Sub-processor list

Sub-processorService providedCategories of data concernedLocation / transfer statusRole
Amazon Web Services EMEA SARL / Amazon Web Services, Inc.Cloud hosting, storage, compute, databases, infrastructure security, backupsPlatform data, identity verification data, document data, biometric data, technical logs, Proof Package dataEU/EEA region preferred; possible transfers depending on services and support modelInfrastructure sub-processor
Microsoft Ireland Operations Ltd / Microsoft CorporationCloud services, Entra ID integration, identity federation, enterprise services, optional hosting or monitoring componentsAdministrator data, authentication metadata, integration data, technical logs, support dataEU Data Boundary / EEA where configured; possible transfers depending on servicesCloud / identity integration sub-processor
Cloudflare, Inc. / Cloudflare Germany GmbHCDN, DDoS protection, web application firewall, DNS, edge securityIP addresses, request metadata, security logs, device/browser metadataGlobal edge network; EEA safeguards requiredSecurity and network sub-processor
Okta, Inc. / Okta entitiesIdentity provider integration, authentication, SSO, IAM integrationAdministrator data, authentication metadata, user identifiers, access logsEEA or third-country processing depending on customer configurationIdentity integration sub-processor
SendGrid / Twilio Inc.Transactional emails, verification invitations, notificationsEmail address, name where applicable, invitation metadata, delivery logsPossible non-EEA transfers; SCCs or equivalent safeguards requiredCommunication sub-processor
Stripe Payments Europe, Ltd / Stripe, Inc.Payment processing, billing support, invoicing where applicableCustomer billing data, business contact data, payment metadataEEA and possible international transfersPayment / billing sub-processor
GitHub, Inc. / Microsoft CorporationSoftware development, code repository, issue tracking, CI/CDDeveloper data, limited technical metadata; no production identity verification data intendedPossible non-EEA transfersDevelopment infrastructure sub-processor
Google Firebase / Google Ireland Limited / Google LLC Mobile application backend services, push notifications, app analytics, crash reporting, authentication support, cloud messaging and mobile infrastructure services, depending on enabled Firebase featuresMobile app identifiers, device data, push notification tokens, crash logs, technical logs, app usage metadata, user identifiers, authentication metadata; no identity document or biometric data intended unless specifically configuredEEA and possible international transfers depending on Firebase services and configuration; Google data processing terms and Firebase sub-processor list applyMobile app infrastructure / analytics / messaging sub-processor
OVHcloud / OVH SAS or relevant OVHcloud entityCloud hosting, infrastructure, servers, storage, networking, backups and related infrastructure servicesPlatform data, technical logs, security logs, customer account data, identity verification data, Proof Package data, and other data hosted on Yumipass infrastructureFrance transfers outside the EEA to be confirmed depending on support, service and contractual setupCloud hosting / infrastructure sub-processor
Favicon Light YumiPass online identity verification solution
EVERYTHING YOU NEED TO KNOW

Frequently Asked Questions

If you have additional questions or need personalized assistance, feel free to reach out to our dedicated support team.

How is this different from a passport photo upload for verification?

Unlike photo-based Passport verification (which can easily be faked with AI), Yumipass app cryptographically verifies the digital signatures inside the Passport’s NFC chip. This ensures:

– The Passport is real and not a forgery.
– The identity data has not been altered.
– The Passport is issued by a legitimate authority.

Why the app suggests to scan Passport with camera?

The Camera is only used to scan the NFC chip access code (similar to PIN), not any personal details. User may also manually enter the NFC chip access code, but where a debit card has 4 digit PIN, Passport may have up to 20 digit “PIN”, making camera more convenient.

What is NFC chip access code?

Think of the NFC chip access code like unlocking a bank card with a PIN. Just as you need to enter a PIN to use a debit card, the Passport’s NFC chip requires a special access key, printed as a Machine Readable Zone (MRZ) or Card Access Number (CAN). This prevents unauthorised scanning of Passport by ensuring that only someone who physically sees the document can access its NFC chip. Without this code, the chip remains locked and unreadable, just like a bank card without its PIN.

Does a user have to first upload Passport to app Wallet to use it?

No. Wallet is optional and only for convenience, so that user won’t have to NFC scan Passport on every verification.

Is the Passport data stored or shared anywhere?

No. Yumipass app performs on-device cryptographic verification and only transmits data if user approves a request from an online service that needs to verify the user’s identity. User may save verified Passport to the Yumipass app Wallet to avoid having to NFC re-scan the Passport in every verification, but this indeed is optional and for convenience only.

Does a user need to register an account in Yumipass?

No. There are no end user accounts in the Yumipass service, therefore no PII data gets stored in the service. Yumipass is not a controller, only an identity claims processor, a secure peer-to-peer service to broker verified identity claims.