idento.

Privacy Policy

Last updated: 8 July 2026

This policy explains how personal data connected to the Idento website, to the Idento software installed in photography studios and to the image-processing service is handled. It is drawn up pursuant to Regulation (EU) 2016/679 (GDPR) and to Italian Legislative Decree 196/2003 as amended.

1. Who processes your data

The provider of the Idento software and service is:

Gian Marco Elti di Rodeano — sole proprietorship
Registered office: Loc. Piana Sant'Angelo, 66050 San Salvo (CH), Italy
VAT no. 07626701002  ·  Tax code LTDGMR74M19H501W
Certified email (PEC): Gianmarcoeltidirodeano@pec.it
Privacy contact: info@idento.it

2. Two distinct roles: please read carefully

Idento processes two types of data in different roles. It is important to distinguish them.

a) Data of the photography studio (our customer)

With respect to the data of the studio that purchases and uses Idento — licence, account and payment data — we are the data controller. This policy governs that data.

b) Photos of the people photographed by the studio

With respect to the photos of the people who visit the studio for an ID photo, the photography studio is the data controller and Idento acts as data processor (Art. 28 GDPR) on its behalf, limited to the technical passage of the images through our systems. The relationship between studio and Idento regarding this data is governed by a data processing agreement (DPA) signed with each studio. The photographed person must contact the studio to exercise their rights over the photo.

3. What data we process, and for what purposes

Category of dataPurposeLegal basis
Website browsing data (IP address, technical server logs)Deliver and protect the website, securityLegitimate interest (Art. 6.1.f)
Email and message if you contact usRespond to requestsResponse to your request (Art. 6.1.b)
Studio account and licence data (studio name, email, machine hardware identifier)Activate the licence, verify its validity, provide supportPerformance of the contract (Art. 6.1.b)
Payment dataManage licence and credit purchasesPerformance of the contract (Art. 6.1.b)
Photos processed with AI (on behalf of the studio)Image enhancement via AI, only when the studio uses an AI featureProcessed on behalf of the controller (the studio) — see §2b

Face detection, not recognition. Idento locates the position of the face in the frame in order to respect a document's measurements (face detection). It does not create biometric templates nor compare identities (facial recognition). The processing therefore does not fall under Art. 9 GDPR.

4. Artificial-intelligence processing

Some Idento features enhance the photo through artificial-intelligence models. To do so, the photo is sent to third-party AI image-processing providers. In this regard:

5. Who we share data with (processors and sub-processors)

To deliver the service we rely on providers that process data on our behalf, appointed as processors pursuant to Art. 28 GDPR:

Polar Software Inc. handles payments as Merchant of Record: it is the legal seller of the licence and of the credits. For the data it collects during the purchase process (billing data, payment data, VAT), Polar does not act as our processor under Art. 28 GDPR, but as an independent controller, under its own privacy policy. We receive from Polar only the data needed to issue and manage the licence (e-mail address, order reference, country).

We do not sell or transfer personal data to third parties for marketing purposes.

6. Where the photos stay, and for how long

Transparency note (CLOUD Act). Cloudflare is a US company. Even with storage and processing in the EU, it cannot be entirely excluded that US authorities may issue access requests under the CLOUD Act. Given the brevity of the processing (the photo transits only for AI processing or QR delivery and is deleted very quickly), the risk is low; we declare it nonetheless for honesty.

7. Transfers outside the European Union

Some providers (§5) may process data outside the European Economic Area as well. In such cases the transfer takes place on the basis of the Standard Contractual Clauses approved by the European Commission or of another adequate safeguard pursuant to Art. 44 et seq. GDPR.

8. Cookies

This website does not use profiling cookies or any tracking or analytics tools. No consent is therefore required and there is no cookie banner. The server may record technical logs (§3) necessary for security. The Idento app stores local preferences on the studio's computer (language, folders, settings) which do not leave the device except for the purposes described above.

9. Minors

ID photos may relate to minors. The consent of the parent or of the person exercising parental responsibility is collected and managed by the photography studio, as the controller of those images. Idento processes such images only on behalf of the studio and with the same safeguards as §2b, §4 and §6.

10. Your rights

You may exercise at any time the rights provided for by Art. 15–22 GDPR: access, rectification, erasure, restriction, objection, portability. For the data of which we are controller (§2a) write to info@idento.it. For the photos taken in the studio (§2b) the reference is the photography studio. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).

11. Changes

This policy may be updated. The version in force is always the one published on this page, with the last-updated date shown at the top.

12. Language

This policy is drawn up in Italian. Any translations are provided as a courtesy: in case of discrepancy the Italian version prevails for data subjects and customers resident in the European Union, and the English version for those resident outside the European Union.