1
The short answer
eID 2 FMP reads a Belgian identity card and passes the data to a FileMaker file belonging to the user. That is all the app does.
- There is no server of ours. The app sends nothing to Filip Piens bv.
- Nothing is stored on the device. Close the app and the reading is gone.
- There is no analytics, no advertising and no crash reporting in it.
- The only place data goes to is the FileMaker file the user points at.
2
Who is responsible
The business or organisation using eID 2 FMP is, under the GDPR, the data controller for the data it reads with the app. It decides why a card is read, what happens to the data and how long it is kept in its own file.
Filip Piens bv only supplies the software. We are not a processor of that data, because we do not receive it, do not store it and have no access to it.
Our details
- Filip Piens bv, Waregemsesteenweg 80, 9770 Kruisem, Belgium
- branch office: Zeedijk 144, 8400 Ostend
- info@filemakerlab.be
3
What data the app reads
eID 2 FMP reads the identity file on the card. That part is freely readable: no PIN, no certificate and no authorisation from any authority is required. It contains:
- surname and given names
- date and place of birth
- sex and nationality
- card number and expiry date
- address: street, postal code and municipality
- the portrait stored on the card
The national register number
That number is in the same file on the card, but the app skips it. It is not read, does not appear on screen, is not sent on, and there is no setting to change that.
What the app does not do
- no use of the card's authentication or digital signature functions, and therefore never a request for a PIN
- no use of the certificates on the card
- no connection whatsoever to the national register or any other government service
- no location data, no contacts, no calendar, no access to photos
4
Where the data goes
The data read sits in the device's working memory for as long as it is on screen. From there it has exactly one destination: the FileMaker file the user specifies.
- If that file is on the device itself, the data never leaves the device.
- If it is on a FileMaker Server, the data goes to that server. That is the user's server, or their service provider's — not ours.
The transfer uses the Claris fmp:// URL scheme, within the device, from app to app.
The portrait
By default the photo travels along in the same transfer, as base64 text. There is a setting to pass the photo through the clipboard instead.
5
How long the data is kept
In eID 2 FMP: not at all. The app writes no card data to disk. What you see on screen is in working memory and disappears as soon as you press Wissen, read another card or quit the app.
Earlier versions of the app did keep a history in a file on the device. That feature has been removed, and the first launch of the current version deletes that old file.
In the user's FileMaker file the data stays for as long as that user decides. That falls outside this app and outside our control.
6
Connections to the internet
The app makes no internet connection of its own accord. There are two exceptions, both at the user's request:
- In the self-test the app can check whether the FileMaker Server given is reachable. That is one request to that server, and only when the user entered a server name themselves. No card data is included.
- The links to our website and to the shop open in Safari, only after the user taps them.
Third parties
The app contains one third-party component: the FEITIAN iOS SDK, a static library that talks to the Bluetooth card reader over the PC/SC protocol. That library performs no network activity; it only drives the accessory.
There is no analytics package, no advertising package, no crash reporting service and no sign-in service.
7
Permissions the app asks for
- Bluetooth — needed to find the card reader and talk to it. Without this permission the app cannot read a card. It is used for nothing else: no location is derived from it and no other nearby devices are tracked or recorded.
Beyond that the app asks for nothing: no location, no camera, no microphone, no contacts, no photos, no notifications.
8
The rights of the data subject
Someone whose identity card was read with this app has, under the GDPR, the right of access, rectification, erasure, restriction and objection. Those rights are exercised with the business using the app, because that business holds the data and is responsible for it.
There is nothing to access with us: we do not hold that data. A request that reaches us anyway can only be forwarded.
Anyone who believes their data is being mishandled can lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels — dataprotectionauthority.be.
9
Children
The app is intended for use by a business, at a counter. It is not directed at children and does not knowingly collect data from children beyond what appears on an identity card that someone presents themselves.
10
Changes to this policy
If something changes in the app that affects this text, the text is updated and the date at the bottom is changed. Anyone who continues to use the app after such a change falls under the new text.
Questions about this policy: info@filemakerlab.be.
This policy was last updated on 25 August 2026.