1. About this policy
BusinessID is a digital identity app. It lets you prove who you are to businesses and public bodies online, log in to their services, approve transactions and share verified information about yourself - without repeating an identity check every time.
BusinessID is provided by Identity Stack A/S, C. A. Olesens Gade 4, 9000 Aalborg, Denmark (CVR no. 42894389) ("Identity Stack", "we", "us"). For everything described in this policy, we are the data controller: we decide why and how your personal data is used, and we answer for it.
We do not handle your personal data on anyone else's instructions - not a Service Provider's, not anyone's. Everything we do with your data, we do as controller, for the purposes set out in section 6. If that ever changes, we will say so here before it does.
This policy explains what personal data we collect, why we use it, how long we keep it, who we share it with and what rights you have. It applies to you whether or not you have any other relationship with us or with the businesses that accept BusinessID.
You do not need to be a customer of Identity Stack to use BusinessID. The app is yours, and your BusinessID identity belongs to you.
2. Words we use
- "You" - the person who has installed the BusinessID app and created an account.
- "Service Provider" - a business, organisation or public body that accepts BusinessID so that you can register, log in, approve a transaction or share data with them.
- "Verification method" - how you prove your identity to us. Either a national electronic ID (in Denmark, MitID) or a European Digital Identity wallet, or a passport or identity document read with your phone and matched against a photo of your face. The current list is in the app.
Service Providers decide for themselves what they do with the data you choose to share with them. For that, they are their own data controllers and their own privacy policy applies - not this one. We tell you who you are sharing with, and what, before you confirm.
3. The data we collect
3.1 Identity data
The data that says who you are. Depending on your verification method, this can include:
- Your name, date of birth, gender and nationality.
- Your address, where the verification method provides it.
- A national identifier, such as a CPR number, where the verification method provides it and a Service Provider is legally entitled to receive it.
- Document data: the type, number, issuing country and expiry date of the document you used, and the portrait photo stored on its chip.
- A record of how strongly your identity was verified.
3.2 Your photo, and biometric data
These are two different things, and we treat them differently.
Your photo is the portrait stored on the chip of your passport or identity document. We keep it as part of your identity - so you can see it in the app, and so it can be shared as a photo credential where you choose to share one. Held this way it is an ordinary photograph, not biometric data. We do not use your stored photo to recognise you, to match it against any other face, or to search for you.
Biometric data is created only during verification. If you verify with a document, we ask you to record a short video of your face, and we use it to check that a real, live person is present and to compare your face with the portrait on the chip. That video and the mathematical face template derived from it are biometric data used to identify you - a special category of personal data under the GDPR. We only process them with your explicit consent, and we delete them shortly afterwards. See section 5.
Face or fingerprint unlock on your own phone is different. That check happens on your device and never reaches us. We only receive the result: unlocked, or not.
3.3 Contact data
- Your mobile phone number, and your email address if you give us one.
3.4 Device and security data
- Details of the phone you use BusinessID on: model, operating system and version, app version, and whether the device appears rooted or jailbroken.
- Device identifiers, cryptographic keys bound to your device, and push notification tokens.
- IP address and approximate country, used to detect fraud.
3.5 Transaction data
- A record of what you did with BusinessID: which Service Provider, at what time, what you were asked for, what you shared and whether you approved or declined.
- Your account history, which you can see in the app.
3.6 Usage data
- How the app is used - screens opened, features used, crashes and errors - so we can find problems and improve it. We keep this separate from your identity data wherever we can.
4. Where the data comes from
- From you: when you enrol, when you choose what to share, and when you contact support.
- From your verification method: a national electronic ID or wallet returns your verified identity after you authenticate; your passport or identity document returns the data on its chip when you hold it to your phone.
- From your device: device and security data are collected by the app itself.
- From Service Providers: what they asked you for, and confirmation of what you approved.
5. Face matching and your consent
Face matching is how we know that the person holding the document is you. Because it uses biometric data, it works like this:
- We explain the check in the app and ask for your explicit consent before it runs. If you do not consent, we cannot verify you with a document - but you can use a national electronic ID or a wallet instead, which involves no biometric check.
- The video and the face template derived from it are used for the liveness and face-match check, and to let us investigate if the check is later disputed or suspected to be fraudulent.
- We delete the video after 30 days and the face template after 90 days. Where a specific check is under active fraud investigation or dispute, we keep the material until that is resolved, and no longer.
- We keep the result of the check - pass or fail, and a score - as evidence that your identity was properly verified. The result is not biometric data.
- Your document portrait is kept for longer, as described in sections 3.2 and 8. It is kept as a photograph, not as biometric data: it is stored separately from our verification systems, which have no access to it, and it is never used to recognise or match a face.
- You can withdraw your consent at any time in the app or by contacting us, and we will delete the biometric material. Withdrawing consent does not undo checks already carried out, and it may mean you have to verify again by another route to keep using BusinessID.
- We never share your biometric data with Service Providers, and we never use it to search for you in any database or to profile you.
6. Why we use your data, and on what legal basis
We only use your personal data where the GDPR allows it.
| What we do | Data used | Legal basis |
|---|---|---|
| Set up your account and verify your identity | Identity, contact, device and security data | Performance of our contract with you (Art. 6(1)(b)) |
| Liveness and face match during document verification | Biometric data (video, face template) | Your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)) |
| Hold your document portrait as part of your identity, and share it as a photo credential where you choose to | Your photo | Performance of our contract with you (Art. 6(1)(b)) - not biometric processing |
| Let you register, log in, approve transactions and share data with a Service Provider | Identity, transaction, device and security data | Performance of our contract with you (Art. 6(1)(b)) |
| Show you your history and manage your account | Identity, transaction data | Performance of our contract with you (Art. 6(1)(b)) |
| Keep a record of what happened, so a transaction can be proven later | Identity, transaction, device and security data | Our legitimate interest in being able to evidence transactions, and legal obligations (Art. 6(1)(f) and 6(1)(c)) |
| Detect and prevent fraud and misuse; keep the service secure | Device, security, transaction data | Our legitimate interest in protecting users and the service (Art. 6(1)(f)) |
| Support you when you contact us | Whatever is relevant to your request | Performance of our contract with you (Art. 6(1)(b)) |
| Fix bugs and improve the app | Usage, device data | Our legitimate interest in improving our service (Art. 6(1)(f)) |
| Meet legal requirements and respond to lawful requests from authorities | Whatever the law requires | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have weighed our interest against your rights and concluded that the processing is limited to what is necessary. You can ask us for details, and you can object - see section 11.
We do not sell your personal data. We do not use it for advertising, and we do not profile you for commercial purposes.
7. Who we share your data with
7.1 Service Providers
When you use BusinessID with a Service Provider, we share exactly what the app shows you before you approve - no more. You see who is asking and what they are asking for, and nothing is sent until you confirm. If you decline, nothing is sent.
Once a Service Provider has received your data, they are responsible for it. We cannot control what they do with it. Read their privacy policy.
This applies to every kind of Service Provider, including a school, club or employer that asks you to use BusinessID to log in. You always choose whether to share, and you can decline.
7.2 Our suppliers
We use suppliers who process personal data on our behalf, under a written data processing agreement and only on our instructions. These include cloud hosting, the document reading and face matching technology, SMS and push notification delivery, error and usage analytics, and customer support tooling. A current list is available on request.
7.3 Your verification method
When you verify with a national electronic ID or a wallet, you authenticate directly with that scheme - in Denmark, the MitID service operated under the Danish Agency for Digital Government. We receive the verified result and the identity data the scheme returns, and never your credentials. The scheme's own privacy information applies to that step.
7.4 Others
We may also disclose personal data where we are legally required to do so, to authorities acting within their powers, to establish or defend legal claims, or to prevent fraud or harm. If we sell or transfer all or part of our business, your data may transfer with it, and this policy will continue to apply until you are told otherwise.
8. How long we keep your data
| Data | Kept for |
|---|---|
| Video recorded for the liveness and face-match check | 30 days from the check |
| Face template derived from it | 90 days from the check, or until you withdraw consent |
| Result of the check (pass or fail, score) | As long as your account exists, then 10 years |
| Your document portrait, held as part of your identity | As long as your account exists, then 10 years |
| Identity, contact and account data | As long as your account exists, then 10 years |
| Transaction records | 10 years from the transaction |
| Device and security data | As long as your account exists, then 10 years |
| Support correspondence | 2 years from the last contact |
| Usage and crash data | 14 months |
Where biometric material is under active fraud investigation or dispute, we keep it until that is resolved, and no longer.
The ten-year periods exist so that a transaction can still be evidenced if it is later disputed, and so that we can meet our legal obligations. When a period ends, we delete or irreversibly anonymise the data.
9. Where your data is stored
Your personal data is stored on servers within the European Economic Area.
A small number of our suppliers may access data from outside the EEA - for example for support. Where that happens, we rely on an adequacy decision of the European Commission, or on the European Commission's Standard Contractual Clauses together with any additional safeguards needed. You can ask us for a copy of the safeguards in place.
10. How we protect your data
- Data is encrypted in transit and at rest.
- Your account is bound to your device using cryptographic keys held in your phone's secure hardware. Those keys never leave your device.
- Access to personal data inside Identity Stack is restricted to staff who need it, and access is logged.
- Biometric material is stored separately from your other data, with its own access controls and deletion schedule.
- We test our systems regularly and maintain an information security management system aligned with ISO/IEC 27001.
11. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and get a copy.
- Have inaccurate data corrected. Some identity data comes from your verification method and can only be changed by verifying again - the app will tell you when that is the case.
- Have your data erased. If you close your account we will delete what we are not required to keep as evidence or by law (see section 8).
- Restrict or object to processing that we base on legitimate interests.
- Withdraw consent at any time, including for face matching. This does not affect processing already carried out.
- Receive your data in a portable, machine-readable format.
- Not be subject to a decision based solely on automated processing that has a legal or similarly significant effect on you. The liveness and face-match check is automated, but a failed check does not end there: you can ask a person at Identity Stack to review it, and you can try again or use another verification method.
To exercise a right, contact us at compliance@businessid.eu. We will respond within one month. If the request is complex we may extend this by up to two further months and will tell you why. We may need to confirm your identity first - usually by asking you to authenticate in the app.
If you are unhappy with how we handle your data, you can complain to the data protection authority in the EU or EEA country where you live, where you work, or where you think the problem happened. Our lead authority is the Danish Data Protection Agency (Datatilsynet), Carl Jacobsens Vej 35, 2500 Valby, Denmark - dt@datatilsynet.dk, www.datatilsynet.dk.
12. Changes to this policy
We may update this policy. If a change matters to you, we will tell you in the app or by email at least 30 days before it takes effect, so you can decide whether to keep using BusinessID. The current version is always available in the app and at businessid.eu/privacy-policy.
13. Contact us
Identity Stack A/S, C. A. Olesens Gade 4, 9000 Aalborg, Denmark (CVR no. 42894389).
- Privacy questions, data rights and our Data Protection Officer: compliance@businessid.eu
- Support: support@businessid.eu