Privacy Policy
Data protection standards and privacy practices for Planurix SSO Admin
1. Information We Collect
We collect personal and identity information essential for authenticating your user identity:
- Identity attributes: Full Name, Email Address, and Phone Number;
- Credential data: Cryptographically hashed passwords and MFA secrets;
- Security telemetry: Timestamped audit logs, IP addresses, and device security markers.
2. Data Processing & Authentication
Your data is used solely for secure identification and access authorization:
- Authenticating credentials against federated identity directories;
- Dispatching multi-factor one-time verification codes (OTP);
- Mitigating unauthorized access, account takeover, and automated bot risks;
- Enforcing strict tenant isolation and role-based permissions.
3. Security & Cryptographic Protection
All communications are secured with TLS 1.3 encryption. Passwords and security tokens are protected using salted cryptographic algorithms. Tokens and verification states are guarded with time-bound HMAC signatures.
4. Session Cookies & Storage
We only employ essential HTTP-only, secure SameSite session cookies necessary to maintain login sessions and protect against cross-site request forgery (CSRF). We do not utilize third-party tracking or advertising cookies.
5. Third-Party Claims & Scopes
User information is never marketed or sold. Identity claims are transferred only to authorized client applications when you perform Single Sign-On, constrained to approved OpenID Connect scopes.
6. Privacy Rights & Compliance
You maintain the right to review, update, or request the purging of your user record in accordance with your organization's regulatory and data governance policies.