01Parties and roles
For customer personal data processed through the platform, the customer is the controller and ID-ware is the processor, acting only on the customer's documented instructions as set out in the customer agreement. Amazon Web Services (AWS) is engaged as a sub-processor, providing the underlying cloud infrastructure. Data-protection questions go to dpo@id-ware.com.
02Scope and purpose
ID-ware processes personal data solely to provide the contracted service - for Photon, collecting and quality-checking ID photos and returning print-ready portraits; for the wider PIAM Suite, brokering one identity record across the customer's systems and doors. Processing is limited to what is necessary for those purposes and to the customer's instructions.
03Sub-processors and the AWS Overlay
ID-ware operates its own application layer (the ID-ware Overlay) on top of AWS infrastructure. AWS is the principal sub-processor, used purely as technology - compute, storage, content delivery, and Amazon Rekognition for face detection. The sub-processing relationship is governed by, and consistent with, the AWS Data Processing Addendum. A current list of sub-processors is available on request, and any addition or replacement is notified at least 30 days in advance with an opportunity to object.
04No model training, no AI development
Customer personal data is not used to train, fine-tune or improve any artificial-intelligence or machine-learning model, whether ID-ware's or a third party's. AWS services are used only to deliver the contracted functionality and, in line with the AWS Data Processing Addendum, AWS does not use customer content to develop or improve its services or models. Photon uses Amazon Rekognition for face detection only - it checks that a single, well-composed face is present. It does not perform facial recognition, does not match or identify people, and stores no biometric templates.
05Data location and residency
Customer personal data is processed in the UK and EU sovereign cloud, with three hosting options: London (AWS eu-west-2), Frankfurt (AWS eu-central-1), and the AWS European Sovereign Cloud (EUSC). Data does not leave the UK or the EU except where the customer agreement expressly provides otherwise.
06Security
Personal data is encrypted in transit and at rest, access is restricted on a least-privilege basis, activity is audit-logged, and the service sits behind a web application firewall. ID-ware holds ISO/IEC 27001 and ISO 9001 and Cyber Essentials Plus; evidence is available to support the customer's own assurance.
07Assistance and data-subject rights
ID-ware assists the controller, taking into account the nature of the processing, in responding to requests from individuals exercising their rights under the UK GDPR and the EU GDPR (access, rectification, erasure, restriction, portability and objection), and in meeting the controller's wider obligations including data-protection impact assessments.
08Personal-data breaches
ID-ware notifies the controller of a personal-data breach affecting the customer's data within 72 hours of becoming aware of it, and provides the information the controller reasonably needs to meet its own notification duties (in phases where not all of it is available at once).
09International transfers
Processing takes place within the UK and EU as described above. Where any transfer outside the UK or EEA is required, it is made under an approved mechanism - for example the UK International Data Transfer Addendum or the EU Standard Contractual Clauses - as set out in the executed agreement.
10Return and deletion
On termination of the service, ID-ware returns or deletes the customer's personal data at the customer's choice, save where retention is required by law, and deletes existing copies within the period set out in the agreement.
11Audit
ID-ware makes available the information necessary to demonstrate compliance with these processing terms, responding to a written information request within two weeks, and supports an audit by the controller or an auditor it mandates as a measure of last resort, including by providing the certifications and reports referenced above.
This is a plain-language summary. The executed Data Processing Agreement, and the AWS Data Processing Addendum it relies on, govern in all cases. To request the full DPA or raise a data-protection question, contact dpo@id-ware.com.