TrustElevate Privacy Notice
Age Assurance and Identity Verification Services
Version 5.0 | Last Updated: April 2026 | Effective Date: April 2026 | ICO: ZA476685
Key Privacy Principle: On-Device Processing
TrustElevate's Age Assessment Services are built on a fundamentally privacy-preserving architecture:
- All facial analysis, biometric processing and age estimation run entirely on your own device — inside your web browser
- Your selfie, ID document images, facial embeddings and biometric data are never transmitted to TrustElevate or to Private Identity LLC
- The only information we receive is the age outcome (an estimated age or a pass/fail result) — encrypted and without any personal identifiers
- Neither TrustElevate nor Private Identity makes any decision about you based on this result — that decision is made by the platform (our Customer) that asked you to complete the check
1. Who We Are
TrustElevate Limited is a provider of age assurance and identity verification technology. We are registered under the Companies Act 2006 (company registration number 08046357). Our registered office is at 8 Coldbath Square, London, EC1R 5HL, United Kingdom.
We are registered with the UK Information Commissioner's Office (ICO), registration number ZA476685.
According to Article 27 of the EU General Data Protection Regulation, our representative in the EEA is TrustElevate Limited (company registration number C97824), with a registered office at 103, Palazzo Pietro Stiges, Strait Street, Valletta VLT 1436, Malta.
Data Protection Contact: For all queries relating to this Privacy Notice and our handling of personal data, please contact our Privacy Officer at privacy@trustelevate.com or write to: The Privacy Officer, TrustElevate, 20 Air Street, Soho, London, W1B 5DL, UK.
2. Our Role: Controller and Processor
TrustElevate operates in two distinct capacities depending on the activity involved.
2.1 When We Act as a Data Controller
TrustElevate is the data controller for personal data we collect and process for our own purposes, including:
- Operating and maintaining our website (trustelevate.com)
- Managing business enquiries, sales and marketing leads
- Providing customer and technical support
- Administering business relationships with our customers and partners
- Complying with our own legal and regulatory obligations
2.2 When We Act as a Data Processor
TrustElevate provides Age Assessment Services used by third-party platforms ("Customers"). TrustElevate acts as a processor or service provider to the Customer that asked you to complete an age estimation or age assurance check. The Customer is the controller and is responsible for telling you why your age is being checked and how the result is used.
We process data only on our Customer's instructions. The Customer is responsible for providing you with their own privacy notice explaining why verification is required and the legal basis for processing.
Typical lawful bases relied upon by our Customers include:
- Legal obligation – e.g. under the Online Safety Act 2023 or gambling legislation
- Compliance with regulatory requirements – such as the UK Age Appropriate Design Code
- Legitimate interests – in preventing access by underage users to age-restricted content
- Substantial public interest – under Schedule 1 of the Data Protection Act 2018
3. Our Technology Partners
3.1 Private Identity LLC (PrivateID)
TrustElevate provides the Age Assessment Services using technology provided and hosted by Private Identity LLC ("Private Identity" or "PrivateID"), a US-based technology provider. Private Identity acts as a sub-processor, processing data on behalf of and on the instructions of TrustElevate.
This Privacy Policy supersedes any other privacy policy that TrustElevate or Private Identity might have on its website insofar as it relates to the Age Assessment Services.
For questions relating to Private Identity's role as service provider or processor to TrustElevate, please contact TrustElevate in the first instance at privacy@trustelevate.com. We will coordinate with Private Identity as appropriate.
3.2 Data Flow Overview
The architecture of TrustElevate's Age Assessment Services means that the flow of personal data is deliberately minimised:
| Step | What Happens | Data That Moves |
|---|---|---|
| 1 | User initiates age check on the Customer's platform | User → Customer platform |
| 2 | Customer platform requests an age check from TrustElevate | Customer → TrustElevate |
| 3 | TrustElevate's on-device models run inside the user's browser. Facial analysis, liveness, age estimation and (if applicable) ID matching all happen locally on the device. No images or biometrics leave the device. | On-device only — no data transmitted |
| 4 | The age result (only) is encrypted on-device and transmitted to Private Identity's servers, then made available to TrustElevate | Encrypted age result only → PrivateID → TrustElevate |
| 5 | TrustElevate returns the age result and a random session identifier to the Customer's platform. The Customer decides what action to take. | Age result + session ID → Customer |
3.3 Sub-Processor List
TrustElevate maintains a list of current sub-processors. This list is available on request by contacting privacy@trustelevate.com. We will notify our Customers in advance of any intended changes to our sub-processors, in accordance with our data processing agreements.
4. The Age Assessment Services
TrustElevate provides two distinct Age Assessment Services. Both are built on the same on-device processing principle.
4.1 Age Estimation Service
The Age Estimation Service enables a user to capture a selfie. When the age check begins, a series of on-device models run entirely within the user's web browser using WebAssembly technology compiled from C++. These models execute inside a browser memory sandbox — no other process can access the models' working memory.
The on-device workflow includes:
- Face detection
- Liveness assessment
- Face landmark detection
- Age estimation (the model runs multiple times using freshly captured frames; results are averaged to produce an Age Estimate)
Throughout this process:
- All processing happens locally on the user's device
- The selfie is not transmitted to TrustElevate, Private Identity, or any other vendor
- All images and model outputs remain in volatile memory only and are deleted and overwritten after each step completes
The only information TrustElevate receives is the Age Estimate for that session, transmitted from the device to Private Identity's servers using industry-standard encryption, and from there made available to TrustElevate. No personal identifiers are transmitted alongside the Age Estimate.
4.2 Age Assurance Service
The Age Assurance Service enables a user to capture (i) an image of the front of a government-issued identity document and (ii) a selfie. All processing runs entirely within the user's web browser using the same WebAssembly architecture.
The on-device workflow includes:
- Generating a facial embedding from the ID document image
- Performing optical character recognition (OCR) across the ID document to extract the date of birth
- Calculating the user's age locally based on the extracted date of birth
- Capturing a live selfie and performing face detection and a liveness check
- Generating a second facial embedding from the live selfie
- Comparing the two facial embeddings locally to confirm whether the faces match
Throughout this process:
- All processing happens locally on the user's device
- The facial embeddings, OCR outputs, ID document images, selfie images, and extracted date of birth are not transmitted to TrustElevate, Private Identity, or any other vendor
- All embeddings and images are deleted immediately after use, typically within approximately one second on modern devices
If the faces match: the calculated Age Result is encrypted on-device using industry-standard encryption and transmitted to Private Identity's servers, from where it is made available to TrustElevate.
If the faces do not match: no age information is transmitted at all. The Age Assurance Service returns a "no match" result only. Neither TrustElevate nor Private Identity receives any biometric data, ID document images, selfies, facial embeddings, OCR data, or extracted date of birth.
4.3 How the Age Output Is Used
In this Privacy Notice, "Age Output" means either an Age Estimate (from the Age Estimation Service) or an Age Result (from the Age Assurance Service).
We use the Age Output solely to confirm to our Customer whether the user is thought to be over or under the age threshold(s) that the Customer has set. When we return the result, we also include a random session identifier, which allows the Customer to associate the result with the relevant user session.
Neither TrustElevate nor Private Identity receives the user's name, contact details, device identifiers, or any other information that would enable identification of the individual. We do not associate the Age Output or session identifier with any such information.
The Customer independently decides what action to take based on the Age Output (e.g. whether to grant or deny access to a product or service, or whether to initiate a further human review process). Neither TrustElevate nor Private Identity engages in any decision-making based solely on automated processing.
5. What Personal Data We Process
5.1 Data Received Through the Age Assessment Services (as Processor)
Given the on-device architecture described in Section 4, the personal data actually received by TrustElevate through the Age Assessment Services is deliberately minimal:
| Data Item | What It Is | Where It Is Processed |
|---|---|---|
| Age Output | Estimated age or pass/fail result against Customer-set threshold | On-device then transmitted (encrypted) to PrivateID → TrustElevate |
| Session identifier | A random identifier allowing the Customer to link the result to the relevant user session. Not linked to any personal identifier | Generated by TrustElevate, shared with Customer |
| Flow status / threshold result | Above or below threshold (set by Customer). Used for billing and quality assurance only | Log files on TrustElevate/PrivateID systems |
| Timestamp | Date and time of the age check session | Log files on TrustElevate/PrivateID systems |
| Redirect URL | The Customer-controlled web address to which the user is returned after the check | Log files only |
Data that stays on device and is NEVER transmitted: selfie images, ID document images, facial embeddings, biometric templates, OCR outputs, extracted date of birth. TrustElevate and Private Identity have no access to any of this data.
5.2 Log Files
We use log files for billing and quality assurance purposes only. Log files contain:
- Flow status (e.g. completed, failed)
- Result against the Customer's threshold (above threshold / below threshold)
- Timestamp of the session
- Redirect URL (the Customer-controlled address to which the user is returned)
Log files do not contain personal data or personal identifiers such as IP addresses, browser type, or any information about the individual. We do not combine log file data with any identifying information.
5.3 Controller Processing (Our Own Business Activities)
When acting as a data controller for our own business activities, we collect and process:
| Category | Examples | Legal Basis |
|---|---|---|
| Contact information | Name, email address, telephone number, business name | Legitimate interests; performance of a contract |
| Business partner data | Business name, first and last name, business email, telephone | Performance of a contract; legitimate interests |
| Website usage data | IP address, browser type, app version, device data, pages visited | Legitimate interests |
| Customer service data | Support queries, correspondence records | Legitimate interests; legal obligation |
| Marketing preferences | Consent to receive newsletters and product updates | Consent |
| Verification data matching | Matching identity data against authoritative sources and third-party databases to verify age and identity (LIA-TE-001) | Legitimate interests (Art. 6(1)(f)) |
| SMS and phone-based verification | Processing mobile/phone number to deliver one-time passcodes and verify ownership of a device for age assurance purposes (LIA-TE-001) | Legitimate interests (Art. 6(1)(f)) |
| IP address and geolocation data | Processing IP address and approximate geolocation to apply jurisdictional rules, detect fraud, and ensure service integrity (LIA-TE-001) | Legitimate interests (Art. 6(1)(f)) |
| System audit logs and security monitoring | Retaining system and transaction audit logs for security monitoring, fraud detection, and accountability (LIA-TE-001, UK GDPR Recital 49) | Legitimate interests (Art. 6(1)(f)) |
6. Why Age Verification Is Required
Age verification and assurance are increasingly required by law and regulation to protect children and young people online. Our Customers use TrustElevate's technology to comply with obligations including:
- The UK Age Appropriate Design Code (Children's Code)
- The UK Online Safety Act 2023
- EU Digital Services Act requirements
- Industry-specific regulatory requirements (e.g. gambling, alcohol, financial services)
The specific legal basis for requiring verification is determined by the Customer (as data controller) and should be set out in their own privacy notice. Our Customers determine how the Age Assessment Services are deployed, including specifying the age thresholds at which the services are applied.
7. How the Verification Process Works
7.1 Data Minimisation by Design
TrustElevate's verification process is designed around the principle of data minimisation. The output returned to the Customer is a simple result against the Customer's chosen threshold:
- Above threshold / Below threshold
- Age Estimate (numerical, no identity information)
- Age Result (pass / no match — no biometric data retained)
No full identity profile is created. The Customer receives only the minimum result needed to make an access decision.
7.2 On-Device Ephemeral Processing
All facial images, biometric templates, and on-device model outputs exist only in volatile browser memory. They are deleted and overwritten after each processing step. They are not written to persistent storage on the device, transmitted over any network, or stored by TrustElevate or Private Identity.
This architecture means that TrustElevate's approach to biometric data goes beyond the standard "ephemeral processing" described in many privacy notices — the data is never transmitted at all.
7.3 Privacy by Design
TrustElevate's age assurance architecture is designed from the outset to minimise the personal data processed and to avoid the creation of persistent identity profiles. The system returns only the minimum verification signal required by the requesting platform, as required by Article 25 of the UK GDPR.
7.4 Data Protection Impact Assessment
TrustElevate has conducted a Data Protection Impact Assessment (DPIA 500150 v5) for its age assurance and identity verification technology, in accordance with Article 35 of the UK GDPR. This covers the processing of biometric data, the use of automated verification technology, and the processing of data relating to children. In addition, a Legitimate Interest Assessment (LIA-TE-001) has been completed to document and justify the use of Legitimate Interests (Art. 6(1)(f)) as the lawful basis for specific processing activities, including verification data matching, SMS verification, IP/geolocation processing, and system audit logging. Both assessments are reviewed periodically. Summaries are available on request to our Customers and supervisory authorities.
8. Children's Data
TrustElevate's core purpose is to help protect children and young people online. We recognise the particular sensitivity of children's personal data and apply enhanced protections:
- We minimise data processed about children to the absolute minimum necessary for age verification
- No facial images or biometric data relating to children (or adults) are ever transmitted to or retained by TrustElevate or Private Identity
- We do not use any data from the Age Assessment Services for marketing, profiling, or any purpose other than the specific verification requested
- We do not create persistent identity profiles
- Only a pass/fail or above/below threshold result is returned to the requesting platform
Where our Customers use TrustElevate to verify the age of users who may be children, the Customer (as data controller) is responsible for ensuring appropriate safeguards are in place and for providing age-appropriate transparency to those users in accordance with the UK Age Appropriate Design Code.
If you are a parent or guardian and believe that a child's data has been processed inappropriately, please contact us at privacy@trustelevate.com.
9. How We Share Your Data
We do not sell personal data. We may share data in the following circumstances:
- With our Customers: the Age Output and session identifier are returned to the Customer's platform. The Customer determines how to use this result.
- With Private Identity (as sub-processor): the encrypted Age Output is transmitted via Private Identity's servers as described in Section 4. Private Identity does not receive biometric data, ID images, or selfies.
- With other service providers: we use third-party providers for business operations including email, IT infrastructure, analytics and support. All are bound by data processing agreements.
- For legal compliance: we may disclose data where required by law, regulation, court order or to cooperate with law enforcement.
- In connection with business transactions: in the event of a merger, acquisition or sale of assets, personal data may be transferred subject to appropriate safeguards.
10. International Data Transfers
Because Private Identity is based in the United States, the encrypted Age Output is transmitted to servers in the US. We ensure appropriate safeguards are in place for all such transfers, including:
- UK International Data Transfer Agreement (UK IDTA) or UK Addendum to the EU Standard Contractual Clauses
- EU Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfer risk assessments conducted in accordance with ICO and EDPB guidance
You may request further information about these safeguards or a copy of relevant contractual terms by contacting privacy@trustelevate.com.
11. Data Retention
11.1 Age Assessment Services Data (as Processor)
| Data Item | Retention Period | Basis |
|---|---|---|
| On-device data (selfie, ID image, embeddings, OCR, biometrics) | Zero — never transmitted, deleted on-device immediately after use | On-device ephemeral processing architecture |
| Age Output (Age Estimate or Age Result) | 90 days, then deleted | Returned to Customer for access decision; short retention for audit trail |
| Session identifier | 90 days, then deleted | Linked to Age Output for Customer reconciliation |
| Log files (flow status, threshold result, timestamp, redirect URL) | Retained for billing and QA; deleted when no longer required | Billing, quality assurance and dispute resolution |
11.2 Controller Data (Our Own Activities)
We retain personal data collected in our capacity as data controller for no longer than necessary:
- Customer and partner records: duration of the business relationship plus 6 years
- Marketing data: until consent is withdrawn or you unsubscribe
- Website analytics data: 26 months
- Support correspondence: 3 years from resolution
- Trial data: duration of trial plus 30 days
Our retention policy is reviewed annually.
12. Data Security
TrustElevate operates a stringent security framework appropriate to the sensitivity of the data we process. Our security measures include:
- Industry-standard encryption (in transit and at rest) for all transmitted data
- On-device ephemeral processing — biometric data is never written to persistent storage or transmitted
- Browser memory sandboxing (WebAssembly) — model working memory cannot be accessed by other processes
- Tokenisation of verification sessions
- Access controls and role-based permissions
- Regular security testing and vulnerability assessments
- Staff training on data protection and information security
- Secure server infrastructure maintained in line with ISO 27001
All suppliers and sub-processors are contractually required to meet equivalent security standards. Despite these measures, no data transmission or storage system is completely secure. If you believe the security of your interaction with us has been compromised, please contact us immediately at privacy@trustelevate.com.
13. Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the following rights. We will respond within one month of a valid request.
13.1 Where TrustElevate Is the Controller
- Right to be informed: this Privacy Notice provides transparency about our processing
- Right of access: request a copy of personal data we hold about you (Subject Access Request)
- Right to rectification: request correction of inaccurate or incomplete data
- Right to erasure: request deletion of personal data in certain circumstances (subject to legal obligations)
- Right to restriction of processing: request that we limit how we use your data
- Right to data portability: request your data in a machine-readable format
- Right to object: you have the right to object to processing based on legitimate interests (Art. 6(1)(f)). This applies specifically to: verification data matching, SMS/phone-based verification, IP address and geolocation processing, and system audit logging (documented in LIA-TE-001). You also have the right to object to processing for direct marketing
- Rights related to automated decision-making: TrustElevate does not make automated decisions with legal or similarly significant effects in its capacity as controller
To exercise any of these rights, contact us at privacy@trustelevate.com.
13.2 Where TrustElevate Is the Processor
Because TrustElevate does not directly access, store, or retain your biometric data, ID images, or selfies, we hold very limited personal data about individual end users of the Age Assessment Services. If you have a question about your personal data or wish to exercise rights in connection with an age check, please contact the Customer (the platform or organisation that asked you to complete the check) in the first instance. TrustElevate will assist the Customer in fulfilling such requests as required.
14. Automated Decision-Making and Profiling
Age estimation and verification involves automated processing of facial images or signals on your device to produce an age result. This processing is carried out entirely on your device — TrustElevate and Private Identity's systems are not involved in the image analysis itself.
The automated processing on-device produces an Age Output (an age estimate or pass/fail result). This is returned to the Customer's platform. The Customer, as data controller, independently decides what action to take based on that result (such as granting or denying access). Neither TrustElevate nor Private Identity makes any decision about you based on automated processing.
Where a Customer's process involves automated decisions that produce legal or similarly significant effects, the Customer (as data controller) is responsible for complying with Article 22 of UK GDPR and for providing you with information about your right to request human review of that decision.
15. Cookies and Analytics
Our website (trustelevate.com) uses cookies and similar tracking technologies. We use essential cookies for website operation and, where you consent, Google Analytics cookies to understand how visitors use our site. You can accept or reject analytics cookies in the banner on this website, or disable cookies in your browser settings at any time.
16. Links to Other Websites
Our website and services may contain links to third-party websites. Once you leave our site, we are not responsible for the privacy practices of those other websites. We encourage you to review the privacy notice of every website you visit.
17. Complaints
If you are dissatisfied with how TrustElevate has processed your personal data, please contact us at privacy@trustelevate.com.
If we are unable to resolve the issue, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: https://ico.org.uk/make-a-complaint/
- Telephone: 0303 123 1113
- Post: The Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
18. Changes to This Privacy Notice
We keep this Privacy Notice under regular review. Where we make material changes, we will take appropriate steps to notify you, including updating the date at the top of this notice. Where we hold your contact details and the changes are significant, we will endeavour to notify you directly.
We will not rely solely on a statement that you should regularly check this notice for changes. Where changes affect processing for which you have given consent, we will seek fresh consent where required.
This Privacy Notice was last updated in April 2026. The Effective Date shown at the top reflects when the current version came into force for the Age Assessment Services.
Document Control
| Field | Detail |
|---|---|
| Document | TrustElevate Privacy Notice — Age Assurance and Identity Verification Services |
| Version | 5.0 |
| Date | April 2026 |
| Effective Date | April 2026 |
| Classification | Public |
| ICO Registration | ZA476685 |
| Contact | privacy@trustelevate.com |
| EEA Representative | TrustElevate Limited (C97824), 103 Palazzo Pietro Stiges, Strait Street, Valletta VLT 1436, Malta |
| Source documents | TrustElevate Privacy Notice v4.0 (March 2026); DPIA 500150 v5 (April 2026); LIA-TE-001 Legitimate Interest Assessment (April 2026) |