Privacy Policy

Privacy Policy

HomePrivacy Policy

Last updated: September 13, 2026

This Privacy Policy explains how International Automobile Agency ("we," "us"), accessible via https://e-iaa.com/, collects, uses, shares, retains, and protects the personal data of visitors and customers worldwide.

Important Notice

Our translation is a private multilingual translation of your active national certificate. It is an independent service, does not replace your original certificate, and is not issued by a public authority or motoring association. We are not affiliated with or a representative of American Automobile Association, Inc (AAA), CAA, or AAS; any similarity in name is coincidental.

International Automobile Agency is a privately held commercial entity. It is not a statutory body, regulatory authority, or state agency, and does not issue state credentials.

1. Controller Identity and Contact

1.1 EU / UK Representative and Data Protection Officer — Current Posture

International Automobile Agency has assessed its obligations under GDPR Art. 27 (EU representative) and Art. 37 (Data Protection Officer). Given the current scale of processing, we have concluded that neither a designated EU/UK representative nor a mandatory DPO is required at this time. We will reassess and appoint these roles if processing scope changes materially. For any data protection inquiries, contact hello@e-iaa.com.

2. Categories of Personal Data We Collect

  • Identity and Contact Data: Full name, date of birth, sex, country of birth, country of residence, email address, phone number (WhatsApp preferred), and shipping address.
  • Identity-Verification Data: Photograph of your original national certificate (front and back), photograph of passport or government photo ID (where collected), passport-style photo, and electronic signature.
  • Order and Transaction Data: Products purchased, format (digital PDF or print + digital), duration term, selected languages, vehicle classes, and payment method indicators. (Payment card details are tokenized and processed securely by Stripe; card numbers are never stored on our servers).
  • Technical and Device Data: IP address, device identifiers, browser type, operating system, referral URLs, and cookie identifiers.
  • Communications Data: Email, live-chat, and support-ticket records.

3. Sources of Personal Data

  • Directly from you: Provided at checkout and during order fulfillment.
  • From your device: Collected via cookies and tracking technologies (see our Cookie Policy).
  • Payment Processors (Stripe): Transaction success indicators, fraud risk signals, and chargeback notifications.
  • Shipping Carriers: Delivery tracking events (e.g., FedEx, DHL, UPS, national postal services).

4. Purposes of Processing and Lawful Bases (GDPR Art. 6)

PurposeLawful Basis
Performing the Contract (Order fulfillment, translation delivery, replacements)Contract performance GDPR Art. 6(1)(b); LGPD Art. 7(V)
Identity Verification & Fraud Prevention (Reviewing uploaded IDs and certificates)Legal obligation and legitimate interests — Art. 6(1)(c) & (f); explicit consent for biometric/special data where applicable under Art. 9(2)(a)
Tax Record-Keeping & Financial AccountingLegal obligation — Art. 6(1)(c)
Sanctions & Compliance Screening (Stripe Radar / OFAC at payment layer)Legal obligation — Art. 6(1)(c)
Customer SupportContract performance & legitimate interests — Art. 6(1)(b) & (f)
Email Marketing (If explicitly opted in)Consent — Art. 6(1)(a); LGPD Art. 7(I)
Analytics & Conversion Tracking (Google Analytics, Google Ads, Meta Pixel)Consent where required (EU/UK/Brazil/Quebec); opt-out where permitted (US states)
Legal Defense & Terms EnforcementLegitimate interests — Art. 6(1)(f)

5. Recipients and Third-Party Processors

We share personal data with trusted third-party service providers bound by written data-processing agreements:

  • Stripe, Inc.: Payment processing (PCI-DSS Level 1 compliant).
  • Shipping Carriers: FedEx, DHL, UPS, and national postal services.
  • Google LLC: Google Analytics, Google Ads conversion measurement, and Google Tag Manager.
  • Meta Platforms, Inc.: Meta Pixel for conversion attribution and WhatsApp Business API.
  • Microsoft Corporation: Microsoft Advertising (Bing UET tag).
  • Twilio, Inc.: Transactional SMS delivery.
  • Communication & Database Infrastructure: Airtable (secure internal record-keeping) and email/support desk software.
  • Legal and Audit Advisors: On a strict need-to-know basis.

We do not sell personal data for monetary consideration.

6. International Data Transfers

Personal data is processed by International Automobile Agency and its infrastructure providers. When data is transferred internationally from the EEA, UK, or Switzerland, we rely on:

  • EU–US Data Privacy Framework (DPF) certification for participating vendors (Stripe, Google, Meta, Microsoft);
  • Standard Contractual Clauses (SCCs) issued by the European Commission;
  • UK International Data Transfer Addendum where applicable.

7. Data Retention

We retain personal data only for as long as necessary to fulfill service commitments, honor our Replacement Guarantees, prevent fraud, and comply with tax laws.

  • Identity Certificates, Photos & Uploaded Scans: Duration of order status + 6 months buffer.
  • Transactional Ledgers & Invoices: 7 years (statutory tax record-keeping requirements).
  • Customer Support Records: 3 years from last interaction.
  • Marketing Contact Lists: Until you exercise your right to unsubscribe or opt out.

8. Automated Decision-Making (GDPR Art. 22)

International Automobile Agency does not subject you to solely automated decision-making that produces legal or significant effects.

  • Payment Layer Screening: Automated fraud engines (e.g., Stripe Radar) may automatically decline transactions flagged for potential fraud. You can request a human review of a declined transaction by contacting hello@e-iaa.com.
  • Human Verification: All translations and order fulfillments are reviewed and approved by human verification specialists.

9. Security Measures

We implement robust technical and organizational security controls, including TLS encryption for data in transit, resting encryption for stored files, access control lists, and tokenized payment processing via Stripe. No cardholder data is stored directly on International Automobile Agency servers.

10. Your Rights

Depending on your place of residence, you may exercise the following rights regarding your data by emailing hello@e-iaa.com:

  • Right to Access & Data Portability: Request copies of your personal data.
  • Right to Rectification: Request correction of incomplete or inaccurate data.
  • Right to Erasure (Deletion): Request deletion of data, subject to legal-hold and compliance exceptions.
  • Right to Object / Opt-Out: Withdraw consent for marketing or opt-out of behavioral advertising tracking.
  • Right to Non-Discrimination: We will never discriminate against you for exercising your privacy rights.

11. Biometric & Sensitive Identity Data

  • To prevent fraud, automated image-matching tools assist human reviewers in comparing uploaded photos against original certificate photos.
  • We do not build persistent facial recognition databases.
  • We do not sell or share identity photos with marketing partners.
  • Verification images are stored securely within your restricted file for the duration outlined in Section 7.

12. Children's Privacy

Our services are strictly intended for individuals 18 years of age or older who hold an active certificate. We do not knowingly collect or process data from minors. If you believe a minor has submitted personal information, contact hello@e-iaa.com for immediate deletion.

13. Cookies and Tracking Technologies

We use essential cookies for core site navigation, secure checkout, and performance. Analytics and advertising pixels (such as Google Ads and Meta Pixel) are deployed to measure service performance. EU/UK and relevant visitors may manage non-essential cookies via our site's consent banner.

14. Electronic Communications (SMS & WhatsApp)

  • Transactional Only: Phone numbers collected at checkout are used exclusively for transactional notifications (e.g., order confirmation, translation PDF delivery, shipping updates).
  • No Promotional Messaging: We do not send marketing SMS or WhatsApp messages.
  • Opt-Out: You may reply STOP to any SMS or WhatsApp message at any time to halt electronic text notifications.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect operational or legal changes. The "Last updated" date at the top indicates when the latest modifications were made. Continued use of our website indicates acceptance of the revised terms.

16. Contact and Complaints

For questions, data access requests, or privacy concerns:

You also reserve the right to lodge a complaint with your local data protection supervisory authority (e.g., ICO in the UK, ANPD in Brazil, or relevant EU Member State DPA).

Operating Entity: International Automobile Agency