PERSONAL INFORMATION COLLECTION STATEMENT

Optional verification. Clear choices about your data.

This notice describes the proposed EVO account-verification service. Sensitive collection is not enabled. Read the collection-specific notice before deciding whether to use any future method.

Notice version: evo-assurance-notice-v1 · Prepared 10 September 2026 · Pre-collection notice

Do not send verification material to support.

There is no verification upload or enrollment on this website. Do not send an identity card, passport, document number, selfie, biometric sample, one-time code or password by email or chat. Existing Google sign-in continues under the existing EVO Privacy Policy.

1. Responsible organization and contact

Genesis Evo Technology LLC is the EVO operator identified on this website. Account-verification and privacy questions can be sent to support@genesis-evo.com. Include only an account or request reference and the issue you need help with; never include identity documents.

support@genesis-evo.com

The existing EVO Privacy Policy covers the wider service. This more specific notice does not silently replace existing account terms, create a new registration method or authorize a new use of previously supplied information.

Existing EVO Privacy Policy

2. Voluntary provision and limited purpose

Google is the only registration provider. Further contact, document, live-person and organization checks are optional. Their only permitted purposes are verifying the account or authorized organization, checking eligibility for a stated sensitive action, reducing duplicate primary identities and protecting that verification process against abuse. They are not a general surveillance or reputation-scoring system.

Before collection, the screen must identify the required and optional fields, the specific feature, why that evidence is necessary, less intrusive methods if available, recipients, processing countries, a fixed retention schedule and the effect of refusing or withdrawing. Consent to one method is not consent to all methods.

Refusing or withdrawing may prevent only the sensitive action that needs the evidence. It must not reduce everyday chat, Work, selected-document use or local AI solely because you have not completed extra identity verification. Service availability, subscription limits and independent account-security or abuse controls still apply.

3. Information that a future method may require

Google account and contact

The existing account identifier and verified sign-in claims. A separately chosen email or SMS challenge may use an address or telephone number, delivery status, challenge result and time. Passwords and one-time codes must not appear in support or audit logs.

Identity document

Only justified fields from an allowed identity card or passport, such as legal name, issuing country, document type and expiry, plus an authenticity result. A document number, image or copy must not be collected merely because it is convenient or you consented. The specific permitted fields must be shown first.

Live person and face matching

If separately enabled, an explicitly captured selfie or short live capture, liveness result and any face-comparison output. A face-geometry template or other biometric identifier may be sensitive biometric data even when described as a derived value. This requires its own notice and affirmative consent where applicable. No background camera or emotion analysis is allowed.

Organization and representative

Business name, registration jurisdiction, registration reference, domain-control result and evidence of authority to represent the organization. A company result does not automatically verify every staff member or expose their private identity.

Minimal verification records

Method, status, reason category, timestamps, consent-notice version and an opaque provider reference. Any duplicate-account comparison identifier remains personal information when linkable; hashing does not make it anonymous. Retaining such an identifier needs a separate purpose and deletion rule.

Your chats, Work files, private mail, browsing history, precise location and payment details are not verification evidence by default. No private life or personality profile is built from this process.

4. Automated verification and mistakes

The intended identity decision is made by automated checks, without routine human review of documents or selfies. Automated checks can produce false matches, reject a valid document or fail to decide. An inconclusive or suspected-duplicate result is not a finding of dishonesty. It must not silently merge accounts or erase your work.

You should receive a usable reason and a route to correct information, retry an automated check or choose a permitted alternative. Rights and process-error support may involve a person handling a request reference and status, but not routine manual identity adjudication. If applicable law requires a safeguard the service cannot provide, that method or feature must remain unavailable in that region.

5. Recipients, confidentiality and processing locations

No new SMS, document, liveness or business-verification provider is enabled by this page. Before one is enabled, EVO must name the provider and relevant subprocessors, their role, processing and storage countries, who can access each data category and the controls on onward disclosure. A vague “trusted partners” statement is not enough to start collection.

The proposed boundary keeps raw documents and biometric captures out of ordinary EVO model prompts, staff dashboards and other users’ profiles. A verification result and the minimum necessary eligibility status may be shared with the relevant EVO service; the identity material is not public. Business-name publication must be separately explained and accepted.

Verification information must not be sold, rented, used for advertising, used to train general AI models or repurposed for health, employment, insurance, credit or personality assessments. Required legal disclosures must be assessed for lawful authority and limited to what is necessary; confidentiality is not an absolute promise against legally compelled access.

6. Retention, withdrawal and deletion

This proposed service currently collects no additional identity documents or biometric material, so it has no live provider retention period to quote. Before collection opens, a public, method-specific schedule must state maximum periods for originals, derived biometrics, challenge data, verification results, consent records, duplicate-check references and backups. Collection remains off until that schedule and deletion verification are in place.

Current internal metadata limits

  • A pending check expires after 15 minutes. A provider may require a shorter period.
  • A successful contact result is valid for at most 90 days; a document or holder result, 365 days; an organization result, 180 days. Validity is not a promise that raw evidence will be stored for that long.
  • Withdrawal or revocation immediately removes active verification claims and the provider-scoped duplicate-check reference. Verification receipt metadata becomes eligible for scheduled removal 30 days after expiry or withdrawal; production erasure remains to be verified.
  • A minimal, non-content request identifier and payload hash remain until account deletion to prevent old requests being replayed. They do not retain an identity number or restore verification. The complete account-deletion workflow is not yet connected; it must be operational before public verification is enabled.

Raw material should be discarded once its disclosed verification purpose is satisfied, within the stated deadline. Withdrawal must stop new checks and remove or invalidate the optional verification and related material under the published schedule. Any required legal preservation must have a specific reason, restricted access and an end condition. Data must not be kept indefinitely “just in case.”

Deleting an optional verification must not silently delete your Google account, Work or unrelated content. Retaining a duplicate-prevention reference after withdrawal or account deletion requires its own disclosed lawful basis and bounded retention; it cannot be hidden in a permanent hash.

7. Access, correction and your choices

Contact support@genesis-evo.com to ask what verification data is held, request access or correction, withdraw a method, request deletion or challenge a process error. A Hong Kong data-access or correction request is normally handled within 40 days under the applicable statutory procedure. Applicable California consumer requests normally have a 45-day response period, subject to permitted extensions and notice. A lawful refusal must be explained. We may need proportionate proof that the request concerns your account, using the least intrusive available method; do not attach identity documents to the first message.

Applicable rights vary by place and service. They may include access, correction, deletion, consent withdrawal, a copy of data, an appeal and a complaint to the relevant regulator. Exercising a privacy right must not itself lead to discrimination or removal of ordinary AI work. A sensitive feature may still require evidence you chose not to provide.

How verification affects features

8. United States and Hong Kong safeguards

Hong Kong: collection must meet the Personal Data (Privacy) Ordinance’s data-protection principles. Identity-card numbers and copies require a justified basis under the relevant Code of Practice, including consideration of less intrusive alternatives; willingness to provide a card is not blanket permission to collect it. The collection screen must explain purpose, obligatory or voluntary provision, consequences, recipient classes and access/correction contact.

United States: requirements differ by state, the data collected and the use. If Illinois biometric law applies, biometric collection requires prior written notice of the purpose and duration, the required written release, a public retention/destruction policy and required safeguards. Other state privacy, biometric, automated-decision and consumer-protection requirements must be evaluated before a method is offered. A selfie and a derived face template may have different legal treatment.

California: where the CCPA applies, a notice at collection must explain categories, purposes, sale or sharing, and the retention period or criteria. Applicable access, correction, deletion and other consumer rights need an operational request route. Automated-decision obligations have their own applicability and phased dates; this page does not imply every requirement applies to every account today.

Texas: where its biometric statute applies, prior notice and consent, restricted disclosure and protective handling are required. Destruction must follow its purpose-based deadline and applicable exceptions, rather than an indefinite account-lifetime default. The method-specific schedule must identify the actual applicable deadline before collection.

  • No document or biometric verification for children is offered in this initial design. A legally reviewed age and regional eligibility policy is required before any future rollout.
  • No claim is made that this pre-collection notice alone establishes compliance in every US state or Hong Kong. Final methods, contracts, safeguards and rights handling must be reviewed for the actual service.

Hong Kong data-protection principles Hong Kong identity-card Code of Practice Illinois Biometric Information Privacy Act California privacy regulations Texas biometric identifier law