IDsig

Privacy policy

Version 1 · 7 October 2026 · applies to the IDsig Android app and the IDsig demonstration.

1. Who we are

IDsig is operated by Alsenet SA, Rue De-Candolle 34, 1205 Geneva, Switzerland (UID CHE-100.482.881). For anything in this policy, write to contact@idsig.app.

2. Two situations, two recipients

The IDsig app is a transport. It captures identity evidence on your phone, at the explicit request of a named organisation, and streams that evidence to that organisation. Who receives your data depends on how you reached the app.

3. What the app collects

Only what the organisation’s request asks for, only after you have seen who is asking and what will be shared, and only once you agree. There is no background or continuous collection.

4. What the app does not do

5. How your data travels and where it is kept

Every item is encrypted on the phone for the specific session, with a key only the receiving server can open, and streamed as it is captured. On the IDsig server, operated by Alsenet SA in Switzerland, the evidence and the resulting verdict are stored encrypted, and every access to a record is written to an append-only log that cannot be edited or deleted.

A financial intermediary may instead operate its own IDsig server. In that case its own policy governs storage, and the registry entry shown to you names it.

6. How long

The app itself retains nothing. The retention period is the organisation’s, and it is shown to you in the app, with its basis, before you agree. For a Swiss financial intermediary this is normally the ten-year record-keeping period of the Anti-Money Laundering Act. The IDsig demonstration currently keeps records for the same ten years.

When a record reaches the end of its period it is marked expired. Destruction is then a deliberate action by the operator, recorded in the access log, never an automatic timer. A record under a legal hold is not destroyed until the hold is lifted.

7. Why this processing is lawful

A financial intermediary identifies you because the Swiss Anti-Money Laundering Act obliges it to. Your approval in the app is how that duty is explained to you and how you decide whether to proceed; it is not a substitute for the duty, and once the transfer starts it cannot be recalled, which the app says before you agree. Where the GDPR applies to you, the same facts apply: the processing serves a legal obligation of the intermediary, and your rights under the GDPR remain.

The IDsig demonstration rests on your consent. You may withdraw it at any time by asking us to erase the record (section 8).

Facial data used to identify a person is sensitive personal data under the Swiss Federal Act on Data Protection and special-category data under the GDPR. It is collected only for the identification you agreed to and for nothing else.

8. Your rights

You may ask for access to your data, for correction, and for erasure. For an identification requested by a financial intermediary, address the request to that intermediary: it holds the record, and it may be required by law to keep it for the period in section 6 even if you ask for erasure. For the demonstration, write to contact@idsig.app; an erasure request is recorded against the record and the record is destroyed unless a legal hold applies.

You may also complain to the Swiss Federal Data Protection and Information Commissioner, or to the supervisory authority of your country where the GDPR applies.

9. Changes

This policy is versioned at the top of the page. A change that affects what is collected or who receives it is reflected in the app’s own consent screens, which always state the recipient, the scope and the retention for the specific request in front of you.