Privacy Statement – ID App Identity Verification Demo

1. General

BPI Services B.V. provides a demo application that allows interested users to voluntarily evaluate a remote identity verification process. This privacy statement explains how BPI Services B.V. handles personal data processed when using this demo.

The demo app is published and managed by BPI Services B.V. via the Apple App Store and Google Play Store and uses the ID app and the associated ID Hub web application.

2. Data controller

BPI Services B.V. is the data controller within the meaning of the General Data Protection Regulation (GDPR) for all personal data processed in the context of this demo.

3. Voluntary use and liability

Use of the demo is entirely voluntary and intended solely for demonstration and evaluation purposes. The demo is not a production environment and cannot be used for formal, legal, or binding identity verification.

BPI Services B.V. accepts no liability for any direct or indirect damage resulting from the use of the demo or from decisions made based on the demo.

4. Purposes of processing

Personal data is processed for the following purposes:

a) enabling and executing a remote identity verification demo;
b) demonstrating document verification and holder verification (selfie comparison);
c) evaluating and improving the operation and performance of the demo and the underlying solutions;
d) informing the user about the use of the demo and their rights.
e) following up on trials for business development purposes, such as answering any questions and sharing relevant information regarding our services.

5. What personal data is processed?

During use of the demo, the following personal data may be processed:

a) the user's email address;
b) personal data from the identity document, including name, date of birth, document number, and document image;
c) biometric data, consisting of:

  • the passport photo from the identity document;
  • a selfie taken by the user for the purpose of holder verification;
    d) information regarding document authenticity checks and chip validation results.

6. How the demo works

The demo proceeds as follows:

a) the user requests an email with a QR code via the website;
b) the user downloads the demo app via the App Store or Google Play;
c) the verification process is started in the app using the QR code;
d) the user completes the process by scanning an international identity document and taking a selfie;
e) the comparison between the document photo and the selfie is performed using the Microsoft Face API, which is utilized as a technical processing service provider;
f) the app displays a summary of the identity verification;
g) after the user provides explicit consent, the data is sent to the ID Hub and the retention period begins;
h) during the retention period, the user may submit a request to receive a report containing the processed personal data and the authenticity checks performed.

7. Retention period

Personal data processed in the context of the demo is retained for a maximum of 7 days after the completion of the identity verification process and is then automatically deleted.

8. Security

BPI Services B.V. implements appropriate technical and organizational measures to secure personal data. The ID app and ID Hub web application are developed and managed in accordance with:

  • ISO/IEC 27001
  • NEN 7510

This ensures an appropriate level of information security.

9. Data subject rights

The user has the right to access the personal data processed during the demo and may request additional information regarding this processing. The user may also request the correction or deletion of data, where applicable.

Because the data is only available temporarily, any request must be submitted no later than 3 days after completing the identity verification process via sales@bpiservices.eu.

10. Disclosure to third parties

Personal data will not be shared with third parties unless necessary for the technical execution of the demo or to comply with legal obligations.

11. Contact

BPI Services B.V. For questions regarding this privacy statement or the processing of personal data, please contact us via the website of BPI Services B.V.

Safety and compliance

Data is securely stored in Europe and processed in full compliance with GDPR regulations. Our software undergoes regular penetration testing and meets the highest security standards.

NEN 7510

We are NEN 7510 certified, the Dutch standard for information security in healthcare.

ISO 9001 & ISO 27001

Certified to ISO 9001 and ISO 27001. All data stored and processed within Europe, in accordance with the GDPR.

Schedule an appointment with David
Sales contact