Privacy Policy
Last updated:
Introduction
This Privacy Policy (“Policy”) describes how Terminal 3 HK Limited (“Terminal 3”, “we”, “us”, “our”) collects, uses, discloses, and protects personal data across our websites, applications (web and mobile), software development kits, application programming interfaces, and related services (collectively, the “Services”), and sets out your privacy rights.
Terminal 3 provides confidential-computing infrastructure that lets organizations store, process, verify, and control access to sensitive data without taking custody of it. Our guiding principle is that access to data should never require its transfer.
We handle personal data in accordance with the data protection laws that apply to us, including the Personal Data (Privacy) Ordinance of Hong Kong (“PDPO”), the European Union General Data Protection Regulation (“GDPR”), the UK General Data Protection Regulation (“UK GDPR”), and Japan’s Act on the Protection of Personal Information (“APPI”). We recognize that information privacy is an ongoing responsibility, and we will update this Policy as we adopt new practices or procedures.
Your use of the Services is also governed by the https://www.terminal3.io/terms-of-service, which set out the terms on which you may use our website and Services.
Who this Policy applies to
This Policy applies to:
- Website visitors — individuals who browse our websites, subscribe to communications, or contact us;
- Identity end users — individuals who hold a Terminal 3 identity account (an “Account”) that is accessed through one of our enterprise customers (each, a “Relying Organization”);
- Developers — individuals who register for and use our developer products, including the Agent Developer Kit; and
- Business contacts — individuals at our enterprise customers, partners, and prospective customers whose contact and account details we hold in order to provide and administer our services and to communicate with them.
Where you access Terminal 3 through a Relying Organization, that organization’s own privacy notice also applies to the data it handles in its relationship with you.
Our role
For your Account, Terminal 3 is a controller. We decide how the identity data held in your Account is protected, how long it is kept, and how you exercise your rights over it. Your Account is yours, it is not tied to any one Relying Organization, and it continues to exist if your relationship with a Relying Organization ends. This Policy describes what we do with that data.
Where a Relying Organization receives information from your Account, it is a separate controller. Once you authorize information to be provided to a Relying Organization or another party, that party decides what it does with the information it receives, and its own privacy notice governs that. We are not responsible for, and this Policy does not cover, what a recipient does with information after you have authorized us to provide it.
For some services we act as a processor. Where we host, join, or analyse data on the documented instructions of an enterprise customer — for example, an analytics service built for that customer — the customer is the controller and we process the data only as instructed. Where personal data is processed by a developer’s application or agent, the developer (and not Terminal 3) is the controller, and Terminal 3 acts as the developer’s processor.
How our infrastructure protects your data
Terminal 3 products are built on T3 Network, our confidential computing layer. T3 Network provides the protections set out below. Which of them apply to a particular item of your personal data depends on the Terminal 3 product you are using and how it has been configured. You can ask us which protections apply to your data in a particular service by contacting us at privacy@terminal3.io.
- Encryption. Personal data is encrypted in transit using industry-standard transport encryption, and at rest using AES-256-GCM. Where the Terminal 3 product you use includes client-side encryption, personal data is encrypted within the client software before it leaves your device.
- Threshold key management. Where threshold key management is applied, encryption keys are split across multiple independent nodes using threshold cryptography (ML-KEM, FIPS 203), and decryption requires a quorum of nodes, so that the compromise of any single node does not expose your data.
- Hardware-secured computation. Where hardware-secured computation is applied, computation is performed inside Trusted Execution Environments (Intel TDX), hardware-isolated regions in which data is processed without plaintext being accessible to the surrounding operating system or to Terminal 3’s infrastructure operators.
- Jurisdictional data residency. Personal data can be pinned to a specific jurisdiction (for example, the EU, APAC, or North America) so that it is stored and processed within that region. Some operational, security, and analytics data is processed in other regions; see “Where your personal data is processed” below.
- Audit trail. Data access, computation, policy evaluation, and credential verification are recorded in an audit log. Where a verifiable audit ledger is applied, those records are tamper-evident and cryptographically linked so that they can be independently verified.
- Post-quantum cryptography. The encryption and key-management standards we use (AES-256-GCM and ML-KEM, FIPS 203) are designed to remain secure against future quantum-computing attacks.
Terminal 3 personnel do not access the personal data held in your Account except where necessary to provide, secure, or support the Services, to investigate a security incident, or where required by law. Such access is logged.
Personal data we collect
We collect personal data directly from you, from your use of the Services, from service providers and partners who help us deliver the Services, and — for website and marketing purposes only — from publicly available sources.
The personal data we collect may include:
- Identifiers — such as your name, email address, date of birth, sex or gender, nationality, identity document details, and national or document identification numbers;
- Identity verification data — images of your identity document, a facial image, and the result of a liveness check. See “Identity verification” below;
- Credential data — verifiable credentials we issue, verify, or revoke, and related metadata, including a record of each presentation made from your Account;
- Digital identity information — such as public wallet addresses and decentralized identifiers (DIDs), where you use those features;
- Account and authentication data — such as account identifiers, login events, and one-time passcodes sent to you;
- Business contact data — such as your name, job title, employer, business email address and telephone number, and our correspondence with you;
- Website and device data — such as your IP address, the region or general location from which you access the internet, browser type, operating system, and information about your use of our website;
- Developer account data — such as registration details, account identifiers, and API credentials; and
- Any other personal data you choose to provide.
Identity verification
To create a verified credential in your Account, we need to confirm that you are the person shown in your identity document.
What we collect. An image of your identity document, a facial image of you, and the result of a liveness check confirming that the facial image was captured from a live person.
Why. The facial image is compared against the photograph in your identity document to confirm that you are its holder. This is biometric data processed for the purpose of uniquely identifying you.
Our legal basis. We ask for your consent before identity verification begins, and that consent covers the collection and use of your identity document image, your facial image, and your liveness result for the purpose of confirming your identity. Because your facial image is used to identify you uniquely, we rely on your explicit consent for it. You may withdraw your consent at any time by contacting us, although we may not be able to continue providing a verified credential if you do. Where the law requires us to retain identity verification records, we retain them on that basis (see “Regulated User Data” below).
Who performs it. Verification is carried out on our behalf by specialist identity verification providers. We are not tied to any one provider; the categories of provider we use and the current providers in each category are listed in our Trust Center at https://trust.terminal3.io. These providers act on our instructions under written data processing terms and may not use your data for their own purposes.
Two categories of identity data
For identity end users, your Account may hold two categories of data, which are treated differently:
- Private User Data — identity data that is protected by cryptographic controls that you authorize. You control access to it. Terminal 3 cannot access, change, or delete your Private User Data without your authorization, except where technically necessary to provide, secure, or support the Services, or where required by law. It is held in protected, access-controlled environments.
- Regulated User Data — identity data that the law requires to be collected and retained, such as data used for identity verification, anti–money-laundering, counter–terrorist-financing, sanctions screening, or fraud prevention. This data is held in controlled record-keeping environments (“Regulatory Vaults”) and may be accessed, retained, or disclosed only as required by law or by valid and verified legal or regulatory process. Because the law requires its retention, you may not be able to delete Regulated User Data on request.
How we use your personal data, and our legal bases
Where the GDPR or UK GDPR applies to you, we rely on the legal bases set out below. Where the PDPO or APPI applies, we use your personal data for the purposes described below and, where those laws require your consent, we obtain it.
| What we do | Why | Legal basis (GDPR / UK GDPR) |
|---|---|---|
| Create and operate your Account; store and manage your credentials | To provide the service you asked for | Performance of a contract with you |
| Verify your identity against your identity document | To issue a credential that others can rely on | Performance of a contract; and, for the facial image and liveness result, your explicit consent (Art. 9(2)(a)) |
| Present information from your Account to a party you authorize | To let you prove something about yourself | Your consent, given for each presentation |
| Keep a record of presentations made from your Account | So that you and we can see what was shared, with whom, and when | Our legitimate interest in the security and accountability of the service, and your interest in the same |
| Operate, secure, monitor, and improve the Services; prevent fraud and abuse | To keep the service working and safe | Our legitimate interests |
| Retain identity verification and screening records | Anti–money-laundering, counter–terrorist-financing, sanctions and equivalent obligations | Compliance with a legal obligation |
| Manage our relationship with enterprise customers, partners, and prospective customers, and administer their accounts | To provide and support the services their organization has bought | Performance of a contract; our legitimate interests |
| Communicate with you about the service | To tell you about changes, security matters, and your Account | Performance of a contract; our legitimate interests |
| Send you marketing, where you have asked for it | To keep you informed | Your consent |
| Website analytics and improvement | To understand and improve how our website works | Our legitimate interests |
Where we rely on legitimate interests, we have considered whether those interests are outweighed by your rights, and you may object at any time (see “Your rights”).
Sharing your personal data
Parties you authorize
The purpose of your Account is to let you prove things about yourself without handing over more than is needed.
When a Relying Organization or another party asks to verify something about you, we show you which specific items of information are requested and who is requesting them. The information is provided only if you authorize that presentation. We do not provide information from your Account to any party without your authorization for that presentation.
Once you authorize a presentation, the specified items are provided to that party, which becomes a separate controller of the information it receives and handles it under its own privacy notice and for its own purposes. We keep a record of each presentation.
Withdrawing your authorization stops future presentations. It does not undo a presentation already made, because the recipient already holds the information — you would need to contact the recipient directly to ask it to delete what it holds, and we will help you identify the recipient if you ask.
Service providers
We use service providers to help us deliver the Services. They act on our instructions under written data processing terms, are required to apply appropriate security measures, and may not use your personal data for their own purposes. The categories we use are:
- cloud hosting and infrastructure;
- identity verification, including document and biometric verification;
- communications, including transactional email and one-time passcodes;
- error monitoring and application performance;
- analytics; and
- professional advisers.
The current providers in each category are listed in our Trust Center at https://trust.terminal3.io, which we keep up to date.
Where required by law
We disclose personal data where we are required to do so by applicable law, regulation, or valid legal process, or where necessary to protect the rights, safety, and security of Terminal 3, our users, or others.
What we do not do
We do not sell your personal data. We do not use the identity data held in your Account to train machine learning models. We do not use it for advertising.
Where your personal data is processed
Terminal 3 HK Limited is established in Hong Kong. We and our service providers operate in a number of countries, and your personal data may be stored and processed in any of them. Where a service supports jurisdictional data residency, identity data can be pinned to a chosen region; some operational, security, and analytics data is processed outside that region.
Where personal data is transferred to a country that does not provide a level of protection recognized as equivalent by the law that applies to you, we put in place a lawful transfer mechanism. Depending on the transfer, that may be an adequacy decision covering the destination, the Standard Contractual Clauses approved by the European Commission together with the UK International Data Transfer Addendum where the transfer is from the United Kingdom, or another mechanism permitted by applicable law. These are supported by technical and organizational measures including encryption and access controls.
You may request information about where your personal data is processed, and a copy of the safeguards we rely on, by contacting us at privacy@terminal3.io.
How long we keep personal data
We retain personal data only for as long as necessary for the purposes set out in this Policy and to comply with our legal and regulatory obligations. Where a credential in your Account is derived from an identity document, it remains valid until that document expires, unless you delete it or ask us to delete it sooner.
You may request deletion of your Private User Data at any time, subject to legally required retention of Regulated User Data. When we delete data, we remove it from active storage; where complete destruction is not technically possible, we render the data permanently inaccessible.
Accounts created through organizations
If you create or hold a Terminal 3 Account through an organization, your Account remains your own and you remain in control of your personal data. The organization may request certain information related to your relationship with it, but it can access that information only if you choose to share it. Terminal 3 provides the infrastructure that allows you to manage this access and does not transfer ownership or control of your data to the organization.
You may contact Terminal 3 directly at privacy@terminal3.io at any time to access, manage, or delete your personal data, including to exercise the rights described in this Policy.
Account portability
Your Terminal 3 Account is personal to you and may be used with more than one organization over time. Even if the organization through which you first signed up discontinues its use of Terminal 3, your Account and associated personal data will remain under your control and continue to be governed by this Policy, until you instruct otherwise (subject to legally required retention of Regulated User Data). Where technically feasible, we will provide your personal data to you, or transfer it, at your request.
Cookies and similar technologies
We use cookies and similar technologies to recognize you when you visit our website, to distinguish you from other users, to monitor web traffic, and to improve our services. Cookies are small data files placed on your computer or mobile device when you visit a website.
We use the following types of cookies:
- Necessary cookies — strictly necessary to provide the services available through our website and to use some of its features, such as access to secure areas. Without these cookies, the services you have asked for cannot be provided.
- Functional cookies — allow our website to remember choices you make, such as your language, and provide enhanced features. The information these cookies collect may be anonymized and they cannot track your browsing activity on other websites.
- Analytics cookies — collect information about how you use our website, including which pages you visited and which links you clicked, so we can compile reports and improve the website. They collect information in a way that does not directly identify anyone.
You can set your browser to refuse all or some cookies, or to alert you when cookies are being sent. To learn how to manage your cookie settings, check your browser’s help menu.
Information we collect through our website
As is true of most websites, our website automatically collects certain information and stores it in log files, which may include IP addresses, the region or general location from which your device accesses the internet, browser type, operating system, and usage information including the pages you view. We use this to administer and secure the website, diagnose problems with our servers, analyze trends and visitor movements, and understand visitor preferences.
Our website may also collect personal data from you when you request assistance through our “Contact Us” form, subscribe to newsletters, or request other information. Terminal 3 has a legitimate interest in understanding how customers and potential customers use its website so that it can provide more relevant products and services.
The terms on which you may use our website and its content are set out in the Terminal 3 Terms of Service.
Children's data
The Services are not available to anyone under 18 years of age or below the age of majority where they live, and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can take appropriate action.
Your rights
Subject to applicable law, you have the following rights in relation to your personal data:
- Right to be informed — to know what personal data we collect and how we use it.
- Right of access — to confirm whether we are processing your personal data and to obtain a copy of it.
- Right to rectification — to have inaccurate personal data corrected.
- Right to erasure — to request deletion of your personal data, subject to certain exceptions, including legally required retention of Regulated User Data.
- Right to restrict processing — to ask us to limit how we process your data in certain circumstances.
- Right to data portability — to receive your data in a portable format or have it transferred where technically feasible.
- Right to object — to object to processing based on our legitimate interests, and to direct marketing at any time.
- Right to withdraw consent — where we rely on your consent, including your explicit consent to biometric verification, you may withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.
- Rights relating to automated decision-making — not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.
Where APPI applies to you, you may also request disclosure of the record of provisions of your personal data to third parties, and request that we cease using or providing your personal data in the circumstances APPI provides for.
Reasonable access to your personal data is provided at no cost. If we cannot provide access within a reasonable time, we will tell you when we can. If we deny access, we will explain why.
To exercise any of these rights, email privacy@terminal3.io.
You also have the right to complain to a data protection authority:
- Hong Kong — Office of the Privacy Commissioner for Personal Data
- Japan — Personal Information Protection Commission
- United Kingdom — Information Commissioner’s Office
- European Union — your national data protection authority
How to contact us
Terminal 3 is headquartered in Hong Kong and has appointed a Data Protection Officer, who can be reached at privacy@terminal3.io with any question or concern about our personal data practices, or to exercise your privacy rights.
For legal notices, contact legal@terminal3.io.
Changes to this Policy
We may update this Policy from time to time. Each version has a version number and an effective date, both shown at the top. Where a change is material, we will take reasonable steps to bring it to your attention. We encourage you to review this Policy periodically.