Your privacy is important

Siip's solutions are privacy by design and privacy by default, thanks to principles like data minimization and data decentralization. This is how we protect your privacy. There has been a lot of focus on privacy and digital security lately, and rightly so. Your privacy is important. At Siip, we are committed to this every single day.

In early July 2026, claims were published on LinkedIn and various blogs regarding how Siip technology functions within Personal Digital Access (PDA) for professional football organizations. The central claims in these publications are factually incorrect. Siip previously issued a brief statement on this matter. We provide further clarification below.

The author claimed that Siip sends an identity profile containing personal data from the document and stores it server-side, but this conclusion and all subsequent conclusions based on it are incorrect.

We perform an authenticity check according to ICAO 9303

Are you using your driver's license, ID card, or passport to register your identity? If so, a cryptographic authenticity check is performed in accordance with the ICAO 9303 standard. This check, also known as 'passive authentication', takes place on the server and confirms that the document and the data are genuine and have not been tampered with. This is a technically necessary and standard step in document verification to prevent fraud and abuse.

A Siip user account

‍‍An account is created using an email address to enable us to provide our services. By doing so, the user accepts Siip's terms and conditions. The user's email address is stored securely on the server.

It works like this: Once a document has been verified as authentic, a Siip user account is created. The verified personal data is then stored decentrally on the user's own phone.

In short, there is no storage of this personal data on a server; this data resides exclusively on the user's phone. The data is stored decentrally on the user's phone, encrypted via a private key linked to your device, and this key never leaves the phone.

Data minimization and data decentralization

Siip stands for data minimization and data decentralization. We apply these principles to our technology and services. As stated in our privacy policy: what is yours, stays yours. Siip stores your data securely on your own phone. You decide when and with whom you share it.

Let's get specific. How does it work if, for example, I use a trusted by Siip app for Personal Digital Access to a stadium?

To create a personal account based on your identity document, you register once. It is quick and easy. You can use your valid driver's license, ID card, or passport. Your personal data is stored encrypted in a digital vault on your phone, not in a central database.

Only when you accept a ticket, for example, do you give permission to share specific data from the app with the Professional Football Organization (BVO). You can see exactly which data is involved in the app before you accept the ticket. This includes your first and last name, preferred name, photo, date of birth, and email address. In this context, 'sharing' means that the BVO is granted access to this data. Siip acts as the data processor, and the BVO is the data controller. This data is automatically deleted no later than 30 days after the event.

App stability and performance

To ensure the stability and security of our apps, we log crashes and errors. No personal data from identity documents is processed for this purpose. This tooling is used solely for app performance and maintenance, not for advertising or tracking users.

DPIA and privacy policy

Siip has prepared a Data Protection Impact Assessment (DPIA) that covers our services. This assessment maps out what the processing entails and why it is necessary, the risks it poses to data subjects, and the measures taken to mitigate those risks.

Publishing a DPIA is not mandatory, nor is it standard practice. The result of a DPIA is the privacy policy, which is a public document. You can find the privacy policy in all our apps and on our website.

Diligence

Transparency regarding the processing of personal data and the security of our infrastructure is our top priority. It is crucial for our services to undergo independent audits to evaluate and, where necessary, improve our processes.

In light of the public discussion, we are having our working methods validated by an independent, authoritative party through an objective technical audit.

In addition, we value the efforts of security researchers and ethical hackers who help us identify and report potential vulnerabilities in a responsible manner. You can do this via our responsible disclosure process.

Do you have questions for our Data Protection Officer?

Feel free to send an email to privacy@siip.group.

Do you have any questions about this post?

Please contact us at info@siip.group.