Last updated: 21 July 2026

Privacy Policy — BioSeal Reader

This policy explains how the BioSeal Reader mobile app (identifier eu.id3.bioseal), published by id3 Technologies, processes your data, in compliance with the General Data Protection Regulation (GDPR) and French data protection law.

Core principle — on-device processing: BioSeal Reader is designed so that biometric data and the images it processes are handled exclusively on your device. They are neither transmitted to our servers, nor to third parties, nor permanently stored by the app.

1. Data Controller

The BioSeal Reader app (identifier eu.id3.bioseal) is published by:

id3 Technologies SAS
5 rue de la Verrerie, 38120 Fontanil-Cornillon, France
Website: id3.eu
Data protection: dpo@id3.eu

2. Data We Process

a) Camera images

The app accesses the camera to (i) read BioSeal / VDS codes (QR code, DataMatrix) and (ii) capture the face and/or fingerprints contactlessly for identity verification. These images are processed in real time, in memory, then deleted; they are neither stored nor transmitted.

b) Biometric data from the capture GDPR art. 9

From the images, the app generates biometric templates (mathematical representations of the face / fingerprints). They are compared locally against the data in the presented BioSeal, are ephemeral (kept in memory for the duration of the verification then erased) and never leave the device.

c) Biometric data inside the read BioSeal

A BioSeal / VDS may contain, in its payload (“manifest”), a photo (the holder's portrait) and other biometric data (facial template, fingerprint minutiae). When such a code is read, the app extracts and processes these data locally to perform the verification, and may display the portrait on screen for visual checking. These data remain on the device, for the duration of the consultation, and are neither transmitted nor stored by the app.

d) Device hardware identifier (licence)

To activate the software licence, a technical device identifier (Hardware ID, non-nominative) may be transmitted to id3's licence servers in order to generate and validate the device-bound licence. No biometric data is attached to this exchange.

e) Network connection data

The app may establish network connections for licence activation (see d) and to check the validity / revocation of the certificates (trust lists, CRL/TSL) used to authenticate BioSeals. These exchanges involve technical and cryptographic data, not your personal or biometric data.

3. Purposes & Legal Bases (GDPR)

PurposeLegal basis
Identity verification and BioSeal authentication (core function)Explicit consent (art. 6-1-a and 9-2-a), given when starting a read or a verification
Software licence managementPerformance of the licence contract / legitimate interest
Security and integrity (certificate revocation checking)Legitimate interest

4. Data Retention

Images, extracted portrait and biometric templates Not retained
Licence file Local, while the app is installed

Images, portraits and templates are processed in memory then deleted as soon as the verification / consultation ends. No personal data is stored on our servers as a result of using the app.

5. Sharing with Third Parties

We do not sell and do not share your data for advertising purposes. The only external exchanges are technical:

  • id3 licence servers — transmission of the (non-nominative) hardware identifier.
  • Trust list services — cryptographic data for certificate authentication.

6. Security

Sensitive data is processed locally. Cryptographic keys are protected by the system's secure mechanisms (Android Keystore). Biometric templates and the extracted portrait are not written in clear text to storage. No biometric data or personally identifiable information is written to the logs.

7. Android Permissions

Camera Reading codes and biometric capture
Network / Internet access Licence activation and certificate checking

8. Your Rights (GDPR)

You have the rights of access, rectification, erasure, restriction, objection and portability. Since the app does not retain your biometric data, no such data is held to be erased on the publisher's side.

To exercise your rights, contact dpo@id3.eu. You may also lodge a complaint with the CNIL (cnil.fr) or the competent data protection authority.

9. Children

The app is not intended for children under 15 and does not knowingly collect their data.

10. Changes to This Policy

We may update this policy from time to time. The “last updated” date at the top of the page reflects the current version.

11. Contact

id3 Technologies
France — website: id3technologies.com
E-mail: contact@id3.eu