This policy explains what personal data AuthOwl collects, why we use it, and the choices and rights you have.
Who we are and scope
AuthOwl is a hosted authentication service based in Cairo, Arab Republic of Egypt. This policy covers the personal data we handle as a controller, namely the data of our own account holders and visitors to our marketing site and dashboard. Personal data belonging to your end-users, which we process on your behalf, is governed by our Data Processing Addendum and by your own privacy notice.
Information we collect
- Account information: name, email address, organization details, and authentication credentials you provide when you sign up or manage your account.
- Usage and telemetry: logs, device and browser information, IP address, and product events we use to operate, secure, and improve the service.
- Billing information: plan, invoices, VAT details, and transaction records. Card details are handled by our payment provider; we do not store full card numbers.
How we use it
We use personal data to provide and maintain the service, authenticate and support you, process billing in EGP, secure our systems and detect abuse, communicate service and administrative messages, comply with legal obligations, and improve our products.
Legal bases
Depending on the context, we rely on the performance of our contract with you, our legitimate interests in running and securing the service, your consent where we ask for it, and compliance with legal obligations. Where we process personal data of individuals in Egypt, we do so in accordance with Egypt’s Personal Data Protection Law (Law No. 151 of 2020, the "PDPL").
Sharing and subprocessors
We do not sell personal data. We share it with service providers who help us run AuthOwl, such as cloud hosting, communications, and payment providers, under contracts that require appropriate safeguards. We may also disclose data where required by law or to protect our rights and users. A current list of subprocessors is available on request.
International transfers
We are based in Egypt and may use providers located in other countries. Where personal data is transferred outside Egypt, we take steps required by the PDPL and other applicable law to ensure an adequate level of protection, including appropriate contractual safeguards.
Data retention
We keep personal data for as long as your account is active and as needed to provide the service, then for the period required to meet legal, tax, and accounting obligations or to resolve disputes. When data is no longer needed, we delete or anonymize it.
Security
We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and monitoring. No system is perfectly secure, but we work to protect personal data and to respond promptly to incidents.
Your rights
Subject to applicable law, you may request to access, rectify, or erase your personal data, object to or restrict certain processing, withdraw consent, and receive a portable copy of data you provided. To exercise these rights, contact us using the details below. We may need to verify your identity before acting on a request.
Cookies
Our site and dashboard use cookies and similar technologies that are necessary to operate the service, keep you signed in, and understand usage. You can control non-essential cookies through your browser settings; disabling some cookies may affect functionality.
Children
AuthOwl is intended for businesses and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us data, please contact us and we will take appropriate steps.
Changes
We may update this policy from time to time. When we make material changes, we will revise the "last updated" date and, where appropriate, notify you.
Contact
For privacy questions or to exercise your rights, contact us at privacy@authowl.dev. You can also reach our Data Protection Officer at dpo@authowl.dev.