title: AnybanQID Privacy Policy version: 1.0.0 effectiveDate: 2026-08-31 lastUpdated: 2026-08-31
Privacy Policy
AnybanQID is operated by Clobe (Pvt) Ltd ("we", "us"), Colombo, Sri Lanka.
AnybanQID is a private digital identity service. It is not operated by, and is not affiliated with, any government body.
1. What we collect
1.1 Identity details you give us at registration
| Data | Why |
|---|---|
| National Identity Card (NIC) number | The unique anchor for your identity |
| Full name, date of birth | Identity claims released to services you sign in to |
| Mobile number | One identity per number; receives one-time codes |
| Email address (optional) | Contact and account recovery |
| Gender, address (optional) | Released only if a service requests them and you consent |
Your NIC number is encrypted at rest. Lookups use a separate keyed one-way index rather than the number itself, so the database cannot be searched by NIC without our key.
1.2 Bank verification
To prove you are who you say you are, we verify that you control a bank account registered to your NIC and mobile number.
- We store your bank name, a masked account number (e.g.
****3456), and an opaque token issued by the bank. - We never store your full bank account number, and we never see your bank password or PIN.
1.3 Your device
Platform, device model, OS version, a device name, and the public half of a cryptographic key pair generated on the device.
The private key never leaves your phone, and it is protected by your device's secure hardware.
1.4 Biometrics — we never receive them
AnybanQID uses your device's own fingerprint or face unlock to authorise actions. Your biometric data never leaves your device and is never transmitted to or stored by us. We receive only the result: that your device confirmed it was you.
1.5 Security and activity records
IP address, session timestamps, device identifier, and the outcome of each sign-in, approval or signing request. Our audit log is tamper-evident: each entry is cryptographically chained to the one before it.
1.6 Documents you sign
We store the document name and a cryptographic hash (SHA-256) of the document. We do not receive, store, or have any ability to read the document itself.
1.7 What we do NOT collect
- Advertising identifiers, and no advertising or analytics SDKs
- No third-party push service — AnybanQID does not use Firebase Cloud Messaging or any comparable service, so no notification metadata is shared with a third party
- No location data
- No contacts, photos, or files. Camera access is used only to scan QR codes, and images are processed on-device and never uploaded
2. Who we share it with
We do not sell your personal data. We share it only as follows.
| Recipient | What | Why |
|---|---|---|
| Your bank (HNB, via JustPay) | NIC, name, mobile, account details you enter | To verify you control the account |
| Mobitel (SMS) | Your mobile number | To deliver one-time codes |
| LankaSign (Certification Authority) | Name and identity details in the certificate subject | To issue your signing certificate |
| verifia (operated by Clobe (Pvt) Ltd) | Bill and payment references | The bill inbox and payment links |
| Services you sign in to | See below | Only with your explicit consent |
2.1 Services you sign in to (relying parties)
When you approve a sign-in, we release only the claims matching the scopes you consented to:
profile→ name, gender, date of birth, addressemail→ email addressphone→ mobile number
A service receives nothing beyond the scopes you approved. Your NIC number is never released as a claim. You can review and revoke any consent in the app.
2.2 Legal disclosure
We may disclose data where required by Sri Lankan law, valid court order, or lawful request from a competent authority. We will notify you unless legally prohibited.
3. Legal basis
- Contract — to provide the identity service you registered for
- Consent — for each release of your details to a relying party, withdrawable at any time
- Legal obligation — identity verification and record-keeping duties
- Legitimate interests — fraud prevention, and the security of the service
4. How long we keep it
We keep your personal data while your AnybanQID account is active.
Audit records of approvals and signatures are retained for as long as required for legal, regulatory and dispute-resolution purposes. These are the records that let a signature be relied on afterwards, and that let you show what you did or did not approve.
Sessions and pending approval requests are short-lived and expire automatically.
When you delete your account, your personal data is erased or irreversibly anonymised, except where the law requires us to keep it.
5. Your rights
Under the PDPA you may:
- Access the personal data we hold about you
- Correct inaccurate details (email and mobile changes require re-verification)
- Withdraw consent from any service, in the app
- Delete your account — in the app, confirmed with a one-time code. This permanently erases your identity record, bank verification and consents.
- Object to processing, and complain to the Data Protection Authority of Sri Lanka
Some records must survive deletion where law requires it — in particular tamper-evident audit entries and issued certificates, which cannot be erased without destroying the integrity of signatures that others rely on.
To exercise a right: sasith@clobe.lk.
6. Security
- NIC numbers encrypted at rest; lookups via a keyed blind index
- Signing keys generated in device secure hardware, never exported
- Every approval gated by a fresh biometric check on your device
- TLS enforced; the app refuses unencrypted connections
- Hardware attestation verifies a device is genuine before it is trusted
- Tamper-evident, hash-chained audit log
No system is perfectly secure. We will notify you and the Data Protection Authority of a breach affecting your data as required by law.
7. Children
AnybanQID is intended for people who hold a Sri Lankan National Identity Card and are old enough to contract for financial services. It is not directed at children.
8. International transfers
Personal data is stored and processed on servers in Singapore
(DigitalOcean region sgp1), not in Sri Lanka. Using AnybanQID therefore
involves a transfer of your personal data outside Sri Lanka.
9. Changes
Material changes will be notified in the app before they take effect. The version and effective date at the top of this page always reflect the current policy.
10. Contact
- Clobe (Pvt) Ltd, Colombo, Sri Lanka
- Privacy: sasith@clobe.lk
To exercise any right above, or to ask anything about how we handle your data, write to sasith@clobe.lk and we will respond.