TrustElevate Privacy Notice

Age Assurance and Identity Verification Services
Version 5.0 | Last Updated: April 2026 | Effective Date: April 2026 | ICO: ZA476685

Key Privacy Principle: On-Device Processing

TrustElevate's Age Assessment Services are built on a fundamentally privacy-preserving architecture:

  • All facial analysis, biometric processing and age estimation run entirely on your own device — inside your web browser
  • Your selfie, ID document images, facial embeddings and biometric data are never transmitted to TrustElevate or to Private Identity LLC
  • The only information we receive is the age outcome (an estimated age or a pass/fail result) — encrypted and without any personal identifiers
  • Neither TrustElevate nor Private Identity makes any decision about you based on this result — that decision is made by the platform (our Customer) that asked you to complete the check

1. Who We Are

TrustElevate Limited is a provider of age assurance and identity verification technology. We are registered under the Companies Act 2006 (company registration number 08046357). Our registered office is at 8 Coldbath Square, London, EC1R 5HL, United Kingdom.

We are registered with the UK Information Commissioner's Office (ICO), registration number ZA476685.

According to Article 27 of the EU General Data Protection Regulation, our representative in the EEA is TrustElevate Limited (company registration number C97824), with a registered office at 103, Palazzo Pietro Stiges, Strait Street, Valletta VLT 1436, Malta.

Data Protection Contact: For all queries relating to this Privacy Notice and our handling of personal data, please contact our Privacy Officer at privacy@trustelevate.com or write to: The Privacy Officer, TrustElevate, 20 Air Street, Soho, London, W1B 5DL, UK.

2. Our Role: Controller and Processor

TrustElevate operates in two distinct capacities depending on the activity involved.

2.1 When We Act as a Data Controller

TrustElevate is the data controller for personal data we collect and process for our own purposes, including:

  • Operating and maintaining our website (trustelevate.com)
  • Managing business enquiries, sales and marketing leads
  • Providing customer and technical support
  • Administering business relationships with our customers and partners
  • Complying with our own legal and regulatory obligations

2.2 When We Act as a Data Processor

TrustElevate provides Age Assessment Services used by third-party platforms ("Customers"). TrustElevate acts as a processor or service provider to the Customer that asked you to complete an age estimation or age assurance check. The Customer is the controller and is responsible for telling you why your age is being checked and how the result is used.

We process data only on our Customer's instructions. The Customer is responsible for providing you with their own privacy notice explaining why verification is required and the legal basis for processing.

Typical lawful bases relied upon by our Customers include:

  • Legal obligation – e.g. under the Online Safety Act 2023 or gambling legislation
  • Compliance with regulatory requirements – such as the UK Age Appropriate Design Code
  • Legitimate interests – in preventing access by underage users to age-restricted content
  • Substantial public interest – under Schedule 1 of the Data Protection Act 2018

3. Our Technology Partners

3.1 Private Identity LLC (PrivateID)

TrustElevate provides the Age Assessment Services using technology provided and hosted by Private Identity LLC ("Private Identity" or "PrivateID"), a US-based technology provider. Private Identity acts as a sub-processor, processing data on behalf of and on the instructions of TrustElevate.

This Privacy Policy supersedes any other privacy policy that TrustElevate or Private Identity might have on its website insofar as it relates to the Age Assessment Services.

For questions relating to Private Identity's role as service provider or processor to TrustElevate, please contact TrustElevate in the first instance at privacy@trustelevate.com. We will coordinate with Private Identity as appropriate.

3.2 Data Flow Overview

The architecture of TrustElevate's Age Assessment Services means that the flow of personal data is deliberately minimised:

StepWhat HappensData That Moves
1User initiates age check on the Customer's platformUser → Customer platform
2Customer platform requests an age check from TrustElevateCustomer → TrustElevate
3TrustElevate's on-device models run inside the user's browser. Facial analysis, liveness, age estimation and (if applicable) ID matching all happen locally on the device. No images or biometrics leave the device.On-device only — no data transmitted
4The age result (only) is encrypted on-device and transmitted to Private Identity's servers, then made available to TrustElevateEncrypted age result only → PrivateID → TrustElevate
5TrustElevate returns the age result and a random session identifier to the Customer's platform. The Customer decides what action to take.Age result + session ID → Customer

3.3 Sub-Processor List

TrustElevate maintains a list of current sub-processors. This list is available on request by contacting privacy@trustelevate.com. We will notify our Customers in advance of any intended changes to our sub-processors, in accordance with our data processing agreements.

4. The Age Assessment Services

TrustElevate provides two distinct Age Assessment Services. Both are built on the same on-device processing principle.

4.1 Age Estimation Service

The Age Estimation Service enables a user to capture a selfie. When the age check begins, a series of on-device models run entirely within the user's web browser using WebAssembly technology compiled from C++. These models execute inside a browser memory sandbox — no other process can access the models' working memory.

The on-device workflow includes:

  • Face detection
  • Liveness assessment
  • Face landmark detection
  • Age estimation (the model runs multiple times using freshly captured frames; results are averaged to produce an Age Estimate)

Throughout this process:

  • All processing happens locally on the user's device
  • The selfie is not transmitted to TrustElevate, Private Identity, or any other vendor
  • All images and model outputs remain in volatile memory only and are deleted and overwritten after each step completes

The only information TrustElevate receives is the Age Estimate for that session, transmitted from the device to Private Identity's servers using industry-standard encryption, and from there made available to TrustElevate. No personal identifiers are transmitted alongside the Age Estimate.

4.2 Age Assurance Service

The Age Assurance Service enables a user to capture (i) an image of the front of a government-issued identity document and (ii) a selfie. All processing runs entirely within the user's web browser using the same WebAssembly architecture.

The on-device workflow includes:

  • Generating a facial embedding from the ID document image
  • Performing optical character recognition (OCR) across the ID document to extract the date of birth
  • Calculating the user's age locally based on the extracted date of birth
  • Capturing a live selfie and performing face detection and a liveness check
  • Generating a second facial embedding from the live selfie
  • Comparing the two facial embeddings locally to confirm whether the faces match

Throughout this process:

  • All processing happens locally on the user's device
  • The facial embeddings, OCR outputs, ID document images, selfie images, and extracted date of birth are not transmitted to TrustElevate, Private Identity, or any other vendor
  • All embeddings and images are deleted immediately after use, typically within approximately one second on modern devices

If the faces match: the calculated Age Result is encrypted on-device using industry-standard encryption and transmitted to Private Identity's servers, from where it is made available to TrustElevate.

If the faces do not match: no age information is transmitted at all. The Age Assurance Service returns a "no match" result only. Neither TrustElevate nor Private Identity receives any biometric data, ID document images, selfies, facial embeddings, OCR data, or extracted date of birth.

4.3 How the Age Output Is Used

In this Privacy Notice, "Age Output" means either an Age Estimate (from the Age Estimation Service) or an Age Result (from the Age Assurance Service).

We use the Age Output solely to confirm to our Customer whether the user is thought to be over or under the age threshold(s) that the Customer has set. When we return the result, we also include a random session identifier, which allows the Customer to associate the result with the relevant user session.

Neither TrustElevate nor Private Identity receives the user's name, contact details, device identifiers, or any other information that would enable identification of the individual. We do not associate the Age Output or session identifier with any such information.

The Customer independently decides what action to take based on the Age Output (e.g. whether to grant or deny access to a product or service, or whether to initiate a further human review process). Neither TrustElevate nor Private Identity engages in any decision-making based solely on automated processing.

5. What Personal Data We Process

5.1 Data Received Through the Age Assessment Services (as Processor)

Given the on-device architecture described in Section 4, the personal data actually received by TrustElevate through the Age Assessment Services is deliberately minimal:

Data ItemWhat It IsWhere It Is Processed
Age OutputEstimated age or pass/fail result against Customer-set thresholdOn-device then transmitted (encrypted) to PrivateID → TrustElevate
Session identifierA random identifier allowing the Customer to link the result to the relevant user session. Not linked to any personal identifierGenerated by TrustElevate, shared with Customer
Flow status / threshold resultAbove or below threshold (set by Customer). Used for billing and quality assurance onlyLog files on TrustElevate/PrivateID systems
TimestampDate and time of the age check sessionLog files on TrustElevate/PrivateID systems
Redirect URLThe Customer-controlled web address to which the user is returned after the checkLog files only

Data that stays on device and is NEVER transmitted: selfie images, ID document images, facial embeddings, biometric templates, OCR outputs, extracted date of birth. TrustElevate and Private Identity have no access to any of this data.

5.2 Log Files

We use log files for billing and quality assurance purposes only. Log files contain:

  • Flow status (e.g. completed, failed)
  • Result against the Customer's threshold (above threshold / below threshold)
  • Timestamp of the session
  • Redirect URL (the Customer-controlled address to which the user is returned)

Log files do not contain personal data or personal identifiers such as IP addresses, browser type, or any information about the individual. We do not combine log file data with any identifying information.

5.3 Controller Processing (Our Own Business Activities)

When acting as a data controller for our own business activities, we collect and process:

CategoryExamplesLegal Basis
Contact informationName, email address, telephone number, business nameLegitimate interests; performance of a contract
Business partner dataBusiness name, first and last name, business email, telephonePerformance of a contract; legitimate interests
Website usage dataIP address, browser type, app version, device data, pages visitedLegitimate interests
Customer service dataSupport queries, correspondence recordsLegitimate interests; legal obligation
Marketing preferencesConsent to receive newsletters and product updatesConsent
Verification data matchingMatching identity data against authoritative sources and third-party databases to verify age and identity (LIA-TE-001)Legitimate interests (Art. 6(1)(f))
SMS and phone-based verificationProcessing mobile/phone number to deliver one-time passcodes and verify ownership of a device for age assurance purposes (LIA-TE-001)Legitimate interests (Art. 6(1)(f))
IP address and geolocation dataProcessing IP address and approximate geolocation to apply jurisdictional rules, detect fraud, and ensure service integrity (LIA-TE-001)Legitimate interests (Art. 6(1)(f))
System audit logs and security monitoringRetaining system and transaction audit logs for security monitoring, fraud detection, and accountability (LIA-TE-001, UK GDPR Recital 49)Legitimate interests (Art. 6(1)(f))

6. Why Age Verification Is Required

Age verification and assurance are increasingly required by law and regulation to protect children and young people online. Our Customers use TrustElevate's technology to comply with obligations including:

  • The UK Age Appropriate Design Code (Children's Code)
  • The UK Online Safety Act 2023
  • EU Digital Services Act requirements
  • Industry-specific regulatory requirements (e.g. gambling, alcohol, financial services)

The specific legal basis for requiring verification is determined by the Customer (as data controller) and should be set out in their own privacy notice. Our Customers determine how the Age Assessment Services are deployed, including specifying the age thresholds at which the services are applied.

7. How the Verification Process Works

7.1 Data Minimisation by Design

TrustElevate's verification process is designed around the principle of data minimisation. The output returned to the Customer is a simple result against the Customer's chosen threshold:

  • Above threshold / Below threshold
  • Age Estimate (numerical, no identity information)
  • Age Result (pass / no match — no biometric data retained)

No full identity profile is created. The Customer receives only the minimum result needed to make an access decision.

7.2 On-Device Ephemeral Processing

All facial images, biometric templates, and on-device model outputs exist only in volatile browser memory. They are deleted and overwritten after each processing step. They are not written to persistent storage on the device, transmitted over any network, or stored by TrustElevate or Private Identity.

This architecture means that TrustElevate's approach to biometric data goes beyond the standard "ephemeral processing" described in many privacy notices — the data is never transmitted at all.

7.3 Privacy by Design

TrustElevate's age assurance architecture is designed from the outset to minimise the personal data processed and to avoid the creation of persistent identity profiles. The system returns only the minimum verification signal required by the requesting platform, as required by Article 25 of the UK GDPR.

7.4 Data Protection Impact Assessment

TrustElevate has conducted a Data Protection Impact Assessment (DPIA 500150 v5) for its age assurance and identity verification technology, in accordance with Article 35 of the UK GDPR. This covers the processing of biometric data, the use of automated verification technology, and the processing of data relating to children. In addition, a Legitimate Interest Assessment (LIA-TE-001) has been completed to document and justify the use of Legitimate Interests (Art. 6(1)(f)) as the lawful basis for specific processing activities, including verification data matching, SMS verification, IP/geolocation processing, and system audit logging. Both assessments are reviewed periodically. Summaries are available on request to our Customers and supervisory authorities.

8. Children's Data

TrustElevate's core purpose is to help protect children and young people online. We recognise the particular sensitivity of children's personal data and apply enhanced protections:

  • We minimise data processed about children to the absolute minimum necessary for age verification
  • No facial images or biometric data relating to children (or adults) are ever transmitted to or retained by TrustElevate or Private Identity
  • We do not use any data from the Age Assessment Services for marketing, profiling, or any purpose other than the specific verification requested
  • We do not create persistent identity profiles
  • Only a pass/fail or above/below threshold result is returned to the requesting platform

Where our Customers use TrustElevate to verify the age of users who may be children, the Customer (as data controller) is responsible for ensuring appropriate safeguards are in place and for providing age-appropriate transparency to those users in accordance with the UK Age Appropriate Design Code.

If you are a parent or guardian and believe that a child's data has been processed inappropriately, please contact us at privacy@trustelevate.com.

9. How We Share Your Data

We do not sell personal data. We may share data in the following circumstances:

  • With our Customers: the Age Output and session identifier are returned to the Customer's platform. The Customer determines how to use this result.
  • With Private Identity (as sub-processor): the encrypted Age Output is transmitted via Private Identity's servers as described in Section 4. Private Identity does not receive biometric data, ID images, or selfies.
  • With other service providers: we use third-party providers for business operations including email, IT infrastructure, analytics and support. All are bound by data processing agreements.
  • For legal compliance: we may disclose data where required by law, regulation, court order or to cooperate with law enforcement.
  • In connection with business transactions: in the event of a merger, acquisition or sale of assets, personal data may be transferred subject to appropriate safeguards.

10. International Data Transfers

Because Private Identity is based in the United States, the encrypted Age Output is transmitted to servers in the US. We ensure appropriate safeguards are in place for all such transfers, including:

  • UK International Data Transfer Agreement (UK IDTA) or UK Addendum to the EU Standard Contractual Clauses
  • EU Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfer risk assessments conducted in accordance with ICO and EDPB guidance

You may request further information about these safeguards or a copy of relevant contractual terms by contacting privacy@trustelevate.com.

11. Data Retention

11.1 Age Assessment Services Data (as Processor)

Data ItemRetention PeriodBasis
On-device data (selfie, ID image, embeddings, OCR, biometrics)Zero — never transmitted, deleted on-device immediately after useOn-device ephemeral processing architecture
Age Output (Age Estimate or Age Result)90 days, then deletedReturned to Customer for access decision; short retention for audit trail
Session identifier90 days, then deletedLinked to Age Output for Customer reconciliation
Log files (flow status, threshold result, timestamp, redirect URL)Retained for billing and QA; deleted when no longer requiredBilling, quality assurance and dispute resolution

11.2 Controller Data (Our Own Activities)

We retain personal data collected in our capacity as data controller for no longer than necessary:

  • Customer and partner records: duration of the business relationship plus 6 years
  • Marketing data: until consent is withdrawn or you unsubscribe
  • Website analytics data: 26 months
  • Support correspondence: 3 years from resolution
  • Trial data: duration of trial plus 30 days

Our retention policy is reviewed annually.

12. Data Security

TrustElevate operates a stringent security framework appropriate to the sensitivity of the data we process. Our security measures include:

  • Industry-standard encryption (in transit and at rest) for all transmitted data
  • On-device ephemeral processing — biometric data is never written to persistent storage or transmitted
  • Browser memory sandboxing (WebAssembly) — model working memory cannot be accessed by other processes
  • Tokenisation of verification sessions
  • Access controls and role-based permissions
  • Regular security testing and vulnerability assessments
  • Staff training on data protection and information security
  • Secure server infrastructure maintained in line with ISO 27001

All suppliers and sub-processors are contractually required to meet equivalent security standards. Despite these measures, no data transmission or storage system is completely secure. If you believe the security of your interaction with us has been compromised, please contact us immediately at privacy@trustelevate.com.

13. Your Rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights. We will respond within one month of a valid request.

13.1 Where TrustElevate Is the Controller

  • Right to be informed: this Privacy Notice provides transparency about our processing
  • Right of access: request a copy of personal data we hold about you (Subject Access Request)
  • Right to rectification: request correction of inaccurate or incomplete data
  • Right to erasure: request deletion of personal data in certain circumstances (subject to legal obligations)
  • Right to restriction of processing: request that we limit how we use your data
  • Right to data portability: request your data in a machine-readable format
  • Right to object: you have the right to object to processing based on legitimate interests (Art. 6(1)(f)). This applies specifically to: verification data matching, SMS/phone-based verification, IP address and geolocation processing, and system audit logging (documented in LIA-TE-001). You also have the right to object to processing for direct marketing
  • Rights related to automated decision-making: TrustElevate does not make automated decisions with legal or similarly significant effects in its capacity as controller

To exercise any of these rights, contact us at privacy@trustelevate.com.

13.2 Where TrustElevate Is the Processor

Because TrustElevate does not directly access, store, or retain your biometric data, ID images, or selfies, we hold very limited personal data about individual end users of the Age Assessment Services. If you have a question about your personal data or wish to exercise rights in connection with an age check, please contact the Customer (the platform or organisation that asked you to complete the check) in the first instance. TrustElevate will assist the Customer in fulfilling such requests as required.

14. Automated Decision-Making and Profiling

Age estimation and verification involves automated processing of facial images or signals on your device to produce an age result. This processing is carried out entirely on your device — TrustElevate and Private Identity's systems are not involved in the image analysis itself.

The automated processing on-device produces an Age Output (an age estimate or pass/fail result). This is returned to the Customer's platform. The Customer, as data controller, independently decides what action to take based on that result (such as granting or denying access). Neither TrustElevate nor Private Identity makes any decision about you based on automated processing.

Where a Customer's process involves automated decisions that produce legal or similarly significant effects, the Customer (as data controller) is responsible for complying with Article 22 of UK GDPR and for providing you with information about your right to request human review of that decision.

15. Cookies and Analytics

Our website (trustelevate.com) uses cookies and similar tracking technologies. We use essential cookies for website operation and, where you consent, Google Analytics cookies to understand how visitors use our site. You can accept or reject analytics cookies in the banner on this website, or disable cookies in your browser settings at any time.

16. Links to Other Websites

Our website and services may contain links to third-party websites. Once you leave our site, we are not responsible for the privacy practices of those other websites. We encourage you to review the privacy notice of every website you visit.

17. Complaints

If you are dissatisfied with how TrustElevate has processed your personal data, please contact us at privacy@trustelevate.com.

If we are unable to resolve the issue, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

18. Changes to This Privacy Notice

We keep this Privacy Notice under regular review. Where we make material changes, we will take appropriate steps to notify you, including updating the date at the top of this notice. Where we hold your contact details and the changes are significant, we will endeavour to notify you directly.

We will not rely solely on a statement that you should regularly check this notice for changes. Where changes affect processing for which you have given consent, we will seek fresh consent where required.

This Privacy Notice was last updated in April 2026. The Effective Date shown at the top reflects when the current version came into force for the Age Assessment Services.

Document Control

FieldDetail
DocumentTrustElevate Privacy Notice — Age Assurance and Identity Verification Services
Version5.0
DateApril 2026
Effective DateApril 2026
ClassificationPublic
ICO RegistrationZA476685
Contactprivacy@trustelevate.com
EEA RepresentativeTrustElevate Limited (C97824), 103 Palazzo Pietro Stiges, Strait Street, Valletta VLT 1436, Malta
Source documentsTrustElevate Privacy Notice v4.0 (March 2026); DPIA 500150 v5 (April 2026); LIA-TE-001 Legitimate Interest Assessment (April 2026)