1. When verification may be requested
Datafuel may request verification at its discretion based on risk signals, before unlocking mail ports 25, 110, 143, 993, or 995, before .gov or other restricted domains, for high-volume or wholesale orders, or potentially for all accounts after launch.
Datafuel also screens countries and transactions against sanctions and excluded-country rules.
2. Providers and information
Verification may be performed by Sumsub or Stripe Identity. Datafuel may request an identity document, selfie or liveness check, company registration, and proof of intended use.
3. Legal basis and retention
The legal basis is legitimate interest in fraud prevention, security, abuse prevention, and controlled access. A legal obligation applies where required by law. Verification data is retained for five years from account closure and may be held by the provider under its policy. Datafuel does not copy identity documents outside the verification provider unless necessary for a lawful purpose.
4. Outcomes and appeal
The result may be approved, a request for additional information, or declined. The Customer may request a review by contacting legal@datafuel.ai or support@datafuel.ai. Datafuel may maintain restrictions during review.
If verification fails and the Account is closed, unused balance may be refunded under the Refund Policy, subject to consumer rights, payment-route limits, fraud controls, and applicable law.
5. Rights
The person may request access, correction, deletion, restriction, portability, or object to processing by contacting privacy@datafuel.ai. A complaint may be lodged with the Garante.
6. Automated checks
Providers may use automated fraud or identity checks. Datafuel will not rely solely on automated processing for a decision producing legal or similarly significant effects without the safeguards required by Article 22 GDPR, including human review and a right to contest where applicable.