Back

Privacy policy

Last updated: February 20, 2026

1. Data controller

ProtectMyId

Email : contact@protectmyid.fr

ProtectMyId® is responsible for processing personal data collected on this platform, in compliance with the General Data Protection Regulation (GDPR).

2. Data collected

For individuals (declarants)

  • Identity: last name, first name, date of birth, email address
  • Stolen documents: document type, number (hashed), holder information (encrypted)
  • Circumstances: date, location, description, filing receipt reference
  • Supporting documents: filing receipt (complaint, loss report, or police log entry). The complaint or police record itself is never collected.

For professional organizations

  • Company: name, SIRET number, address, contact details
  • Legal representative: last name, first name, professional email
  • Usage data: search history (hashed queries)
  • Proof of registration (Kbis extract): collected solely to verify the organization's legal existence and its representative's authority.

3. Purpose of processing

  • Allow victims to report their stolen documents
  • Allow organizations to verify if a document has been reported stolen
  • Validate declarations and organization registrations
  • Ensure the security and integrity of the platform

4. Legal basis for processing

Individuals (declarants): processing is based on the performance of a contract (Article 6(1)(b) GDPR). By creating an account and accepting the Terms of Service, you enter into a service contract with ProtectMyId whose purpose is the blocking and reporting of your documents. Processing your data is necessary to perform this service; it does not rely on your consent.

Organizations (verification): processing is based on legitimate interest (Article 6(1)(f) GDPR) in preventing document fraud and identity theft, an interest shared by victims, organizations and society.

Offence-related data: information relating to a theft, loss or breach is processed in strict compliance with Article 10 GDPR. Only the filing receipt is collected; the complaint and police report are never collected.

5. Security measures

AES-256-GCM Encryption

Sensitive personal data (names, dates of birth, locations) is encrypted using the AES-256-GCM algorithm.

SHA-256 Hashing

Document numbers are hashed with HMAC-SHA256, making direct reading impossible.

Complete traceability

Every access and every action is logged in an immutable audit log.

Strict access control

Multi-factor authentication, JWT tokens with rotation, and role-based access control.

6. Your rights

Under the GDPR, you have the following rights:

  • Right of access: view your personal data
  • Right to rectification: correct inaccurate data
  • Right to erasure: delete your account and data
  • Right to data portability: export your data in a readable format
  • Right to object: object to the processing of your data
  • Right to restriction: restrict the processing of your data

To exercise your rights, contact us at: dpo@protectmyid.fr

7. Data retention

Active account data: retained for the duration of service use.

After account deletion: data anonymized or erased within 30 days.

Audit logs: retained for 12 months for security purposes.

Kbis extract: retained for the duration of the contractual relationship as proof of verification (KYC), then deleted.

8. Cookies

ProtectMyId only uses strictly necessary technical cookies for the service to function (authentication session). No tracking or advertising cookies are used.