LOQR logo
Security Fraud · Privacy Security

LOQR

LOQR is a Portuguese identity orchestration platform for banks and financial institutions, combining remote identity verification, KYC/KYB compliance automation and qualified electronic signature under eIDAS 2.0 and GDPR, delivered as pre-built customer journeys rather than standalone tools.

Active GDPR compliant Contact Sales API available Verified by Guidaio
Overview

What is LOQR?

LOQR is an identity orchestration platform published by LOQR, S.A., a Portuguese company headquartered in Felgueiras with a second office in Lisbon. The company describes itself as an AI-Powered Journey-as-a-Service provider for financial institutions and positions the product as trust infrastructure for banks operating under eIDAS 2.0 and the GDPR.

The platform is organised around three families of capabilities. KYC/KYB covers identity document checks, device, phone, email and IP checks, bank account verification, AML screening and PEP, RCA and SIP screening. Identity Verification covers facematch, liveness detection, self-video interviews and live interviews. e-Sign covers three levels of electronic signature: advanced signature, advanced certificate signature and qualified certificate signature.

Four named offerings package those capabilities. LOQR|core orchestrates the full digital identity lifecycle and connects to core banking systems and CRMs. LOQR|one is a plug-and-play compliance option aimed at regulated organisations with limited IT resources. LOQR|brick exposes the same trust primitives as modular APIs, with no predefined journey. LOQR|sign delivers qualified electronic signature with a one-shot qualified certificate issued in real time, LOQR acting as Registration Authority under the certification authority UANATACA.

Pre-built journeys ship with the platform: online account opening, customer data update, online access recovery, digital account closure and adding a second account holder. A back office adds business metrics through Digital Insights, alongside compliance proof generation and audit logs.

The certifications displayed include LINCE, awarded by the Spanish national cryptologic centre (CCN), ISO/IEC 27001:2022 with the certificate published in full, and ISO/IEC 30107-3, plus eIDAS, GDPR and iBETA badges. The ISO 27001 scope was recently extended to the production platform and its supporting infrastructure. Named banking references include novobanco, Santander, ActivoBank, Millennium BCP, BAI Europa, WiZink, Banco CTT, BIG and Banco Atlantico.

LOQR claims 85% journey success, 80% shorter onboarding, 80% fraud detection and prevention efficiency and 324% customer return on investment, figures published without a stated method. Infrastructure is described as built and operated in Europe. Free side tools, namely a compliance diagnostic, a checklist generator and a public signature validator, are available without an account.

What it does

  • Verify a customer's identity remotely through document checks, facial biometrics and liveness detection
  • Run KYC/KYB checks and AML screening against sanctions, PEP, RCA and SIP lists
  • Have a document signed with a qualified electronic signature in under three minutes
  • Issue a one-shot qualified certificate in real time, with no prior enrolment
  • Orchestrate pre-built journeys: online account opening, customer data update, access recovery, account closure
  • Embed trust primitives into an existing product through the modular LOQR|brick APIs
  • Track multi-signer workflows and retrieve the cryptographic audit trail attached to each signature
Audience

When to use LOQR / When not to

A quick filter to help you decide if LOQR is the right fit.

When to use LOQR

  • Banks and financial institutions digitalising remote account opening and customer lifecycle management
  • KYC/KYB and AML compliance teams answering to a European regulator
  • Insurers, healthcare, real-estate and HR organisations that need a legally binding qualified signature
  • Software vendors looking for auditable trust primitives exposed as modular APIs through LOQR|brick
  • Regulated mid-sized organisations wanting a plug-and-play compliance layer with minimal IT resources, via LOQR|one

When not to use LOQR

  • Individuals and freelancers looking for a personal e-signature tool: the product is strictly business-to-business
  • Teams that want to sign up online and start the same day: there is no self-service plan, only a demo booking or a call with an expert
  • Buyers who need public pricing to size a budget: no rate card, no free trial and no free plan are published
  • Developers who want to assess the API before any commercial contact: LOQR|brick is sold as API-first, yet no public documentation is available
  • Organisations that need a mobile app, or qualified signature outside the countries where, in the words of the LOQR|sign privacy policy, the technical specificities allow it
Get started

How to use LOQR

A typical end-to-end flow, from setup to results.

  1. Start at the Book a demo page or the talk to an expert form: there is no self-service sign-up and no online purchase
  2. In the meantime, try the free resources that need no account: the 11-question compliance diagnostic, the checklist generator and the signature validator at trust.loqr.com
  3. Scope the need with the sales team and choose the entry point: LOQR|core, LOQR|one, LOQR|brick or LOQR|sign
  4. For LOQR|core, connect the platform to your core banking system and CRM using drag-and-drop workflows or API-based flow management
  5. For LOQR|brick, have your own engineers embed the APIs in your product as auditable trust primitives, with no predefined journey imposed
  6. Configure the journey to run: online account opening, customer data update, online access recovery or digital account closure
  7. In a LOQR|sign flow, the signer's identity is verified first through facial recognition and liveness detection
  8. A one-shot qualified certificate is then issued instantly, with no prior enrolment required from the signer
  9. The document is signed and multi-signer workflows are tracked through to completion
  10. Retrieve the audit trail and cryptographic protections attached to each signed document; LOQR states that a customer can later move from LOQR|brick to LOQR|core without changing provider, contracts or trust model
Quick read

Pros & Cons

Pros

  • Qualified electronic signature recognised across EU member states, with the same legal value as a handwritten signature
  • One-shot qualified certificate issued in real time, removing the pre-enrolment step from remote onboarding
  • Verifiable certifications: LINCE from the Spanish national cryptologic centre, ISO/IEC 27001:2022 with the certificate published as a PDF, and ISO/IEC 30107-3
  • Named banking references, with client logos displayed on the site
  • Personal data announced as processed within the European Economic Area, with no transfers to third countries
  • Two technical routes, modular APIs with LOQR|brick or turnkey orchestration with LOQR|core, and an announced migration path between them
  • Free compliance tools usable without an account, plus a reachable DPO and an explicit rights procedure

Cons

  • No public pricing and no pricing page: the only commercial entry point is a demo
  • No public API documentation, although LOQR|brick is explicitly sold as API-first
  • No terms of service published anywhere on the site
  • No named list of sub-processors: they are described by category only
  • Nothing is stated about whether models are trained on customer data, and no opt-out is documented
  • The site privacy policy is dated February 2021, well behind the LOQR|sign policy of September 2024, and one of its mailto links still points to info@loqr.io while the visible address is info@loqr.com
  • No mobile app published on the App Store or Google Play, no free trial and no free plan
Pricing

Pricing & Plans

No pricing is published. The site carries no pricing page, and no amount, currency or billing unit appears anywhere on it. There is no free trial and no free plan. LOQR|one is described as cost-effective, with flexible pricing meaning a customer only pays for what is needed, but no figure supports that statement. Commercial terms are obtained by booking a demo or talking to an expert, which makes the pricing model contact-sales. A few side resources are free and require no account: the compliance diagnostic, the checklist generator and the public signature validator.

Plan 1
LOQR|core
  • full orchestration of the digital identity lifecycle
  • integrated with core banking systems and CRMs. Price on request
Plan 3
LOQR|brick
  • modular trust primitives exposed as APIs
  • with no predefined journey. Price on request
Plan 4
LOQR|sign
  • qualified electronic signature with a one-shot qualified certificate. Price on request
Announced progression
  • start on LOQR|brick
  • move up to LOQR|core
  • sign with LOQR|sign. No rate card is published for any of the four offerings
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how LOQR handles your data.

GDPR overview

GDPR compliance is explicitly claimed. Both policies cite Regulation (EU) 2016/679 and Portuguese Law no. 58/2019 of 8 August. The rights listed are information, access, portability, rectification, erasure, restriction, objection, not being subject to automated decision-making, and withdrawal of consent. The supervisory authority named is the Comissao Nacional de Protecao de Dados (CNPD), with full contact details published: Av. D. Carlos I, 134 - 1.o, 1200-651 Lisboa, +351 213 928 400, geral@cnpd.pt. Rights are exercised through dpo@loqr.com for LOQR|sign and info@loqr.com under the site policy. As the company is established in Portugal, no Article 27 representative is required. The dating is uneven: the site policy is marked Updated February 24, 2021, while the LOQR|sign policy is dated 10 September 2024.

Who owns the data?

For LOQR|sign, the controller is LOQR, S.A., NIPC 513653457, with registered office at Rua Dona Maria II 15, 4610-164 Felgueiras, Portugal (privacy policy of 10 September 2024). LOQR acts as Registration Authority on behalf of the certification authority UANATACA, which issues the qualified certificate. The data processed include full name, phone number, email address, a photograph of the identity document, its number and type, a video selfie and the content of the documents submitted for signature. Data subjects are registered users, customers and third parties whose details appear in those documents. Rights are exercised with the DPO at dpo@loqr.com, or by registered letter to the registered office marked EXERCISE OF RIGHTS.

Reuse rights

No terms of service are published, so reuse conditions appear only in the two privacy policies. Under the LOQR|sign policy (10 September 2024), personal data are processed to deliver the signature service and issue the qualified certificate, to invoice, to detect and prevent fraud, to manage the customer relationship and to handle complaints. The site policy (24 February 2021) adds system maintenance, statistical analysis, service delivery, handling of requests, consent-based marketing communications, recruitment and security supervision. The legal bases cited are consent, performance of the contract, legal obligations and legitimate interest. Processors are described by category only - cloud storage, email management, IT security, website maintenance - with no named list. The site takes no position on whether customer data are used to train models, and documents no opt-out.

Data retention & training

Retention summary
Two regimes coexist. The LOQR|sign privacy policy (10 September 2024) sets a single figure: personal data will only be retained by LOQR for 15 years counting from the revocation of the qualified certificate issued. The site privacy policy (24 February 2021) sets no figure at all. It states that data are kept for as long as necessary or legally required for the purposes pursued, using criteria adapted to each processing operation and the civil and criminal limitation periods that apply. Once those periods expire, data are deleted or anonymised, unless a distinct and prevailing purpose justifies keeping them. Buyers should note that fifteen years from certificate revocation is a long horizon and belongs in any data protection impact assessment.
GDPR contact

Hosting summary

The site privacy policy (24 February 2021) states that the personal data collected will be processed within the European Economic Area and that there are no international transfers of data to third countries or international organisations. Where processing outside the EEA does occur, it announces appropriate safeguards, adequacy decisions and standard contractual clauses. The LOQR|sign policy (10 September 2024) is more specific: a transfer outside the EEA is possible only where the European Commission has recognised an adequate level of protection, failing which the safeguards of Article 46(2) and (3) GDPR apply, and it describes that probability as residual. LOQR|brick is presented as built and operated in Europe, running on the same infrastructure used by leading European banks. No hosting country, data centre location or cloud provider is named anywhere on the site. Note that the domain resolves to an anycast CDN address routed through Amazon in the United States, which indicates nothing about where the data themselves are processed.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting LOQR.

  • No public pricing: no budget can be estimated before contacting the sales team
  • No terms of service published: the contractual framework cannot be reviewed before negotiation
  • The performance figures on display (85%, 80%, 80%, 324%) are vendor claims with no published method or source
  • The site contradicts itself on return on investment: 324% on the homepage and the Platform page, 300% on the About page
  • Fifteen-year retention of the data attached to a qualified certificate is a long horizon that belongs in any data protection impact assessment
  • No named list of sub-processors, and no public statement on whether customer data are used to train models
  • Documentation hygiene: the site privacy policy has not been updated since February 2021, and one of its mailto links still points to info@loqr.io instead of info@loqr.com
Setup

Setup & Integrations

Technical difficulty

High, and never self-service. Every deployment starts with a commercial demo, as there is no online sign-up. LOQR|one is presented as designed for fast implementation, avoiding extensive customisation and requiring minimal IT resources and integration effort. LOQR|core connects to core banking systems and CRMs through drag-and-drop workflows or API-based flow management. LOQR|brick requires the customer's own engineers to integrate the APIs, with no public documentation to work from. In practice this is a banking integration project touching compliance, security and core systems, so expect IT, security and compliance stakeholders rather than a single team.

Deployment

Web appAPI

Integrations

UANATACA
Company

Behind LOQR

Company name
LOQR, S.A.
Founded
INFORMATION_NOT_FOUND
Country of origin
🇵🇹 Portugal
Headquarters
R. Dona Maria II, 15, 4610-164 Felgueiras, Portugal
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇺🇸 United States

Fundraising

2015 - pre-seed round, alongside participation in the Startup Braga acceleration programme (About us timeline)
2018 - seed round (About us timeline)
2021 - Series A of EUR 8 million (About us timeline)
Investors named on the About page: EDP Ventures (EDP Cleantech fund), Banco Portugues de Fomento, Iberis Capital, Semapa Next, BiG Start Ventures and HCapital
European public funding NORTE-02-0752-FEDER-043720, internationalisation: EUR 482,529.07 eligible cost, EUR 217,138.08 from the ERDF, 2019-2022
European public funding NORTE-06-3827-FEDER-000119: EUR 135,625.03, 2017-2019
Project 25776, LOQR - Digital Trust AI, under the Portuguese Recovery and Resilience Plan: EUR 375,988.61 eligible cost, EUR 281,991.46 from the European Union, 1 November 2025 to 30 October 2027
Share capital recorded at the Portuguese commercial registry: EUR 76,589.00

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Does LOQR publish its prices?
No. There is no pricing page and no amount appears anywhere on the site. Pricing is obtained by booking a demo or talking to an expert, and there is no free trial and no free plan.
Is a LOQR|sign signature legally binding?
The site presents the qualified electronic signature as recognised across EU member states, with the same legal value as a handwritten signature.
How long does it take to sign a document?
The site states that a qualified electronic signature can be completed end to end in under three minutes.
Which certifications does LOQR hold?
LINCE, awarded by the Spanish national cryptologic centre (CCN), ISO/IEC 27001:2022 with the certificate published as a PDF, and ISO/IEC 30107-3. eIDAS, GDPR and iBETA badges are also displayed.
Where is the data hosted?
The site privacy policy states that personal data are processed within the European Economic Area with no international transfers to third countries. LOQR|brick is described as built and operated in Europe. No hosting country, data centre or cloud provider is named.
How long is the data kept?
For LOQR|sign, personal data are retained for 15 years counting from the revocation of the qualified certificate issued. The site policy gives no figure, only the duration necessary for the purposes and the applicable legal limitation periods.
Is there an API?
Yes. LOQR|brick exposes modular APIs and is sold as API-first, but no public documentation is accessible.
Who issues the qualified certificate?
LOQR acts as Registration Authority on behalf of the certification authority UANATACA, which issues the qualified certificate.
How do I exercise my GDPR rights?
Write to dpo@loqr.com, or send a registered letter to the registered office in Felgueiras with EXERCISE OF RIGHTS as the subject.
Is there a mobile app?
No application is published on the App Store or on Google Play.
Conclusion

Should you pick LOQR?

LOQR occupies a deliberately narrow position: regulated trust infrastructure for European financial institutions, not a general-purpose e-signature tool. Within that niche the case is solid. The qualified electronic signature carries the same legal value as a handwritten one across EU member states, the one-shot qualified certificate removes the enrolment step that usually slows remote onboarding, and the compliance claim rests on evidence rather than assertion: LINCE certification from the Spanish national cryptologic centre, ISO/IEC 27001:2022 with the certificate published in full, ISO/IEC 30107-3, and named banking references including novobanco, Santander, Millennium BCP and Banco CTT. Personal data are announced as processed within the European Economic Area, with no transfer to third countries.

The counterweight is commercial opacity, and it is complete. There is no pricing page, no terms of service and no public API documentation, the last being awkward for a product line, LOQR|brick, explicitly sold as API-first. The performance figures on display, 85% journey success, 80% shorter onboarding, 324% return on investment, come with no published method, and the site contradicts itself: the same ROI figure appears as 300% on the About page and 324% on the homepage and the Platform page. The legal documentation is uneven too: the site privacy policy has not been revised since February 2021 while the LOQR|sign policy dates from September 2024, and one residual mailto link still points at a former domain.

The practical consequence is straightforward. For a European bank, insurer or regulated organisation with a procurement process and a compliance team, LOQR is a rational shortlist candidate, and the missing documents will surface during negotiation. For anyone wanting to evaluate independently, read the contract, test the API or estimate a budget before speaking to sales, the door is closed. Everything starts with a demo.