Privacy Policy

Last Updated: June 24, 2025

CCPA Compliant
GDPR Compliant
ISO/IEC 27701

Arbitra.org, a SaaS platform providing independent identity verification (IDV) benchmarking and testing, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our website, benchmarking reports, synthetic datasets, and client solution testing. We comply with the California Consumer Privacy Act (CCPA), General Data Protection Regulation (GDPR), Illinois Biometric Information Privacy Act (BIPA), Florida Information Protection Act (FIPA), New York's NYDFS and SHIELD Act, Texas Data Privacy and Security Act (TDPSA), ISO/IEC 27701, NIST 800-63-3, and vendor terms (e.g., Jumio, Persona, Mitek).

Information We Collect

Synthetic Data

Our benchmarking and testing services primarily use synthetic datasets (e.g., 500 simulated California driver's licenses) containing no real personally identifiable information (PII) or biometric data. These datasets simulate state-of-the-art fraud vectors (e.g., deepfakes, digital forgeries) for research and client testing.

Real User Profiles

For limited client solution testing, we may collect real user profiles (e.g., names, photos) with explicit, documented consent, in compliance with CCPA, GDPR, BIPA, and TDPSA.

Public Data

Benchmarking reports rely on publicly available data (e.g., G2, Gartner, NIST, vendor websites) with no PII.

Website Usage Data

Non-personal data (e.g., IP addresses, browser type) is collected via cookies for analytics, as described in our Cookie Policy.

Contact Information

If you contact us (e.g., via forms), we collect only provided information (e.g., name, email) to respond.

How We Use Information

Benchmarking

Public data and synthetic datasets generate IDV reports, compliant with AAMVA and ISO/IEC 30107/19795-2 standards.

Client Solution Testing

Synthetic datasets and consented real user profiles test client IDV solutions against fraud vectors (e.g., deepfakes, face swaps), with client permission and vendor consent (e.g., Jumio, Persona) to avoid terms violations.

Website Improvement

Non-personal data enhances user experience.

Communication

Contact information supports inquiries or newsletter updates (with opt-in consent).

Data Sharing and Disclosure

No Unauthorized Sharing

Synthetic data and public data are not shared as PII. Real user profiles are shared only with client and vendor consent, under strict agreements.

Service Providers

Non-personal data may be shared with trusted providers (e.g., analytics, hosting) under confidentiality agreements, compliant with CCPA, GDPR, and NYDFS.

Legal Requirements

Data may be disclosed if required by law or to protect our rights, per FIPA, SHIELD Act, or other regulations.

Data Security

We use end-to-end encryption, access controls, and regular audits (aligned with ISO/IEC 27701 and NIST 800-63-3) to protect synthetic datasets, real user profiles, and website data. Synthetic datasets include watermarks to trace misuse. No system is entirely secure, and users assume associated risks.

Your Privacy Rights

CCPA/GDPR/BIPA/TDPSA Rights

California, EU, Illinois, and Texas residents may request access, deletion, or opt-out of personal data (if collected). Real user profiles are managed with explicit consent.

How to Exercise Rights

Contact legal@arbitra.org. We respond within 45 days (CCPA), 30 days (GDPR/FIPA), or as required.

Vendor Compliance

Client testing respects vendor terms (e.g., Jumio, Persona, Mitek) by obtaining consents and anonymizing results unless authorized.

Cookies and Tracking

See our Cookie Policy for details on cookies used for website functionality and analytics.

International Data Transfers

For future expansion (e.g., Brazil), we comply with GDPR for cross-border transfers, using synthetic data to minimize risks.

Third-Party Links

Links to third-party sites (e.g., G2, Gartner) are provided for convenience. We are not responsible for their practices.

Changes to This Policy

Updates will be posted here with a revised "Last Updated" date. Continued use constitutes acceptance.

Contact Us

Email: legal@arbitra.org
Address: Arbitra, [Insert Address], California, USA