DAPI Certification
DAPI Certification

Privacy & Cookie Policy

DAPI certification is designed to minimize data exposure while producing verifiable technical documentation. This page explains what data we collect, why we collect it, how we protect it, what rights you have, and which cookies the site uses.

Last updated: January 9, 2026

Section 01

Who Is the Data Controller

The Data Controller is Informatica in Azienda di Emanuel Celano, the organization that operates DAPI Certification (the "Service").

For any privacy-related request, data protection request, or to exercise your rights: contact us using the official email address published on the website's contact page. We will respond to your request within the timeframes required by applicable data protection laws.

Our approach to data protection is based on transparency, data minimization, and respect for your fundamental rights under the GDPR (Regulation (EU) 2016/679) and other applicable privacy laws.

Section 02

What Data We Process

Depending on your service request and how you interact with DAPI, we may process the following categories of personal data:

  • Identification and contact data: first name, last name, email address, country of residence, and any additional information you voluntarily provide on the certification request form, in email communications, or in support interactions
  • Verification files you submit (the "Certification Files"): typically up to four identity-related files, including: (1) a valid government-issued identity document (passport, national ID card, driving licence), (2) a frontal facial photograph, (3) an audio voice recording, and (4) a short verification video. The specific files required may vary depending on the certification package
  • Technical metadata generated during certification: original file names (as provided by you), file sizes, file formats, SHA-256 cryptographic hashes, qualified timestamp certificates, DAPI certification code, certification date, and internal process logs documenting process handling and integrity verification procedures
  • Website usage data and technical data: when you visit our website, we collect limited technical information including IP address, user agent string, device type, browser information, referring URL, pages visited, and timestamps. This data is collected through server logs and, if enabled, analytics cookies for website security and performance optimization
  • Communication records: emails, messages, and other communications between you and DAPI support relating to your certification request, delivery, or information requests

Important

Your Certification Files contain sensitive biometric and identity data. DAPI handles this data with the highest level of security and minimizes retention according to the rigorous protocols detailed in Section 6 (Data Minimization and Retention).

Section 03

What We DO NOT Do

DAPI is built on privacy-first principles. To be absolutely clear about what we DO NOT do with your data:

  • We DO NOT create a public biometric database. DAPI is not a biometric registry, an identity verification platform, or a searchable database. Your biometric data is used exclusively for your private certification and is not stored in any form that allows searching, matching, or comparison with other users
  • We DO NOT publish or make your certification public. Your certification package, certificate, and all related materials are private. Nothing is indexed by search engines, made publicly accessible, or published online. Only you receive the certification deliverables
  • We DO NOT create searchable profiles or verification badges. There is no public "DAPI profile" associated with your name or identity (for DAPI-IDS). The certification exists exclusively as a private documentary package in your possession
  • We DO NOT sell, rent, or exchange personal data. Your data is never sold to third parties, data brokers, advertisers, or marketing companies
  • We DO NOT use your biometric data for purposes unrelated to your certification. Your facial photos, voice recordings, and verification videos are processed exclusively to generate the requested certification – never for facial recognition systems, voice analysis products, AI training datasets, or any other purpose
Section 04

Purposes of Processing

We process your personal data only for legitimate, specific, and clearly defined purposes. Every processing activity is limited to what is necessary to achieve that purpose.

  • Service delivery and contract performance: to perform the DAPI certification service you requested, including receiving files, generating hashes, applying the timestamp, creating the certificate, quality control, and secure delivery of the complete certification package
  • Technical documentation and supporting elements: to generate cryptographic hashes (SHA-256), apply qualified timestamps (eIDAS-compliant), create process documentation, and produce technical elements that support the integrity and time reference of the certified materials
  • Security and fraud prevention: to protect the Service from misuse, impersonation attempts, fraudulent certification requests, unauthorized access, and abuse of our systems. This includes legitimacy verification and security monitoring
  • Customer support and communication: to respond to your questions, provide technical assistance, provide secure instructions for sending files, assist with certificate use, and resolve any issues relating to your certification
  • Legal compliance and regulatory obligations: to meet requirements under applicable law including accounting obligations, tax regulations, anti-money-laundering rules (where applicable), and responding to legitimate requests from competent authorities
  • Service improvement: to analyze aggregated and anonymized (not individual) usage patterns to improve website performance, security measures, and the efficiency of the certification process
Section 05

Legal Basis for Processing

Under the GDPR and applicable data protection laws, we process personal data on the basis of one or more of the following legal grounds:

  • Performance of a contract (GDPR Art. 6(1)(b)): processing is necessary to perform the DAPI certification service you requested and to which you are a party. This covers service delivery, file processing, certificate generation, and delivery
  • Legal obligation (GDPR Art. 6(1)(c)): processing is required to comply with legal obligations including accounting requirements, tax regulations, and responses to legitimate requests from competent authorities (courts, law enforcement, regulatory bodies)
  • Legitimate interests (GDPR Art. 6(1)(f)): processing is necessary for our legitimate interests in: (a) maintaining website security and preventing abuse, (b) fraud prevention and legitimacy verification, (c) protecting our systems and intellectual property, (d) internal administration and business operations. We carefully balance these interests against your rights and freedoms
  • Consent (GDPR Art. 6(1)(a)): only when processing is based exclusively on your voluntary consent (for example, optional marketing communications if enabled, or optional analytics cookies). You have the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal

Special category data

Photographs, voice recordings, and video may involve the processing of biometric data when subjected to specific technical processing aimed at the unique identification of a person. When the DAPI process involves the processing of data belonging to the special categories set out in GDPR Art. 9, such processing is carried out on the basis of the data subject's explicit consent and, where applicable, the further conditions provided for by applicable law. The possible applicability of other exceptions under Art. 9, including those relating to the establishment, exercise, or defense of legal claims, depends on the specific circumstances and their respective legal grounds.

Section 06

Data Minimization and Retention

DAPI is specifically designed to minimize the retention of sensitive biometric content while maintaining the verifiability and documentary value of the certifications issued. We follow rigorous data minimization principles.

Certification Files (Biometric Data)

Your identity files (identity document, facial photo, voice recording, verification video) are processed exclusively to produce your certification package and are NOT retained longer than necessary for delivery and quality verification:

  • Deletion: files are permanently deleted within 48 hours of certification delivery
  • Email deletion: emails containing your files are deleted from the mail servers within 30 days of certification delivery

Certification Metadata (Retained)

The following technical metadata is retained because it is necessary to maintain the verifiability and documentary value of the certification issued:

  • Cryptographic hashes (SHA-256): fingerprints that cannot be decoded to reconstruct the original files
  • Qualified timestamp certificates: RFC 3161 timestamps documenting the certification date
  • Basic metadata: your name, DAPI code, certification date, technical file specifications
  • Process logs: documentation of process handling and integrity verification records
  • Delivery receipts: confirmation that the certification package was delivered

Other Data Retention Periods

  • Support communications: retained for operational purposes for up to 2 years, or longer if required for legal/accounting obligations
  • Website logs and analytics: typically retained for 6-12 months for security and performance analysis
  • Accounting/tax records: retained for the periods required by law (typically 10 years in Italy)

Important

Retention periods may vary depending on your specific case, legal requirements in your jurisdiction, and any ongoing legal proceedings requiring data retention. Contact us for specific information about the retention periods applicable to your certification.

Section 07

Where Data Is Stored and Processed

Data is processed through controlled, secure channels with restricted access:

  • Certification processing: accessible only to the forensic expert responsible for certification
  • Email communications: managed through certified electronic mail (PEC) providers and secure email services compliant with Italian and European data protection standards
  • Website hosting: infrastructure located in EU data centers with appropriate security certifications and GDPR compliance
  • Metadata storage: retained certification metadata (hashes, timestamps, process logs) stored on secure servers in Italy/EU with encrypted backups

Access to your data is strictly limited to authorized personnel directly involved in certification processing, delivery, and support. We implement role-based access controls, audit logging, and need-to-know principles.

Section 08

Data Sharing and Recipients

We do not share your Certification Files or personal data with third parties except when necessary to provide the service or required by law. Possible recipients include:

  • Timestamp service providers: eIDAS-qualified timestamp authorities that generate RFC 3161 timestamps. These providers receive only technical data (hashes), not your biometric files or personally identifiable information
  • Email/communication providers: certified electronic mail (PEC) services and secure communication platforms used to send instructions and deliver the certification package. These providers process data as processors under strict contractual obligations
  • Infrastructure and hosting providers: server hosting, backup services, and technical infrastructure necessary for secure storage and operation of the website. Selected based on GDPR compliance and appropriate security standards
  • Legal and regulatory authorities: courts, law enforcement, tax authorities, or other competent authorities when disclosure is required by a valid legal request, court order, or applicable law
  • Professional advisors: legal counsel, accountants, or auditors when necessary for legal compliance, dispute resolution, or financial obligations (under professional confidentiality obligations)

Data Processing Agreements

When third-party service providers process personal data on our behalf, we enter into Data Processing Agreements (DPAs) ensuring appropriate security measures, confidentiality obligations, and GDPR compliance.

Section 09

International Transfers

DAPI prioritizes processing data within the European Union to benefit from strong GDPR protections. However, if data must be transferred outside the EU/EEA (for example, if you are located outside Europe or if certain service providers operate internationally), we adopt the safeguards required by law:

  • Standard Contractual Clauses (SCCs): contractual terms approved by the EU Commission that ensure adequate data protection in countries without EU adequacy decisions
  • Adequacy decisions: transfers to countries recognized by the EU Commission as providing adequate data protection (United Kingdom, Switzerland, Japan, etc.)
  • Additional safeguards: encryption in transit and at rest, access controls, security certifications, and contractual commitments from recipients

Contact us if you need specific information about international transfers relevant to your certification, including details on the safeguards applied and copies of the relevant transfer mechanisms.

Section 10

Security Measures

We implement technical and organizational security measures appropriate to the sensitivity of the data, including biometric information. Security measures include (where relevant):

  • Access controls: role-based access, strong authentication, least-privilege principles, and audit logging of all access to sensitive data
  • Encryption: TLS/SSL encryption for data in transit (website, email) and encryption at rest for sensitive stored data and backups
  • Cryptographic integrity: SHA-256 hashing allows verification of file integrity and detection of any unauthorized modifications
  • Monitoring and logging: security monitoring, intrusion detection, audit trails, and periodic security reviews
  • Incident response: documented procedures for detecting, responding to, and reporting security incidents including data breaches

Security incident notification

In the unlikely event of a data breach affecting your personal data, we will inform you and the competent supervisory authorities within the timeframes required by the GDPR (72 hours to the authority, without undue delay to data subjects).

Section 11

Cookies and Tracking

DAPI uses cookies and similar technologies for essential website functionality, security, and (optionally) analytics. Our approach:

  • Essential cookies: required for the website to function correctly (session management, security, load balancing). These cannot be disabled and do not require consent as they are strictly necessary
  • Security cookies: used to prevent abuse, detect suspicious activity, and protect against attacks (e.g. rate limiting, bot detection)
  • Analytics cookies (subject to consent): help us understand how visitors use the website, through statistical information about page usage and navigation. Analytics cookies must not be activated before the user has given consent, when such consent is required by applicable regulations
  • Marketing cookies: DAPI does not use marketing, advertising, or tracking cookies from third-party networks

You can control cookie preferences through your browser settings. Note that blocking essential cookies may affect website functionality. Detailed information about cookies is available in Part II – Cookie Policy on this page.

Section 12

Your Rights Under the GDPR

Depending on your jurisdiction (particularly if you are located in the EU/EEA or the UK), you have the following rights regarding your personal data:

Your data protection rights

  • Right of access (Art. 15): request confirmation of whether we process your personal data and obtain a copy of that data along with information about the processing
  • Right to rectification (Art. 16): request correction of inaccurate personal data or completion of incomplete data
  • Right to erasure / "right to be forgotten" (Art. 17): request deletion of your personal data under certain circumstances (see Section 13 for important limitations relating to certified evidence)
  • Right to restriction of processing (Art. 18): request that we restrict processing of your data in specific situations (contested accuracy, unlawful processing, etc.)
  • Right to data portability (Art. 20): receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller (where technically feasible)
  • Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing purposes
  • Right to withdraw consent (Art. 7): if processing is based on consent, you can withdraw consent at any time without affecting the lawfulness of prior processing
  • Right to lodge a complaint (Art. 77): lodge a complaint with the supervisory authority (in Italy: the Garante per la Protezione dei Dati Personali, the Italian Data Protection Authority) if you believe your rights have been violated

How to Exercise Your Rights

To exercise any of these rights, contact us using the official email address published on the website's contact page. Please include:

  • Full first and last name and contact information
  • Your DAPI certification code (if applicable)
  • The specific right you wish to exercise and relevant details
  • Proof of identity (to prevent unauthorized access)

We will respond to your request within one month (extendable by two additional months for complex requests). If we cannot fulfil your request, we will explain why and inform you of your right to lodge a complaint with a supervisory authority.

Section 13

Requests Relating to Certified Evidence

Important limitation on erasure and restriction rights

Because DAPI produces technical documentation that may also be used in legal or dispute contexts, some data may need to be retained where there is a legal basis permitting or requiring retention, even following an erasure request.

Depending on the circumstances and applicable legal basis, data that may need to be retained includes:

  • Cryptographic hashes (SHA-256): necessary to verify that the certificates we issue remain consistent with the original files and have not been altered. Without the retained hashes, the certificate loses verifiability
  • Timestamp certificates: a time reference that cannot be deleted without invalidating the documentary value of the timestamp
  • Process documentation: logs establishing how certification was performed, necessary for legal proceedings where methodology may be challenged
  • Certification metadata: basic information (name, DAPI code, date) linking you to the certificate issued, required if legal disputes concern the certificate's integrity

Legal basis for retention: GDPR Art. 17(3)(e) provides an exception to the right to erasure where processing is necessary for the establishment, exercise, or defense of legal claims. The possible applicability of this or other exceptions is assessed in relation to the request received, the data concerned, and the specific circumstances.

If you request erasure and we must decline due to these limitations:

  • We will specifically explain which data cannot be deleted and why
  • We will confirm deletion of all data that CAN be deleted (e.g. support communications, website usage data)
  • We will provide available alternatives (restriction, anonymization where possible)
  • We will inform you of your right to lodge a complaint with the supervisory authority if you disagree
Section 14

Changes to This Privacy & Cookie Policy

We may update this policy periodically to reflect:

  • Changes or improvements to the DAPI service
  • Updates to applicable data protection laws or regulations
  • New security measures or processing activities
  • Feedback from supervisory authorities or data protection assessments

The latest version of this policy will always be published on this page with the "Last updated" date at the top. Substantial changes that significantly affect your rights will be communicated to you by email (if we have your contact information) or through a prominent notice on the website.

Changes become effective from the date of publication. We encourage you to review this policy periodically to stay informed about how we protect your data.

Section 15

Privacy and Data Protection Contacts

For privacy questions, data protection requests, or to exercise your rights under the GDPR and applicable data protection laws, contact us using the official contact details published on the website.

Privacy and data protection requests

We take your privacy rights seriously and aim to respond to all requests within the legal timeframes. For the fastest response, include your DAPI certification code (if applicable) and clearly indicate which right you wish to exercise.

Supervisory Authority (Italy)

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Italian data protection authority:

Garante per la Protezione dei Dati Personali (Italian Data Protection Authority)
Piazza Venezia 11, 00187 Rome, Italy
Website: www.garanteprivacy.it
Email: garante@gpdp.it

Section 16 – Part II

Introduction to the Cookie Policy

Our site, dapi-certification.com, uses cookies and related technologies (for convenience, all referred to as "cookies"). In this section we inform you which cookies the site uses, for what purpose, and how you can manage them.

Section 17

What Are Cookies, Scripts, and Web Beacons

What are cookies?

A cookie is a small file sent along with the pages of this site and stored by your browser on your computer's hard drive or another device. The information it contains may be returned to our servers on a subsequent visit.

What are scripts?

A script is a piece of code used to make our site function correctly and interactively. This code runs on our server or on your device.

What are web beacons?

A web beacon (or tracking pixel) is a small, invisible text or image element present on a web page and used to monitor site traffic.

Section 18

Types of Cookies

Technical or functional cookies

Some cookies ensure that certain parts of the site work correctly and that your preferences remain known. These cookies may be installed without your consent, as they are strictly necessary for the site to function.

Statistics cookies

We use statistics cookies to optimize the site experience for our users. With these cookies, we obtain information about site usage in aggregated form. We ask for your consent before installing statistics cookies.

Marketing/tracking cookies

Marketing/tracking cookies are cookies, or other forms of local storage, used to create user profiles for advertising purposes or to track the user on this site or across multiple sites for similar marketing purposes. DAPI does not use cookies of this type.

Section 19

Cookies Actually Used

The site dapi-certification.com uses Google Analytics as a third-party statistical analytics technology. Where the related processing requires user consent, Google Analytics is activated only after such consent has been given through the site's preference management system.

Service Category Consent required
Google Analytics Statistics Yes

We do not install marketing, advertising, or cross-site tracking cookies. No other third-party technology installs cookies on this site.

Section 20

Consent

When you visit our site for the first time, we show you a banner with an explanation about cookies. As soon as you select your preferences, you consent to the use of the cookie categories you selected, as described in this policy. You can disable the use of cookies through your browser, keeping in mind that the site may no longer function correctly. Declining statistics cookies does not prevent use of the site's essential features. Preferences expressed may subsequently be changed, or consent withdrawn, through the tools made available on the site or, where applicable, through your browser settings.

Category Status
FunctionalAlways active
Statistics (Google Analytics)Subject to your consent
MarketingNot used
Section 21

How to Manage Cookies

You can use your browser to delete cookies automatically or manually. You can also specify that certain cookies not be installed, or adjust your browser settings so you are notified every time a cookie is installed. For more information about these options, see your browser's help section.

Please note that the site may not function correctly if all cookies are disabled. If you delete cookies from your browser, on your next visit the strictly necessary cookies may be reinstalled, and for categories requiring consent, only after a new choice by the user when required.

Section 22

Your Rights and Contacts for the Cookie Policy

The rights relating to personal data that may be collected via cookies (for example, aggregated statistical data from Google Analytics) are the same rights described in Section 12 – Your Rights Under the GDPR: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to the supervisory authority.

For questions about this Cookie Policy or to exercise your rights, use the same contacts indicated in Section 15 – Contacts and Data Protection Officer.

Questions about privacy or cookies?

We are committed to transparency and respect for your fundamental rights. If you have questions about this policy, how we handle your data, or wish to exercise your GDPR rights, don't hesitate to contact us.