Siip's solutions are privacy by design and privacy by default, thanks to principles like data minimization and data decentralization. This is how we protect your privacy. There has been a lot of focus on privacy and digital security lately, and rightly so. Your privacy is important. At Siip, we are committed to this every single day.
Are you using your driver's license, ID card, or passport to register your identity? If so, a cryptographic authenticity check is performed in accordance with the ICAO 9303 standard. This check, also known as 'passive authentication', takes place on the server and confirms that the document and the data are genuine and have not been tampered with. This is a technically necessary and standard step in document verification to prevent fraud and abuse.
An account is created using an email address to enable us to provide our services. By doing so, the user accepts Siip's terms and conditions. The user's email address is stored securely on the server.
It works like this: Once a document has been verified as authentic, a Siip user account is created. The verified personal data is then stored decentrally on the user's own phone.
In short, there is no storage of this personal data on a server; this data resides exclusively on the user's phone. The data is stored decentrally on the user's phone, encrypted via a private key linked to your device, and this key never leaves the phone.
Siip stands for data minimization and data decentralization. We apply these principles to our technology and services. As stated in our privacy policy: what is yours, stays yours. Siip stores your data securely on your own phone. You decide when and with whom you share it.
To create a personal account based on your identity document, you register once. It is quick and easy. You can use your valid driver's license, ID card, or passport. Your personal data is stored encrypted in a digital vault on your phone, not in a central database.
Only when you accept a ticket, for example, do you give permission to share specific data from the app with the Professional Football Organization (BVO). You can see exactly which data is involved in the app before you accept the ticket. This includes your first and last name, preferred name, photo, date of birth, and email address. In this context, 'sharing' means that the BVO is granted access to this data. Siip acts as the data processor, and the BVO is the data controller. This data is automatically deleted no later than 28 days after the event.
To ensure the stability and security of our apps, we log crashes and errors. No personal data from identity documents is processed for this purpose. This tooling is used solely for app performance and maintenance, not for advertising or tracking users.
Siip has prepared a Data Protection Impact Assessment (DPIA) that covers our services. This assessment maps out what the processing entails and why it is necessary, the risks it poses to data subjects, and the measures taken to mitigate those risks.
Publishing a DPIA is not mandatory, nor is it standard practice. The result of a DPIA is the privacy policy, which is a public document. You can find the privacy policy in all our apps and on our website.
Transparency regarding the processing of personal data and the security of our infrastructure is our top priority. It is crucial for our services to undergo independent audits to evaluate and, where necessary, improve our processes.
In light of the public discussion, we are having our working methods validated by an independent, authoritative party through an objective technical audit.
In addition, we value the efforts of security researchers and ethical hackers who help us identify and report potential vulnerabilities in a responsible manner. You can do this via our responsible disclosure process.
Feel free to send an email to privacy@siip.group.
Please contact us at info@siip.group.
In early July 2026, claims were published on LinkedIn and various blogs regarding how Siip technology functions within Personal Digital Access (PDA) for professional football organizations. The central claims in these publications are factually incorrect. Siip previously issued a brief statement on this matter. We provide further clarification below.
The author claimed that Siip sends an identity profile containing personal data from the document and stores it server-side, but this conclusion and all subsequent conclusions based on it are incorrect.
Your privacy on this website
1 cookie, for security purposes only, until you close your browser
This website uses as few cookies as possible. We only use one technical cookie that is strictly necessary for site security. As this does not require consent, you will not see a cookie banner.
The _cfuvid cookie, placed by Cloudflare, protects the site against abuse and overloading (rate limiting) and ensures that visitors sharing the same IP address, such as those on an office network or VPN, are not accidentally blocked as a single visitor.
Retention period: until you close your browser. This cookie is not used for tracking, profiling, or marketing. Cloudflare processes this data as our processor; data may be processed outside the EU (USA) based on the standard contractual clauses in Cloudflare's data processing agreement.
Legal basis: our legitimate interest in securing the website (Art. 6(1)(f) GDPR).
We use Plausible Analytics for our visitor statistics.
Plausible does not use cookies and does not store any personal data. Your IP address is only used briefly to count visitors and is then immediately discarded. The data is processed and stored on servers within the EU. We only see totals, such as the number of visitors and pages visited.
This website is owned by Siip Group.
Questions about this cookie policy?
Please contact us at privacy@siip.group.
You have the right to access, rectify, erase, and restrict your data, as well as the right to object to the use of the security cookie based on our legitimate interest. Because this cookie is automatically deleted when you close your browser and is not linked to a personal file, there is generally little to access or erase, but you may exercise these rights at any time by contacting us. The situation is slightly different for Plausible: we do not track any data that can be traced back to you, so there is nothing to request in that regard. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
