Privacy
Scanning a passport does not require an account
That single design decision does more for privacy here than any policy paragraph could: with no authentication on the public tier, there is no individual record to build in the first place.
- Public tier
- No account
- Scan profiling
- None
- Last updated
- 2026-08-22
Definition
What personal data does CirculeID process?
Very little. Passport records describe products, not people. We process contact details for customer and prospect communication, account data for authenticated users of the product, and aggregate scan information that identifies no one. Scanning a public passport requires no account and creates no profile.
Where a customer chooses to associate a person with an item — registering ownership, a warranty, or a repair — that is a deliberate act by that customer, who is the controller for it. It is never a by-product of someone scanning something.
Processing
What is processed, and on what basis
| Data | Purpose and basis | Retention |
|---|---|---|
| Passport records | Serving the product record. Processed on behalf of the customer, who is controller. Usually not personal data. | For the product’s service life, as the customer configures |
| Account data | Authenticating users of the authenticated product. Necessary for performance of the contract. | For the life of the account, then deleted |
| Contact details | Responding to enquiries and account communication. Legitimate interest, or contract. | Until you ask us to stop, or the relationship ends |
| Aggregate scan data | Reporting engagement to the brand. Identifies no individual and builds no profile. | Aggregated on collection; no individual record exists |
| Operational logs | Security, audit and incident investigation. Legitimate interest and legal obligation. | A bounded window, then deleted |
| Ownership registrations | Only where a customer offers it and a person opts in. Consent, held by that customer. | Set by the customer as controller |
Your rights
What you can ask for
Where CirculeID is the controller — enquiries, account data, our own communications — you can ask for access to your data, correction, erasure, restriction of processing, portability, and you can object to processing carried out on the basis of legitimate interest. Write to ceo@fistasolutions.com and we will act on it.
Where we process on behalf of a customer, which covers most passport data, that customer is the controller. We will route your request to them promptly and support them in answering it, but the decision is theirs rather than ours to make.
You can also complain to a supervisory authority. We would rather you raised it with us first so we have a chance to fix it, but that is your choice and not a precondition.
Data residency is selectable per tenant, and EU-resident deployments keep passport records, events and credentials within the EU. Subprocessors are named in the data processing terms attached to the customer agreement, and changes are notified in advance.
Answers
Frequently asked questions
Are people tracked when they scan a product?
No. The public tier of a passport resolves without an account and without authentication, so there is no identity to attach behaviour to. Brands receive aggregate scan information — counts, coarse region, which sections were opened — and never an individual record. This is a property of the architecture rather than a setting.
Is passport data personal data?
Usually not. A passport describes a product: materials, origin, footprint, repairability. It becomes personal data only where a customer deliberately associates a person with an item, such as registering ownership or a warranty — which is why that is always an explicit, separate choice rather than a by-product of scanning.
Why is passport data not stored on a blockchain?
Partly for this reason. An immutable ledger cannot honour a correction or an erasure request, so putting a record that might contain personal data on one converts a compliance feature into a compliance problem. Only cryptographic digests are anchored, and a digest reveals nothing about the record.
How do I exercise my rights over my data?
Write to ceo@fistasolutions.com. Where CirculeID is the controller we will act on the request directly. Where we process on behalf of a customer — which is the case for most passport data — we will route it to that customer and support them in responding, because the decision is theirs to make.
Who else processes this data?
Subprocessors are named in the data processing terms attached to the customer agreement, along with what each is used for and where it operates. Changes are notified in advance rather than announced afterwards, so a customer can object before the change takes effect.
Next step
Ask us a specific privacy question
Particularly if you are assessing us as a processor. A generic answer is not much use during a DPIA, and we would rather give you a specific one.