Avizzy Auth
← Back
Avizzy ("we", "us", "our") operates the Avizzy Auth authentication service and acts as the data controller for the personal data described in this policy.
Contact: contact@avizzy.eu
We collect only the minimum data necessary to provide authentication services:
| Category | Data | Source |
|---|---|---|
| Account data | Email address, display name / username | You or your social login provider |
| Authentication | Hashed & salted password (Argon2id) | You (email+password registration only) |
| Social identifiers | Provider user ID (Discord ID, Roblox ID), provider username | Discord / Roblox via OAuth2 |
| Session data | SHA-256 token hash, IP address, browser user-agent, expiry time | Your browser / device |
| Audit log | Event type (login, logout, password reset, etc.), timestamp, IP address | System-generated |
| Email queue | Email address, message content (verification / reset / magic-link emails) | You |
We do not collect payment information, precise location, contacts, or any data beyond what is required for secure authentication.
When you sign in with a social provider, that provider may share limited profile data (see section 5). We never receive your social provider password.
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process your personal data under the following lawful bases:
We use your personal data exclusively to:
We do not use your data for advertising, profiling, or sale to third parties.
We do not sell, rent, or share your personal data with third parties for their own purposes. Data may be disclosed to:
We retain your personal data for as long as your account exists. Specific retention periods:
| Data type | Retention period |
|---|---|
| Account data (email, password hash, username) | Until account deletion |
| Social connections | Until unlinked or account deletion |
| Active sessions | Until expiry (default 30 days) or logout |
| Revoked / expired sessions | Deleted automatically on next cleanup cycle |
| Auth tokens (verification, reset, magic link) | Deleted after use or expiry (max 24 hours) |
| Audit log | 90 days, then permanently deleted |
| Email queue records | 30 days after sending, then permanently deleted |
When you request account deletion, all personal data is permanently removed within 30 days, except where retention is required by law.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, email contact@avizzy.eu. We will respond within 30 days. There is no fee for reasonable requests.
You also have the right to lodge a complaint with your local data protection authority (e.g. the ICO in the UK, or your national supervisory authority in the EU).
We do not use third-party tracking cookies or advertising cookies.
The following first-party cookies and storage are used solely to operate the service:
| Name | Purpose | Duration |
|---|---|---|
session | Admin dashboard session (dashboard users only, not end users) | Session / configurable TTL |
csrf | CSRF protection for form submissions | Session |
End-user session tokens are managed by the application you are signing in to, not stored in cookies by this service.
We implement appropriate technical and organisational measures to protect your personal data:
If you discover a security vulnerability, please report it responsibly to contact@avizzy.eu.
Avizzy Auth is not directed at children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at contact@avizzy.eu and we will delete it promptly.
If your application is directed at users under 13, you are responsible for obtaining appropriate parental consent.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes that affect how we use your data will be communicated via the application or by email where possible.
Continued use of any application that authenticates through Avizzy Auth after a policy update constitutes acceptance of the revised policy.
For any privacy-related questions, data requests, or to file a complaint, contact:
Avizzy
Email: contact@avizzy.eu
If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority.
For questions about this document, data requests, or any other concern, email us at contact@avizzy.eu. We aim to respond within 5 business days.