Privacy Policy
Last updated: 19 August 2026
1. Who we are and how to contact us
Mobai AS provides biometric and identity-verification technology. We in Mobai respect your privacy and are committed to protecting your personal data. This policy explains what personal data we process, why, on what legal basis, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act (personopplysningsloven).
- Mobai AS, organization number 922 935 815
- Studievegen 16, 2815 Gjøvik, Norway
- Data Protection Officer: privacy@mobai.bio
You can contact our Data Protection Officer at the address above with any question about this policy or about how we handle your personal data.
2. Our two roles
Mobai's relationship to your personal data depends on the situation, and this determines who is responsible for it.
When we act as a data processor. We provide identity-verification and biometric services, such as face verification, liveness and presentation-attack detection, and identity-document checks, to organizations such as banks, electronic-identity (eID) providers and public bodies. When you go through an identity check powered by Mobai, that organization decides why and how your data is used. They are the data controller; Mobai only processes your data on their documented instructions, under a data processing agreement. See §3.
When we act as a data controller. Mobai is the data controller when it decides why and how data is processed, for example when you visit our website, contact us, apply for a job, or when we carry out our own research, development and service-improvement work. See §4.
3. If your data was processed during an identity check, authentication or anti-fraud check (Mobai as processor)
If you completed an identity verification, authentication or anti-fraud check (for example, when opening an account or obtaining an electronic ID or verifying that you are you by authentication in an app) using Mobai's technology, the organization you were dealing with is the controller of that data. To exercise your rights, please contact that organization first. Where your request concerns data the organization cannot access directly, we will assist them in responding.
For these services, personal data is processed only for the purposes the customer has instructed us to carry out. Depending on which of our services the organization uses and how they have configured it, this may include identity details (such as name, telephone number and national identity number), data read from an identity document (including the reference facial image), a facial image captured during the session, and the facial comparison between them.
- We process this data on that organization's documented instructions
- We do not keep it longer than the period agreed with that organization. For our physical identity-proofing service, that period is at most 30 days from the verification request, and for most of our authentication offerings it would be processing within milliseconds before it is deleted. Where a different period applies to another of our services, it is set out in that organization's agreement with us.
- Where we are required by law to keep something longer, we keep only what is required, and only for as long as it is required.
- After that point we keep a record of the derived data that does not contain personal information, such as aggregated outcomes that do not identify you to us, for purposes such as statistics and invoicing. This is explained in §7.
Where a facial image is used to uniquely identify a person, this is special-category data under the GDPR; the customer (controller) is responsible for the condition that permits it and for informing you.
4. How we use your personal data as a controller
For each activity we set out what we collect, why, the legal basis, and how long we keep it.
4.1 Visitors to our website
When you visit mobai.bio, we use an analytics tool called Datadog Browser RUM to understand how the site is used and to keep it working properly. It runs only if you accept it. We do not use it to identify you, to build a profile of you, or for advertising, and we do not use advertising or social-media tracking tools on our site.
What we collect if you accept. The pages you view; the site, link or campaign that brought you to us; an approximate location worked out from your IP address (country and city level); your device, browser and screen size; page load and performance timings; errors that occur in your browser; and clicks on links and buttons.
What we do not collect. Anything you type into a field on our site is hidden in your own browser before anything is sent, so it never reaches us. We do not record or replay your screen.
Legal basis. Your consent (Article 6(1)(a) GDPR), given through the banner on our site. You can decline, and you can withdraw your consent at any time using the link in the footer of the site. Withdrawing stops the collection and removes the identifier from your browser. Withdrawing does not affect anything collected before you withdrew.
Who processes it, and where. Datadog processes this on our behalf as our data processor, under a data processing agreement, on servers in the EU.
How long we keep it. Deletion is automatic and needs no request from you: 30 days for visits, page views, clicks and errors, and 15 days for performance data.
What is stored on your device
| What | Set by | What it does | Is it personal data? | How long | Consent needed? |
|---|---|---|---|---|---|
_dd_s (cookie) | Datadog, first-party | Ties the pages of a single visit together. Holds a randomly generated ID — no name, no email, no login. | Yes. The random ID is an identifier, and it is combined with the analytics information described above. | The cookie itself lasts 1 year. The visit ID inside it expires after 15 minutes of inactivity, or after 4 hours. | Yes. We delete it when you withdraw your consent. |
mobai.consent.v1 (browser storage, not a cookie) | Mobai | Remembers whether you said yes or no, so that we stop asking. | No. It holds only your choice. | Until you clear it | No. It is the record of your own choice, so it is strictly necessary. |
We also load the jQuery software library from a content delivery network so that the site displays correctly. It sets no cookies and stores nothing on your device.
Asking for a copy of your analytics data, or asking us to delete it. The analytics information we hold contains no name, no email address and no account — only a randomly generated ID. We cannot work out from that ID who you are, and we do not collect additional information about you in order to make that possible (Article 11 GDPR).
If you want to exercise your rights over this information, you can send us the value of the _dd_s cookie from your browser, and we will use it to locate and act on the records it relates to. Because that ID is regenerated regularly, it will normally reach your current visit rather than earlier ones. Your other controls are: decline analytics, withdraw your consent at any time, and the automatic deletion described above.
4.2 When you contact us
If you contact us by email or through our support channel, we process your name, contact details and the content of your message in order to respond to and manage your inquiry. Our basis is our legitimate interest (Article 6(1)(f)) in responding to people who contact us. We keep this while we deal with your inquiry and afterwards as a record of our correspondence, for as long as it remains useful for that purpose. Where you or the organization you work for is or becomes a customer, we keep it for as long as that relationship continues.
4.3 Sales and customer relationships
We hold business contact details and records of our dealings with prospective and existing customers in our customer-relationship management system, to manage those relationships. Where we have not obtained your details from you directly, we obtain them from publicly available sources such as company websites and professional networking sites, and from business contacts and referrals. Our basis is our legitimate interest (Article 6(1)(f)) in running and developing our business by marketing our services to organizations that may be interested in them. We keep this for as long as we have a business relationship with you or the organization you work for, or for as long as the realistic prospect of a business relationship continues.
4.4 Job applicants
If you apply for a role at Mobai. We advertise and manage our recruitment through Vouch (Vouch AS, org. nr. 930 248 096). When you apply, we process the information in your application — name, contact details, CV, cover letter, certificates and references — together with any interview notes and assessments, in order to evaluate your application and run a fair process. Our basis is that the processing is necessary to take steps at your request before entering into a contract (Article 6(1)(b) GDPR). Any checks that go beyond the information you provide are carried out only with your consent (Article 6(1)(a)). We may also work with external recruiting partners.
Two separate records. Vouch processes your application on our instructions as our data processor. Vouch is separately the data controller for the user account you hold with them, which is why you can view, correct or delete your own information there and control which companies have access to it. Alongside that, we keep our own copy of your application. Deleting your profile with Vouch does not automatically remove our copy — to have that deleted, contact us using the details in §14.
Automated ranking. Our recruitment platform uses automated processing to rank applications and indicate how well a candidate matches a role. It does not decide anything — every decision about who progresses and who is hired is made by a person at Mobai.
How long we keep your application. We keep your application, our assessments and the record of the recruitment for 36 months from the date the position is filled or the process is closed. Our basis for keeping it during that period is our legitimate interest (Article 6(1)(f)) in being able to account for and defend the process: we need it to answer questions about the recruitment, to meet our legal obligation to tell applicants about the qualifications of the person appointed, and to defend ourselves against any claim arising from the process. Where a complaint, dispute or claim relating to the recruitment has been raised, we keep the information relevant to it until that matter is finally resolved. You can ask us to delete your information at any time, and we will do so unless we are required to keep it by law or need it in connection with a legal claim.
Staying in touch about future roles. Your profile with Vouch remains yours after our process ends, and you decide whether Mobai continues to have access to it. If you keep that access open, we may contact you about roles that come up later. You can change this or delete your profile at any time from your Vouch account.
4.5 Research, development and service improvement
We develop and improve our biometric technology, including face verification, presentation-attack (liveness) detection, deepfake detection, injection attack prevention and identity-document checks, so that it is accurate and resistant to fraud. Our basis is our legitimate interest (Article 6(1)(f)) in the quality, reliability and security of our services; fraud prevention is recognized as a legitimate interest under the GDPR.
The data we use to develop and test our technology. We use datasets that we license or purchase from specialist data suppliers, publicly available research datasets, and datasets from collection exercises that we run or commission ourselves. These datasets contain facial images and video of people who took part in a data collection. We hold them for our research and development purposes, under contract where they are supplied to us by others. We use them only to develop, train and test our technology, and never to identify the people in them.
We do not use verification data to develop our technology. Personal data processed when we carry out a verification for one of our customers is never used to train our algorithms, and it is not copied into the datasets we use for research and development. Where our customer has instructed us to do so, we may use it to check that a new or improved version of one of our checks performs as intended before it is put into service. That happens within the service environment and within the retention period described in §3.
Information about how our checks perform. Once the information that identifies a person has been removed from a verification record, what remains is a record of the outcome and technical details about the check, such as the document type, whether the check passed or failed, anti-fraud results and error codes. We treat this as anonymized in our hands, as explained in §7, and we use it for statistics, invoicing, quality monitoring and strengthening our fraud controls.
5. Who we share data with (recipients)
We do not sell personal data, and we share it only where necessary. Where a recipient processes personal data on our behalf, it does so as our processor under a data processing agreement with appropriate safeguards (Article 28). We may also disclose personal data to public authorities where we are legally required to do so. The recipients we use fall into these categories:
- cloud hosting and infrastructure providers;
- business-software providers (such as customer-relationship, analytics, communications and IT-support tools);
- specialist technology sub-processors used to deliver our verification services;
- recruiting partners, where relevant.
We provide our customers with the specific sub-processors used for their services in the data processing agreement we enter into with them.
6. International transfers
We keep personal data within the EU/EEA wherever we can. Our verification services and the personal data processed through them are hosted in data centers within the EU/EEA. Some of the established business-software providers we use for our own operations may process limited personal data outside the EU/EEA. Where that happens, we rely on a transfer mechanism permitted under Chapter V of the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards we rely on by contacting us.
7. How long we keep your data
We keep personal data only for as long as necessary for the purpose for which it was collected, or as required by law. How long we keep data for each activity is described in the sections above. Data processed as part of our verification services is deleted, or stripped of the information that identifies you, within the period described in §3.
Anonymized data. In some cases, rather than deleting data we anonymize it. Anonymization means we remove or alter the information that identifies you, so that we can no longer link the data back to you using means reasonably likely to be used. Once data has been anonymized in this way, it is no longer personal data in our hands. We keep and use such anonymized data, for example a record of the transaction and its outcome, aggregated statistics on how our checks perform, patterns that help us detect and prevent fraud, and records needed for invoicing. We never use it to try to identify you.
8. How we keep your data secure
We align our internal security program with the ISO/IEC 27001 standard. It is the leading international framework for Information Security Management Systems. This means Mobai follows rigorous best practices to protect data confidentiality, integrity, and availability. Our measures include encryption of data in transit, minimizing how much biometric data we hold and how long we hold it, strict access controls, continuous monitoring, and privacy by design and by default (Article 25). Our biometric components are independently tested.
9. Your rights
Under the GDPR you have the right to access your personal data; to have inaccurate data corrected; to have data erased in certain circumstances; to restrict processing; to object to processing based on our legitimate interests; and to data portability where processing is based on consent or a contract. Where a decision is based solely on automated processing and produces legal or similarly significant effects, you have rights under Article 22.
Where we hold data that does not identify you and we cannot link it back to you, we are not required to obtain additional information about you simply in order to identify you (Article 11 GDPR). Our website analytics is the main example of this. If you can give us information that lets us find the records concerned, we will act on your request — see §4.1 for how.
Objecting to direct marketing. Where we process your personal data for direct marketing purposes, you have the right to object at any time. This right is unconditional: you do not need to give a reason, we do not weigh it against our own interests, and once you object we will stop using your data for that purpose.
Where our processing is based on your consent, you can withdraw that consent at any time. This does not affect any processing we carried out before you withdrew it.
To exercise your rights for data where Mobai is the controller, contact privacy@mobai.bio. We will respond without undue delay and in any event within one month. If your request is complex, we may extend this by up to two further months, and we will tell you within the first month if that happens and why. Where Mobai acted as a processor during an identity check, please contact the organization that asked you to verify your identity (the controller); we will assist them as needed.
You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet), Postboks 458 Sentrum, 0105 Oslo, postkasse@datatilsynet.no, or with the supervisory authority in your country of residence.
10. Automated decision-making
Mobai's technology produces verification results (such as whether a face matches a document, or whether a presentation appears genuine). Where such a result is used to make a decision about you, that decision is made by our customer as controller, who is responsible for any safeguards required under Article 22. In our own capacity as a controller, we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
11. Children
Our services and website are directed at organizations, not children. During identity verification, a facial image is not captured where the person being verified is under 18, unless specifically agreed otherwise with the customer, as described in §3.
12. Employees
Personal data about Mobai's own employees is covered by a separate internal staff privacy notice and is not described in this policy.
13. Changes to this policy
We may update this policy from time to time. The date of the current version is shown at the top of this page. We will communicate material changes as appropriate.
14. Contact
For any privacy question, contact our Data Protection Officer: privacy@mobai.bio. Mobai AS, Studievegen 16, 2815 Gjøvik, Norway.
