01Who controls your information
IDENT GROUP LTD, trading as Ident.ink, is the controller when it decides why and how personal information is used to operate Ident.ink.
- Controller
- IDENT GROUP LTD
- Address
- 80 Castleway SouthWirralUnited KingdomCH46 1PB
- Privacy contact
- privacy@ident.ink
- General contact
- outreach@identgroup.ink or Ident.ink Support
- Company registration
- 17390459, England and Wales
- Company site
- identgroup.ltd
No Data Protection Officer is claimed by this notice. Privacy enquiries are handled through the privacy contact unless a formally appointed DPO is later identified in the Imprint.
02Scope and our different roles
This notice applies to Ident.ink websites, accounts, configurable organisation workspaces, professional profiles, Business Chat, studios, hosting, bots, databases, developer services, support, recruitment and related communications.
Ident.ink is normally the controller for account administration, billing, security, support and its own service analytics. When an organisation places personal information about its staff, customers, players or contacts into a private workspace and determines the purpose, that organisation is normally the controller and Ident.ink acts as its processor. The organisation must give its own notice and have a lawful basis. Its instructions and the applicable data-processing terms govern that processing.
Public content is public by design. Private, team-only and account-only content is handled according to the visibility and permission controls selected by the user, subject to security, moderation and law.
03What we use and why
The schedule below is the core processing record for ordinary platform use. More than one lawful basis may apply when separate purposes are involved. We do not change basis retrospectively merely because another basis would be convenient.
| Purpose and information | Lawful basis | Retention and recipients |
|---|---|---|
| Accounts and requested servicesName, email, verified status, identifiers, settings, profile, projects, teams and service content. | Contract. Steps requested before entering a contract. | Retention For the account or service lifetime, then deletion or anonymisation subject to the periods and exceptions below.Recipients Infrastructure and communications providers; people you deliberately share with. |
| Authentication and account securityPassword hashes, passkey public credentials, MFA configuration, sessions, device and browser details, login history, request-security events and hashed network indicators. Security events record bounded metadata and evidence hashes rather than request bodies, passwords or complete tokens. | Contract and our legitimate interests in protecting accounts, users and infrastructure. | Retention Challenges expire after their stated short lifetime. Expired challenge records are cleaned after 24 hours. Security evidence is reviewed and kept only while proportionate to the threat or claim.Recipients Security and infrastructure providers; authorities where lawfully required. |
| Automated abuse and bot preventionreCAPTCHA response, interaction and risk signals, browser and device information, and network information observed by Google when the challenge loads. | Our legitimate interests in preventing automated account abuse, credential attacks, spam, fraudulent submissions and infrastructure misuse. | Retention Ident.ink uses the short-lived verification response only to decide whether the protected request may continue. Google controls its own processing and retention under its published terms and privacy policy.Recipients Google reCAPTCHA. The challenge is loaded only on protected submission flows. |
| Publishing, Network and Business ChatProfile, posts, connections, memberships, messages, reports, creator video metadata, chosen media-provider references, moderation decisions, daily audience totals and short-lived pseudonymous view receipts. Ident.ink does not receive Creator Network video files. For signed-out viewing, the service derives a keyed pseudonym from observed network and browser information; it does not store the raw address in the view receipt. | Contract. Legitimate interests for abuse prevention and service integrity. | Retention Content remains until deleted by the user, account closure, expiry selected for ephemeral content, or a justified moderation or legal hold. Creator view receipts are removed after eight days; compact daily totals and necessary moderation evidence may remain longer for audience integrity, settlements and disputes.Recipients Chosen recipients, workspace members or the public according to the visibility selected. Mux, Bunny Stream or the creator's own host receives video only when deliberately selected by the creator. |
| Subscriptions, Market verification, store orders, payments, payouts and payroll instructionsPlan, customer, subscription, invoice, Market assessment, Identity Verification Session and Connect account identifiers and statuses, store, product, order quantity, customer email, transaction status, card brand and last four digits. Stripe retains identity evidence, checkout billing and shipping details under its own notice; Ident.ink does not store identity-document copies, verified identity outputs, complete card numbers or complete bank details. | Contract; legal obligations for tax, accounting and fraud controls; legitimate interests in debt and abuse prevention. | Retention For the relationship and the applicable accounting, tax, chargeback, fraud and legal-claims periods.Recipients Stripe, financial institutions, payout recipients, authorised Market reviewers, professional advisers and authorities where required. |
| Support, complaints and legal requestsContact details, correspondence, attachments, account context, investigation evidence and outcomes. | Contract, legal obligation and legitimate interests in resolving disputes, protecting rights and demonstrating accountability. | Retention For the case lifecycle and then for the period reasonably required for complaints, limitation, regulatory or legal-claims purposes.Recipients Support personnel, relevant providers, advisers, regulators, courts and authorities where necessary. |
| Reliability, analytics and product improvementAccount ID, feature events, service route, timing, error type and aggregated operational measures. Product analytics do not intentionally contain message text, passwords or payment credentials. | Legitimate interests for essential reliability and security. Consent for optional browser measurement. | Retention Product events: 30 days. Operational metrics: 90 days. Aggregated or genuinely anonymous statistics may be kept longer.Recipients Authorised operations personnel and contracted infrastructure providers. |
| Recruitment and business enquiriesIdentity, contact details, work history, submitted links, application answers and correspondence. | Steps requested before a possible contract and legitimate interests in assessing applications and maintaining recruitment records. | Retention For the application process and a proportionate period afterwards for future contact, equality monitoring where lawful, dispute handling and legal claims.Recipients Authorised hiring personnel and providers used to communicate with the applicant. |
| Business outreach and newslettersBusiness contact details, source, campaign history, engagement and suppression status. | Consent where required. Otherwise, documented legitimate interests for relevant corporate contacts, subject to PECR and the right to object. | Retention Until consent is withdrawn, the purpose ends, or an objection is received. A minimal suppression record is retained to honour the objection.Recipients Email delivery providers and authorised commercial personnel. |
Special-category and criminal-offence information: Ident.ink does not ask ordinary users to provide it as a standard account requirement. If it is included in support, workplace content or a legal report, it is restricted and processed only where an additional condition under applicable law is identified. Do not place sensitive information in public fields.
04Sources and information you must provide
We obtain information directly from you, from an organisation that invites or manages you, from people who communicate with you through the service, from connected services you authorise, from payment and identity providers, and from public sources used for a specific business or safety purpose. Where information is obtained indirectly, this notice is provided within the period required by law unless a lawful exception applies.
An email address, authentication method and essential security records are required to operate an account. Billing details are required for a paid plan. Information marked optional is not contractually required. If required information is not provided, the relevant account, payment, verification or protected feature cannot be supplied.
06OAuth, connected applications and the developer API
A third-party OAuth application cannot operate until the founder has approved its registration. Approval checks the application identity, stated purpose, redirect addresses, contact route, privacy notice and requested scopes. Approval is a security gate, not an endorsement or guarantee.
A published private workspace uses Ident.ink OAuth to confirm the account and project permission. Its portal session is held in a short-lived, HttpOnly cookie restricted to the Ident.ink API host and Workspace API path. Customer subdomains do not receive the account session or the portal credential, and they are not granted general cross-origin access to Ident.ink APIs.
The consent screen names the application and lists each scope. Data is disclosed only after the signed-in account approves those scopes. Access tokens expire after one hour, refresh tokens after 30 days, and authorisation codes after five minutes. Tokens can be revoked from connected-app controls. Passwords, browser sessions, full payment details, private messages and unrelated users’ information are not available through the public API.
Once an independent application receives information, its operator is a separate controller for its own use. Read that operator’s privacy notice and contact it to request deletion of copies already received. Revoking Ident.ink access prevents new authorised access but cannot erase data from another controller’s systems.
08Retention, deletion and legal holds
We do not retain identifiable information indefinitely merely because it may become useful. At the end of a stated period, information is deleted, anonymised or reviewed against documented necessity. The schedule in section 3 gives the ordinary periods or criteria.
Closing an account immediately removes its Creator Network videos from Ident.ink discovery, clears playback and provider references, disables encrypted provider connections and deletes short-lived view receipts. Because creator video files are uploaded directly into the creator’s own Mux, Bunny Stream or self-hosted account, closing Ident.ink cannot delete a file from infrastructure the creator independently controls. The creator remains responsible for deleting that provider copy. Necessary settlement, payout, moderation and dispute records may be retained under the periods and legal grounds stated here.
- OAuth authorisation codes expire after five minutes, access tokens after one hour and refresh tokens after 30 days unless revoked sooner.
- Product events are retained for 30 days and operational metrics for 90 days.
- Ephemeral end-to-end encrypted Network messages are configured to expire after five minutes.
- Unverified ordinary accounts may be deleted after a notified grace process. Paid, financial, privileged, disputed and legally held records are excluded from automatic deletion while the reason applies.
- Encrypted backups expire under protected rotation. A deleted item may remain inaccessible in a backup until that backup expires and is not restored separately except for disaster recovery or legal necessity.
A legal hold, fraud investigation, unpaid transaction, regulatory duty or live claim may extend an otherwise applicable period. The hold is limited to relevant information and reviewed when its purpose ends.
09International transfers
Some providers and user-authorised application operators may process information outside the United Kingdom. Before a restricted transfer by Ident.ink, we use an available legal mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful derogation where appropriate. We assess supplementary technical and organisational measures where required.
To request the applicable safeguard or information about where a category of data is processed, email privacy@ident.ink. Commercial confidentiality and third-party rights may require us to provide a relevant extract rather than an entire contract.
10Automated systems, moderation and review
Automated controls detect spam, known prohibited content, exposed credentials, malicious requests, account abuse, payment anomalies and security threats. They may reject a request, reduce distribution, quarantine content, require verification or temporarily restrict access. Signals may include account history, request pattern, bounded content indicators, device information and pseudonymised network evidence. The legal-policy ledger records the matched rule, action, detector version and one-way evidence hash rather than storing a second plaintext copy.
Ident.ink does not use ordinary product analytics to make solely automated decisions that produce legal or similarly significant effects. A phrase or credential match does not determine criminal guilt or create a fine. Where an automated safety or account action materially affects a person, they receive a policy reference and can challenge it, make representations, correct relevant information and request human intervention through Support. The logic, consequences and safeguards are explained in the Automated Rule Enforcement Policy.
Where UK law permits a significant solely automated decision on a valid lawful basis, Ident.ink must still apply the safeguards required by the UK GDPR as amended by the Data (Use and Access) Act 2025. Special-category data is not used for such a decision unless an additional lawful condition and the required safeguards exist.
11How information is protected
Controls include encrypted transport, password hashing, protected secrets, passkeys and multifactor authentication, role-based access, least privilege, input and request validation, rate controls, service isolation, audit trails, encrypted backups and restore testing. Public requests are confined to documented application and API operations; they do not grant shell, process, host filesystem, secret-store, backup, control-plane or private-network access. Sensitive administrative actions are separately authorised and logged.
Security telemetry is minimised to what is reasonably needed to identify, contain and investigate abuse. Isolation and filtering do not change the visibility selected for customer content, and they do not permit Ident.ink to use private content for unrelated purposes.
No internet service can guarantee absolute security. Users must protect credentials and recovery methods, review connected applications, configure visibility correctly and report suspected compromise promptly to security@ident.ink.
12Your rights and how to exercise them
Subject to applicable conditions and exemptions, you may request access, correction, erasure, restriction, portability or information about processing. You may withdraw consent at any time.
You may object at any time to direct marketing. You may also object to processing based on legitimate interests, including related profiling. Direct marketing will stop. For another objection, we will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims.
Submit a request through privacy@ident.ink or Support. State the account email, the right being exercised and enough detail to locate the information. We may request proportionate identity evidence. We normally respond within one month, subject to a lawful extension for a complex or numerous request. We will explain any refusal, fee, extension or limitation.
If the concern is unresolved, you may complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. If another supervisory authority has jurisdiction, you may complain there instead. You may also seek a judicial remedy where applicable.
13Privacy complaints
A concern about how personal information was used, a rights request was handled, or a privacy incident was managed can be submitted electronically through Support or by email to privacy@ident.ink. Label it as a privacy complaint, describe the issue and desired resolution, and include the relevant account or case reference without sending passwords, identity documents or complete payment details.
In accordance with the Data (Use and Access) Act 2025 complaint requirements, we take appropriate steps to facilitate complaints, acknowledge a complaint within 30 days and respond without undue delay. We may request proportionate information needed to investigate. The response explains the outcome and any further internal or external route. Using this procedure does not prevent a complaint to the ICO or a court.
14Children
Ident.ink is designed for businesses, creators, developers, esports organisations and professional use. It is not directed to a child who cannot lawfully consent to the relevant online service. Where UK consent is the basis for an online service offered directly to a child under 13, authorisation from the holder of parental responsibility is required. Organisations using Ident.ink with younger people remain responsible for an appropriate lawful basis, age-appropriate notice and safeguards.
Contact privacy@ident.ink if information may have been provided by or about a child without lawful authority.
15Changes, prior versions and evidence
The version and effective date at the top identify this notice. Material changes are recorded on Transparency and notified through an appropriate account or email channel before a new use begins where law requires notice or renewed consent. Continued use is not treated as consent where valid consent is legally required.
Operational records, consent receipts, terms acceptances, OAuth grants and administrative audit events are retained where necessary to demonstrate the notice and choices applicable at a particular time. Prior published versions may be requested through Support.