Last Updated: December 19, 2024

Last Updated: December 19, 2024

Privacy Policy

1. Introduction

Porte ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our cloud access management and entitlement governance solution ("Porte" or the "Service"). Please read this Privacy Policy carefully to understand our practices regarding your personal data.

2. Data Controller

For the purposes of the General Data Protection Regulation (GDPR), Porte acts as both a data controller and a data processor, depending on the context of data processing activities.

3. Personal Data We Collect

3.1 Data You Provide to Us

Account information (name, email address, job title, company name)

Authentication credentials

Contact information for support and billing

Communication preferences

Any other information you choose to provide

3.2 Data We Automatically Collect

Log data (IP addresses, browser type, pages visited)

Device information (operating system, unique device identifiers)

Usage data related to your interaction with Porte

Access and authentication logs

Analytics data about service usage

3.3 Data From Third Parties

Information from AWS services integrated with Porte

Information from identity providers

Public information from professional networks

4. How We Use Your Personal Data

We process your personal data for the following purposes:

4.1 Service Provision

Managing your account and providing our services

Processing and recording access requests and approvals

Maintaining audit trails for compliance purposes

Authenticating users and managing permissions

4.2 Service Improvement

Analyzing service usage patterns

Debugging and optimizing performance

Developing new features

Creating aggregated analytics

4.3 Communication

Sending service updates and notifications

Responding to support requests

Providing information about related products or services

Sending security alerts

5. Legal Basis for Processing

We process your personal data under the following legal bases:

Contract performance: Processing necessary to provide our services

Legal obligations: Compliance with applicable laws and regulations

Legitimate interests: Improving our services and maintaining security

Consent: Where specifically requested and provided by you

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by law. When data is no longer needed, it will be securely deleted or anonymized.

7. Data Sharing and Transfers

7.1 Third-Party Service Providers

We may share your data with trusted service providers who assist us in:

Hosting and infrastructure services

Analytics services

Customer support tools

Payment processing

7.2 Legal Requirements

We may disclose your information if required by law, regulation, or legal process.

7.3 International Transfers

When we transfer data outside the EEA, we ensure appropriate safeguards are in place through:

Standard contractual clauses

Adequacy decisions

Other legal mechanisms as required by GDPR

8. Your Rights Under GDPR

You have the following rights regarding your personal data:

Right to access

Right to rectification

Right to erasure

Right to restrict processing

Right to data portability

Right to object

Rights related to automated decision-making

Right to withdraw consent

To exercise these rights, please contact us at [privacy@porte.com].

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

Encryption at rest and in transit

Access controls and authentication

Regular security assessments

Employee training

Incident response procedures

10. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to:

Maintain your session

Remember your preferences

Analyze service usage

Improve security

You can control cookie settings through your browser preferences.

11. Children's Privacy

Our services are not intended for children under 16. We do not knowingly collect personal data from children under 16.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes through our service or by email.

13. Contact Information

For questions about this Privacy Policy or our privacy practices, please contact:

Data Protection Officer  Email: [privacy@porte.com

14. Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you have concerns about how we process your personal data.