Privacy policy
Last updated: 10 August 2026
GoParse exists to read identity documents without keeping them. This policy explains, in plain language, what personal data we handle, why, and what your rights are. It covers two distinct roles: we are the controller for data about you and your account, and the processor for the documents your systems submit to our API on your behalf. It also lists every cookie and piece of browser storage we use (see section 7) — the list is short on purpose.
1. Who we are
The controller responsible for the processing described in sections 2, 4 and 5 is LIZZIT Michele (P.IVA: 02996460305) — GoParse is a brand of LIZZIT Michele. For anything related to personal data, contact us at privacy@goparse.it. We aim to answer privacy enquiries within a few business days.
2. Data we process as a controller
This is the data we decide to collect ourselves in order to run the service. We keep it deliberately minimal.
Account data
When you sign up we store your email address, your name, and — if you provide them during onboarding — your company name and intended use case. Your password is stored only as a salted hash; we cannot read it, and it is never written to logs.
Billing data
Paid subscriptions are handled by our payment provider, Stripe. Card numbers and other payment credentials are entered directly on Stripe's systems and never touch our servers. We store only the references we need to manage your subscription: a Stripe customer ID, a subscription ID, your plan, its status and the current billing period end.
Usage metadata
For each API request we record aggregate metadata: the generic document type detected (for example “passport” or “identity card”), the number of images received, documents detected and persons found, the number of warnings, the HTTP status, the processing latency and a timestamp. Explicitly: we never record names, document numbers, dates of birth, images, or any other content read from a document. Usage metadata is what powers your dashboard and our quota accounting — nothing in it identifies a document holder.
Support and contact messages
If you write to us through the contact form or by email, we process the details you choose to share (name, email address, company, expected volume, and your message) to respond to your request.
3. Data we process as a processor
The images you submit to the API — and the structured fields our pipeline extracts from them, such as names, dates of birth and document numbers — are personal data of the document holders. For this data, you (our customer) are the controller and we act strictly as your processor under Article 28 GDPR:
- Document contents are processed transiently in memory, solely to produce the API response you requested.
- They are never persisted — not to disk, not to a database, not to backups, not to logs.
- They are never used to train models or improve the service.
- They are deleted from memory as soon as the API response has been returned to you.
Because you are the controller, you must ensure you have a lawful basis for every document you process through the API and that document holders are informed as required. The terms of this relationship are set out in our data processing agreement.
4. Legal bases
Where we act as a controller, we rely on the following bases under Article 6(1) GDPR:
- Contract (Art. 6(1)(b)) — creating and operating your account, providing the API and dashboard, billing your subscription, and answering support requests.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure, preventing abuse and fraud, enforcing quotas, and understanding aggregate usage of the service. We only use metadata for this; never document contents.
- Consent (Art. 6(1)(a)) — optional analytics cookies, which run only if you opt in via the cookie banner. You can withdraw consent at any time (see Cookies and browser storage below).
5. Retention
- Usage metadata is retained for 12 months, then deleted.
- Account data is retained until you delete your account; you can do this yourself at any time from your account settings.
- Contact requests are retained for 24 months after our last exchange.
- Billing records held by Stripe may be kept longer where tax and commercial law require it.
Document contents are not listed here because they are never stored in the first place (see section 3).
6. Recipients and processors
We share personal data only with the service providers we need to run GoParse, under data processing agreements:
| Recipient | Purpose | Location & safeguards |
|---|---|---|
| Stripe | Payments, subscription billing and invoicing | EU / US — EU Standard Contractual Clauses |
| Hosting provider | Infrastructure the service runs on | EU |
We do not sell personal data, and we do not share it with advertisers.
7. Cookies and browser storage
Cookies are small text files a website stores in your browser so it can recognise you between page loads — for example, to keep you signed in. Browsers also offer localStorage, a similar mechanism for storing small values that are not sent to the server with every request. Strictly necessary cookies are required for the service to function and do not need consent; anything optional — such as analytics — does. This is everything GoParse uses:
| Name | Type | Purpose | Duration |
|---|---|---|---|
pid_session | Strictly necessary cookie | Keeps you signed in to your account (authentication session) | 30 days |
pid-cookie-consent | localStorage | Stores your consent choice so we do not ask again | Until cleared |
We would only ever run privacy-friendly analytics, and only after you opt in through the cookie banner. To be transparent: no analytics are currently active — if that changes, the tool and its cookies will be listed in the table above before it is enabled, and it will remain off unless you have consented.
You can reopen the consent banner at any time and change your choice — withdrawing consent is as easy as giving it:
You can also delete cookies and site data through your browser settings at any time. If you delete the pid_session cookie you will be signed out; if you delete the stored consent choice, the banner will simply appear again on your next visit.
8. International transfers
The service is hosted in the EU, and documents submitted to the API are processed on EU infrastructure. Where a provider processes data outside the European Economic Area — as Stripe may for payment processing — the transfer is protected by the EU Standard Contractual Clauses and supplementary measures where required.
9. Your rights
Under Articles 15–21 GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- receive your data in a portable format (Art. 20);
- object to processing based on legitimate interests (Art. 21).
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal. You can export or delete your account data yourself from the dashboard settings, or contact privacy@goparse.it. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you live or work.
If you are a document holder whose ID was processed through our API by one of our customers, please direct your request to that customer — they are the controller for that data, and we hold no copy of it. We will support them in responding as their processor.
10. Security
All traffic to the API and dashboard is encrypted in transit with TLS. API keys and passwords are stored only as hashes. Access to production systems follows the least-privilege principle, and application logs contain metadata only — never document contents. No security measure is absolute, but our architecture is designed so that the most sensitive data — the contents of identity documents — simply is not there to be stolen.
11. Changes to this policy
We may update this policy as the service or the law evolves. The current version is always published on this page with its “last updated” date. If a change materially affects how we handle your data, we will notify you by email or in the dashboard before it takes effect.