Legal
Retention & destruction policy
Last updated September 29, 2026
Dokimos ID follows a data-minimization model: collect what verification requires, delete transient artifacts quickly, and keep only what employers and regulators need.
Default retention schedule
- Transient verification artifacts in Dokimos ID (session references and any cached media): deleted automatically on an organization-configured schedule counted from the interview date (or from cancellation if the interview is canceled). Default is 7 days; maximum is 90 days (aligned with Veriff's typical media retention). Each deletion is logged in the audit trail. Government ID and selfie images are not stored by Dokimos ID; they are held by our verification provider (Veriff) and deleted under Veriff's default retention schedule (within 90 days).
- PDF verification reports: retained for the employer organization for 90 days after the report is generated to support hiring decisions and compliance review, then deleted automatically (or earlier on a deletion request).
- Consent records: retained with the versioned policy text the candidate accepted.
- Audit log: retained as an immutable record of data events.
- Live check recordings: video recorded by the Recall.ai meeting bot is deleted from Recall.ai right after the face comparison, and the daily retention job deletes any recording that remains on the transient-artifact schedule above. Each deletion is logged.
What we do not store long-term
- Raw face templates or biometric imagery from live checks.
- Interview join links before verification passes.
- Biometric data beyond what Veriff processes as processor of record.
Destruction
Scheduled deletion jobs run via Convex. Each deletion event is logged. Employers may request export or deletion of subject data by contacting hello@dokimosid.com.