Last updated: December 31, 2020
This policy (together with our terms of service and any other documents referred to in it) sets out:
- Information we collect about you
- Cookies and other technologies
- How we use your information
- Our promotional updates and communications
- Who we give your information to
- Where we store your information
- How we protect your information
- How long we keep your information
- Your rights
- Changes to this policy
- Contact us
Auth0’s GDPR representative, for purposes of Article 27 of the GDPR, is Lionheart Squared. Lionheart Squared may be contacted at:
Lionheart Squared (Europe) Ltd., 2 Pembroke House, Upper Pembroke Street 28-32, Dubline, D02 EK84 Irelandauth0@lionheartsquared.eu
Information we collect about you
We will collect and process the following personal data from you:
Information you give us
This is information about you that you give us directly when you interact with us
This is information about you that you give us by filling in forms on our site or by corresponding with us by phone, e-mail or otherwise. It includes information you provide when you register to use our site, subscribe to our service, search for a product, in discussion boards or other social media functions on or via our site, enter a competition, promotion or survey, submit a query, providing information at trade shows or sponsored events and when you report a problem with our site. The information you give us may include your name, address, e-mail address and phone number, financial and credit card information, personal description and photograph, login and password details.
It may also include employment details if you send us a CV, resumé or other details of your employment history in connection with an advertised job vacancy or a general enquiry regarding employment opportunities with us.
Information we collect about you from your use of our site
We will automatically collect information from you each time you visit our site. This includes:
- Technical information
- Information about your visit
- IP Location data
- Technical information may include the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, operating system and platform;
- Information about your visit may include the full Uniform Resource Locators (URL), clickstream to, through and from our site (including date and time), page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, and any phone number used to call our customer service number or social media handle used to connect with our customer service team.
- Location data - IP addresses are collected and location is inferred based on IP location.
Information we receive from other sources.
This is information we receive about you:
- If you use any of the other websites or apps we operate or the other services we provide.
- From third parties we work with.
In this case we will have informed you when we collected that data if we intend to share your data internally and combine it with data collected on this site. We will also have told you for what purpose we will share and combine your data. We are working closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, and search information providers).
Cookies and other technologies
How we use your information
We use information held about you in the following ways:
- Information you give to us:
We will use this information to:
- Take steps in order to enter into any contract or carry out our obligations arising from any contract entered into between you and us including:
- administering your account with us;
- Verifying and carrying out financial transactions in relation to payments you make;
- notifying you about changes to our service.
- Provide you with information about our products or services we feel may interest you, if you have given your consent to receiving marketing material from us at the point we collected your information, where required by law or otherwise in our legitimate interests provided these interests do not override your right to object to such communications. override your right to object to such communications. ect to such communications. override your right to object to such communications.
- Ensure in our legitimate interests that:
- content from our site is presented in the most effective manner for you and for your computer.
- we provide you with the information, products and services that you request from us. you with the information, products and services that you request from us.
- Information you give to us:
We will use this information in our legitimate interests, where we have considered these are not overridden by your rights:
- To administer our site and for internal operations, including troubleshooting, data analysis, testing, research, statistical and survey purposes.
- To keep our site safe and secure.
- For measuring or understanding the effectiveness of advertising we serve to you and others, and to deliver relevant advertising to you.
- To improve our site to ensure that content is presented in the most effective manner for you and for your computer.
- To allow you to participate in interactive features of our service, when you choose to do so.
- Information we receive from other sources
We may combine this information with information you give to us and information we collect about you in our legitimate interests (where we have considered that these are not overridden by your rights). We will use this information and the combined information for the purposes set out above (depending on the types of information we receive).
Our promotional updates and communications
Where permitted in our legitimate interest or with your prior consent where required by law, we will use your personal information for marketing analysis and to provide you with promotional update communications by email about our products and services. You can object to further marketing at any time by checking and updating your contact details within your account, or selecting the "unsubscribe" link at the end of all our marketing and promotional update communications to you, or by submitting your email address here.
Who we give your information to
We may give your information to:
- Any member of our group, which means our subsidiaries, our ultimate holding company and its subsidiaries, who support our processing of personal data under this policy. If any of these parties are using your information for direct marketing purposes, we will only transfer the information to them for that purpose with your prior consent.
- Selected third parties
Our selected third parties may include:
- Organisations who process your personal data on our behalf and in accordance with our instructions and applicable law. This includes organizations supporting the services we offer through the site, in particular organizations providing website and data hosting services, providing fulfilment services, distributing any communications we send, supporting or updating marketing lists, and facilitating feedback on our services. These organisations (which may include third party suppliers, agents, sub-contractors and/or other companies in the Auth0 group of companies) will only use your information to the extent necessary to perform their support functions.
- Analytics and search engine providers that assist us in the improvement and optimisation of our site and subject to the cookie section of this policy (this will not identify you as an individual).
- Business partners who jointly with us provide services to you and with whom we have entered into agreements in relation to the processing of your personal data , a list of whom can be found here.
- Payment processing providers who provide secure payment processing services. (Your payment card details are not shared with us by the provider.)
We will disclose your personal information to third parties:
- If Auth0 or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets.
Where we store your information
If your personal information originates in the EEA or Switzerland, we may transfer it outside the EEA or Switzerland for the reasons below--where the transfer is to a country that the applicable EEA or Swiss data protection authorities have determined does not provide adequate protection, such transfers will be subject to appropriate safeguards, for example the EU Commission's Model Clauses(otherwise known as the Standard Contractual Clauses):
- In order to store it.
- In order to enable us to provide goods or services to you and fulfil our contract with you. This includes order fulfilment, processing of payment details, and the provision of support services.
- Where we are legally required to do so.
- In order to facilitate the operation of our group of businesses, where it is in our legitimate interests and we have concluded these are not overridden by your rights.
The site may, from time to time, make chat rooms, message boards, news groups and/or other public forums available to its users. Any information that is disclosed in these areas becomes public information and you should exercise caution when using these and avoid posting any personal information
The site is intended for use only by persons who are at least 16 years of age. By using the site, you confirm to us that you meet this requirement. If you are under the age of 18, you confirm you have received permission from your parent or guardian before using this site or sending us personal information.
How we protect your information
All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted using SSL technology.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.
Our site may, from time to time, contain links to external sites. We are not responsible for the privacy policies or the content of such sites.
How long we keep your information
We retain personal data during any period in which you have expressed an interest in our products and services, for as long as you have an account with us in order to meet our contractual obligations to you, and for six years after that to identify any issues and resolve any legal proceedings. We may also retain aggregate information beyond this time for research purposes and to help us develop and improve our services. You cannot be identified from aggregate information retained or used for these purposes.
EU Citizen rights under GDPR
- You have the right under certain circumstances:
- to be provided with a copy of your personal data held by us;
- to request the rectification or erasure of your personal data held by us;
- to request that we restrict the processing of your personal data (while we verify or investigate your concerns with this information, for example);
- to object to the further processing of your personal data, including the right to object to marketing;
- to request that your provided personal data be moved to a third party.
- You may opt out at any time from allowing further access by us to your location data by emailing firstname.lastname@example.org.
- Your right to withdraw consent:
Where the processing of your personal information by us is based on consent, you have the right to withdraw that consent without detriment at any time by going here.
You can also exercise the rights listed above at any time by contacting us at email@example.com.
We would appreciate the opportunity to directly address any GDPR issues you may have. Please contact us at firstname.lastname@example.org. You do, however, have the right to approach your local data protection authority, (see http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.html for data protection authorities in the EU).
Data processed on behalf of our Customers
Customer agreements are in place with each Auth0 customer. These agreements cover data transfers to third parties that may occur as part of Auth0’s provision of its services to the customer.
Strictly Necessary Cookies
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site.
All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies we will not know when you have visited our site, and will not be able to monitor its performance.
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages.
If you do not allow these cookies then some or all of these services may not function properly.
- _gd session_session
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites.
They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
Transfers of EU & Swiss Data into the US
We are aware that, on July 16, 2020, in the Schrems II case, the European Court of Justice invalidated the EU-US Privacy Shield as a means of ensuring adequate protection for personal data transferred to the US. We are also aware that the Swiss Data Protection Authority and Information Commissioner invalidated the Swiss-US Privacy Shield in September 2020. In reflection of these rulings, where we transfer personal data originating in the EEA or in Switzerland to the US, those transfers are made under the Standard Contractual Clauses approved by the European Commission for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection.
Auth0 is subject to the investigatory and enforcement authority of the United States Federal Trade Commission (FTC).
Pursuant to the Privacy Shield principles we still acknowledge the right of EU and Swiss individuals to access their personal data to inspect, update, or correct it. EU and Swiss individuals wishing to exercise this right may do so by emailing Auth0 at email@example.com.
Under the Privacy Shield, we may be liable for the onward transfer of personal data to third parties as described above under, “Who we give your information to.”
Note that we do not share any personal data with non-agent third parties or for uses other than those for which the information was originally provided. If this practice should change in the future we will update this policy accordingly and provide individuals with opt-out or opt-in choice, as required. We may be required to release personal data in response to lawful requests by public authorities including to meet national security and law enforcement requirements.
In compliance with the Privacy Shield Principles, Auth0 commits to resolve complaints about your privacy and our collection or use of your personal information transferred to the United States pursuant to Privacy Shield. European Union and Swiss individuals with Privacy Shield inquiries or complaints should first contact Auth0 at:
or Adam Nunn at:
10800 NE 8th Street Suite 600 Bellevue, Washington 98004
Auth0 has further committed to refer unresolved privacy complaints under the Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers for more information and to file a complaint. This service is provided free of charge to you. If your Privacy Shield complaint cannot be resolved through the above channels, under certain conditions, you may invoke binding arbitration for some residual claims not resolved by other redress mechanisms. See Privacy Shield Annex 1 at https://www.privacyshield.gov/article?id=ANNEX-I-introduction
Changes to this policy
10800 NE 8th Street, Suite 600, Bellevue, WA 98004, U.S.A.
+1 (425) 312-6521