How IdentiGate OÜ collects, uses, discloses, and protects personal data when you use our digital identity and Advanced Electronic Signature services.
Table of Contents
This Privacy & Cookie Policy (“Policy”) describes how IdentiGate OÜ (“IdentiGate”, “we”, “us”, “our”), a private limited company incorporated under the laws of the Republic of Estonia, collects, uses, discloses, and protects personal data when you use our digital identity and Advanced Electronic Signature services and related platforms.
IdentiGate provides digital identity certificate services that enable individuals to authenticate their identity and create Advanced Electronic Signatures in accordance with Article 26 of Regulation (EU) No 910/2014 (the “eIDAS Regulation”), as amended by Regulation (EU) 2024/1183 (“eIDAS 2.0”). Our services require the collection and processing of identity verification data from government-issued NFC-enabled documents.
This Policy applies to all individuals who use our services, visit our websites, or otherwise interact with IdentiGate. We are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the Estonian Personal Data Protection Act (isikuandmete kaitse seadus, IKS), the eIDAS Regulation, and applicable United States state privacy laws.
The data controller responsible for processing your personal data is:
| Company | IdentiGate OÜ |
| Registry Code | 17384140 |
| Address | Seebi 1-1906, 11316 Tallinn, Estonia |
| privacy@identigate.com | |
| Data Protection Officer | Gustav Poola — dpo@identigate.com |
For matters relating to data protection, including exercising your rights as a data subject, you may contact our Data Protection Officer (Gustav Poola) at dpo@identigate.com.
During the onboarding process, you are required to scan your government-issued NFC-enabled passport or identity card. The document scanning, NFC chip reading, and biometric verification are performed using FaceTec Technology, which IdentiGate operates on its own EU-based infrastructure. No personal data is transmitted to FaceTec, Inc. We collect:
To verify that you are the legitimate holder of the identity document, we process biometric data using liveness detection and facial recognition technology provided by FaceTec, Inc. (“FaceTec”). The FaceTec software is operated by IdentiGate on our own servers — no biometric data or personal data is transmitted to FaceTec. We process:
Payment processing is handled entirely by the Apple App Store and Google Play Store. IdentiGate does not process, store, or have access to your payment card details.
Your Digital Certificate is issued only against a valid identity document and its validity never exceeds the validity of that document, whose expiry date is read from the document’s chip. When your identity document is renewed, renewal of your Digital Certificate requires completing the full onboarding verification again — document verification, liveness detection, and biometric comparison — so that every certificate in your identity’s history carries its own independently verified binding. We record the verification events and results of each issuance as described in Section 7.
We process your personal data only when we have a valid legal basis under applicable law:
| Purpose | Data Categories | Legal Basis (GDPR) |
|---|---|---|
| Identity verification and certificate issuance | Identity data, biometric data | Art. 6(1)(a) Consent; Art. 9(2)(a) Explicit consent for biometric data |
| Managing your account and subscription | Account data, contact details, transaction history | Art. 6(1)(b) Performance of contract |
| Advanced Electronic Signature services | Identity data, certificate records, audit logs | Art. 6(1)(b) Performance of contract |
| Evidencing the validity of issued certificates and signatures (dispute resolution) | Verification records, transaction records | Art. 6(1)(f) Legitimate interest; retention per Art. 17(3)(e) |
| Fraud prevention and security | Technical data, device identifiers, access logs | Art. 6(1)(f) Legitimate interest |
| Customer support and communications | Contact details, communication records | Art. 6(1)(b) Contract; Art. 6(1)(f) Legitimate interest |
| Legal and regulatory compliance | Identity data, transaction records | Art. 6(1)(c) Legal obligation |
The facial biometric data we process constitutes special category data under Article 9 of the GDPR. We process this data only with your explicit consent, provided during the onboarding process before any biometric data is collected.
You may withdraw your consent to biometric processing at any time. Withdrawal will prevent us from providing the digital identity and Advanced Electronic Signature services. Withdrawal does not affect the lawfulness of processing already carried out. Verification records relating to certificates already issued are retained for the period described in Section 7, on the basis of Article 17(3)(e) GDPR (establishment, exercise or defence of legal claims), notwithstanding withdrawal.
Why biometric verification is objectively necessary: Biometric identity verification is not optional — it is the core technical mechanism through which we ensure the person requesting a Digital Certificate is the legitimate holder of the identity document presented. Without biometric liveness verification, the system cannot distinguish a real person from a photograph, video replay, or deepfake attack. This stems from fundamental security obligations under the eIDAS Regulation.
The identity verification process involves automated decision-making, including biometric facial matching and document authenticity checks performed by FaceTec Technology. Legal basis: explicit consent (Article 22(2)(c) GDPR) and necessity for performance of contract (Article 22(2)(a) GDPR).
You have the right to: obtain meaningful information about the logic involved; request human intervention if automated verification fails; and express your point of view and contest any decision. Contact: privacy@identigate.com.
Why we retain verification records. Your Digital Certificate is a long-lived trust anchor: relying parties, courts, and other third parties may — potentially years after issuance — require proof that your identity was correctly verified when a certificate was created or a signature was made. Such proof can only be provided from the records that existed at that time. We therefore retain, for each certificate issuance, the verification record needed to evidence it: the document data read from the chip at onboarding (including the chip serial number), the extracted document data, the facial recording and derived facial map, the liveness and biometric comparison results with processing metadata, and the timestamps and audit trail of the verification events. These records are stored encrypted, protected against tampering, and accessible only for dispute-resolution and audit purposes.
Retention periods:
Upon expiry of the applicable period, records are deleted. Where you delete your account, personal data outside the retained verification records is erased within 30 days.
Pilot phase: the service currently operates as a limited pilot programme (TestFlight). Verification records and certificates created for pilot participants will be deleted when the service transitions to production; participants will be informed in advance and asked to complete onboarding anew under the production service and its then-current policy.
We do not sell your personal data.
Current sub-processors:
| Sub-processor | Purpose | Location / transfer basis |
|---|---|---|
| Hetzner Online GmbH | Hosting and data storage (IdentiGate-operated physical servers) | Germany, EU |
| Cloudflare, Inc. | Network security and reverse proxy for our public website (identigate.com) only — website visits transit and are transiently processed at Cloudflare’s edge (TLS termination for security filtering), and the website origin is not directly reachable from the internet. Service traffic — onboarding, identity verification, and signing between the App and our servers — does not transit Cloudflare. Cloudflare stores no personal data | Global network (Cloudflare, Inc. is US-headquartered); Cloudflare Customer Data Processing Addendum incorporating EU Standard Contractual Clauses |
| Apple Inc. (App Store) / Google LLC (Play Store) | Subscription payment processing | As per store terms |
| Apple Inc. (APNs) / Google LLC (FCM) | Mobile push notifications for authentication and signing requests. The notification is a content-free wake-up signal only — it carries no names, document information, or request content; upon waking, the App retrieves the request directly from IdentiGate’s servers. Only the device push token and the fact that a notification was sent transit Apple/Google. | USA — EU-US Data Privacy Framework (Apple Inc. and Google LLC are certified participants); EU Standard Contractual Clauses as fallback safeguard |
Full list available at privacy@identigate.com.
Embedded Software Components: The App incorporates FaceTec Technology for identity document scanning, NFC chip reading, biometric liveness detection, and facial matching. IdentiGate operates FaceTec software on its own EU-based infrastructure. FaceTec, Inc. does not receive, process, or store any personal data from our users and is not a data processor under the GDPR.
When you use your Digital Certificate with third-party services (“relying parties”), the following is disclosed to that relying party, each for a stated purpose:
We never disclose to relying parties: your biometric data, your identity document images or chip data, your date of birth, your national identity code, or any other attribute content. Relying parties are independent controllers of the data they receive.
We may disclose personal data when required by law, in response to valid legal process, or to protect our legal rights.
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity under the same privacy protections. We will notify you before your data is subject to a different privacy policy.
Your personal data is primarily processed and stored within the EEA on IdentiGate-operated infrastructure. While the App incorporates technology from FaceTec, Inc. (US-based), no personal data is transmitted to FaceTec — all FaceTec software runs on IdentiGate’s own EU infrastructure. Identity, biometric, and signing data is exchanged directly between the App and IdentiGate’s servers in Germany and does not transit Cloudflare. Our public website (identigate.com) is fronted by Cloudflare’s global network: website visits (visitor IP addresses and related technical data) are processed transiently at Cloudflare’s edge for security purposes under Cloudflare’s Customer Data Processing Addendum, which incorporates EU Standard Contractual Clauses given Cloudflare, Inc.’s United States establishment. Cloudflare does not store personal data from our website or services. Push notifications transit Apple and Google as described in Section 8.1. For any other transfers outside the EEA, we implement EU Standard Contractual Clauses.
Residents of California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may also have rights to know, delete, correct, opt out of data sales (we do not sell personal data), and non-discrimination.
Contact us at privacy@identigate.com or use the contact details in Section 2. Response within one month (GDPR) or 45 days (U.S. state law), extendable for complex requests.
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee, or the supervisory authority in your EU member state of habitual residence or place of work.
We have conducted a DPIA in accordance with Article 35 of the GDPR, evaluating necessity, proportionality, risks, and safeguards for our biometric and automated processing activities. Reviewed periodically. Summary available at dpo@identigate.com.
Where required by law, we obtain your consent before placing non-essential cookies. Manage preferences through the cookie settings link in our website footer.
For users under 18: verifiable parental or legal guardian consent is required before collecting any personal data; the parent or guardian may exercise all data subject rights on the minor’s behalf; enhanced data protection safeguards apply.
When we make material changes: at least 30 days’ prior notice via email and/or the App; updated Policy posted with a new Effective Date; renewed consent sought where required for changes to biometric processing.
This Privacy & Cookie Policy forms part of the contractual framework between you and IdentiGate, together with the Terms and Conditions, the User Consent for Data Processing, and the User Agreement. This Policy prevails on all matters relating to personal data. On all other matters, the Terms and Conditions prevail.
| Company | IdentiGate OÜ |
| Address | Seebi 1-1906, 11316 Tallinn, Estonia |
| General Privacy | privacy@identigate.com |
| Data Protection Officer | Gustav Poola — dpo@identigate.com |
| General Support | support@identigate.com |
| Phone | +372 5860 8191 |