Privacy Policy
Welcome to Digital Partners Yazılım Ltd Şti. We prioritize client’s privacy and are committed to protecting our clients’ personal information. This Privacy Policy describes how we collect, use, and safeguard data in connection with our digital identity verification and authentication services. By using our services, clients agree to the terms outlined in this policy.
Privacy Policy
1. Introduction
Digital Partners Yazılım Ltd Şti (“Digital Partners Yazılım Ltd Şti”, “we”, “us”) provides Mobile ID, a digital identity platform enabling citizens to authenticate, authorise payments, give electronic consent, sign documents and verify their identity through their mobile device.
We take privacy seriously by design. Mobile ID is built on a sovereign deployment model: citizen identity data resides in infrastructure owned and controlled by the government of the country of deployment, and Digital Partners Yazılım Ltd Şti does not have independent access to it.
This Privacy Policy explains how personal data is processed in connection with the Mobile ID platform and the Digital Partners Yazılım Ltd Şti website. It applies alongside the privacy notices issued by the relevant government authority in each country where Mobile ID is deployed.
2. Our Role: Sub-Processor, Not Data Controller
Understanding who is responsible for your data is fundamental to how Mobile ID works:
- Data Controller: The government authority of the country of deployment (or the ministry or agency it designates) determines why and how citizen data is processed. It is the primary point of accountability for citizens’ personal data.
- Processors: Ministries and agencies allocated by the data controller may process data on its behalf for the operation of national services.
- Digital Partners Yazılım Ltd Şti (Processor / Sub-Processor): We process personal data solely on the documented instructions of the data controller, to deliver, operate, maintain and support the Mobile ID platform. We do not use citizen data for our own purposes, and we process limited data for testing purposes only with the controller’s written permission.
Where citizens wish to exercise rights over their personal data, the data controller is the correct first point of contact. We provide the controller with all assistance necessary to respond (see Section 10).
3. Personal Data We Might Process with Permission
3.1 Identity and contact data
- Identity information: Full name, national identification number, date of birth and other identifiers required for identity verification, as defined by the data controller.
- Contact information: Email address and mobile phone number, where provided.
3.2 Biometric and enrolment data
Biometric data (such as facial images or fingerprints) used for enrolment is captured, stored and matched by the relevant government identity authority within its own systems. Digital Partners Yazılım Ltd Şti does not collect, store or retain biometric templates.
3.3 Cryptographic keys
Mobile ID is built so that the citizen’s private signing key is generated and held on the citizen’s own device, protected by hardware-backed secure storage. Digital Partners Yazılım Ltd Şti never holds, transmits or has access to a citizen’s private key. This is a deliberate design decision: it means no one — including us — can sign or authenticate on your behalf.
3.4 Device and technical data
- Device information: IP address, device type and model, operating system and version, and app version, used to ensure security, performance and compatibility.
- Usage and log data: System and transaction logs (for example, the time and outcome of an authentication event) recorded for security monitoring, auditing and service reliability. Logs record that an event occurred — not the content of the documents or services you access.
4. Why We Process Data, and On What Basis
We process data strictly in line with the instructions of the data controller and applicable law, for the following purposes:
The legal basis for processing citizen data is established by the data controller under the law of the country of deployment — typically the performance of a public task, legal obligation, or the citizen’s consent, depending on the service.
5. What We Never Do with Your Data we Process
- We do not sell personal data to anyone, for any purpose.
- We do not use personal data for advertising or marketing.
- We do not build profiles of citizens’ behaviour across the services they use.
- We do not access citizen data held in government infrastructure except as instructed by the data controller for support and maintenance, under logged and auditable access.
6. Data Sharing and Sub-Processors
We share data only as instructed by the data controller and where required by law:
- Service providers: Vetted providers who help us develop, operate and maintain the platform. Each is bound by written confidentiality and data processing obligations, may use data only to perform their contracted services, and is engaged as a sub-processor only with the data controller’s authorisation.
- Government authorities: Ministries, agencies and approved relying parties designated by the data controller, to deliver the services citizens request.
- Legal requirements: Regulators, courts or law enforcement where disclosure is required by law, or where necessary to protect our legal rights or address misuse of the platform.
7. International Data Transfers
Under the sovereign deployment model, citizen identity data is hosted within infrastructure designated by the data controller, normally within the country of deployment. Where any personal data must be transferred across borders — for example, limited technical support data — we do so only with the data controller’s authorisation and with appropriate safeguards, such as contractual data protection clauses, in place.
8. Data Retention
Retention periods for citizen identity data are set by the data controller in accordance with the law of the country of deployment. Data we process in our own systems is kept only as long as necessary for the purposes described in this policy:
- Technical and security logs: Retained for the period required for security monitoring, auditing and legal compliance, then deleted or anonymised.
- Testing data: Processed only with the controller’s permission and deleted or anonymised when testing concludes.
- End of contract: On termination of our engagement, data is returned to the data controller or securely destroyed, at the controller’s instruction.
9. How We Protect Data
- Encryption: Data is encrypted in transit (TLS) and at rest.
- Device-bound keys: Citizens’ private keys are generated and stored in hardware-backed secure storage on their own device and never leave it.
- PKI-based trust: Authentication and signing are based on X.509 public key infrastructure, providing verifiable, certificate-based trust.
- Access controls: Access to systems and data is restricted to authorised personnel on a need-to-know basis, with strong authentication and full audit logging.
- Secure development and operations: Security testing, vulnerability management and secure data centres protect the platform throughout its lifecycle.
No system can guarantee absolute security, but security is engineered into Mobile ID at every layer, and we review our measures continually against evolving threats.
10. Data Breach Notification
If we become aware of a personal data breach affecting data we process, we will notify the data controller without undue delay, provide the information needed to assess and contain the breach, and support any notification to affected individuals or regulators that the controller is required to make under applicable law.
11. Your Rights
Citizens have rights over their personal data under the law of the country of deployment, exercisable through the data controller and its designated agencies. Depending on applicable law, these typically include the right to:
- Access: Obtain a copy of the personal data held about you.
- Rectification: Have inaccurate or incomplete data corrected.
- Erasure: Request deletion of your data, subject to legal retention requirements.
- Restriction and objection: Restrict or object to certain processing activities.
- Withdraw consent: Withdraw consent at any time, where processing is based on consent.
- Complain: Lodge a complaint with the data protection authority in your country.
If you contact us directly with a request concerning citizen data, we will refer it to the relevant data controller and assist in responding.
12. Children
Eligibility for Mobile ID, including any minimum age and the conditions under which minors may be enrolled, is determined by the data controller under national law. We do not knowingly process children’s data outside those conditions.
13. Cookies and Similar Technologies
Our website uses cookies and similar technologies to keep the site working securely, remember preferences and understand how the site is used so we can improve it. You can manage or disable cookies through your browser settings; disabling essential cookies may affect site functionality. The Mobile ID application itself does not use advertising or third-party tracking cookies.
14. Legal Framework
Digital Partners Yazılım Ltd Şti is established in Türkiye and complies with the Turkish Law on the Protection of Personal Data (KVKK, Law No. 6698). For each Mobile ID deployment, the processing of citizen data is governed by the data protection law of the country of deployment and the data processing terms agreed with the data controller. Our practices are aligned with internationally recognised data protection principles, including lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on our website with an updated effective date, and material changes will be highlighted. We encourage you to review this policy periodically.
16. Contact Us
For questions about this Privacy Policy or our data practices:
Digital Partners Yazılım Ltd Şti
Sultan Selim Mah. Eski Buyukdere Cad. No: 61, İç Kapı No: 1, Kağıthane 34415, Istanbul, Türkiye
