
IDPIC / Company
Data protection principles
IDPIC should process only the data required to provide document-photo tools, accounts, payment and necessary support. Processing follows purpose limitation, minimisation, integrity and confidentiality principles.
Global
document coverage
Expanding
photo format library
Private
encrypted processing
Secure transfer and storage
The production site uses HTTPS for traffic between the browser and the service. Uploaded images are held in private object storage and are not published as public media or searchable content.
Access controls
Account, order and photo access is tied to verified users and limited authorisation. Users should choose a unique password and avoid leaving sessions or downloaded files on public or shared devices.
Payment security
Payments are handled by a third-party payment provider. IDPIC does not store complete card details in its own interface, and payment sessions remain separated from portrait-processing data.
Ongoing checks and incident reporting
Report suspected unauthorised access or an exposed download link to support@tryidpic.com with the time and relevant task reference. Do not post the link publicly or send passwords. Security controls can reduce exposure, but this page does not claim an independent certification, an audit result or absolute protection that has not been established.
Cookies and privacy choices
Essential storage may maintain sign-in, language and core workflows. Non-essential measurement or performance technologies should provide transparent information and a choice whenever they are enabled.
Encryption and necessary processing
HTTPS protects traffic between your browser and the service, and uploaded files use access controls rather than a public gallery. Server-side image processing still requires the service and its necessary processors to handle the image. Transport encryption must not be described as a promise that no server can access the photo. A signed preview or download link can provide temporary access. Treat that link as private, avoid posting it publicly and remove downloaded copies from shared devices. No security measure removes every risk.
Deletion is a separate control
Photo deletion follows the published 7-day unpaid and 30-day paid policy, and you may initiate earlier deletion. The end of a session, a successful download or signing out does not itself confirm deletion. Check the deletion result or request confirmation from support when needed. Deleting portrait files does not automatically erase an order or security record. Records needed for payment reconciliation, dispute handling or legal obligations are considered separately under the privacy policy.