Privacy policy for IDEX Biometrics ASA
Last updated: 4 September 2026
1. Who we are
IDEX Biometrics ASA (“IDEX”, “we”) is the data controller for the processing of personal data described in this policy. Contact: Henrik Ibsens gate 90, 0255 Oslo, Norway · org. no. 976 846 923 · phone (+47) 67 83 91 19 · mailbox@idexbiometrics.com. This policy covers the processing of personal data of people outside our organisation; processing of employee data is described in a separate internal notice. IDEX Biometrics ASA is the parent company of IDEX Biometrics UK Ltd (company no. 09193617); personal data may be shared within the group, with IDEX Biometrics ASA as controller unless otherwise stated. Our website, products and services are directed at businesses and professionals, not at children.
2. Biometric data: designed never to reach us
Our cards are built on a match-on-card architecture: your fingerprint is captured, stored and matched entirely on the card. Neither IDEX nor the organisation that issued your card receives, stores or has access to it. The organisation that deploys IDEX cards to its users decides why and how the cards are used and is therefore the data controller for that deployment – responsibility does not require holding the data. If you have questions about a card issued to you by your employer, bank or another organisation, please contact that organisation. IDEX itself processes biometric data only in internal product development and testing, with participants’ explicit consent (GDPR article 9(2)(a)).
3. What we process, why, and for how long
We process personal data for the purposes below. We keep personal data no longer than necessary for each purpose; the criteria we use are stated for each.
| Purpose | Data | Legal basis (GDPR art. 6) | How long |
| Website and analytics | Usage, device and browser data via cookies and similar technologies, and server log files (IP address) | Consent (a) for all non-essential cookies, as required by the Norwegian Electronic Communications Act § 3-15; legitimate interest (f) in a functioning, secure site for strictly necessary cookies and for server logs used to secure the site and prevent abuse | As stated per cookie in our cookie declaration, which lists all tools and durations and is kept up to date automatically; server logs are kept briefly for security purposes. Manage or withdraw consent any time via cookie settings |
| Enquiries, sales, agreements and events | Contact details, correspondence, quote and agreement data, event registrations, invoicing and payment information | Contract or pre-contract steps (b); legitimate interest (f) in managing business relationships where you represent your employer; legal obligation (c) for bookkeeping | For as long as the dialogue or relationship is active, then deleted or anonymised; bookkeeping records five years under the Norwegian Bookkeeping Act, and longer where required by law or regulatory obligations. |
| Marketing you signed up for | Contact and business details, subscription status. | Consent (a), in line with the Marketing Control Act § 15; marketing to existing customer contacts under legitimate interest (f), always with the possibility to object and opt-out | Until you unsubscribe; a minimal suppression record is kept to document your choice |
| Support | Contact details, request content and history (Zendesk platform, including an automated assistant). Assistant conversations are handled under the same safeguards as other support data and are not used by our provider to train its own models. | Legitimate interest (f) in providing effective support; contract (b) where support follows from an agreement | Until the case is closed and a follow-up period of 24 months has passed |
| Job applications | Application, CV, interview notes, references you have provided | Steps prior to an employment contract (b); legitimate interest (f) in recruiting | Deleted when the process is concluded, unless you consent to us keeping it for future openings |
| Whistleblowing | The identity of the reporter (unless the report is anonymous), the content of the report, and personal data about persons mentioned in it | Legal obligation (c) under the Norwegian Working Environment Act chapter 2 A; legitimate interest (f) in investigating and addressing reported concerns. The reporter’s identity is treated confidentially in line with chapter 2 A | As long as necessary to process and follow up the report, then deleted; records of concluded cases are kept only where required to document proper handling |
| Shareholders and insider lists | Shareholder data (register kept in Euronext Securities Oslo), insider lists | Legal obligation (c) under securities law and the Market Abuse Regulation | As required by law; insider lists are stored for at least five years |
Please do not include personal data about other people, for example employee lists or access logs, in support requests; if troubleshooting requires such data, we will agree on a suitable process first.
4. The IDEX Card mobile apps
The IDEX Card apps for iOS and Android manage enrolment of IDEX cards. Enrolment happens on the card itself: the app does not receive, store or transmit your fingerprint data. The apps process only limited technical data, such as device information and crash diagnostics, based on article 6(1)(b) and (f). Crash diagnostics and device information are retained only as long as needed to diagnose and fix issues and to understand how the apps are used. This section serves as the privacy policy for the apps.
5. Who receives personal data
We do not sell personal data. We use carefully selected service providers (data processors) for CRM and marketing, customer support, web analytics and tag management, consent management, e-mail delivery and web hosting, under data processing agreements that permit them to process personal data only on our documented instructions and never for their own purposes. A complete and current list of our processors, including their location, is available on request. Some recipients are independent controllers: auditors and legal advisers, public authorities where disclosure is required, our registrar and Euronext Securities Oslo, and shipping providers for physical deliveries. Where a distributor or integration partner is better placed to serve you, we may share your business contact details with that partner, based on our legitimate interest (article 6(1)(f)) in routing your enquiry to the right party. We will tell you when we do so, and you may object at any time; the partner then processes your details under its own privacy policy. We may share personal data with our accounting service providers for invoicing, bookkeeping, payment processing and compliance with legal accounting and tax obligations.
6. Transfers outside the EEA
We primarily use suppliers located within the European Economic Area (EEA). Transfers of personal data to our UK group company are covered by the European Commission’s adequacy decision for the United Kingdom. Transfers to suppliers in the United States rely on the EU–US Data Privacy Framework where the recipient is certified. Where the recipient is not certified, we rely on the Commission’s Standard Contractual Clauses as a safeguard. You can request a copy of the relevant safeguards using the contact details in section 1.
7. Your rights
You may request access to, rectification or erasure of your personal data, and restriction of processing. You may also request data portability where processing is based on consent or contract. You may object to processing based on legitimate interest; an objection to direct marketing is always honoured without further assessment. Where processing is based on consent, you may withdraw it at any time with effect for the future. Contact us via the details in section 1; we respond within one month (extendable by two months for complex requests, in which case we will let you know). You may complain to the Norwegian Data Protection Authority (Datatilsynet, www.datatilsynet.no) or your local supervisory authority. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
8. Security and changes
We apply technical and organisational measures appropriate to the risk, and our product architecture itself minimises personal data by design. We may update this policy; the date at the top shows the latest revision.

