Privacy Policy
Last updated: 8 July 2026
This policy explains how personal data connected to the Idento website, to the Idento software installed in photography studios and to the image-processing service is handled. It is drawn up pursuant to Regulation (EU) 2016/679 (GDPR) and to Italian Legislative Decree 196/2003 as amended.
1. Who processes your data
The provider of the Idento software and service is:
Gian Marco Elti di Rodeano — sole proprietorship
Registered office: Loc. Piana Sant'Angelo, 66050 San Salvo (CH), Italy
VAT no. 07626701002 · Tax code LTDGMR74M19H501W
Certified email (PEC): Gianmarcoeltidirodeano@pec.it
Privacy contact: info@idento.it
2. Two distinct roles: please read carefully
Idento processes two types of data in different roles. It is important to distinguish them.
a) Data of the photography studio (our customer)
With respect to the data of the studio that purchases and uses Idento — licence, account and payment data — we are the data controller. This policy governs that data.
b) Photos of the people photographed by the studio
With respect to the photos of the people who visit the studio for an ID photo, the photography studio is the data controller and Idento acts as data processor (Art. 28 GDPR) on its behalf, limited to the technical passage of the images through our systems. The relationship between studio and Idento regarding this data is governed by a data processing agreement (DPA) signed with each studio. The photographed person must contact the studio to exercise their rights over the photo.
3. What data we process, and for what purposes
| Category of data | Purpose | Legal basis |
|---|---|---|
| Website browsing data (IP address, technical server logs) | Deliver and protect the website, security | Legitimate interest (Art. 6.1.f) |
| Email and message if you contact us | Respond to requests | Response to your request (Art. 6.1.b) |
| Studio account and licence data (studio name, email, machine hardware identifier) | Activate the licence, verify its validity, provide support | Performance of the contract (Art. 6.1.b) |
| Payment data | Manage licence and credit purchases | Performance of the contract (Art. 6.1.b) |
| Photos processed with AI (on behalf of the studio) | Image enhancement via AI, only when the studio uses an AI feature | Processed on behalf of the controller (the studio) — see §2b |
Face detection, not recognition. Idento locates the position of the face in the frame in order to respect a document's measurements (face detection). It does not create biometric templates nor compare identities (facial recognition). The processing therefore does not fall under Art. 9 GDPR.
4. Artificial-intelligence processing
Some Idento features enhance the photo through artificial-intelligence models. To do so, the photo is sent to third-party AI image-processing providers. In this regard:
- The photo is sent for the sole purpose of producing the requested image and returning it.
- By contract, your photos are never used to train artificial-intelligence models.
- Providers may temporarily retain the image according to their own technical retention policies; the up-to-date list of providers is available on request at info@idento.it and is detailed in the DPA signed with the studio.
- Images produced by the AI may carry a provenance marking (e.g. C2PA/SynthID) inserted by the model provider: it is not removed.
5. Who we share data with (processors and sub-processors)
To deliver the service we rely on providers that process data on our behalf, appointed as processors pursuant to Art. 28 GDPR:
- Cloudflare, Inc. — hosting and network on which the processing (worker) runs, through which the photo transits to the AI provider and, for QR delivery, temporary storage of the photo (R2, EU) until automatic deletion.
- AI image-processing providers — see §4.
Polar Software Inc. handles payments as Merchant of Record: it is the legal seller of the licence and of the credits. For the data it collects during the purchase process (billing data, payment data, VAT), Polar does not act as our processor under Art. 28 GDPR, but as an independent controller, under its own privacy policy. We receive from Polar only the data needed to issue and manage the licence (e-mail address, order reference, country).
We do not sell or transfer personal data to third parties for marketing purposes.
6. Where the photos stay, and for how long
- Processed photos remain on the studio's computer. Idento does not permanently store them on its own servers.
- When the studio uses an AI feature (§4), the photo is transmitted to the Idento servers (Cloudflare, with an EU jurisdictional restriction) and to the AI provider for processing only, then returned; it is not retained beyond the technical time needed.
- If the studio uses QR delivery, the photo is uploaded to Cloudflare R2 (EU jurisdictional restriction) only for the time needed for the customer's download: the link is valid for a few minutes at the counter or a few hours, after which the photo is automatically deleted from our servers. QR delivery is optional: alternatively the studio hands over the file locally, without any cloud.
- Studio data (account, licence) is retained for the duration of the relationship and for the period required by legal obligations (e.g. tax).
Transparency note (CLOUD Act). Cloudflare is a US company. Even with storage and processing in the EU, it cannot be entirely excluded that US authorities may issue access requests under the CLOUD Act. Given the brevity of the processing (the photo transits only for AI processing or QR delivery and is deleted very quickly), the risk is low; we declare it nonetheless for honesty.
7. Transfers outside the European Union
Some providers (§5) may process data outside the European Economic Area as well. In such cases the transfer takes place on the basis of the Standard Contractual Clauses approved by the European Commission or of another adequate safeguard pursuant to Art. 44 et seq. GDPR.
8. Cookies
This website does not use profiling cookies or any tracking or analytics tools. No consent is therefore required and there is no cookie banner. The server may record technical logs (§3) necessary for security. The Idento app stores local preferences on the studio's computer (language, folders, settings) which do not leave the device except for the purposes described above.
9. Minors
ID photos may relate to minors. The consent of the parent or of the person exercising parental responsibility is collected and managed by the photography studio, as the controller of those images. Idento processes such images only on behalf of the studio and with the same safeguards as §2b, §4 and §6.
10. Your rights
You may exercise at any time the rights provided for by Art. 15–22 GDPR: access, rectification, erasure, restriction, objection, portability. For the data of which we are controller (§2a) write to info@idento.it. For the photos taken in the studio (§2b) the reference is the photography studio. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
11. Changes
This policy may be updated. The version in force is always the one published on this page, with the last-updated date shown at the top.
12. Language
This policy is drawn up in Italian. Any translations are provided as a courtesy: in case of discrepancy the Italian version prevails for data subjects and customers resident in the European Union, and the English version for those resident outside the European Union.