Privacy and deletion
eSIM passport document handling
eSIM fulfilment currently accepts synthetic passport fixtures only in local and private staging environments. Real passport uploads are disabled in production until the event team evidences the required legal basis, provider purpose, storage location, access controls, retention schedule, deletion workflow and breach-response process.
What is implemented now
Synthetic files are checked for allowed PDF, PNG or JPEG formats, screened by the malware adapter, stored through the private object storage interface, linked to explicit consent and kept out of Cloudinary and public media paths. Organiser access uses short-lived signed links and records an audit event with the access purpose.
Deletion
Attendees can delete the synthetic fixture attached to an eSIM order. Deletion removes the private object where the current storage adapter supports it, marks the document record deleted and returns the eSIM order to a document-required state.
Before real passports
A public policy page alone is not enough to enable real passport collection. Production remains gated until every compliance prerequisite is complete and the approved workflow is reflected in the running system.