AnybanQIDDeveloper Docs

title: AnybanQID Privacy Policy version: 1.0.0 effectiveDate: 2026-08-31 lastUpdated: 2026-08-31

Privacy Policy

AnybanQID is operated by Clobe (Pvt) Ltd ("we", "us"), Colombo, Sri Lanka.

AnybanQID is a private digital identity service. It is not operated by, and is not affiliated with, any government body.


1. What we collect

1.1 Identity details you give us at registration

DataWhy
National Identity Card (NIC) numberThe unique anchor for your identity
Full name, date of birthIdentity claims released to services you sign in to
Mobile numberOne identity per number; receives one-time codes
Email address (optional)Contact and account recovery
Gender, address (optional)Released only if a service requests them and you consent

Your NIC number is encrypted at rest. Lookups use a separate keyed one-way index rather than the number itself, so the database cannot be searched by NIC without our key.

1.2 Bank verification

To prove you are who you say you are, we verify that you control a bank account registered to your NIC and mobile number.

  • We store your bank name, a masked account number (e.g. ****3456), and an opaque token issued by the bank.
  • We never store your full bank account number, and we never see your bank password or PIN.

1.3 Your device

Platform, device model, OS version, a device name, and the public half of a cryptographic key pair generated on the device.

The private key never leaves your phone, and it is protected by your device's secure hardware.

1.4 Biometrics — we never receive them

AnybanQID uses your device's own fingerprint or face unlock to authorise actions. Your biometric data never leaves your device and is never transmitted to or stored by us. We receive only the result: that your device confirmed it was you.

1.5 Security and activity records

IP address, session timestamps, device identifier, and the outcome of each sign-in, approval or signing request. Our audit log is tamper-evident: each entry is cryptographically chained to the one before it.

1.6 Documents you sign

We store the document name and a cryptographic hash (SHA-256) of the document. We do not receive, store, or have any ability to read the document itself.

1.7 What we do NOT collect

  • Advertising identifiers, and no advertising or analytics SDKs
  • No third-party push service — AnybanQID does not use Firebase Cloud Messaging or any comparable service, so no notification metadata is shared with a third party
  • No location data
  • No contacts, photos, or files. Camera access is used only to scan QR codes, and images are processed on-device and never uploaded

2. Who we share it with

We do not sell your personal data. We share it only as follows.

RecipientWhatWhy
Your bank (HNB, via JustPay)NIC, name, mobile, account details you enterTo verify you control the account
Mobitel (SMS)Your mobile numberTo deliver one-time codes
LankaSign (Certification Authority)Name and identity details in the certificate subjectTo issue your signing certificate
verifia (operated by Clobe (Pvt) Ltd)Bill and payment referencesThe bill inbox and payment links
Services you sign in toSee belowOnly with your explicit consent

2.1 Services you sign in to (relying parties)

When you approve a sign-in, we release only the claims matching the scopes you consented to:

  • profile → name, gender, date of birth, address
  • email → email address
  • phone → mobile number

A service receives nothing beyond the scopes you approved. Your NIC number is never released as a claim. You can review and revoke any consent in the app.

2.2 Legal disclosure

We may disclose data where required by Sri Lankan law, valid court order, or lawful request from a competent authority. We will notify you unless legally prohibited.


3. Legal basis

  • Contract — to provide the identity service you registered for
  • Consent — for each release of your details to a relying party, withdrawable at any time
  • Legal obligation — identity verification and record-keeping duties
  • Legitimate interests — fraud prevention, and the security of the service

4. How long we keep it

We keep your personal data while your AnybanQID account is active.

Audit records of approvals and signatures are retained for as long as required for legal, regulatory and dispute-resolution purposes. These are the records that let a signature be relied on afterwards, and that let you show what you did or did not approve.

Sessions and pending approval requests are short-lived and expire automatically.

When you delete your account, your personal data is erased or irreversibly anonymised, except where the law requires us to keep it.


5. Your rights

Under the PDPA you may:

  • Access the personal data we hold about you
  • Correct inaccurate details (email and mobile changes require re-verification)
  • Withdraw consent from any service, in the app
  • Delete your account — in the app, confirmed with a one-time code. This permanently erases your identity record, bank verification and consents.
  • Object to processing, and complain to the Data Protection Authority of Sri Lanka

Some records must survive deletion where law requires it — in particular tamper-evident audit entries and issued certificates, which cannot be erased without destroying the integrity of signatures that others rely on.

To exercise a right: sasith@clobe.lk.


6. Security

  • NIC numbers encrypted at rest; lookups via a keyed blind index
  • Signing keys generated in device secure hardware, never exported
  • Every approval gated by a fresh biometric check on your device
  • TLS enforced; the app refuses unencrypted connections
  • Hardware attestation verifies a device is genuine before it is trusted
  • Tamper-evident, hash-chained audit log

No system is perfectly secure. We will notify you and the Data Protection Authority of a breach affecting your data as required by law.


7. Children

AnybanQID is intended for people who hold a Sri Lankan National Identity Card and are old enough to contract for financial services. It is not directed at children.


8. International transfers

Personal data is stored and processed on servers in Singapore (DigitalOcean region sgp1), not in Sri Lanka. Using AnybanQID therefore involves a transfer of your personal data outside Sri Lanka.


9. Changes

Material changes will be notified in the app before they take effect. The version and effective date at the top of this page always reflect the current policy.


10. Contact

To exercise any right above, or to ask anything about how we handle your data, write to sasith@clobe.lk and we will respond.

Version 1.0.0 · effective 30 August 2026