Skip to main content

How is my KYC data handled and protected?

Written by Pulse.hl | Hyperbeat

Both Hyperbeat's identity verification and Noah's onboarding process are powered by Sumsub, a regulated identity verification provider. This article explains exactly what happens to the personal data you submit during KYC - how it's used, how long it's kept, how it's secured, and who can access it.


What is Sumsub's role?

Sumsub acts as a data processor - meaning it processes your personal data only under Hyperbeat's instructions and strictly for the purpose of identity verification. Hyperbeat, as the data controller, determines why your data is collected and sets the boundaries of how it can be used.

In practice: your data is processed solely to verify your identity for regulatory compliance (KYC/AML). Nothing more.


How your data is used

Your personal data - including your identity documents, selfie, and liveness check - is used exclusively to:

  • Authenticate your identity document

  • Run biometric facial comparison and liveness detection

  • Screen against sanctions lists and PEP (Politically Exposed Person) databases

  • Satisfy anti-money laundering (AML) and counter-terrorism financing (CFT) obligations

Your data is not used for marketing, sold to third parties, or used for any purpose beyond what's needed to complete your identity check.


How long your data is stored

Data retention is governed by legal requirements:

  • Regulatory minimum: For AML-regulated services, applicable law requires personal data to be retained for 5 years after the end of the relationship. This is a legal obligation Sumsub's clients must comply with, not an arbitrary choice.

  • Deletion on request: You can request deletion of your data at any time. Deletion requests are processed within 30 days. Upon deletion, data is removed from all systems — no backup copies are retained, and biometric data is destroyed in a way that makes it non-recoverable even by forensic techniques.


How your data is protected

Sumsub maintains enterprise-grade security across its infrastructure:

In transit: All data is transmitted over encrypted channels using TLS 1.2+ / TLS 1.3.

At rest: All personal data is encrypted at rest on servers located in Tier III data centres in Germany (EU).

Certifications: Sumsub holds the following independently audited certifications:

  • SOC 2 Type II - security, availability, and confidentiality controls

  • ISO/IEC 27001 - information security management

  • ISO/IEC 27017 - cloud-specific security controls

  • ISO/IEC 27018 - protection of personally identifiable information in public cloud

  • PCI DSS - payment card industry data security standard

Ongoing assurance: Sumsub runs regular internal and external audits, vulnerability assessments, penetration testing, and a bug bounty programme.


Requesting deletion of your data

You have the right to request deletion of your personal data at any time. To submit a request, contact Hyperbeat support and we will coordinate the deletion process on your behalf. You may also contact Sumsub's Data Protection Officer directly at [email protected].

Note that data subject to a legal retention obligation (such as AML records) cannot be deleted before the legally required period expires.


FAQs

Why does KYC require biometric data (a selfie/liveness check)? The liveness check is required to confirm that the person submitting an ID is physically present and matches the document - it prevents identity fraud and document spoofing. It is a standard part of regulated identity verification.

Is my data stored in the EU? Yes. All personal data processed by Sumsub is stored on dedicated servers in Germany, within the European Union.

Can Sumsub use my data for their own products or AI training? No. As a data processor, Sumsub can only process your data according to Hyperbeat's instructions. It cannot use your data for its own commercial purposes such as marketing or AI model training.

What if I want to access the data held about me? You have the right to request a copy of your personal data. Contact Hyperbeat support or reach out to Sumsub directly at [email protected]. Requests are fulfilled within 30 days.

Is Sumsub GDPR compliant? Yes. Sumsub is registered with the UK Information Commissioner's Office (ICO) and processes data in line with EU GDPR and UK GDPR requirements, including lawful basis, data minimisation, purpose limitation, and data subject rights.

Did this answer your question?