1. Verification methodology
NexionLabs verifies credential presentations using the OID4VP 1.0 protocol against issuer-signed credentials. The verification does not access, store, or process the underlying identity document. Pass/Fail decisions are derived from cryptographic proof validation, not from identity matching or biometric comparison at the gateway layer. This statement is a draft pending review by qualified legal counsel.
2. Data handling
Verification session metadata (timestamps, outcome, policy receipt hash) is retained per the partner's configured retention policy. Raw identity attributes presented during verification are not stored by NexionLabs and are not accessible to NexionLabs personnel. The partner receives only the attributes permitted by their workflow configuration. This statement is a draft pending review by qualified legal counsel.
3. Audit trail
Each verification produces a signed Activity Receipt anchored to a hash-chain. The receipt can be independently verified by any party holding the receipt ID and the partner's public verification key. This audit trail is designed to satisfy GDPR Art. 5(2) accountability requirements and regulator evidence expectations under ARCOM, Ofcom OSA, and equivalent frameworks. This statement is a draft pending review by qualified legal counsel.