PassuraStart free

Legal

Privacy policy

What we collect, why we collect it, and what you can make us do about it.

Last updated 21 August 2026 · Data controller: PENDING — confirm before launch
Draft — pending legal review

This document is a working draft published for transparency while Passura is in closed beta. It has not been reviewed by a qualified lawyer, it is not an executed agreement, and it does not yet bind either party. If you need a signed version to complete a procurement review, contact us and we will send the executed document.

Outstanding before this is binding
  • Confirm the controller/processor split: Passura is a processor for end-user data belonging to customer tenants, and a controller for customer account data. The drafting below assumes that split and a lawyer should confirm it holds.
  • Confirm the stated lawful bases, particularly legitimate interest for security logging and rate limiting.
  • Confirm retention periods against the values actually implemented in the codebase before they are represented as commitments.
  • Add the supervisory authority details and complaint route for the operator’s member state (AEPD, Spain).
  • Decide whether an Article 27 representative or a DPO is required; on current scale neither appears to be, but that needs confirming.

1. Who we are

Passura is an authentication service operated by PENDING — confirm before launch, NIF PENDING — confirm before launch, registered at PENDING — confirm before launch. For questions about this policy or to exercise any right described below, contact PENDING — confirm before launch.

Passura serves two groups of people, and the distinction matters for your rights. If you have a Passura account, we are the controllerof your account data. If you are signing in to somebody else's application that uses Passura, that application is the controller and we are their processor — your requests should go to them, and we will support them in answering you.

2. What we collect

For end users authenticating through a customer's application:

  • Email address, and a display name if the application supplies one.
  • A password hash, if password sign-in is enabled. We store an Argon2id hash and never the password itself.
  • Multi-factor secrets, if MFA is enabled — a TOTP seed, or a short-lived one-time code delivered by email.
  • Authentication events in the audit log: what happened, when, the IP address, and the user agent.
  • Session records for issued refresh tokens, so sessions can be revoked.

We do not collect special-category data, we do not run analytics on this site, and we set no advertising or tracking cookies anywhere in the product.

3. Why we process it

To authenticate users and maintain sessions, which is performance of the contract with the customer whose application you are signing in to. To keep accounts secure — rate limiting, abuse detection, and the audit log — which we treat as legitimate interest. And to meet legal obligations where one applies, such as retaining records we are required to keep.

4. Where your data lives

All customer and end-user data is stored in the EU, on OVHcloud infrastructure in Gravelines, France. Data is not replicated outside that jurisdiction.

Some of our sub-processors are established outside the EU even where the data they handle stays inside it. We publish the complete list, including each processor's country of establishment, at passura.dev/sub-processors. Read that page alongside this one — it is the specific answer to “who else can see this”.

5. How long we keep it

Account data is retained while the account exists. When an end user is deleted, the record is soft-deleted immediately — sessions are revoked and the account stops working at once — and hard-deleted after a grace period, which defaults to 30 days and is configurable per tenant. One-time codes are deleted after they expire. Rate-limiting records are retained for 90 days by default.

Audit log entries outlive the user they describe: when a user is hard-deleted the audit rows survive with the user reference removed. This is deliberate — a security trail that can be erased by the person being audited is not a security trail.

6. Your rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your data, and to object to processing. Where we are the processor rather than the controller, exercise these against the application you signed in to; they have tooling from us to answer.

You also have the right to lodge a complaint with a supervisory authority in the member state where you live or work.

7. Changes to this policy

Material changes are announced by email to account holders before they take effect. The date at the top of this page always reflects the current version.