LOQR
LOQR is a Portuguese identity orchestration platform for banks and financial institutions, combining remote identity verification, KYC/KYB compliance automation and qualified electronic signature under eIDAS 2.0 and GDPR, delivered as pre-built customer journeys rather than standalone tools.
What is LOQR?
LOQR is an identity orchestration platform published by LOQR, S.A., a Portuguese company headquartered in Felgueiras with a second office in Lisbon. The company describes itself as an AI-Powered Journey-as-a-Service provider for financial institutions and positions the product as trust infrastructure for banks operating under eIDAS 2.0 and the GDPR.
The platform is organised around three families of capabilities. KYC/KYB covers identity document checks, device, phone, email and IP checks, bank account verification, AML screening and PEP, RCA and SIP screening. Identity Verification covers facematch, liveness detection, self-video interviews and live interviews. e-Sign covers three levels of electronic signature: advanced signature, advanced certificate signature and qualified certificate signature.
Four named offerings package those capabilities. LOQR|core orchestrates the full digital identity lifecycle and connects to core banking systems and CRMs. LOQR|one is a plug-and-play compliance option aimed at regulated organisations with limited IT resources. LOQR|brick exposes the same trust primitives as modular APIs, with no predefined journey. LOQR|sign delivers qualified electronic signature with a one-shot qualified certificate issued in real time, LOQR acting as Registration Authority under the certification authority UANATACA.
Pre-built journeys ship with the platform: online account opening, customer data update, online access recovery, digital account closure and adding a second account holder. A back office adds business metrics through Digital Insights, alongside compliance proof generation and audit logs.
The certifications displayed include LINCE, awarded by the Spanish national cryptologic centre (CCN), ISO/IEC 27001:2022 with the certificate published in full, and ISO/IEC 30107-3, plus eIDAS, GDPR and iBETA badges. The ISO 27001 scope was recently extended to the production platform and its supporting infrastructure. Named banking references include novobanco, Santander, ActivoBank, Millennium BCP, BAI Europa, WiZink, Banco CTT, BIG and Banco Atlantico.
LOQR claims 85% journey success, 80% shorter onboarding, 80% fraud detection and prevention efficiency and 324% customer return on investment, figures published without a stated method. Infrastructure is described as built and operated in Europe. Free side tools, namely a compliance diagnostic, a checklist generator and a public signature validator, are available without an account.
What it does
- Verify a customer's identity remotely through document checks, facial biometrics and liveness detection
- Run KYC/KYB checks and AML screening against sanctions, PEP, RCA and SIP lists
- Have a document signed with a qualified electronic signature in under three minutes
- Issue a one-shot qualified certificate in real time, with no prior enrolment
- Orchestrate pre-built journeys: online account opening, customer data update, access recovery, account closure
- Embed trust primitives into an existing product through the modular LOQR|brick APIs
- Track multi-signer workflows and retrieve the cryptographic audit trail attached to each signature
When to use LOQR / When not to
A quick filter to help you decide if LOQR is the right fit.
When to use LOQR
- Banks and financial institutions digitalising remote account opening and customer lifecycle management
- KYC/KYB and AML compliance teams answering to a European regulator
- Insurers, healthcare, real-estate and HR organisations that need a legally binding qualified signature
- Software vendors looking for auditable trust primitives exposed as modular APIs through LOQR|brick
- Regulated mid-sized organisations wanting a plug-and-play compliance layer with minimal IT resources, via LOQR|one
When not to use LOQR
- Individuals and freelancers looking for a personal e-signature tool: the product is strictly business-to-business
- Teams that want to sign up online and start the same day: there is no self-service plan, only a demo booking or a call with an expert
- Buyers who need public pricing to size a budget: no rate card, no free trial and no free plan are published
- Developers who want to assess the API before any commercial contact: LOQR|brick is sold as API-first, yet no public documentation is available
- Organisations that need a mobile app, or qualified signature outside the countries where, in the words of the LOQR|sign privacy policy, the technical specificities allow it
How to use LOQR
A typical end-to-end flow, from setup to results.
- Start at the Book a demo page or the talk to an expert form: there is no self-service sign-up and no online purchase
- In the meantime, try the free resources that need no account: the 11-question compliance diagnostic, the checklist generator and the signature validator at trust.loqr.com
- Scope the need with the sales team and choose the entry point: LOQR|core, LOQR|one, LOQR|brick or LOQR|sign
- For LOQR|core, connect the platform to your core banking system and CRM using drag-and-drop workflows or API-based flow management
- For LOQR|brick, have your own engineers embed the APIs in your product as auditable trust primitives, with no predefined journey imposed
- Configure the journey to run: online account opening, customer data update, online access recovery or digital account closure
- In a LOQR|sign flow, the signer's identity is verified first through facial recognition and liveness detection
- A one-shot qualified certificate is then issued instantly, with no prior enrolment required from the signer
- The document is signed and multi-signer workflows are tracked through to completion
- Retrieve the audit trail and cryptographic protections attached to each signed document; LOQR states that a customer can later move from LOQR|brick to LOQR|core without changing provider, contracts or trust model
Pros & Cons
Pros
- Qualified electronic signature recognised across EU member states, with the same legal value as a handwritten signature
- One-shot qualified certificate issued in real time, removing the pre-enrolment step from remote onboarding
- Verifiable certifications: LINCE from the Spanish national cryptologic centre, ISO/IEC 27001:2022 with the certificate published as a PDF, and ISO/IEC 30107-3
- Named banking references, with client logos displayed on the site
- Personal data announced as processed within the European Economic Area, with no transfers to third countries
- Two technical routes, modular APIs with LOQR|brick or turnkey orchestration with LOQR|core, and an announced migration path between them
- Free compliance tools usable without an account, plus a reachable DPO and an explicit rights procedure
Cons
- No public pricing and no pricing page: the only commercial entry point is a demo
- No public API documentation, although LOQR|brick is explicitly sold as API-first
- No terms of service published anywhere on the site
- No named list of sub-processors: they are described by category only
- Nothing is stated about whether models are trained on customer data, and no opt-out is documented
- The site privacy policy is dated February 2021, well behind the LOQR|sign policy of September 2024, and one of its mailto links still points to info@loqr.io while the visible address is info@loqr.com
- No mobile app published on the App Store or Google Play, no free trial and no free plan
Pricing & Plans
No pricing is published. The site carries no pricing page, and no amount, currency or billing unit appears anywhere on it. There is no free trial and no free plan. LOQR|one is described as cost-effective, with flexible pricing meaning a customer only pays for what is needed, but no figure supports that statement. Commercial terms are obtained by booking a demo or talking to an expert, which makes the pricing model contact-sales. A few side resources are free and require no account: the compliance diagnostic, the checklist generator and the public signature validator.
- full orchestration of the digital identity lifecycle
- integrated with core banking systems and CRMs. Price on request
- plug-and-play compliance solution built for fast implementation with minimal IT resources. Price on request
- modular trust primitives exposed as APIs
- with no predefined journey. Price on request
- qualified electronic signature with a one-shot qualified certificate. Price on request
- start on LOQR|brick
- move up to LOQR|core
- sign with LOQR|sign. No rate card is published for any of the four offerings
Data, GDPR & hosting
A consolidated view of how LOQR handles your data.
GDPR overview
GDPR compliance is explicitly claimed. Both policies cite Regulation (EU) 2016/679 and Portuguese Law no. 58/2019 of 8 August. The rights listed are information, access, portability, rectification, erasure, restriction, objection, not being subject to automated decision-making, and withdrawal of consent. The supervisory authority named is the Comissao Nacional de Protecao de Dados (CNPD), with full contact details published: Av. D. Carlos I, 134 - 1.o, 1200-651 Lisboa, +351 213 928 400, geral@cnpd.pt. Rights are exercised through dpo@loqr.com for LOQR|sign and info@loqr.com under the site policy. As the company is established in Portugal, no Article 27 representative is required. The dating is uneven: the site policy is marked Updated February 24, 2021, while the LOQR|sign policy is dated 10 September 2024.
Who owns the data?
For LOQR|sign, the controller is LOQR, S.A., NIPC 513653457, with registered office at Rua Dona Maria II 15, 4610-164 Felgueiras, Portugal (privacy policy of 10 September 2024). LOQR acts as Registration Authority on behalf of the certification authority UANATACA, which issues the qualified certificate. The data processed include full name, phone number, email address, a photograph of the identity document, its number and type, a video selfie and the content of the documents submitted for signature. Data subjects are registered users, customers and third parties whose details appear in those documents. Rights are exercised with the DPO at dpo@loqr.com, or by registered letter to the registered office marked EXERCISE OF RIGHTS.
Reuse rights
No terms of service are published, so reuse conditions appear only in the two privacy policies. Under the LOQR|sign policy (10 September 2024), personal data are processed to deliver the signature service and issue the qualified certificate, to invoice, to detect and prevent fraud, to manage the customer relationship and to handle complaints. The site policy (24 February 2021) adds system maintenance, statistical analysis, service delivery, handling of requests, consent-based marketing communications, recruitment and security supervision. The legal bases cited are consent, performance of the contract, legal obligations and legitimate interest. Processors are described by category only - cloud storage, email management, IT security, website maintenance - with no named list. The site takes no position on whether customer data are used to train models, and documents no opt-out.
Data retention & training
Hosting summary
The site privacy policy (24 February 2021) states that the personal data collected will be processed within the European Economic Area and that there are no international transfers of data to third countries or international organisations. Where processing outside the EEA does occur, it announces appropriate safeguards, adequacy decisions and standard contractual clauses. The LOQR|sign policy (10 September 2024) is more specific: a transfer outside the EEA is possible only where the European Commission has recognised an adequate level of protection, failing which the safeguards of Article 46(2) and (3) GDPR apply, and it describes that probability as residual. LOQR|brick is presented as built and operated in Europe, running on the same infrastructure used by leading European banks. No hosting country, data centre location or cloud provider is named anywhere on the site. Note that the domain resolves to an anycast CDN address routed through Amazon in the United States, which indicates nothing about where the data themselves are processed.
Things to keep in mind
Risks and trade-offs to weigh before adopting LOQR.
- No public pricing: no budget can be estimated before contacting the sales team
- No terms of service published: the contractual framework cannot be reviewed before negotiation
- The performance figures on display (85%, 80%, 80%, 324%) are vendor claims with no published method or source
- The site contradicts itself on return on investment: 324% on the homepage and the Platform page, 300% on the About page
- Fifteen-year retention of the data attached to a qualified certificate is a long horizon that belongs in any data protection impact assessment
- No named list of sub-processors, and no public statement on whether customer data are used to train models
- Documentation hygiene: the site privacy policy has not been updated since February 2021, and one of its mailto links still points to info@loqr.io instead of info@loqr.com
Setup & Integrations
Technical difficulty
High, and never self-service. Every deployment starts with a commercial demo, as there is no online sign-up. LOQR|one is presented as designed for fast implementation, avoiding extensive customisation and requiring minimal IT resources and integration effort. LOQR|core connects to core banking systems and CRMs through drag-and-drop workflows or API-based flow management. LOQR|brick requires the customer's own engineers to integrate the APIs, with no public documentation to work from. In practice this is a banking integration project touching compliance, security and core systems, so expect IT, security and compliance stakeholders rather than a single team.
Deployment
Integrations
Behind LOQR
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
Does LOQR publish its prices?
Is a LOQR|sign signature legally binding?
How long does it take to sign a document?
Which certifications does LOQR hold?
Where is the data hosted?
How long is the data kept?
Is there an API?
Who issues the qualified certificate?
How do I exercise my GDPR rights?
Is there a mobile app?
Should you pick LOQR?
LOQR occupies a deliberately narrow position: regulated trust infrastructure for European financial institutions, not a general-purpose e-signature tool. Within that niche the case is solid. The qualified electronic signature carries the same legal value as a handwritten one across EU member states, the one-shot qualified certificate removes the enrolment step that usually slows remote onboarding, and the compliance claim rests on evidence rather than assertion: LINCE certification from the Spanish national cryptologic centre, ISO/IEC 27001:2022 with the certificate published in full, ISO/IEC 30107-3, and named banking references including novobanco, Santander, Millennium BCP and Banco CTT. Personal data are announced as processed within the European Economic Area, with no transfer to third countries.
The counterweight is commercial opacity, and it is complete. There is no pricing page, no terms of service and no public API documentation, the last being awkward for a product line, LOQR|brick, explicitly sold as API-first. The performance figures on display, 85% journey success, 80% shorter onboarding, 324% return on investment, come with no published method, and the site contradicts itself: the same ROI figure appears as 300% on the About page and 324% on the homepage and the Platform page. The legal documentation is uneven too: the site privacy policy has not been revised since February 2021 while the LOQR|sign policy dates from September 2024, and one residual mailto link still points at a former domain.
The practical consequence is straightforward. For a European bank, insurer or regulated organisation with a procurement process and a compliance team, LOQR is a rational shortlist candidate, and the missing documents will surface during negotiation. For anyone wanting to evaluate independently, read the contract, test the API or estimate a budget before speaking to sales, the door is closed. Everything starts with a demo.
- Choosing a selection results in a full page refresh.
- Opens in a new window.