Version 2026-09-02
Privacy policy
This policy explains which personal data Fesa ID processes, for which purpose, who is responsible for it and how you can exercise your rights under Law 81 of 2019 of the Republic of Panama and its regulation (Executive Decree 285 of 2021).
Draft pending legal review. This notice disappears once the text is approved.
1. Who processes your data
Fesa ID is a platform operated by Formas Eficientes, S.A. ("Fesa"), domiciled in the Republic of Panama.
When a client organization (a company, insurer, school, event organizer or other entity) issues credentials to its staff, members, students or attendees, that organization is the data controller. Fesa acts as data custodian: it processes the data only under the organization's instructions, under a data processing agreement.
When you create a Fesa ID account or register an organization, Fesa is the controller of your account data (name, email, encrypted password, language, access logs).
2. Which data is processed
Depending on how you use the platform:
- Account data: name, email, username, encrypted password, language, last login and active sessions.
- Credential data: name, role, photo, email, phone, organization and the fields the organization defines in its template (for example employee number, department, policy number).
- Sensitive data only when the organization includes it in the credential and has obtained the holder's express consent (for example blood type or health plan information).
- Technical data: IP address, device and browser type, page from which an action was taken, date and time, recorded in the audit log and in the view and verification statistics of each credential.
3. Purposes
- Issue, display, update, suspend and revoke digital credentials, including Apple Wallet and Google Wallet passes.
- Let a third party verify that a credential is valid by scanning its QR code.
- Send the platform's operational emails: credential delivery, verification codes, password reset, status notices.
- Keep an audit log of who did what, when and from where, for security and to meet the legal obligations of regulated organizations.
- Produce aggregated usage statistics for the issuing organization.
4. Legal basis
Processing relies on the holder's consent, on the contractual or employment relationship between the holder and the issuing organization, and on the organization's legal obligations. Sensitive data is processed only with the holder's prior, express and informed consent, collected by the responsible organization.
5. Who can see a credential
The public page of a credential shows only the fields the organization chose to include in the design. It is reachable by anyone who scans the QR code or opens the link; the link contains a random, unguessable identifier and is not indexed by search engines.
The verification page shows a minimal set: photo, name, role, issuing organization, validity status and dates. It never shows the holder's contact details.
6. Where data is hosted and who receives it
Data is hosted on servers contracted by Fesa outside Panama, with providers that guarantee security measures equivalent to those required by Law 81 of 2019. Fesa relies on the following sub-processors to operate the platform:
- Server and database providers (hosting of the application and its information).
- Cloudflare (storage of images and pass files).
- Resend (transactional email delivery).
- Apple and Google (only when the holder adds the credential to Apple Wallet or Google Wallet).
7. Retention
Credential data is kept while the credential is valid and for the period the responsible organization sets for its issuance records, never beyond the applicable legal limit. Account data is kept while the account exists. The audit log is kept as long as needed to answer requests from regulated organizations and authorities.
8. Your rights
You may exercise the rights of access, rectification, cancellation, objection and portability provided by Law 81 of 2019.
If your credential was issued by an organization, address your request to that organization, which is the controller; Fesa will support it as custodian. For your Fesa ID account data, write to privacidad@fesa.com.pa. Access requests are answered within ten business days and rectification requests within five business days.
You may also file a complaint with the National Authority for Transparency and Access to Information (ANTAI).
9. Security
Fesa applies encryption in transit, role- and organization-based access control, two-factor authentication for administrators, lockout after failed attempts, an audit log and daily backups. In the event of a security incident affecting personal data, Fesa informs the responsible organization immediately so it can notify holders and ANTAI within the legal deadline.
10. Changes to this policy
When this policy changes, the version date at the top is updated and, for material changes, you will be asked to accept it again at sign-in.