How we handleyour data.
Photon and the wider ID-ware platform are built for organisations that have to answer hard questions about data. Here is where your data lives, how it is protected, and the privacy stance behind Photon - in plain terms, and limited to what we can stand behind.
Standing answers for a security review
Trust · standing answers- Residency
- UK London (eu-west-2) and EU Frankfurt (eu-central-1), both AWS commercial cloud, or the AWS European Sovereign Cloud (EUSC) for sovereign customers. Data stays within UK and EU jurisdiction.
- Encryption
- In transit and at rest.
- Certifications
- ISO 9001, ISO/IEC 27001 and Cyber Essentials Plus at the organisation level; TISAX participant.
- Testing
- Regular penetration testing, with findings tracked to resolution. Audit logging and a web application firewall in front of the platform.
- Photon privacy
- Face detection only - never facial recognition, and no biometric templates.
UK and EU sovereign cloud.
Hosted in the UK and EU.
The website and the Photon service can run from London (AWS eu-west-2) or Frankfurt (AWS eu-central-1), both AWS commercial cloud, or the AWS European Sovereign Cloud (EUSC) for sovereign customers. Your data stays within UK and EU jurisdiction.
Website data only.
This site stores website data: content you read, the enquiry details you choose to send us, and the references we need to process a purchase. It is separate from the Photon product service that handles photos.
Card details never touch our systems.
Payments are taken through Stripe's hosted checkout. Card numbers go straight to Stripe and are never stored on ID-ware infrastructure.
Encrypted, logged, tested.
Encryption in transit and at rest.
Traffic is served over HTTPS, and data is encrypted where it is stored.
Audit logging and a web application firewall.
Requests pass through a web application firewall, and access is logged so activity can be reviewed.
Regular penetration testing.
The platform is tested regularly by security professionals, and findings are tracked to resolution. Access is designed around least privilege and separated environments.
Photon detects faces. It never recognises them.
Detection, not recognition.
Photon checks a photo for quality and composition and removes the background. It uses face detection to find the face in the frame. It does not perform facial recognition, and it does not create or store biometric templates.
Kept only as long as needed.
Personal data is held only for the purpose it was given, kept no longer than your settings allow, and deleted on request. The full detail, your rights, and how to exercise them are in the privacy notice.
Held at the organisation level.
ID-ware holds ISO 9001 (quality management) and ISO/IEC 27001 (information security) at the organisation level, with Cyber Essentials Plus, and is a TISAX participant. TISAX is a registered trademark of the ENX Association. GDPR, NIS2 and DORA alignment is maintained across the platform.
Under UK and EU data protection law.
ID-ware processes personal data under UK GDPR and EU GDPR. You have the rights those laws give you, including access, correction and deletion. The privacy notice sets out how to exercise them and how to reach the relevant supervisory authority.
Still have a question?
Security and procurement teams are welcome to get in touch before starting a trial. We answer plainly.
There is no glossy security pack - just direct answers from the team that runs the platform.