Effective 7 August 2026.
What DNI Check does
DNI Check is a technical tool for reading and verifying compatible identity credentials and documents presented as QR codes. It checks their structure, integrity, electronic signature and validity. Depending on the credential and the operator's configuration, it can display the result on the device and send authorised data to another device or server controlled by the operator.
Role of DNIWallet SL
DNIWallet SL develops and technically supplies DNI Check. It does not determine why the app is used, which identity data is requested, how long it is retained or who receives it. DNIWallet SL does not receive or store scanned credentials, identity data or verification results; does not offer servers for receiving or processing them; and does not use them for advertising, analytics, profiling or any purpose of its own. DNIWallet SL is therefore not the controller of identity data processed by operators using DNI Check, nor a processor of that data by default.
The operator is the data controller
The organisation or professional using DNI Check and deciding the purpose of each identity check is the data controller. The operator decides which credential and fields are necessary, whether the result is displayed only on the device or sent to another system, whether a record is kept, how long information is retained and who may access it. Questions about the use of identity data and requests to exercise data-protection rights must be addressed to the operator that requested or performed the check.
Data processed
DNI Check can process the fields disclosed by the credential holder, such as name, photograph, document identifier, date of birth, age or adult status, sex, nationality, issue and expiry dates, together with the cryptographic information required to verify authenticity, the verification result and the date and time of the operation. The exact data depends on the document and mode selected. Some modes prove only a fact, such as adult status, without disclosing the remaining identity data.
Scanning and on-device processing
The camera is used only to locate and decode the QR code presented to the device. Camera frames are processed for that purpose and are not sent to DNIWallet SL or used for facial recognition, advertising or profiling. The credential's cryptographic validation is performed by components built into the app.
Paired devices
A mobile device can be paired with a receiving iPad, Mac or Windows computer controlled by the operator. When this feature is used, authorised data and the verification result are transmitted directly between the paired devices using the app's protected pairing channel. DNIWallet SL does not take part in that communication and receives no copy. Local-network access is requested only when needed to discover, pair with or communicate with the operator's devices.
Operator-controlled integrations
The operator may configure DNI Check to send a verification result to its own server or service. The destination is selected and controlled by the operator; DNIWallet SL does not provide the receiving server and receives no copy. The operator is responsible for the lawfulness, security, retention and subsequent use of data in that system. DNI Check does not send identity data to advertising networks, analytics platforms or other third parties on its own initiative.
Local verification or visit log
Receiving devices can keep a local verification or visit log when the operator enables that function. It may contain credential fields, the validation result, date and time, the scanning device and notes entered by the operator. The log remains under the operator's control; DNIWallet SL cannot access it and receives no copy. The operator can review and delete entries on the receiving device and must set a retention period appropriate to its purpose.
Purpose and legal basis
DNI Check provides the technical tool but does not establish the purpose or legal basis of processing. The operator must inform individuals, identify a valid legal basis, request only necessary data, meet applicable data-protection obligations and handle individual rights. Voluntarily presenting a credential does not by itself replace the operator's legal obligations.
Retention and deletion
DNIWallet SL does not retain credentials, identity data or verification results. When information is stored on a receiving device or operator server, the operator alone determines its retention period and must delete it when no longer necessary, unless the law requires retention. Uninstalling DNI Check removes local app data according to the operating system, but does not erase copies the operator has sent to or stored on other devices or servers.
Recipients and international transfers
DNIWallet SL does not disclose identity data processed by DNI Check to third parties and does not make international transfers of that data. If the operator configures an external device, server or service as a recipient, the operator must identify recipients, inform affected individuals and implement all required safeguards, including those for international transfers.
Security
DNI Check includes technical mechanisms intended to protect device pairing, communications and result integrity. The operator is responsible for protecting devices and servers under its control, restricting access to authorised personnel, keeping systems updated and applying measures appropriate to the data. Incidents involving operator-controlled devices or servers must be reported to that operator.
Device permissions
DNI Check may request camera access to scan QR codes, local-network access to discover and communicate with paired receiving devices, and notifications when a feature needs to report a connection or event. Permissions can be managed in system settings. Denying a permission can prevent the corresponding feature from working.
Individual rights
Requests for access, correction, deletion, objection, restriction or portability concerning an identity check must be sent to the operator that requested or performed it. DNIWallet SL cannot locate, view, change or delete that information because it does not receive it and has no access to the operator's systems.
Technical support
Technical support is available at support@dnicheck.app. Do not email document photographs, QR credentials, verification results or other identity data. Information voluntarily provided in a support request is used only to answer and manage that technical request.
Changes to this policy
This policy may be updated when DNI Check features or applicable requirements change. Material changes will be identified by a new effective date.
Application provider
DNIWallet SL
Plaza de Pablo Ruiz Picasso, planta 14ª, 28020 Madrid, Spain
support@dnicheck.app