What identity checks Saha runs, what documents we may ask for, and how they're handled.
Government ID Verification Disclosure
Last Updated: August 28, 2026
Saha offers optional government ID verification through Didit, our third-party identity verification service provider. This verification is separate from the mandatory face-liveness verification required to access Saha's core features.
By choosing to complete ID verification, you acknowledge and consent to the processing described below, including the processing of identity and biometric information where required by applicable law.
Government ID verification is voluntary. You can continue using Saha's core features without completing ID verification, subject to the requirements applicable to those features.
If you successfully complete ID verification, Saha may display an "ID-Verified" badge on your profile to help other users identify profiles that have completed this additional verification.
Other users will not have access to your government ID, ID document image, or the personal information contained in your document.
When you choose to verify your identity, Didit may process information such as:
The specific information processed may depend on the verification method and features enabled for your verification session. Didit's DPA identifies identity-document information, selfie/video and facial biometric data, contact information, device/connection information, and AML/sanctions information among the categories that may be processed.
Didit processes your submitted information to perform identity verification checks. These may include:
Identity verification is an automated and technology-assisted process. A verification result is a verification signal and does not constitute an absolute guarantee that an identity document or identity is genuine. Didit's terms expressly state that verification results support the client's decision-making and do not guarantee the identity of an end user or the absence of fraud.
Saha uses ID verification to help:
Didit processes verification data on Saha's behalf for purposes including identity verification, age verification, fraud prevention, and KYC/AML-related obligations where applicable.
Saha acts as the party responsible for determining why and how your personal information is processed for Saha's services. Didit acts as Saha's data processor when providing its verification services and processes personal information according to Saha's instructions and its Data Processing Agreement with Saha.
Didit may use approved subprocessors to provide parts of its services. Didit maintains a list of subprocessors and requires them to follow applicable data-protection obligations.
Didit states that it maintains technical and organizational safeguards designed to protect personal information. These include encryption of data at rest and in transit, access controls, environment separation, security monitoring, resilience measures, and regular security testing.
Didit also states that its security and verification infrastructure is supported by certifications and assessments including SOC 2 Type 1, SOC 2 Type 2, ISO/IEC 27001:2022, and iBeta Level 1 Presentation Attack Detection (PAD).
Verification information is retained according to the retention configuration applicable to Saha's verification services and applicable legal requirements.
Didit's default retention setting for verification personal data is stated as unlimited, unless a shorter period is configured. Didit allows retention periods to be configured between 30 days and 10 years, and individual verification records may be deleted through the available management tools.
However, biometric information is always subject to applicable biometric-privacy laws and any shorter or stricter legal retention requirements.
Where permitted by applicable law, you may request deletion of your verification information by contacting Saha at privacy@the-saha.com. Requests will be handled in accordance with applicable law, Saha's policies, and its agreement with Didit.
Didit may process anonymized, pseudonymized, or aggregated information derived from verification data for purposes such as improving its identity-verification, biometric, fraud-detection, liveness, face-matching, deepfake-detection, and risk-scoring technologies.
Didit may also use such information to help identify and prevent recurring fraud patterns across applications using its services.
Didit states that this processing is performed using measures such as anonymization, pseudonymization, aggregation, and access controls so that the information used for these purposes cannot reasonably be linked to an identifiable individual outside the underlying verification record.
Where applicable, an individual may request an opt-out from this processing by requesting deletion of the underlying verification record or by contacting privacy@didit.me with the relevant verification/session information.
Didit states that primary personal data processed through its services is hosted in the European Economic Area (EEA).
Where personal information is transferred outside the EEA, Didit states that such transfers are made using legally recognized safeguards, such as Standard Contractual Clauses, adequacy decisions, or another legally valid transfer mechanism under applicable data-protection law.
If Didit cannot complete verification—for example, because of poor document quality, an unsupported or expired document, suspected manipulation, or an unsuccessful liveness or face-match check—you may be asked to retry or continue without the ID-Verified badge.
A failed verification attempt does not automatically result in account suspension. However, activity that appears fraudulent, abusive, or intended to manipulate the verification process may be reviewed and may result in action under Saha's Terms of Service.
You are responsible for providing accurate and authentic information during verification.
You may:
Where applicable, Saha will obtain the notices, permissions, and consents required by law before submitting personal or biometric information to Didit. Didit's DPA places responsibility on the client for establishing the applicable lawful basis and obtaining required end-user consents.
Didit has contractual obligations to notify Saha of confirmed personal-data breaches affecting Saha's data and to cooperate with Saha in investigating and addressing such incidents.
Didit's DPA states that confirmed personal-data breaches affecting client data are to be reported to the client without undue delay and within 48 hours of confirmation, together with relevant information regarding the affected data and the measures taken or proposed to address the incident.
If you have questions about Saha's ID verification process, your verification information, or a request to delete your information, contact:
For additional information about Didit's processing practices, you may also review Didit's applicable privacy and data-processing documentation.