Effective Date: June 25, 2026
Passify ("we", "us") operates the identity and compliance infrastructure at passify.biz. This policy explains what data we collect, how we use it, and your rights.
What we store:
What we do NOT store:
Identity verification is performed by third-party providers (e.g., Blockpass). Personal data is submitted directly to these providers, never through Passify's servers. Please review their privacy policies for data handling details.
We use collected data to: (a) authenticate dashboard operators; (b) issue and verify onchain attestations; (c) enforce compliance rules; (d) maintain audit trails required by regulations; (e) detect abuse and enforce rate limits.
Attestation records are retained for the lifetime of the attestation plus 7 years for regulatory compliance. Audit logs are retained indefinitely. Account data is retained until account deletion is requested.
We use encryption in transit (TLS), hashed credentials (bcrypt), session tokens (JWT with expiry and revocation), and role-based access controls.
Depending on your jurisdiction, you may have rights to access, correct, or delete your personal data. Contact privacy@passify.biz with requests.
We use a single httpOnly session cookie for authentication. We do not use analytics cookies or third-party tracking.
We will notify operators of material changes via email. Continued use after notification constitutes acceptance.
Data protection inquiries: privacy@passify.biz