Avizzy Avizzy Auth
Privacy Policy Terms of Service
← Back

Privacy Policy

Last updated: 2026-06-21 Applies to all applications using Avizzy Auth

Contents

  1. Data Controller
  2. Information We Collect
  3. Legal Basis for Processing
  4. How We Use Your Data
  5. Data Sharing
  6. Data Retention
  7. Your Rights
  8. Cookies & Storage
  9. Security
  10. Children's Privacy
  11. Policy Changes
  12. Contact & Complaints

1Data Controller

Avizzy ("we", "us", "our") operates the Avizzy Auth authentication service and acts as the data controller for the personal data described in this policy.

Contact: contact@avizzy.eu

2Information We Collect

We collect only the minimum data necessary to provide authentication services:

CategoryDataSource
Account dataEmail address, display name / usernameYou or your social login provider
AuthenticationHashed & salted password (Argon2id)You (email+password registration only)
Social identifiersProvider user ID (Discord ID, Roblox ID), provider usernameDiscord / Roblox via OAuth2
Session dataSHA-256 token hash, IP address, browser user-agent, expiry timeYour browser / device
Audit logEvent type (login, logout, password reset, etc.), timestamp, IP addressSystem-generated
Email queueEmail address, message content (verification / reset / magic-link emails)You

We do not collect payment information, precise location, contacts, or any data beyond what is required for secure authentication.

When you sign in with a social provider, that provider may share limited profile data (see section 5). We never receive your social provider password.

3Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data under the following lawful bases:

  • Contract performance (Article 6(1)(b)): Processing your account data, credentials, and session data is necessary to provide the authentication service you have requested.
  • Legitimate interests (Article 6(1)(f)): Audit logging and security measures (rate limiting, fraud detection) are necessary for the security of our systems and to protect you and other users.
  • Legal obligation (Article 6(1)(c)): We may retain certain records to comply with applicable law.

4How We Use Your Data

We use your personal data exclusively to:

  • Create and manage your user account
  • Authenticate you when you sign in (email+password or social login)
  • Send transactional emails: email verification, password reset, magic links
  • Maintain and revoke login sessions
  • Detect and prevent fraudulent or abusive activity (rate limiting, audit log)
  • Link and unlink social provider accounts at your request

We do not use your data for advertising, profiling, or sale to third parties.

5Data Sharing and Third-Party Services

We do not sell, rent, or share your personal data with third parties for their own purposes. Data may be disclosed to:

  • Social login providers — when you choose to authenticate with Discord or Roblox, your browser communicates with those providers. We receive only the profile data they expose (ID, username, email if available). Each provider has its own privacy policy:
    • Discord Privacy Policy
    • Roblox Privacy Policy
  • Infrastructure providers — our hosting, database, and email delivery providers process data on our behalf under data processing agreements.
  • Legal requirements — we may disclose data if required by law, court order, or to protect the rights, safety, or property of Avizzy or others.

6Data Retention

We retain your personal data for as long as your account exists. Specific retention periods:

Data typeRetention period
Account data (email, password hash, username)Until account deletion
Social connectionsUntil unlinked or account deletion
Active sessionsUntil expiry (default 30 days) or logout
Revoked / expired sessionsDeleted automatically on next cleanup cycle
Auth tokens (verification, reset, magic link)Deleted after use or expiry (max 24 hours)
Audit log90 days, then permanently deleted
Email queue records30 days after sending, then permanently deleted

When you request account deletion, all personal data is permanently removed within 30 days, except where retention is required by law.

7Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17): Request deletion of your account and all associated personal data.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to restrict processing (Art. 18): Request that we limit how we use your data in certain circumstances.
  • Right to object (Art. 21): Object to processing based on legitimate interests.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, email contact@avizzy.eu. We will respond within 30 days. There is no fee for reasonable requests.

You also have the right to lodge a complaint with your local data protection authority (e.g. the ICO in the UK, or your national supervisory authority in the EU).

8Cookies and Local Storage

We do not use third-party tracking cookies or advertising cookies.

The following first-party cookies and storage are used solely to operate the service:

NamePurposeDuration
sessionAdmin dashboard session (dashboard users only, not end users)Session / configurable TTL
csrfCSRF protection for form submissionsSession

End-user session tokens are managed by the application you are signing in to, not stored in cookies by this service.

9Security

We implement appropriate technical and organisational measures to protect your personal data:

  • Passwords are hashed with Argon2id — a modern, memory-hard algorithm. We never store plaintext passwords.
  • Session tokens are stored only as SHA-256 hashes. A database breach does not expose usable tokens.
  • Sensitive fields (e.g. SMTP credentials) are encrypted at rest with AES-256-GCM.
  • All communications use TLS (HTTPS). HTTP connections are redirected to HTTPS.
  • Rate limiting protects authentication endpoints against brute-force attacks.

If you discover a security vulnerability, please report it responsibly to contact@avizzy.eu.

10Children's Privacy

Avizzy Auth is not directed at children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at contact@avizzy.eu and we will delete it promptly.

If your application is directed at users under 13, you are responsible for obtaining appropriate parental consent.

11Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes that affect how we use your data will be communicated via the application or by email where possible.

Continued use of any application that authenticates through Avizzy Auth after a policy update constitutes acceptance of the revised policy.

12Contact and Complaints

For any privacy-related questions, data requests, or to file a complaint, contact:

Avizzy
Email: contact@avizzy.eu

If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.

✉

Contact us

For questions about this document, data requests, or any other concern, email us at contact@avizzy.eu. We aim to respond within 5 business days.

© 2026 Avizzy Privacy Policy Terms of Service