Legal
Privacy Policy
This policy explains the information Trueonic processes when you visit our website, create a workspace, or use the identity-risk platform.
Effective August 4, 2026
1. Scope and roles
Trueonic acts as a controller for account, website and business-onboarding information. For identity and event data submitted by a customer through the platform, the customer is the controller and Trueonic acts as its processor.
2. Information we collect
We collect account details such as name, work email and authentication credentials; business profile details such as company, scale, use cases and integration requirements; and operational records such as audit events, API request metadata and security logs.
When customers integrate Trueonic, the platform may process identifiers, device and browser characteristics, IP and network information, account references, risk events and behavioral timing aggregates. The browser SDK does not collect passwords, keystroke contents, private form-field contents or permission-gated sensor data.
3. How we use information
We use information to provide and secure the service, create explainable risk decisions, maintain tenant isolation, prevent abuse, support customers, improve reliability and comply with legal obligations. We do not sell personal information or use customer event data for third-party advertising.
4. Legal bases
Depending on location and context, processing is based on performance of a contract, legitimate interests in operating and securing the service, consent where required, and compliance with legal obligations.
5. Retention and deletion
Customer-configured retention controls apply to platform data. Account and audit records are retained for security, contractual and legal requirements. Authorized workspace users can export or delete account data through the platform; additional requests can be sent to privacy@trueonic.io.
6. Security and international transfers
Trueonic uses access controls, encryption in transit, encrypted sensitive fields at rest, hashed credentials and API secrets, audit trails and tenant-scoped authorization. No system is perfectly secure. Where information crosses borders, appropriate contractual or legal safeguards should be used.
7. Your choices and rights
Depending on your jurisdiction, you may request access, correction, deletion, portability, restriction or objection. Customers should normally direct end-user requests through their organization because they control the submitted data.
8. Contact and changes
Questions and privacy requests can be sent to privacy@trueonic.io. Material policy changes will be reflected by an updated effective date and, where appropriate, an in-product notice.