This is the privacy notice of International Driving Authority. It explains what personal information we collect, why, how long we keep it, who we share it with, and what you can ask us to do about it. It should be read together with our Cookie Policy, which covers cookies and similar technologies, and our Terms of Service.
1. Who is responsible for your data
The controller of personal data collected on this website is:
INTERNATIONAL DRIVING AUTHORITY LLP
Limited liability partnership registered in the United Kingdom, number OC418927
This policy is written to meet the requirements of the UK GDPR and the Data Protection Act 2018, the EU General Data Protection Regulation, the California Consumer Privacy Act as amended by the CPRA, and the Brazilian General Data Protection Law. If you believe it does not satisfy the law of your jurisdiction, tell us at [email protected] and we will look at it.
2. What we collect
Information you give us when you apply. Your first and last name, date of birth, sex, eye colour and height where the document format requires them, email address, postal address, telephone number, the details of your national driving licence including its number and categories, and your citizenship.
Images you upload. Photographs of your national driving licence (front and back), a photograph of yourself for the document, and a specimen signature.
Payment information. The payment method you chose, the transaction reference, and a masked card reference. We never see or store your full card number — it goes directly to our payment provider.
Information collected automatically. Log data such as your IP address, device and browser type, operating system, referring page, and the date, time and pages of your visit. Cookie and similar identifiers, described in our Cookie Policy.
Your correspondence with us. Emails, chat messages, and support tickets, including anything you choose to send us in them.
3. Where the data comes from
Almost all of it comes from you directly, when you fill in the application form or write to us. The rest is generated automatically when you use the website, or is passed to us by our payment provider when you pay. If a partner agent places an order on your behalf, we receive your details from them, and they are responsible for having your permission to send them.
4. Why we process it, and our legal basis
To perform our contract with you — to check your application, produce your document, deliver it, provide support, and enforce our agreement. (UK/EU GDPR Art. 6(1)(b))
To comply with legal obligations — tax and accounting records, and responding to lawful requests from authorities. (Art. 6(1)(c))
Our legitimate interests — securing our systems, preventing fraud, analysing and improving the website, and defending legal claims. (Art. 6(1)(f))
Your consent — for marketing messages and for non-essential cookies. You can withdraw it at any time, and withdrawing it is as easy as giving it. (Art. 6(1)(a))
5. What we do not do
We think this is as important as the list above.
We do not use facial recognition. The photograph you upload is looked at by a person. We do not run it through face-matching software, we do not derive a face template or any measurement of your face geometry, we do not perform a liveness check, and we do not compare your face against any database.
We make no automated decisions about you. No application is approved or refused by a machine. Every decision is made by a member of our team, so the rights in Article 22 of the GDPR concerning solely automated decision-making do not arise.
We do not sell your personal information, and we do not trade it.
We do not use your documents or your photograph for advertising, for training any model, or for any purpose other than reviewing, producing, and supporting your order, preventing fraud, meeting our legal obligations, or defending legal claims as described in this policy.
If this ever changes, we will update this policy before the change takes effect, not after.
6. Who we share it with
We share the minimum necessary, and only with parties who need it to deliver our service:
Payment providers — Stripe, PayPal, Binance Pay, and our banking partners where applicable, to take and refund payments. They operate their own fraud and sanctions screening at the payment layer.
Carriers — DHL, FedEx, UPS, EMS, and postal operators, who receive your name and delivery address in order to deliver your booklet.
Service providers — hosting, email delivery, customer support tooling, and analytics, bound to use the data only for the service they provide to us.
Partner agents — where you ordered through one, they see the order they placed.
Authorities — where we are legally required to disclose, or where disclosure is necessary to protect our rights, our property, or the safety of any person.
We may also transfer your information as part of a merger, acquisition, financing, reorganisation, or sale of assets. If that happens, the acquirer is bound by this policy for data collected before the transfer.
7. International transfers
We are established in the United Kingdom, and some of our service providers operate outside it, including in the United States. Where personal data leaves the UK or the European Economic Area, we rely on the transfer mechanisms available to us — an adequacy decision where one exists, or the UK International Data Transfer Addendum and the EU Standard Contractual Clauses where one does not — together with the safeguards our providers apply.
8. How long we keep it
Your application, the images you submitted, and the record of your order form a single business record. We keep that record for 10 years from the completion of the order.
That period is not arbitrary. We are required to keep accounting records for six years after the end of the accounting period they fall in; a document we issue may need to be verified, or its issue disputed, years after it was produced; and the images are what allow us to demonstrate that we issued the document correctly, on the basis of what you actually sent us.
What
How long
Application data, uploaded images, order and delivery record, correspondence
10 years from completion of the order
Payment records (masked reference and transaction identifier)
Kept indefinitely, so that we do not contact you again
9. Deleting your data
You can ask us to delete your data at any time, and you do not have to give a reason. Write to [email protected].
We will delete everything we are not legally required to keep, and we will confirm to you what was deleted. Records we must retain by law — principally the accounting record of a transaction — cannot be deleted before their retention period expires. We restrict those to that purpose alone: they are not used for anything else, and they are deleted when the period ends.
Two consequences worth knowing before you ask. Deleting the record of an issued document means we can no longer confirm its authenticity if someone asks us to verify it, and we can no longer reissue it if you lose it. And if your order is still in progress, deletion means we cannot complete it.
10. Your rights
Depending on where you live, you have some or all of the following rights. We do not charge for exercising them, and we do not treat you differently for doing so.
access the personal information we hold about you, and receive a copy;
correct information that is inaccurate or incomplete;
request deletion, as described above;
restrict or object to certain processing;
receive your information in a portable, machine-readable format;
withdraw consent at any time, where we rely on it;
lodge a complaint with a supervisory authority.
United Kingdom and European Economic Area. These rights arise under the UK GDPR and the EU GDPR. In the UK you may complain to the Information Commissioner's Office; in the EEA, to your national data protection authority.
California. Under the CCPA as amended by the CPRA you may request disclosure of the categories and specific pieces of personal information we collected, request deletion or correction, and opt out of any sale or sharing. We do not sell personal information. We do not knowingly collect the personal information of anyone under 16.
Brazil. Under the LGPD you may request confirmation of processing, access, correction, anonymisation or deletion, portability, and information about with whom we have shared your data.
Elsewhere. If your local law gives you a right not listed here, tell us and we will honour it where we can.
To exercise any right, write to [email protected]. We take reasonable steps to verify your identity first — usually by writing to the email address on the order — because acting on an unverified request would itself be a breach. We respond within 30 days, and tell you if we need longer.
11. Security
We encrypt data in transit using TLS. Access to our systems is limited to the people who need it for their work. Payment card data never reaches our servers. We use current, supported software and keep it patched.
No system is completely secure, and we would rather say so than claim otherwise. If we become aware of a breach affecting your personal data, we will notify the relevant supervisory authority and, where the law requires it, you.
12. Marketing
We send marketing messages only where you have agreed to receive them. Every message contains an unsubscribe link, and you can also write to us. Messages about an order you have placed — confirmations, status updates, delivery notifications — are not marketing and are sent regardless.
13. Children
Our service is not directed at children and we do not knowingly collect personal information from them. If you believe a child has provided us with personal data, contact us and we will remove it.
14. Changes to this policy
We may update this policy. Material changes are posted on this page and the date at the top is updated. Where a change affects how we use data we already hold, we will tell you before it takes effect.
15. Contact and complaints
For any privacy question, or to exercise a right, write to [email protected]. We would rather hear from you first, but you may complain to a supervisory authority at any time — in the United Kingdom, the Information Commissioner's Office at ico.org.uk.