Your Data, Your Rights
Effective Date: 14/10/2025
Last Updated: 14/10/2025
Version: 1.0
Welcome to AuthNGo (the "Authentication Platform", "we", "us", or "our"). We are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our passwordless authentication platform and associated services.
This policy applies to all users of our platform, including:
Under the General Data Protection Regulation (GDPR) and other applicable data protection laws, you have important rights regarding your personal data. We respect these rights and have implemented self-service tools to help you exercise them. For more information, see Section 9 "Your Rights and Choices."
Data Controller: AuthNGo LTD
Address: Galbally, Enniscorthy, Y21 WK72, County Wexford, Ireland
Email: privacy@authngo.com
Data Protection Officer (DPO): dpo@authngo.com
For Tenant Organizations:
For Tenant Users:
To provide passwordless authentication via FIDO2/WebAuthn, we collect:
Important: We do NOT store passwords, biometric data, or private keys.
We use essential cookies for authentication:
| Cookie Name | Purpose | Duration |
|---|---|---|
client_info | Client device and session information | 1 year |
sessionId | Authentication session management | 1 year |
accessToken | API authentication token | 15 minutes |
All cookies are HTTP-only, Secure, and SameSite=Strict. Because these cookies are essential for the authentication service to function, they do not require your consent under GDPR ePrivacy Directive.
We use your personal data for:
Legal Basis: We process data based on contract performance (GDPR Article 6(1)(b)), legitimate interests (Article 6(1)(f)), legal obligations (Article 6(1)(c)), and consent (Article 6(1)(a)) where applicable.
We do NOT sell your data to third parties.
We share data only with trusted service providers:
| Data Category | Retention Period |
|---|---|
| Account Data | Duration of account + 30 days |
| Activity Logs | 90 days, then anonymized |
| Billing Records | 7 years (legal requirement) |
We implement industry-leading security measures:
Under GDPR, you have the following rights:
How to Exercise Your Rights: Use the self-service tools in your account settings, or contact privacy@authngo.com
Primary Data Location: European Union (France - Scaleway datacenters)
Some service providers (e.g., Stripe for payment processing) may process data outside the EU. We ensure all transfers comply with GDPR Chapter V requirements through Standard Contractual Clauses (SCCs) and adequacy decisions.
Our platform is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe your child has provided us with personal data, please contact us immediately at privacy@authngo.com
You have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.
Our Lead Supervisory Authority:
Data Protection Commission (DPC) Ireland
21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
Website: https://www.dataprotection.ie
Email: info@dataprotection.ie
We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days before they take effect. Non-material changes will be reflected by updating the "Last Updated" date.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:
General Privacy Inquiries: privacy@authngo.com
Data Protection Officer: dpo@authngo.com
Response Time: Within 5 business days for inquiries, within 1 month for rights requests
By using our services after the Effective Date, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.