Identity and Evidence Verification Policy
How Reedleys verifies the identity and authority of applicants and the authenticity, ownership and relevance of the evidence behind a profile, while protecting privacy.
Version 1.0 · Effective 31 July 2026 · The current online version controls.
Applies to: Reedleys and the Reedleys website, applications, directory, verification and recognition services.
Important: Where mandatory local law gives a person greater or non-waivable rights, that law prevails.
1. Purpose
This policy explains how Reedleys verifies the identity and authority of applicants and evaluates the authenticity, ownership and relevance of evidence used for directory, verification and recognition services.
Verification reduces impersonation and false claims but cannot eliminate all fraud or guarantee a person's future conduct, competence or service quality.
2. Who may be verified
Reedleys may verify:
- an individual professional creating or publishing a profile;
- an owner, director, officer, employee or authorized representative claiming an organization profile;
- a person submitting an appeal, complaint, data-rights request or sensitive account change;
- the organization, domain, credential, licence, certificate or other evidence connected to a profile.
3. Organization verification methods
Depending on the organization and jurisdiction, Reedleys may use one or more of the following:
- official company, charity, tax, professional or business registry information;
- domain control or DNS verification;
- an email address at the organization's controlled domain;
- a business telephone or address confirmation;
- officer, director, ownership or employment records;
- signed authorization from a verifiable authorized person;
- business licences, assumed-name records or operational documents;
- manual review where technical verification is unavailable.
A generic email account, social profile or unclaimed directory listing alone may be insufficient to prove authority.
4. Professional identity verification methods
Reedleys may use:
- a government-issued identity document;
- a selfie, short video, liveness check or one-to-one facial comparison;
- name, date-of-birth and document-validity checks;
- address or contact verification;
- professional registry, licence or credential checks;
- a manual review or alternative method where reasonably available.
The exact method may depend on location, document availability, risk, technology and legal requirements.
5. Biometric and facial verification
Where a selfie or video is technically compared with an identity-document image, the process may involve biometric information and, in some jurisdictions, sensitive or special-category personal data.
Reedleys will seek to:
- provide clear notice before collection;
- obtain consent or explicit consent where required;
- use the information only for identity, fraud-prevention, security and closely related purposes described at collection;
- avoid using verification images for advertising, unrelated profiling or model training by Reedleys;
- provide a manual or non-biometric alternative where reasonably feasible and legally appropriate;
- limit access and retention;
- assess the privacy and security risks of the provider and method.
A third-party verification provider may collect and process the document, selfie, liveness data or biometric template. Its own privacy notice and contractual role may also apply. How this data is handled overall is described in the Global Privacy and Data Protection Notice.
6. Evidence verification methods
Reedleys may verify evidence by:
- checking an issuer, official registry or licensing database;
- validating a secure certificate link, QR code, digital signature or document reference;
- contacting an issuer or authorized source;
- comparing names, dates, scopes and status across records;
- checking metadata, visible alterations or consistency indicators;
- reviewing a controlled website, account, domain or platform;
- requesting an explanation, translation or clearer copy;
- using specialist or automated document tools as an aid.
7. Evidence quality requirements
Evidence should be legible, complete enough to understand, connected to the applicant, current where time-sensitive and capable of reasonable verification.
Reedleys may reject or give reduced weight to:
- heavily cropped or edited records;
- screenshots without an identifiable source;
- expired, revoked or inactive documents presented as current;
- documents belonging to another person or entity without a valid connection;
- self-written declarations where independent support is reasonably expected;
- altered, fabricated, misleading or unlawfully obtained material;
- unnecessary sensitive information that should have been redacted.
8. Data minimization and redaction
Applicants should provide only what is necessary. Unless specifically required, they should redact unrelated account numbers, financial balances, signatures, identification numbers, client data, employee data and other sensitive information while leaving the name, issuer, date, status and relevant content visible.
Reedleys may ask for a less-redacted version only where necessary to complete a legitimate check.
9. Verification results
A result may be:
- verified or confirmed;
- verified with limitations;
- inconclusive or requiring further information;
- failed or not verified;
- referred for manual review;
- rejected due to evidence-integrity concerns.
A failed automated check does not necessarily mean fraud. Where reasonable, Reedleys may allow another attempt or manual review.
10. False information and misuse
Evidence-integrity concerns may include document alteration, impersonation, fabricated credentials, borrowed licences, false authority, manipulated screenshots, fabricated reviews or deliberate concealment of material contradictions.
Before a materially adverse finding, Reedleys will normally consider whether there may be an innocent explanation. Serious or repeated misconduct may result in rejection, suspension, withdrawal, preservation of relevant records, provider notification or referral to an appropriate authority where lawful and necessary.
11. Security and access
Identity and verification information is restricted to authorized personnel and providers with a legitimate need. Reedleys uses proportionate technical and organizational safeguards and seeks contractual commitments from service providers concerning confidentiality, security, deletion and subprocessors.
No online system is completely secure, and verification does not remove the applicant's responsibility to protect account credentials.
12. Retention
Raw identity documents, selfies and liveness materials should be retained for the shortest practical period and are normally scheduled for deletion or de-identification within the period stated in the Public Data Retention Schedule, unless they are needed for an active dispute, fraud investigation, legal obligation or security incident.
Reedleys may retain a verification result, date, provider reference, status and limited audit information for longer so that it can maintain account integrity and defend assessment decisions.
13. Children and vulnerable persons
Professional and organization account holders must normally be at least 18 years old or the age of legal majority applicable to the service. Reedleys does not intentionally use biometric identity verification for children unless a specific service, lawful basis and appropriate safeguards have been established.
14. Rights and complaints
Privacy rights, including access, correction, deletion, restriction, objection, consent withdrawal and applicable biometric rights, are described in the Global Privacy and Data Protection Notice.
A person may appeal an identity-related assessment decision under the Appeals Policy or complain about the verification process under the Complaints Policy.
Related policies
This policy forms part of the Reedleys Legal & Terms framework. See also the Assessment and Recognition Decision-Making Policy, the Global Privacy and Data Protection Notice and the Public Data Retention Schedule.