Data Processing Agreement (DPA)
Version 1.0 — 8 July 2026 · pursuant to Art. 28 GDPR
This agreement governs the processing, by Idento, of the images of the people photographed by the Studio. It supplements the Terms of Service and the Privacy Policy. It is deemed to be signed between the Parties upon acceptance of the Terms during licence activation.
1. The Parties and roles
- Data controller: the photography Studio that uses Idento and decides the purposes and means of processing the photos of its own customers.
- Data processor: Gian Marco Elti di Rodeano — sole proprietorship, VAT no.
07626701002, registered office Loc. Piana Sant'Angelo, 66050 San Salvo (CH), Italy (hereinafter "Idento"), which processes the photos exclusively on behalf of the Studio.
2. Subject matter, duration, nature and purpose
| Subject matter | AI enhancement of the images provided by the Studio and, if the Studio uses QR delivery, temporary storage of the photo solely for the customer's download. Note: framing and measurements happen locally on the Studio's PC and do not entail any processing by Idento. |
|---|---|
| Duration | For the duration of the licence; each image is processed only for the technical time needed (see §7). |
| Nature | Automated image-processing operations for the sole duration of the AI request. |
| Purpose | To produce the enhanced ID photo requested by the Studio. |
| Types of data | Face images (ordinary data, Art. 6 GDPR — Idento performs face detection, not biometric recognition). |
| Categories of data subjects | The people photographed by the Studio, including any minors. |
3. Controller's instructions
Idento processes the data only on documented instructions of the Studio. Use of the software in accordance with its documentation constitutes a documented instruction. Idento informs the Studio if, in its opinion, an instruction infringes the GDPR or other data-protection rules.
4. Confidentiality
Idento ensures that the persons authorised to process the data are bound by an appropriate obligation of confidentiality.
5. Security (Art. 32 GDPR)
- Encrypted transmission of the images (TLS).
- Processed images remain on the Studio's computer; they transit to the Idento servers only when the Studio uses an AI feature (for processing only) or QR delivery.
- Server-side processing runs on Cloudflare with an EU jurisdictional restriction; the images are not retained beyond the technical time needed.
- For QR delivery: the photo is uploaded to Cloudflare R2 (EU) under a dedicated path, with a link valid for a few minutes (counter) or a few hours, and automatically deleted (expired link + periodic cleanup). The Studio's logos stay outside this path and are not subject to deletion.
- Access controls.
- The images are never used to train artificial-intelligence models.
6. Sub-processors
The Studio authorises Idento to use the sub-processors listed below. Idento imposes on them data-protection obligations equivalent to those of this agreement and remains responsible for their performance. Idento gives advance notice of any changes, giving the Studio the opportunity to object.
| Sub-processor | Activity | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, network, temporary image storage (R2, EU) | USA / EU |
| AI image-processing providers | Image enhancement (only if the Studio uses an AI feature) | EU / non-EU |
The up-to-date named list of AI providers is available on request at info@idento.it.
7. Deletion and return
At the end of the processing the images are deleted according to the rules of §5. Idento does not retain copies of the images beyond the technical time needed. On request, Idento confirms deletion in writing.
8. Assistance to the Controller
Taking into account the nature of the processing, Idento assists the Studio, with appropriate measures, in fulfilling its obligations to respond to data-subject requests (Art. 15–22 GDPR) and its obligations regarding security, breach notification and impact assessment (Art. 32–36 GDPR). Since the images are deleted within a short time, most requests must be handled by the Studio, the only stable holder of the photos.
9. Data breaches
Idento informs the Studio without undue delay after becoming aware of a personal-data breach concerning the images processed on its behalf, providing the information useful for the Studio's obligations towards the Data Protection Authority and the data subjects.
10. Transfers outside the EU
Where a sub-processor processes data outside the European Economic Area, the transfer takes place on the basis of the European Commission's Standard Contractual Clauses or of another adequate safeguard (Art. 44 et seq. GDPR). Idento notes that Cloudflare is a US company: even with storage in the EU, access under the CLOUD Act cannot be entirely excluded; the risk is mitigated by the brevity of the processing: the photo transits only for AI processing or for QR delivery and is deleted within a very short time.
11. Audit
Idento makes available to the Studio the information necessary to demonstrate compliance with Art. 28 GDPR and allows, with reasonable notice and in compliance with confidentiality, audits conducted by the Studio or by an appointed party.
12. Minors
The collection of the consent of the parent or of the person exercising parental responsibility, for the photos of minors, is the responsibility of the Studio as Controller. Idento processes such images with the same safeguards as §5.
13. Precedence and governing law
In the event of a conflict between this agreement and the Terms of Service regarding the processing of data on behalf of the Studio, this agreement prevails. Italian law applies; for B2B disputes the court of Vasto (CH), Italy has jurisdiction.
This agreement is drawn up in Italian; any translations are provided as a courtesy: in case of discrepancy, the Italian version prevails for Studios established in the European Union and the English version for those established outside the European Union.
This DPA is deemed to be signed upon acceptance of the Terms of Service during activation. A Studio that requires a signed copy on letterhead may request one at info@idento.it.