Legal document

Privacy Policy

Last updated: August 28, 2026

AXIUM Identity provides sign-in and single sign-on (SSO/OAuth) services that other applications rely on to authenticate you. This policy explains what information we process to do that safely, why we process it, who we share it with, and how you can access, correct, or delete it.

In short

Overview

This policy applies to AXIUM Identity, the authentication and OAuth 2.0 / OpenID Connect service that lets you sign in to AXIUM Identity itself and to any third-party application ("relying party") that uses AXIUM Identity for sign-in. It does not cover the privacy practices of the relying parties themselves, who are responsible for how they use the information AXIUM Identity provides to them once you've authorized it.

Information we collect

Depending on how you use AXIUM Identity, we may process:

Account and profile data
Name, email address, username, password hash, profile picture, organization, and language preference.
OAuth / SSO connection data
The identity provider you sign in with, your provider account identifier, the scopes and permissions you grant, and access/refresh tokens issued to authorized applications.
Authentication and session logs
Sign-in timestamps, IP address, approximate location, device and browser information, and multi-factor authentication events, kept to secure your account and detect suspicious activity.
Support and communication data
Messages you send us and the information needed to respond to them.

We do not sell your personal information, and we do not collect more than is needed to provide secure authentication.

How we use information

We use this information to create and secure your account, authenticate you across applications you connect, provide requested features, detect and prevent fraud or misuse, comply with legal obligations, and offer support. We do not use your authentication data for advertising or profiling.

Sharing and disclosure

We share information only in these situations:

  • With applications you authorize — limited to the profile fields and scopes you approve during the OAuth consent step.
  • With infrastructure sub-processors — such as hosting and email delivery providers, bound by contract to protect your data and process it only on our instructions.
  • For legal reasons — where required to comply with a legal obligation, protect our rights, or respond to a lawful request from a public authority.

We never sell or rent your personal information to third parties for marketing purposes.

Connected identity providers

If you choose to sign in using an external identity provider (for example, a Google, Microsoft, or GitHub account), that provider will share with us the profile information you've agreed to disclose, typically your name, email address, and account identifier. Your relationship with that provider is governed by its own privacy policy, which we encourage you to review.

Cookies and similar technologies

AXIUM Identity uses strictly necessary cookies to maintain your session, protect against cross-site request forgery, and remember your language preference. We do not use advertising or third-party tracking cookies. You can control cookies through your browser settings, though disabling essential cookies will prevent sign-in from working correctly.

Data retention

We retain account data for as long as your account is active. Sign-in and security logs are typically kept for up to 12 months to support fraud detection and troubleshooting. Access and refresh tokens expire automatically according to each application's configuration and can be revoked at any time from your account settings. When you delete your account, we remove or anonymize associated personal data, except where a longer retention period is required by law.

International transfers

Where personal information is transferred outside your country of residence, we use appropriate safeguards, such as standard contractual clauses or equivalent legal mechanisms, to ensure it continues to receive an adequate level of protection.

Security

We protect your information with industry-standard measures, including encryption in transit and at rest, salted password hashing, access controls limiting who can view account data, continuous monitoring for suspicious activity, and support for multi-factor authentication. No method of transmission or storage is completely secure, but we work to continuously improve our safeguards.

Your rights

Depending on your location, you may have the right to:

  • AccessObtain a copy of the personal data we hold about you.
  • RectificationCorrect inaccurate or incomplete data.
  • ErasureRequest deletion of your account and data.
  • PortabilityReceive your data in a portable format.
  • RestrictionLimit how we process your data.
  • ObjectionObject to certain processing based on legitimate interest.

To exercise any of these rights, contact info@sifogroup.com. If you are located in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.

Account and data deletion

To request deletion of your account and associated personal information, email info@sifogroup.com from the address linked to your account with the subject "Account deletion".

We may ask you to verify your identity before processing the request. We may retain limited information where required by law or for legitimate security purposes, such as fraud-prevention records.

Children's privacy

AXIUM Identity is not directed to children and is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.

Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal requirements. We will update the "Last updated" date above and, for material changes, provide additional notice such as an in-app message or email.

Contact

For privacy questions, requests, or concerns, contact us at info@sifogroup.com. We aim to respond to all legitimate requests within one month.

Loading…
Loading the web debug toolbar…
Attempt #