
Business Data (KYB)
Company registration details, UBO information, beneficial ownership documents, and business licences for KYB checks.
AML & Compliance Data
Sanctions screening results, PEP status, adverse media checks, and risk scores generated during compliance workflows.
Communication Data
Messages and records from support requests, sales conversations, and any other direct communications with us.
Biometric data is treated as Special Category Data under GDPR Article 9 and receives the highest level of protection. We process biometric data only with explicit consent or where required by law.
How We Use Your Data
We use personal data only for the purposes described below and only to the extent necessary for those purposes:
| Purpose | Description |
|---|---|
| Identity Verification | Verifying the identity of end users on behalf of our business clients via document checks, biometric matching, and liveness detection. |
| Fraud Detection & Prevention | Analysing patterns and signals to detect fraudulent documents, synthetic identities, and suspicious activity in real time. |
| KYC/KYB Compliance | Supporting regulated enterprises in meeting their legal obligations under AML, KYC, and KYB regulations across global jurisdictions. |
| Service Provision | Delivering, maintaining, and improving the Pixl platform, APIs, and dashboard for our business clients. |
| Platform Security | Monitoring for abuse, security threats, and technical issues to maintain platform integrity and uptime. |
| Analytics & Improvement | Aggregated, anonymised analysis of service usage to improve accuracy, performance, and user experience. |
| Legal Obligations | Complying with applicable laws, regulations, court orders, and regulatory requests. |
| Business Communications | Responding to enquiries, providing customer support, and sending service-related notifications. |
We do not sell your personal data to third parties. We do not use personal data for automated decision-making that produces legal or similarly significant effects without human oversight.
Legal Basis for Processing
Where GDPR or equivalent legislation applies, we rely on the following legal bases for processing your personal data:
- Contract Performance (Art. 6(1)(b) GDPR): Processing necessary to fulfil our contractual obligations to business clients and their end users.
- Legal Obligation (Art. 6(1)(c) GDPR): Processing required to comply with applicable laws and regulatory requirements, including AML and KYC obligations.
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing necessary for fraud prevention, platform security, and service improvement, balanced against data subject rights.
- Explicit Consent (Art. 6(1)(a) & Art. 9(2)(a) GDPR): For biometric and special category data, and for optional communications such as marketing newsletters.
- Vital Interests / Public Task: In exceptional circumstances where processing is necessary to protect a person's vital interests or assist law enforcement.
For users in California, we comply with the CCPA and its amendment, the CPRA. We do not sell or share personal information as defined under the CCPA.
Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We may share data with the following categories of recipients under strict contractual obligations:
- Business Clients (Data Controllers): Verification results and associated data are shared with the business client that initiated the verification request.
- Technology Sub-Processors: Trusted cloud infrastructure providers who process data solely on our instructions and under Data Processing Agreements (DPAs).
- Regulatory & Law Enforcement Authorities: Where we are legally compelled to disclose data by applicable law, court order, or regulatory mandate.
- Professional Advisors: Lawyers, auditors, and accountants bound by confidentiality obligations.
- Business Transfers: In a merger, acquisition, or sale of assets, data may be transferred to the acquiring entity subject to the same protections.
All sub-processors are contractually bound to process data only as directed by Pixl and maintain security standards equivalent to or exceeding our own. A full list is available on request to privacy@pixl.ai.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal or regulatory requirements.
| Data Category | Retention Period | Reason |
|---|---|---|
| Identity & document data | Typically 1-7 years (per client contract) | Regulatory AML/KYC requirements |
| Biometric data (facial images) | Deleted within 90 days of verification | Minimisation - special category data |
| API & audit logs | 13 months | Security monitoring & incident response |
| Usage & analytics data | Up to 26 months | Product improvement |
| Contact / enquiry data | 3 years from last interaction | Business relationship management |
When data reaches its retention limit, it is permanently deleted or anonymised so it can no longer be linked to an individual.
International Data Transfers
Pixl is headquartered in India and operates globally. Personal data may be transferred to and processed in countries outside your country of residence, including India, the EEA, the United Kingdom, and the United States.
When transferring personal data across borders, we ensure adequate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to countries without an adequacy decision.
- UK International Data Transfer Agreements (IDTAs) for transfers from the United Kingdom.
- Adequacy Decisions issued by the European Commission or the UK Secretary of State where applicable.
- Compliance with India's Digital Personal Data Protection Act, 2023 (DPDPA) for processing personal data of Indian residents.
Your Privacy Rights
Depending on your jurisdiction, you may have some or all of the following rights. Contact us at privacy@pixl.ai to exercise them.
Request a copy of the personal data we hold about you and information on how it is used.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data where there is no compelling reason for continued processing.
Request that we limit how we use your data in certain circumstances.
Receive your data in a structured, machine-readable format and transfer it to another service.
Object to processing based on legitimate interests or for direct marketing purposes at any time.
Withdraw previously given consent at any time without affecting the lawfulness of prior processing.
Lodge a complaint with your local data protection authority if you believe we have mishandled your data.
We will respond to all legitimate requests within 30 days. We may need to verify your identity before processing your request.
If you are an end user verified through one of our business clients, please direct your request to that client in the first instance, as they are the Data Controller.
Security
Pixl is ISO 27001:2022 certified and implements a comprehensive Information Security Management System (ISMS). Our technical and organisational security measures include:
- AES-256 encryption for data at rest; TLS 1.2+ for all data in transit.
- Role-based access control (RBAC) and multi-factor authentication (MFA) for all internal systems.
- Continuous security monitoring, intrusion detection, and automated threat response.
- Regular penetration testing and independent third-party security audits.
- Strict data minimisation - we collect only what is necessary for the stated purpose.
- Employee security training and background checks for personnel with access to sensitive data.
- Documented incident response and breach notification procedures aligned with GDPR Article 33.
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by applicable law.
Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience and analyse site usage. Cookies are small text files stored on your device.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Essential for the website to function. Enable navigation, security checks, and access to secure areas. | Session |
| Functional | Remember your preferences such as cookie consent choices and language settings. | Up to 1 year |
| Analytics | Collect anonymised data on how visitors use our website to help us improve its performance. | Up to 2 years |
| Marketing | Deliver relevant advertisements and track the effectiveness of our campaigns. Only set with your consent. | Up to 1 year |
You can manage your cookie preferences at any time using our Cookie Settings panel accessible from the cookie icon on this page.
Children's Privacy
Pixl's Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take immediate steps to delete that information.
If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately at privacy@pixl.ai.
Where our business clients use our platform for age verification purposes, the collection of data from minors is governed by the business client's own legal basis and consent framework.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will:
- Update the Last Updated date at the top of this page.
- Notify active business clients via email or in-dashboard notification at least 30 days before the changes take effect.
- Where required by law, seek renewed consent for any new processing activities.
Your continued use of our Services after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please reach out. We are committed to resolving any privacy concerns promptly and transparently.
Data Privacy Team
For privacy-specific enquiries, data subject requests, and DPA matters:
privacy@pixl.aiRegistered Office
Unit No. III A-2, 3rd Floor, Phase II, Carnival Infopark,
Kakkanad, Kochi - 682 042, Kerala, India
You also have the right to lodge a complaint with your local supervisory authority. In India, this is the Data Protection Board of India. In the EU/EEA, this is your national Data Protection Authority (DPA).