Privacy Policy
How Sifr AI collects, uses, and protects information in its identity governance workspace.
1. Who we are
Sifr AI operates an identity governance and compliance workspace that helps organisations discover, assign ownership to, and audit non-human identities — including service accounts, API keys, bots, automated workflows, contractors, and AI agents. References to "Sifr", "we", "our", or "us" in this policy refer to Sifr AI and its operators.
For privacy enquiries, contact us at privacy@sifrhq.com.
2. Information we collect
We collect information in the following categories:
- Account information: name, work email address, and organisation name provided when you create an account or request access.
- Authentication data: authentication tokens and session state from your identity provider (Google, GitHub, or company SSO). We do not receive or store your identity-provider password.
- Workspace records: governance records you create within the product — identity inventory entries, ownership assignments, access requests, workflow state, audit log events, and report artefacts.
- Connector configuration: connection settings and credentials you supply to integrate Sifr with external identity systems. Credentials are stored encrypted at rest.
- Usage and log data: IP addresses, browser and device type, pages visited, feature interactions, and error events collected for security, debugging, and product improvement.
- Communications: contents of support, security review, or demo-request messages you send to us.
Sifr is not the authoritative store for your organisation's live identity data. External identity providers (Okta, Entra ID, SailPoint, and similar) remain sources of truth for live identity and access state. Sifr stores the governance, workflow, and evidence records it creates on top of those systems.
3. How we use information
- Operate, maintain, and improve the Sifr identity governance workspace.
- Authenticate workspace users and enforce access controls.
- Process and route access requests, approvals, and certification campaigns.
- Generate audit evidence, compliance reports, and governance artefacts.
- Detect and respond to security threats, abuse, or product errors.
- Communicate product updates, service notices, and security alerts.
- Respond to support, demo, or security review requests.
We do not sell your personal information. We do not use workspace identity or governance data to train external AI or machine-learning models.
4. Legal bases for processing (EEA / UK)
Where the GDPR or UK GDPR applies, our legal bases for processing personal data are:
- Contract: processing necessary to deliver the Sifr workspace you have subscribed to or requested access for.
- Legitimate interests: security monitoring, fraud prevention, product reliability, and communicating service changes — where these interests are not overridden by your rights.
- Consent: for optional communications where we rely on your consent. You may withdraw consent at any time.
- Legal obligation: where processing is required by applicable law.
5. Data sharing and subprocessors
We share data with a limited set of service providers that help us operate the product. Each subprocessor is bound by appropriate data-protection agreements. We do not share personal data with third parties for their own marketing purposes.
Categories of subprocessors include: cloud hosting and infrastructure, authentication services, error monitoring, and customer communication tools. An up-to-date subprocessor list is available upon request at privacy@sifrhq.com.
We may disclose information if required by law, court order, or to protect the rights, property, or safety of Sifr, our customers, or the public.
6. Data retention
We retain workspace records for the duration of your organisation's account, plus a reasonable period thereafter to allow for recovery, legal holds, or compliance obligations. Audit log and evidence artefacts are retained in accordance with the governance policies configured in your workspace. You may request deletion of your personal information subject to applicable legal obligations.
7. Security
Sifr applies technical and organisational controls appropriate to a governance and compliance product: encrypted credentials, access-controlled infrastructure, session management, and structured audit logging. For a detailed security posture, see our Security & Trust Center.
No system is perfectly secure. If you believe you have discovered a security vulnerability, report it to security@sifrhq.com.
8. Your rights
Depending on your location, you may have rights to access, correct, port, restrict, or erase your personal data. You may also object to certain processing or withdraw consent where processing relies on it.
To exercise these rights, contact privacy@sifrhq.com. We will respond within the timeframe required by applicable law. For EEA or UK residents, you have the right to lodge a complaint with your local data protection authority.
9. Cookies and tracking
Sifr uses session cookies required for authentication and workspace state. We may use minimal analytics to understand product usage patterns. We do not use advertising trackers or third-party marketing pixels. Where law requires consent for non-essential cookies, we will obtain it.
10. International transfers
Sifr operates infrastructure in cloud regions. If your data is transferred outside your jurisdiction, we rely on appropriate transfer mechanisms (such as EU Standard Contractual Clauses for EEA data) to ensure adequate protection. Contact us for specifics applicable to your deployment.
11. Changes to this policy
We may update this policy to reflect product changes or legal requirements. Material changes will be communicated to active workspace administrators by email. Continued use of the product after the effective date of an updated policy constitutes acceptance of the revised terms.
12. Contact
For privacy questions, data subject requests, or subprocessor information, contact privacy@sifrhq.com.
For security disclosures, use security@sifrhq.com.