Privacy Notice
Version 1 January 2026
This Privacy Notice explains how Identra collects, uses, and protects personal information in connection with our websites and Services.
1. Information we collect
We collect account information you provide (such as name and email), usage and diagnostic data needed to operate the Services securely, and information you send us directly (for example, through the contact form). As an authentication provider, we also process end-user identity data on behalf of our customers — for that data, our customer is the controller and we are the processor.
2. How we use information
We use information to provide, secure, and improve the Services; to authenticate users and prevent abuse; to communicate with you; and to comply with legal obligations. We do not sell personal information.
3. Security
Security is the product. We apply default-deny access controls, encrypt secrets at rest, hash credentials, isolate tenant data at the database row level, and maintain tamper-evident audit logs. No system is perfectly secure, but we design for failure to be closed.
4. Data retention
We retain personal information only as long as needed to provide the Services and meet legal obligations. Customer Data is retained and deleted according to the customer's configuration and our Data Processing Addendum.
5. Your rights
Depending on your location, you may have rights to access, correct, delete, or port your personal information, or to object to certain processing. To exercise them, contact us. For end-user data we process on a customer's behalf, please contact that customer.
6. International transfers
We may process information in countries other than your own. Where we do, we use appropriate safeguards for cross-border transfers.
7. Contact
For privacy questions or requests, use our contact form.
This is Identra's baseline Privacy Notice.