Privacy Policy
Last updated: September 13, 2026
This Privacy Policy explains how International Driving Permit Agency ("IDPA," "we," "us"), operated by its mother company International Automobile Agency (https://e-iaa.com/), collects, uses, shares, retains, and protects the personal data of visitors and customers worldwide on internationaldrivingpermitagency.com.
Our IDPA Driver's License Translation is a certified translation of your valid domestic driver's license, formatted in accordance with the 1949 Geneva Convention on Road Traffic and the 1968 Vienna Convention on Road Traffic. It is not an International Driving Permit (IDP) issued by a government or motoring association, and does not replace your original driver's license. We are not affiliated with AAA (American Automobile Association), CAA (Canadian Automobile Association), ATA (American Translators Association), AAS (Automobile Association of Singapore), or any government or motoring organization; similarity in name is coincidental.
International Automobile Agency is a privately held entity. It is not a government body, regulatory authority, or instrumentality of any government. It does not issue government permits, licenses, or official documents of any kind.
1. Controller Identity and Contact
- Data Controller: International Driving Permit Agency (Mother Company: International Automobile Agency)
- Mother Company Website: https://e-iaa.com/
- General Support Contact: hello@e-iaa.com
1.1 EU / UK Representative and Data Protection Officer — Current Posture
IDPA has assessed its obligations under GDPR Art. 27 (EU representative) and Art. 37 (Data Protection Officer). Given the current scale of processing, IDPA has concluded that neither a designated EU/UK representative nor a mandatory DPO is required at this time. We will reassess and appoint these roles if processing scope changes materially. For any data protection inquiries, contact hello@e-iaa.com.
2. Categories of Personal Data We Collect
- Identity and Contact Data: Full name, date of birth, sex, country of birth, country of residence, email address, phone number (WhatsApp preferred), and shipping address.
- Identity-Verification Data: Photograph of your domestic driver's license (front and back), photograph of passport or government ID (where collected), passport-style selfie, and electronic signature.
- Order and Transaction Data: Products purchased, format (digital PDF or print + digital), validity term, selected languages, vehicle classes, and payment method indicators. (Payment card details are tokenized and processed securely by Stripe; card numbers are never stored on our servers).
- Technical and Device Data: IP address, device identifiers, browser type, operating system, referral URLs, and cookie identifiers.
- Communications Data: Email, live-chat, and support-ticket records.
3. Sources of Personal Data
- Directly from you: Provided at checkout and during order fulfillment.
- From your device: Collected via cookies and tracking technologies (see our Cookie Policy).
- Payment Processors (Stripe): Transaction success indicators, fraud risk signals, and chargeback notifications.
- Shipping Carriers: Delivery tracking events (e.g., FedEx, DHL, UPS, national postal services).
4. Purposes of Processing and Lawful Bases (GDPR Art. 6)
| Purpose | Lawful Basis |
|---|---|
| Performing the Contract (Order fulfillment, document translation delivery, replacements) | Contract performance GDPR Art. 6(1)(b); LGPD Art. 7(V) |
| Identity Verification & Fraud Prevention (Reviewing uploaded IDs and documents) | Legal obligation and legitimate interests — Art. 6(1)(c) & (f); explicit consent for biometric/special data where applicable under Art. 9(2)(a) |
| Tax Record-Keeping & Financial Accounting | Legal obligation — Art. 6(1)(c) |
| Sanctions & Compliance Screening (Stripe Radar / OFAC at payment layer) | Legal obligation — Art. 6(1)(c) |
| Customer Support | Contract performance & legitimate interests — Art. 6(1)(b) & (f) |
| Email Marketing (If explicitly opted in) | Consent — Art. 6(1)(a); LGPD Art. 7(I) |
| Analytics & Conversion Tracking (Google Analytics, Google Ads, Meta Pixel) | Consent where required (EU/UK/Brazil/Quebec); opt-out where permitted (US states) |
| Legal Defense & Terms Enforcement | Legitimate interests — Art. 6(1)(f) |
5. Recipients and Third-Party Processors
We share personal data with trusted third-party service providers bound by written data-processing agreements:
- Stripe, Inc.: Payment processing (PCI-DSS Level 1 compliant).
- Shipping Carriers: FedEx, DHL, UPS, and national postal services.
- Google LLC: Google Analytics, Google Ads conversion measurement, and Google Tag Manager.
- Meta Platforms, Inc.: Meta Pixel for conversion attribution and WhatsApp Business API.
- Microsoft Corporation: Microsoft Advertising (Bing UET tag).
- Twilio, Inc.: Transactional SMS delivery.
- Communication & Database Infrastructure: Airtable (secure internal record-keeping) and email/support desk software.
- Legal and Audit Advisors: On a strict need-to-know basis.
We do not sell personal data for monetary consideration.
6. International Data Transfers
Personal data is processed by International Automobile Agency and its infrastructure providers. When data is transferred internationally from the EEA, UK, or Switzerland, we rely on:
- EU–US Data Privacy Framework (DPF) certification for participating vendors (Stripe, Google, Meta, Microsoft);
- Standard Contractual Clauses (SCCs) issued by the European Commission;
- UK International Data Transfer Addendum where applicable.
7. Data Retention
We retain personal data only for as long as necessary to fulfill service commitments, honor our Replacement Guarantees, prevent fraud, and comply with tax laws.
- Identity Documents, Selfies & Driver's License Scans: Lifetime of IDPA validity + 6 months buffer.
- Transactional Ledgers & Invoices: 7 years (statutory tax record-keeping requirements).
- Customer Support Records: 3 years from last interaction.
- Marketing Contact Lists: Until you exercise your right to unsubscribe or opt out.
8. Automated Decision-Making (GDPR Art. 22)
IDPA does not subject you to solely automated decision-making that produces legal or significant effects.
- Payment Layer Screening: Automated fraud engines (e.g., Stripe Radar) may automatically decline transactions flagged for potential fraud. You can request a human review of a declined transaction by contacting hello@e-iaa.com.
- Human Verification: All identity document translations and order fulfillments are reviewed and approved by human verification specialists.
9. Security Measures
We implement robust technical and organizational security controls, including TLS encryption for data in transit, resting encryption for stored files, access control lists, and tokenized payment processing via Stripe. No cardholder data is stored directly on IDPA servers.
10. Your Rights
Depending on your place of residence, you may exercise the following rights regarding your data by emailing hello@e-iaa.com:
- Right to Access & Data Portability: Request copies of your personal data.
- Right to Rectification: Request correction of incomplete or inaccurate data.
- Right to Erasure (Deletion): Request deletion of data, subject to legal-hold and compliance exceptions.
- Right to Object / Opt-Out: Withdraw consent for marketing or opt-out of behavioral advertising tracking.
- Right to Non-Discrimination: We will never discriminate against you for exercising your privacy rights.
11. Biometric & Sensitive Identity Data
- To prevent fraudulent applications, automated image-matching tools assist human reviewers in comparing uploaded selfies against driver's license photos.
- We do not build persistent facial recognition databases.
- We do not sell or share identity photos with marketing partners.
- Verification images are stored securely within your restricted application file for the duration outlined in Section 7.
12. Children's Privacy
Our services are strictly intended for individuals 18 years of age or older who hold a valid driver's license. We do not knowingly collect or process data from minors. If you believe a minor has submitted personal information, contact hello@e-iaa.com for immediate deletion.
13. Cookies and Tracking Technologies
We use essential cookies for core site navigation, secure checkout, and performance. Analytics and advertising pixels (such as Google Ads and Meta Pixel) are deployed to measure service performance. EU/UK and relevant visitors may manage non-essential cookies via our site's consent banner.
14. Electronic Communications (SMS & WhatsApp)
- Transactional Only: Phone numbers collected at checkout are used exclusively for transactional notifications (e.g., order confirmation, translation PDF delivery, shipping updates).
- No Promotional Messaging: We do not send marketing SMS or WhatsApp messages.
- Opt-Out: You may reply STOP to any SMS or WhatsApp message at any time to halt electronic text notifications.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect operational or legal changes. The "Last updated" date at the top indicates when the latest modifications were made. Continued use of internationaldrivingpermitagency.com indicates acceptance of the revised terms.
16. Contact and Complaints
For questions, data access requests, or privacy concerns:
- Email: hello@e-iaa.com
- Operating Entity: International Driving Permit Agency (Mother Company: International Automobile Agency)
You also reserve the right to lodge a complaint with your local data protection supervisory authority (e.g., ICO in the UK, ANPD in Brazil, or relevant EU Member State DPA).
Operating Entity: International Driving Permit Agency (Mother Company: International Automobile Agency)