HomePrivacy & Cookie Policy

Privacy & Cookie Policy

How IdentiGate OÜ collects, uses, discloses, and protects personal data when you use our digital identity and Advanced Electronic Signature services.

Effective Date: 1 September 2026·Version 2.1·Document Owner: IdentiGate OÜ  ·  Registry Code: 17384140
Download full policy (PDF)

Table of Contents

  1. Introduction and Scope
  2. Data Controller and Contact Details
  3. Personal Data We Collect
  4. Purposes and Legal Bases for Processing
  5. Special Categories of Data (Biometric Data)
  6. Automated Decision-Making and Profiling
  7. Data Retention
  8. Data Sharing and Disclosure
  9. International Data Transfers
  10. Your Rights
  11. Security of Your Data
  12. Data Breach Notification
  13. Data Protection Impact Assessment
  14. Cookies and Similar Technologies
  15. Children's Privacy
  16. Changes to This Policy
  17. Document Hierarchy
  18. Contact Us

1. Introduction and Scope

This Privacy & Cookie Policy (“Policy”) describes how IdentiGate OÜ (“IdentiGate”, “we”, “us”, “our”), a private limited company incorporated under the laws of the Republic of Estonia, collects, uses, discloses, and protects personal data when you use our digital identity and Advanced Electronic Signature services and related platforms.

IdentiGate provides digital identity certificate services that enable individuals to authenticate their identity and create Advanced Electronic Signatures in accordance with Article 26 of Regulation (EU) No 910/2014 (the “eIDAS Regulation”), as amended by Regulation (EU) 2024/1183 (“eIDAS 2.0”). Our services require the collection and processing of identity verification data from government-issued NFC-enabled documents.

This Policy applies to all individuals who use our services, visit our websites, or otherwise interact with IdentiGate. We are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the Estonian Personal Data Protection Act (isikuandmete kaitse seadus, IKS), the eIDAS Regulation, and applicable United States state privacy laws.

2. Data Controller and Contact Details

The data controller responsible for processing your personal data is:

CompanyIdentiGate OÜ
Registry Code17384140
AddressSeebi 1-1906, 11316 Tallinn, Estonia
Emailprivacy@identigate.com
Data Protection OfficerGustav Poola — dpo@identigate.com

For matters relating to data protection, including exercising your rights as a data subject, you may contact our Data Protection Officer (Gustav Poola) at dpo@identigate.com.

3. Personal Data We Collect

3.1 Identity Verification Data (from NFC-Enabled Documents)

During the onboarding process, you are required to scan your government-issued NFC-enabled passport or identity card. The document scanning, NFC chip reading, and biometric verification are performed using FaceTec Technology, which IdentiGate operates on its own EU-based infrastructure. No personal data is transmitted to FaceTec, Inc. We collect:

  • Full name (first name, middle name where applicable, and last name)
  • Date of birth
  • National identity code (where available and applicable)
  • Document number
  • Document expiry date (which also bounds the validity of your Digital Certificate — see Section 3.6)
  • NFC chip serial number
  • The facial image stored on your document’s chip, retained within your verification record (see Section 7), and the facial biometric template derived from it

3.2 Biometric Verification Data

To verify that you are the legitimate holder of the identity document, we process biometric data using liveness detection and facial recognition technology provided by FaceTec, Inc. (“FaceTec”). The FaceTec software is operated by IdentiGate on our own servers — no biometric data or personal data is transmitted to FaceTec. We process:

  • Live facial biometric data captured via your device camera, from which a facial representation is derived and compared against the facial image read from your document’s NFC chip
  • Liveness detection data (to confirm the presence of a real, live person and exclude photographs, replays, and synthetic media)
The facial recording captured during onboarding and the three-dimensional facial map derived from it are retained, in encrypted form, as part of your verification record (see Section 7). They serve a single purpose: evidencing — including in the event of a later dispute — that the person to whom a certificate was issued was verified as the legitimate holder of the identity document at the time of issuance. They are never used for any other purpose, never disclosed to relying parties, and are accessible only under the restricted conditions described in Sections 7 and 11.

3.3 Account and Service Data

  • Email address and contact information
  • Account credentials (passwords stored only in hashed form)
  • Certificate subscription details and transaction history
  • Digital certificate metadata (issuance date, validity period, certificate serial number)
  • Your IdentiGate user identifier — an opaque reference number (GUID) we assign to your identity to maintain accurate records and to allow relying parties to reference your authentication events without receiving your national identity code or other attribute content (see Section 8.2)

3.4 Technical and Usage Data

  • Device identifiers and operating system information
  • IP addresses and approximate geographic location
  • Service access logs and authentication timestamps
  • Browser type and language preferences

3.5 Payment Information

Payment processing is handled entirely by the Apple App Store and Google Play Store. IdentiGate does not process, store, or have access to your payment card details.

3.6 Certificate Lifecycle Data

Your Digital Certificate is issued only against a valid identity document and its validity never exceeds the validity of that document, whose expiry date is read from the document’s chip. When your identity document is renewed, renewal of your Digital Certificate requires completing the full onboarding verification again — document verification, liveness detection, and biometric comparison — so that every certificate in your identity’s history carries its own independently verified binding. We record the verification events and results of each issuance as described in Section 7.

4. Purposes and Legal Bases for Processing

We process your personal data only when we have a valid legal basis under applicable law:

Purpose Data Categories Legal Basis (GDPR)
Identity verification and certificate issuance Identity data, biometric data Art. 6(1)(a) Consent; Art. 9(2)(a) Explicit consent for biometric data
Managing your account and subscription Account data, contact details, transaction history Art. 6(1)(b) Performance of contract
Advanced Electronic Signature services Identity data, certificate records, audit logs Art. 6(1)(b) Performance of contract
Evidencing the validity of issued certificates and signatures (dispute resolution) Verification records, transaction records Art. 6(1)(f) Legitimate interest; retention per Art. 17(3)(e)
Fraud prevention and security Technical data, device identifiers, access logs Art. 6(1)(f) Legitimate interest
Customer support and communications Contact details, communication records Art. 6(1)(b) Contract; Art. 6(1)(f) Legitimate interest
Legal and regulatory compliance Identity data, transaction records Art. 6(1)(c) Legal obligation

5. Special Categories of Data (Biometric Data)

The facial biometric data we process constitutes special category data under Article 9 of the GDPR. We process this data only with your explicit consent, provided during the onboarding process before any biometric data is collected.

Important: The biometric data captured during onboarding — the facial recording, the derived facial map, and biometric templates — is retained in encrypted form solely as part of your verification record, for the evidentiary purpose and period described in Section 7. It is never used for any other purpose, never shared with relying parties or any third party, and is protected by the safeguards described in Section 11. All biometric processing takes place exclusively on IdentiGate’s own EU infrastructure.

You may withdraw your consent to biometric processing at any time. Withdrawal will prevent us from providing the digital identity and Advanced Electronic Signature services. Withdrawal does not affect the lawfulness of processing already carried out. Verification records relating to certificates already issued are retained for the period described in Section 7, on the basis of Article 17(3)(e) GDPR (establishment, exercise or defence of legal claims), notwithstanding withdrawal.

Why biometric verification is objectively necessary: Biometric identity verification is not optional — it is the core technical mechanism through which we ensure the person requesting a Digital Certificate is the legitimate holder of the identity document presented. Without biometric liveness verification, the system cannot distinguish a real person from a photograph, video replay, or deepfake attack. This stems from fundamental security obligations under the eIDAS Regulation.

6. Automated Decision-Making and Profiling

The identity verification process involves automated decision-making, including biometric facial matching and document authenticity checks performed by FaceTec Technology. Legal basis: explicit consent (Article 22(2)(c) GDPR) and necessity for performance of contract (Article 22(2)(a) GDPR).

You have the right to: obtain meaningful information about the logic involved; request human intervention if automated verification fails; and express your point of view and contest any decision. Contact: privacy@identigate.com.

7. Data Retention

Why we retain verification records. Your Digital Certificate is a long-lived trust anchor: relying parties, courts, and other third parties may — potentially years after issuance — require proof that your identity was correctly verified when a certificate was created or a signature was made. Such proof can only be provided from the records that existed at that time. We therefore retain, for each certificate issuance, the verification record needed to evidence it: the document data read from the chip at onboarding (including the chip serial number), the extracted document data, the facial recording and derived facial map, the liveness and biometric comparison results with processing metadata, and the timestamps and audit trail of the verification events. These records are stored encrypted, protected against tampering, and accessible only for dispute-resolution and audit purposes.

Retention periods:

  • Identity verification records and certificate data: lifetime of the certificate plus 7 years (Estonian accounting and commercial law; evidentiary requirements for electronic signatures)
  • Biometric verification data (facial recording, facial map, biometric templates): retained encrypted as part of the verification record for the same period as identity verification records — lifetime of the certificate plus 7 years. Biometric data not forming part of a verification record is deleted within 30 days of account deletion.
  • Account information: while active and for 7 years thereafter (Estonian Accounting Act, Äriseadustik)
  • Technical logs: 12 months for security, troubleshooting, and fraud prevention
  • Communication records: 3 years from the date of communication

Upon expiry of the applicable period, records are deleted. Where you delete your account, personal data outside the retained verification records is erased within 30 days.

Pilot phase: the service currently operates as a limited pilot programme (TestFlight). Verification records and certificates created for pilot participants will be deleted when the service transitions to production; participants will be informed in advance and asked to complete onboarding anew under the production service and its then-current policy.

8. Data Sharing and Disclosure

We do not sell your personal data.

8.1 Sub-Processors

Current sub-processors:

Sub-processor Purpose Location / transfer basis
Hetzner Online GmbH Hosting and data storage (IdentiGate-operated physical servers) Germany, EU
Cloudflare, Inc. Network security and reverse proxy for our public website (identigate.com) only — website visits transit and are transiently processed at Cloudflare’s edge (TLS termination for security filtering), and the website origin is not directly reachable from the internet. Service traffic — onboarding, identity verification, and signing between the App and our servers — does not transit Cloudflare. Cloudflare stores no personal data Global network (Cloudflare, Inc. is US-headquartered); Cloudflare Customer Data Processing Addendum incorporating EU Standard Contractual Clauses
Apple Inc. (App Store) / Google LLC (Play Store) Subscription payment processing As per store terms
Apple Inc. (APNs) / Google LLC (FCM) Mobile push notifications for authentication and signing requests. The notification is a content-free wake-up signal only — it carries no names, document information, or request content; upon waking, the App retrieves the request directly from IdentiGate’s servers. Only the device push token and the fact that a notification was sent transit Apple/Google. USA — EU-US Data Privacy Framework (Apple Inc. and Google LLC are certified participants); EU Standard Contractual Clauses as fallback safeguard

Full list available at privacy@identigate.com.

Embedded Software Components: The App incorporates FaceTec Technology for identity document scanning, NFC chip reading, biometric liveness detection, and facial matching. IdentiGate operates FaceTec software on its own EU-based infrastructure. FaceTec, Inc. does not receive, process, or store any personal data from our users and is not a data processor under the GDPR.

8.2 Relying Parties

When you use your Digital Certificate with third-party services (“relying parties”), the following is disclosed to that relying party, each for a stated purpose:

  • Your document-verified full name — so the relying party can identify you with the assurance of a state-issued identity document rather than self-declared information;
  • Certificate validity information and the signature/authentication result — the proof of the event itself;
  • Your IdentiGate user identifier (GUID) — an opaque reference number allowing the relying party to keep accurate records and distinguish persons with identical names, without receiving your national identity code.

We never disclose to relying parties: your biometric data, your identity document images or chip data, your date of birth, your national identity code, or any other attribute content. Relying parties are independent controllers of the data they receive.

8.3 Legal and Regulatory Authorities

We may disclose personal data when required by law, in response to valid legal process, or to protect our legal rights.

8.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity under the same privacy protections. We will notify you before your data is subject to a different privacy policy.

9. International Data Transfers

Your personal data is primarily processed and stored within the EEA on IdentiGate-operated infrastructure. While the App incorporates technology from FaceTec, Inc. (US-based), no personal data is transmitted to FaceTec — all FaceTec software runs on IdentiGate’s own EU infrastructure. Identity, biometric, and signing data is exchanged directly between the App and IdentiGate’s servers in Germany and does not transit Cloudflare. Our public website (identigate.com) is fronted by Cloudflare’s global network: website visits (visitor IP addresses and related technical data) are processed transiently at Cloudflare’s edge for security purposes under Cloudflare’s Customer Data Processing Addendum, which incorporates EU Standard Contractual Clauses given Cloudflare, Inc.’s United States establishment. Cloudflare does not store personal data from our website or services. Push notifications transit Apple and Google as described in Section 8.1. For any other transfers outside the EEA, we implement EU Standard Contractual Clauses.

10. Your Rights

10.1 Rights Under the GDPR (EEA Residents)

  • Right of access — obtain a copy of your personal data (Article 15)
  • Right to rectification — correct inaccurate personal data (Article 16)
  • Right to erasure — deletion in certain circumstances; erasure of identity records results in termination of services; verification records within their retention period are retained for the establishment, exercise or defence of legal claims (Article 17, incl. Article 17(3)(e))
  • Right to restriction — limit processing in certain circumstances (Article 18)
  • Right to data portability — receive data in a machine-readable format (Article 20)
  • Right to object — object to processing based on legitimate interests (Article 21)
  • Right to withdraw consent — at any time, without affecting prior lawful processing (Article 7(3))
  • Rights related to automated decision-making — obtain human intervention (Article 22; see Section 6)

10.2 Rights Under U.S. State Privacy Laws

Residents of California, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may also have rights to know, delete, correct, opt out of data sales (we do not sell personal data), and non-discrimination.

10.3 Exercising Your Rights

Contact us at privacy@identigate.com or use the contact details in Section 2. Response within one month (GDPR) or 45 days (U.S. state law), extendable for complex requests.

10.4 Right to Lodge a Complaint

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at aki.ee, or the supervisory authority in your EU member state of habitual residence or place of work.

11. Security of Your Data

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Two-party key architecture: your signing capability is protected by a scheme in which two independent keys are generated separately on your device and within IdentiGate’s infrastructure, and each authentication or signature requires both — no single party, including IdentiGate, ever holds a complete signing key, so neither a compromise of our infrastructure alone nor loss of your device alone enables misuse of your identity
  • PIN protection of certificate functions on your device
  • IdentiGate-operated physical servers in secure, access-controlled EU data centres, shielded from direct internet access
  • Verification records stored encrypted and tamper-protected, with access restricted to dispute-resolution and audit purposes
  • Role-based access controls and principle of least privilege
  • Regular security assessments and vulnerability management
  • Employee security training and confidentiality obligations
  • Incident response and data breach notification procedures
  • Business continuity and disaster recovery planning

12. Data Breach Notification

  • Notification to the Estonian Data Protection Inspectorate within 72 hours (Article 33 GDPR)
  • Notification to affected individuals without undue delay where the breach poses high risk (Article 34 GDPR)
  • Internal breach register maintained including effects and remedial actions

13. Data Protection Impact Assessment

We have conducted a DPIA in accordance with Article 35 of the GDPR, evaluating necessity, proportionality, risks, and safeguards for our biometric and automated processing activities. Reviewed periodically. Summary available at dpo@identigate.com.

14. Cookies and Similar Technologies

  • Strictly necessary cookies — essential for website operation; cannot be disabled
  • Functional cookies — remember your preferences and settings
  • Analytics cookies — help us understand how visitors interact with our website

Where required by law, we obtain your consent before placing non-essential cookies. Manage preferences through the cookie settings link in our website footer.

15. Children’s Privacy

For users under 18: verifiable parental or legal guardian consent is required before collecting any personal data; the parent or guardian may exercise all data subject rights on the minor’s behalf; enhanced data protection safeguards apply.

16. Changes to This Policy

When we make material changes: at least 30 days’ prior notice via email and/or the App; updated Policy posted with a new Effective Date; renewed consent sought where required for changes to biometric processing.

17. Document Hierarchy

This Privacy & Cookie Policy forms part of the contractual framework between you and IdentiGate, together with the Terms and Conditions, the User Consent for Data Processing, and the User Agreement. This Policy prevails on all matters relating to personal data. On all other matters, the Terms and Conditions prevail.

18. Contact Us

CompanyIdentiGate OÜ
AddressSeebi 1-1906, 11316 Tallinn, Estonia
General Privacyprivacy@identigate.com
Data Protection OfficerGustav Poola — dpo@identigate.com
General Supportsupport@identigate.com
Phone+372 5860 8191