GDPR
Last updated: August 28, 2026
Scope and roles
This notice explains how ScoreID approaches personal-data processing under the General Data Protection Regulation. Depending on the service and relationship, ScoreID may act as a data controller for its own processing activities or as a processor acting on documented instructions from an institutional customer.
Lawful bases
Personal data is processed only where a valid legal basis applies. These bases may include performing a contract, meeting a legal obligation, protecting legitimate interests, protecting vital interests or obtaining consent. Where consent is relied upon, it may be withdrawn at any time without affecting earlier lawful processing.
Data subject rights
Individuals may have the right to access and correct their data, request erasure or restriction, object to certain processing, receive portable data and challenge certain automated decisions. Requests are assessed and answered within the periods required by applicable law, subject to lawful exceptions.
Processors and transfers
Service providers that process personal data for ScoreID are required to follow appropriate confidentiality, security and data-processing obligations. International transfers are protected using an applicable adequacy decision, approved contractual safeguards or another lawful transfer mechanism.
Protection and contact
ScoreID applies measures designed to protect the confidentiality, integrity and availability of personal data and maintains processes for assessing and responding to incidents. To exercise a GDPR right or ask a data-protection question, contact hello@scoreid.com. You may also contact the competent supervisory authority.