Privacy Policy

Effective 17 September 2026 · Version 1.0 · Controller: Dieng — HTL

X-Trust is built so that we cannot identify the people behind verification requests. This policy explains what limited data we hold, why we hold it, how long we keep it and what you can ask us to do with it.

In one minute

  • What we hold: the buyer email used at checkout, purchase records, hashed API key material, and anonymized verification events (a score and a one-way hash).
  • What we never hold: names, addresses, identity documents, KYC files, biometrics, end-user identities, card numbers or advertising profiles.
  • What we never do: sell personal data, run advertising trackers, or build profiles of people.
  • Your controls: access, correction, deletion, restriction, objection and portability, exercised by one email to diengamine.htl@gmail.com.

1. Design principle: zero PII, zero KYC

Most verification products ask you to hand over personal data. X-Trust is built the other way round: the Service produces a signed human-presence signal without needing to know who anyone is. Our default configuration never receives your end users' names, contact details, documents or biometrics, and we do not ask you for them. We do not perform identity verification, know-your-customer checks, sanctions screening or credit assessment.

2. Who is responsible for your data

Dieng — HTL (Human Trust Layer), an independent software vendor based in Côte d'Ivoire, is the data controller for the limited data described in this policy. Contact: diengamine.htl@gmail.com.

Paddle.com Market Ltd. is the Merchant of Record for all purchases and acts as an independent controller of the payment, billing and tax data you give at checkout. We never receive that data. Paddle's own privacy notice governs it; we receive only a limited confirmation (email address, transaction reference, pack purchased, amount, currency, tax country, payment status).

If you use the Service inside your own product, you are the controller of the data your product collects about your end users, and we act as your service provider for the verification signal. A data processing addendum is available on request.

3. What we collect

Buyer email and purchase record. The email address you provide at checkout, plus the transaction reference, pack size, amount, currency, purchase date, tax country and payment status supplied by Paddle. We use this to issue your API key, meter your balance, provide support and meet accounting obligations.

API key records. A key identifier and prefix, a cryptographic hash of the secret, the creation date, the revocation date and the associated pack. The full secret is shown once at issuance; we cannot recover it afterwards.

Anonymized verification events. For each billable verification event we record a numeric score, a one-way hash derived from request metadata using a rotating salt, a coarse timestamp, the key identifier and the decision. The hash lets us detect repeated abuse patterns; because the salt rotates, events cannot be reverse-engineered into identities.

Transient technical data. Short-lived request metadata such as source IP address, user-agent string, response status and latency. Used for rate limiting, abuse detection, fraud prevention and debugging. Kept in rotating operational logs only.

Support correspondence. If you write to us, we keep the email thread and your address so we can answer and keep a record of what was agreed.

4. What we never collect

5. Cookies and similar technologies

Our pages and API do not use advertising cookies, analytics cookies or third-party trackers. When you pay, you are transferred to Paddle's checkout, where Paddle may set its own cookies to process the payment and prevent card fraud.

6. Why we process data, and on what legal basis

We comply with Ivorian data protection law, in particular Law No. 2013-450 of 19 June 2013 on the protection of personal data, and we align our practices with the principles of the EU GDPR as a matter of good practice for our international customers.

7. How long we keep it

8. Who we share data with

We do not sell, rent or trade personal data. We share the minimum necessary with service providers under written data protection terms:

Legal requests. We may disclose data if compelled by law. Because we hold almost nothing, such a request can rarely be answered with personal data.

Business transfer. If the Service is sold or merged, the limited data described here may transfer with it. This policy continues to apply.

9. International transfers

We operate from Côte d'Ivoire and use providers whose infrastructure may be located in other countries. Where personal data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses approved by the European Commission, adequacy decisions, or the provider's equivalent binding commitments, together with encryption in transit.

10. Security

If a security incident affects your data, we will notify you without undue delay and, where the law requires, the competent supervisory authority within 72 hours of becoming aware.

11. Your rights

Subject to applicable law, you may ask us to:

Send requests to diengamine.htl@gmail.com. We respond within 30 days. We will never ask for an identity document. Note that we cannot look up your individual verification events, because they are anonymised.

12. Scoring and automated processing

The Service computes a confidence score about a request, not about a person. The features describe characteristics of a session. We do not build behavioural profiles, we do not sell scores, and we do not make decisions with legal or similarly significant effects about your end users. Any action taken on the basis of a verification result is taken by you, in your own system, under your own policies. We ask customers not to rely on the score as the sole basis for high-stakes decisions.

13. Children

The Service is intended for business use by adults and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we hold an email address belonging to a child, contact us and we will delete it promptly.

14. Changes to this policy

We may update this policy. The current version is always published on this page with a new effective date. For material changes we will give reasonable notice, and at least 14 days where required by law, by email to the buyer address on record or by a prominent notice on our site.

15. Contact

Privacy questions, data requests and security reports:

Dieng — HTL (Human Trust Layer)
Email: diengamine.htl@gmail.com
Country: Côte d'Ivoire

Payments, invoices and card data are handled by Paddle.com Market Ltd. as Merchant of Record; please contact Paddle directly for questions about the payment data you provided at checkout.