Privacy Policy
AXIUM Identity provides sign-in and single sign-on (SSO/OAuth) services that other applications rely on to authenticate you. This policy explains what information we process to do that safely, why we process it, who we share it with, and how you can access, correct, or delete it.
In short
- We process the minimum information needed to create your account, authenticate you, and keep your account secure — profile details, connected sign-in methods, and sign-in activity logs.
- We never sell your personal information, and we only share the specific data an application you approve is entitled to receive.
- You can access, correct, export, or delete your data at any time by contacting info@sifogroup.com.
Overview
This policy applies to AXIUM Identity, the authentication and OAuth 2.0 / OpenID Connect service that lets you sign in to AXIUM Identity itself and to any third-party application ("relying party") that uses AXIUM Identity for sign-in. It does not cover the privacy practices of the relying parties themselves, who are responsible for how they use the information AXIUM Identity provides to them once you've authorized it.
Information we collect
Depending on how you use AXIUM Identity, we may process:
- Account and profile data
- Name, email address, username, password hash, profile picture, organization, and language preference.
- OAuth / SSO connection data
- The identity provider you sign in with, your provider account identifier, the scopes and permissions you grant, and access/refresh tokens issued to authorized applications.
- Authentication and session logs
- Sign-in timestamps, IP address, approximate location, device and browser information, and multi-factor authentication events, kept to secure your account and detect suspicious activity.
- Support and communication data
- Messages you send us and the information needed to respond to them.
We do not sell your personal information, and we do not collect more than is needed to provide secure authentication.
How we use information
We use this information to create and secure your account, authenticate you across applications you connect, provide requested features, detect and prevent fraud or misuse, comply with legal obligations, and offer support. We do not use your authentication data for advertising or profiling.
Legal basis for processing
Where applicable law requires it, we rely on the following bases: performance of a contract (to provide the authentication service you've requested), legitimate interest (to secure accounts and prevent abuse), legal obligation (record-keeping and law enforcement requests), and consent (where you've explicitly opted in, such as optional communications).
Connected identity providers
If you choose to sign in using an external identity provider (for example, a Google, Microsoft, or GitHub account), that provider will share with us the profile information you've agreed to disclose, typically your name, email address, and account identifier. Your relationship with that provider is governed by its own privacy policy, which we encourage you to review.
Data retention
We retain account data for as long as your account is active. Sign-in and security logs are typically kept for up to 12 months to support fraud detection and troubleshooting. Access and refresh tokens expire automatically according to each application's configuration and can be revoked at any time from your account settings. When you delete your account, we remove or anonymize associated personal data, except where a longer retention period is required by law.
International transfers
Where personal information is transferred outside your country of residence, we use appropriate safeguards, such as standard contractual clauses or equivalent legal mechanisms, to ensure it continues to receive an adequate level of protection.
Security
We protect your information with industry-standard measures, including encryption in transit and at rest, salted password hashing, access controls limiting who can view account data, continuous monitoring for suspicious activity, and support for multi-factor authentication. No method of transmission or storage is completely secure, but we work to continuously improve our safeguards.
Your rights
Depending on your location, you may have the right to:
- AccessObtain a copy of the personal data we hold about you.
- RectificationCorrect inaccurate or incomplete data.
- ErasureRequest deletion of your account and data.
- PortabilityReceive your data in a portable format.
- RestrictionLimit how we process your data.
- ObjectionObject to certain processing based on legitimate interest.
To exercise any of these rights, contact info@sifogroup.com. If you are located in the European Economic Area, you also have the right to lodge a complaint with your local data protection authority.
Account and data deletion
To request deletion of your account and associated personal information, email info@sifogroup.com from the address linked to your account with the subject "Account deletion".
We may ask you to verify your identity before processing the request. We may retain limited information where required by law or for legitimate security purposes, such as fraud-prevention records.
Children's privacy
AXIUM Identity is not directed to children and is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
Changes to this policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. We will update the "Last updated" date above and, for material changes, provide additional notice such as an in-app message or email.
Contact
For privacy questions, requests, or concerns, contact us at info@sifogroup.com. We aim to respond to all legitimate requests within one month.