GDPR Compliance & Your Rights
Last updated: July 2, 2026
Introduction
The General Data Protection Regulation (GDPR) strengthens and unifies data protection for individuals in the European Union and applies to organisations that process the personal data of EU residents. AuthRobo is committed to protecting your privacy and handling personal data in line with the GDPR. This page explains your rights and how we meet our obligations.
Our role: controller and processor
AuthRobo processes personal data in two capacities:
- As a controllerfor the accounts of developers and organisations that use the AuthRobo dashboard (“Owners”).
- As a processor for the end-user data that Owners collect through their applications. In that case the Owner is the controller. If you are an end user, please direct data requests to the operator of the app you signed in to; we will support them in responding.
Your rights under GDPR
As a data subject, you have the following rights:
- Right to information — to be told how your personal data is collected, used, and processed.
- Right of access — to request a copy of the personal data we process about you.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure (“right to be forgotten”) — to request deletion of your data in certain circumstances.
- Right to restrict processing — to limit how we process your data in specific situations.
- Right to data portability — to receive your data in a structured, commonly used format.
- Right to object — to object to processing based on legitimate interests or to direct marketing.
- Rights related to automated decision-making — including profiling. AuthRobo does not make decisions with legal or similarly significant effects about you solely by automated means.
How we protect your data
We implement technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest;
- One-way hashing of passwords (bcrypt) — plaintext passwords are never stored;
- RS256-signed tokens verified against a published JWKS;
- Authenticated encryption (AES-256-GCM) of sensitive secrets;
- Strict per-application (tenant) isolation between Owners;
- Access controls, least-privilege access, and logging;
- Incident response procedures.
Legal basis for processing
- Contract — where processing is necessary to provide the service.
- Legitimate interest — to secure and operate the service.
- Legal obligation — where required by law.
- Consent — where you have given clear consent for a specific activity.
Data retention
- Owner account data — retained while the account is active and for up to 90 days after deletion.
- End-user data — retained per the controlling Owner’s instructions; deleting an end user or app removes the associated records.
- Billing records — retained as required for financial and legal compliance.
- Logs — retained for a limited period for security and operations.
International data transfers
When we transfer personal data outside the EU/EEA, we rely on appropriate safeguards, such as:
- Adequacy decisions by the European Commission;
- Standard Contractual Clauses (SCCs);
- Other lawful transfer mechanisms as applicable.
Our sub-processors are listed in our Privacy Policy.
Data breach notification
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify affected parties and the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where we act as a processor, we will notify the affected Owner without undue delay.
How to exercise your rights
To exercise your rights, contact us using the details below. We will respond within one month (extendable to three months for complex requests). If you are an end user of a Customer App, contact that app’s operator; we will assist them as your controller’s processor.
- Email: privacy@authrobo.com
- Through your account settings, where available.
Data Processing Addendum
Business customers who require a Data Processing Addendum (DPA) covering our processing of End-User Data on their behalf can request one at privacy@authrobo.com.
Complaints
If you believe we have not complied with the GDPR, you have the right to:
- Lodge a complaint with us directly;
- File a complaint with your local Data Protection Authority;
- Seek a judicial remedy through the courts.
Contact
Data controller: [AuthRobo legal entity name], [registered address]. Data protection contact: privacy@authrobo.com. Where a Data Protection Officer is appointed, their contact details will be published here.
Updates to this policy
We may update this page to reflect changes in our practices or legal requirements. Material changes will be indicated by the “Last updated” date above.