{{ COMPANY_NAME }}
and obtain qualified legal review before production deployment.
Privacy Policy
Last updated: 11 May 2026
1. Who we are
The data controller for the personal data processed through LoginSeal is 12inc.eu, registered at [NOT_SET: COMPANY_ADDRESS], registration number [NOT_SET: REGISTRATION_NUMBER]. You can reach our Data Protection Officer at privacy@id.devquest.invalid.
2. What data we collect
We collect the minimum data required to operate an identity provider. Categories include:
- Identity data: name, email address.
- Authentication data: hashed password, optional TOTP secret, recovery codes (hashed), session tokens.
- Technical data: IP address (truncated where feasible), user agent, locale, timezone.
- OAuth data: grants you have issued to third-party applications, scopes approved, last-used timestamp.
- Communication data: log of transactional email sent to you (subject, timestamp), bounce status.
- Account events: login history, two-factor enrollment dates, password change dates.
3. Why we collect it (legal bases)
We rely on the following Article 6 GDPR bases:
- Article 6(1)(b) - performance of a contract: creating and maintaining your account, providing single sign-on, enforcing your authentication choices.
- Article 6(1)(f) - legitimate interest: security monitoring, anti-fraud, abuse mitigation, rate limiting, audit logging. We have weighed your interests against ours and consider these proportionate.
- Article 6(1)(c) - legal obligation: retention of certain records where EU or applicable national law mandates it (for example fraud-prevention logs).
- Article 6(1)(a) - consent: only where strictly required, namely for non-essential cookies and optional product communications.
4. How long we keep it
- Active accounts: for the lifetime of the account.
- Closed accounts: tombstoned for 30 days, then erased. Limited audit metadata may persist where required by law (typically 12 months for fraud prevention, 6 years for accounting).
- Authentication logs: 12 months.
- Transactional email log: 90 days.
- OAuth grants: retained until revoked.
- Backups: rolling 30 day window before automated rotation.
5. Your privacy rights
Depending on where you live, you may have the right to access, correct, delete, restrict, export, or object to the use of your personal data. You may also have the right to withdraw consent where processing is based on consent, and to lodge a complaint with your national data protection authority (for example: APD/GBA in Belgium, CNIL in France, BfDI in Germany, AP in the Netherlands).
These rights are not always absolute. Some requests may depend on the reason we process the data, our legal obligations, security needs, fraud prevention, account integrity, or the rights of other users.
To exercise your rights, contact privacy support at privacy@id.devquest.invalid. We may need to verify your identity before completing a request. We normally respond without undue delay and within one month. If a request is complex or we receive many requests, we may extend this by up to two further months and will tell you why within the first month.
- Access: request a copy of personal data associated with your account.
- Rectification: correct inaccurate profile or account data.
- Erasure: request deletion of your account and associated personal data, subject to legal retention limits.
- Restriction: request that we limit active processing where privacy law allows. While a restriction is active on your LoginSeal account, we will pause linked-app sign-in (because federated login requires processing identity, session, scope, and security data) and stop optional processing such as notifications, marketing, telemetry, and linked-app syncs. Limited processing may continue where necessary for security, legal obligations, account access, or actions you request. You can lift a restriction at any time from your privacy settings.
- Portability: receive account data in a machine-readable format where applicable.
- Objection: object to processing based on legitimate interests, subject to review.
- Withdraw consent: change cookie or consent preferences where processing is based on consent.
- Complaint: contact your national data protection authority (APD/GBA in Belgium, CNIL in France, BfDI in Germany, AP in the Netherlands).
You can also self-serve a data export and account deletion from the in-product portal at /profile/privacy.
6. Subprocessors and data sharing
We share data only with the following categories of recipient:
- OAuth client applications you have explicitly authorised. The scope of data shared is shown on the consent screen at the time of authorisation. You can revoke any grant at /profile/linked-apps.
- Hosting provider: [NOT_SET: HOSTING_PROVIDER], which stores the operational database and runs the application servers.
- Email provider: [NOT_SET: MAIL_PROVIDER], which delivers transactional email.
- Law enforcement, only on receipt of a valid legal request that meets EU adequacy and proportionality standards.
7. International transfers
Where a subprocessor is located outside the EEA, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision. The current list of subprocessors is published at privacy@id.devquest.invalid on request.
8. Cookies
We use a small number of strictly necessary cookies plus a consent cookie that records your cookie preferences. See the dedicated Cookie Policy for details.
9. Children
The minimum age to consent on your own behalf is 16, in line with GDPR Article 8 (the default age set by the Regulation; several member states have set a lower threshold). Below that age, registration requires verifiable parental consent.
10. Changes to this policy
Material changes are announced by email at least 30 days before they take effect. Non-material changes (typo fixes, clarifications) are versioned in our consent log without individual notice.
11. Contact
Data Protection Officer: privacy@id.devquest.invalid. Postal: [NOT_SET: COMPANY_ADDRESS]. The supervisory authority for our establishment is CNIL (Commission Nationale de l'Informatique et des Libertes).