Privacy Policy

Last updated: 12 September 2026

1. What we collect

SirAuth is an authentication service, so we deliberately collect as little as possible:

2. What we never do

3. How data is protected

All traffic is encrypted with TLS. Passwords are never stored — the service is passwordless by design. API tokens and end-user credentials are stored hashed. Access to production systems is limited to operators with hardware-key authentication.

4. Retention

5. Subprocessors

We run our own infrastructure. The only subprocessors are our hosting and email-delivery providers, listed on request at privacy@sirauth.com.

6. Your rights

You can request access to, correction of, or deletion of your personal data at any time. Depending on your jurisdiction you may also have the right to data portability and to lodge a complaint with a supervisory authority.

7. Contact

Privacy questions: privacy@sirauth.com.