Privacy Statement

Table of contents

1. Introduction

This Privacy Statement is relevant for visitors of our website and (future) users of Vidua. We highly value your ease and convenience while making use of Vidua and in order to provide optimal security we handle your personal data with utmost care, integrity and transparency. With this Privacy Statement we would like to inform you about which data we collect, how we collect your data (directly or indirectly), why we collect your data (for which purposes), on the basis of which principles (lawfulness) and how we further handle your data.

2. Who are we?

Cleverbase ID B.V. (hereafter: Vidua or We), an ETSI/eIDAS accredited Qualified Trust Service Provider under the supervision of Radiocommunications Agency. We are located at Maanweg 174, 2516 AB in Hague, the Netherlands, and registered in the Chamber of Commerce (Kamer van Koophandel), registration number 67419925. Vidua also is the brand name and trademark under which We deliver the services to you as a user.

3. Which personal data do we process?

We process the following personal data in order to offer our products and services:

Vidua has no legal basis for processing your citizen service number (=BSN) and does not want to do that either. Therefore, ensure that the citizen service number is covered during the registration process. The citizen service number (BSN) can be found in various places on the Dutch passport and on the Dutch identity card. Depending on your model, it can be found on the back of the plastic card under the title “persoonsnummer”; and behind a readable QR code on the back of the plastic card of the passport or the back of the identity card. Tape the BSN in these places, for example with opaque tape.

For some models, the citizen service number is also located in the MRZ (= Machine Readable Zone), the two lines of text at the bottom of the front of the plastic card of the passport or the three lines of text on the back of the identity card. This entire code must be readable when the photo is being scanned with the app. We mask the citizen service number ourselves with an overlay, so that we do not save it. After the photo scan, we ask you to tape the citizen service number in the MRZ, because we cannot mask it during the video.

4. How and for what purpose do we use your data?

We use this data to be able to properly carry out the application procedure.

4.1 Registration at Vidua

We collect the following data:

  • Identity details
  • Technical details
  • Contact details

To register you as a new client, we use your identity and contact details to lawfully and correctly determine and confirm your identity. We need the above mentioned data to comply with Dutch Identification legislation. We use technical details to maintain and optimize the registration process.

4.2 Mobile application use

We collect the IP address to make statistical analyzes about the use of the Vidua app using Firebase Analytics. The last eight numbers of the IP address are masked and no other personal data is shared. Vidua has concluded a data processing agreement with Firebase Analytics and does not use other statistical analysis services for application use in combination with Firebase Analytics.

Since we like to help everyone to register with Vidua, customer service can contact you by email (one time) if you have not yet completed your registration attempt, but can still complete it.

4.3 Signing with Vidua

Vidua shares the following data with the (third party) signature application used by you for the signing process:

  • Signing certificate
    • Public key
    • Full name end-user

These details are needed by your (third party) signature application, so you can use Signing with Vidua.

4.4 Identity Federation by Vidua

Vidua creates, stores and shares the following data:

  • The identity attributes that you have consented to share.
  • A consent statement signed by you stating that you consent to sharing your personal data with the requesting third party. The consent contains information on which data you share with whom and for what purpose.

These details are used for sharing certain identity attributes with requesting third parties, so you can make use of Identity Federation by Vidua.

5. Lawfulness of processing

Organisations are only allowed to process personal data if they have a basis for doing so. The General Data Protection Regulation (GDPR) lists six possible lawful bases. We use four of these bases for our various processing operations:

6. Storage period of the data

We do not store your personal data for longer than strictly necessary for the purpose for which we obtained it. We base this assessment on the type of personal data, the product or service for which we have obtained the data, and what you, as the data subject, can reasonably expect as a retention period.

For the personal data that are processed to lawfully determine and confirm your identification, we use a retention period of maximum ten years: we store your personal data for as long as your certificate is valid, maximum three years, and on top of that seven more years based on legislation after the expiration date of the certificate.

7. Data security

We do everything to offer optimal data security and to secure your personal data against loss and illegitimate usage. All employees of Vidua who have knowledge of personal data in the context of their duties are obliged to maintain confidentiality. Your personal data will only be shared with third parties in case of necessity with regard to above mentioned purposes. Vidua has been evaluated by an independent auditor and is ISO27001 certified. ISO27001 is the standard for information security.

8. Your rights

Based on the General Data Protection Regulation, you are entitled to the following rights:

In case you would like to know which of your personal data We process and for which purposes, or in case you would like to invoke one of the above mentioned rights, please get in touch with us via klantenservice@vidua.nl. We will inform you as soon as possible about your request.

9. Recipients of your personal data

The following persons and/or authorities possibly have access to your personal data:

10. Questions

In case of any questions related to the way we handle your privacy or in case you would like to invoke one or more of your rights as mentioned above, please get in touch with us via email klantenservice@vidua.nl, via post “Maanweg 174, 2516 AB Hague, the Netherlands” or via phone: +31 70 820 96 80.

11. Revisions

We are entitled to revise our Privacy Statement at any given moment. We will announce this revision via our website. In case we want to radically change the underlying principles, we will actively reach out to you.

12. Dutch Data Protection Authority

We would like to support you in case you have a complaint regarding the processing of your personal data. Based on privacy legislation, you can file a complaint with the Dutch Data Protection Authority about the processing of your personal data. This is possible via the website of the Dutch Data Protection Authority: https://www.autoriteitpersoonsgegevens.nl/en.