Privacy Policy
Last updated: 27 June 2026
This Privacy Policy explains how Hefes LLC ("Hefes", "we", "us") collects, uses, protects, and shares personal data when you use the Veri5 Notary document-notarization service (the "Service"). We are committed to handling your data lawfully, fairly, and with appropriate security, including in line with data-protection frameworks such as the EU GDPR and PDPA-style regimes where they apply to you.
1. Data We Collect
- Account information — your name, email address, and account or Veri5 Number identifier, provided through Veri5 Passport single sign-on.
- Uploaded documents and descriptions — the files you submit for notarization and any titles, descriptions, or metadata you add.
- Payment metadata — records of purchases and credit balances. Payments are processed by Stripe; we do not store full card numbers, only limited transaction metadata returned by the processor.
- Usage and log data — including IP address, device and browser information, timestamps, and actions taken, which we also use to investigate abuse reports and protect the Service.
- KYB information — for organisations that apply to issue credentials, the business-verification documents and details you submit.
2. How Your Documents Are Protected
Document protection is central to this Service:
- Documents are encrypted at rest (using a strong authenticated-encryption suite) and stored in encrypted storage via Pinata/IPFS.
- Only the SHA-256 hash of a document is written to the secure verification registry — never the document itself, and never its plaintext contents.
- Access via share links is granted only through unguessable, expiring tokens, which the owner can revoke at any time.
3. How We Use Data
- to provide, operate, and improve the Service, including creating and verifying notarization records;
- to process payments and manage credit balances;
- to prevent, detect, and investigate abuse, fraud, and security threats;
- to comply with our legal obligations; and
- for content that is reported or that we reasonably believe is illegal, to cooperate with and disclose information to law-enforcement and regulatory authorities.
We rely on the legal bases of contract performance, our legitimate interests in operating and securing the Service, your consent (where required), and compliance with legal obligations.
4. Sharing With Third Parties
We share data only as needed to run the Service:
- Stripe — payment processing;
- Pinata / IPFS — encrypted storage of documents;
- Veri5 Passport — identity and single sign-on;
- Authorities — where required by law or in response to valid legal process, or in connection with reported or illegal content.
We do not sell your personal data.
5. International Data Transfers
The Service and its providers may process data in countries other than your own. Where we transfer personal data across borders, we take steps to ensure an appropriate level of protection, such as relying on adequacy decisions or standard contractual safeguards consistent with applicable data-protection law.
6. Data Retention
We keep account, notarization, and payment records for as long as your account is active and as needed to provide the Service, meet legal and accounting obligations, and resolve disputes. Records connected to reported or illegal content may be retained under legal hold for as long as necessary to assist authorities, even after a deletion request. The encrypted copy of a notarized document is hosted for 10 years from the date of notarization (renewable — see "Document Retention & Renewal" below), after which it is deleted on schedule, while only its non-personal fingerprint and timestamp are kept permanently. Encrypted documents are also deleted upon valid request, subject to those holds.
7. Document Retention & Renewal
We separate the permanent integrity proof of a document from the time-limited hosting of the document file itself, so that personal documents are not retained for longer than necessary:
- The proof is permanent. A document's digital fingerprint (SHA-256 hash) and timestamp are recorded permanently and never expire. This record contains no personal content — it only proves that a specific file existed, unaltered, at a given time.
- Hosted storage lasts 10 years. The actual encrypted copy of your document is hosted (stored, retrievable, and shareable) for 10 years from the date of notarization, included in the one-time notarization fee.
- Renewal. Before the 10-year period ends, the owner may renew or extend hosted storage for a further period; a renewal fee, payable in credits, applies.
- After expiry (if not renewed). The encrypted copy is permanently deleted from our storage, but the fingerprint, timestamp, and notarization record are kept permanently. Integrity can still be proven afterwards by re-submitting the original document — its fingerprint will match the retained record. You never lose the proof; you only lose our hosted copy of the file.
We advise you to keep your own copy of every document you notarize.
8. Your Rights
Subject to applicable law, you may request to:
- access the personal data we hold about you;
- correct inaccurate or incomplete data;
- delete your data and close your account; and
- object to or restrict certain processing, or request data portability.
These rights are subject to legal limits — in particular, we cannot erase data placed under legal hold in connection with reported or illegal content, and a notarization fingerprint already written to the secure verification registry is, by design, immutable. To exercise your rights, contact [email protected].
9. Security
We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption at rest, access controls, token-based share access, and logging. No system is perfectly secure, but we work to protect your information and to respond promptly to incidents.
10. Children
The Service is not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact [email protected] and we will take appropriate action.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, where appropriate, provide additional notice. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact
For privacy questions or to exercise your rights, contact our privacy team at [email protected]. To report abusive or illegal content, contact [email protected].