> For the complete documentation index, see [llms.txt](https://oten.gitbook.io/kms-support/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://oten.gitbook.io/kms-support/privacy-and-terms/privacy-policy.md).

# Privacy Policy

### 1. Introduction <a href="#id-1-introduction" id="id-1-introduction"></a>

This Privacy Policy describes how Oten ("we," "us," or "our") collects, uses, discloses, and protects information in connection with our Key Management Service ("Oten KMS" or the "Service"). This policy applies to all users of our Oten KMS platform, including administrators, developers, and end-users.

We are committed to protecting your privacy and ensuring the security of all data processed through our Service.

***

### 2. Information We Collect <a href="#id-2-information-we-collect" id="id-2-information-we-collect"></a>

#### 2.1 Account Information <a href="#id-21-account-information" id="id-21-account-information"></a>

* Organization name and contact details
* Administrator names and email addresses
* Billing information (processed by third-party payment providers)
* Authentication credentials (hashed credentials, public keys, or identity tokens; passwords are never stored in plaintext)

#### 2.2 Service Usage Data <a href="#id-22-service-usage-data" id="id-22-service-usage-data"></a>

* API call logs and timestamps
* Key creation, rotation, and management activities
* Authentication events and access logs
* Error logs and diagnostic information

#### 2.3 Cryptographic Metadata <a href="#id-23-cryptographic-metadata" id="id-23-cryptographic-metadata"></a>

* Key identifiers (Key IDs)
* Key configurations and policies
* Key version information
* Access control settings and conditions
* Cryptographic metadata does not include key material, key derivation secrets, or plaintext cryptographic parameters.

#### 2.4 Integration Data <a href="#id-24-integration-data" id="id-24-integration-data"></a>

* Google Workspace CSE configuration data
* Google Drive integration metadata
* Third-party service connection details
* TEE (Trusted Execution Environment) attestation data is used solely to verify trusted execution environments and is not used for profiling or tracking users.

#### 2.5 Technical Information <a href="#id-25-technical-information" id="id-25-technical-information"></a>

* IP addresses
* Device identifiers
* Browser type and version
* Operating system information

***

### 3. Information We Do NOT Collect or Access <a href="#id-3-information-we-do-not-collect-or-access" id="id-3-information-we-do-not-collect-or-access"></a>

**Important:** Our Oten KMS is designed with zero-knowledge principles for customer-managed cryptographic material (CMKs), including plaintext keys and encrypted customer content.

* We do **NOT** have access to your plaintext encryption keys
* We do **NOT** store or access data encrypted using your Customer Managed Keys (CMKs)
* We do **NOT** retain the content of wrap/unwrap operations
* We do **NOT** access files stored in your Google Drive or other integrated services

***

### 4. How We Use Your Information <a href="#id-4-how-we-use-your-information" id="id-4-how-we-use-your-information"></a>

#### 4.1 Service Provision <a href="#id-41-service-provision" id="id-41-service-provision"></a>

* Authenticate users and manage access controls
* Process key management operations
* Maintain and improve Service performance
* Provide customer support

#### 4.2 Security and Compliance <a href="#id-42-security-and-compliance" id="id-42-security-and-compliance"></a>

* Detect and prevent fraudulent or unauthorized activities
* Monitor for security threats and vulnerabilities
* Comply with legal obligations and regulatory requirements
* Generate audit logs for compliance purposes

#### 4.3 Service Improvement <a href="#id-43-service-improvement" id="id-43-service-improvement"></a>

* Analyze usage patterns to improve Service features
* Identify and fix technical issues
* Develop new features and capabilities

#### 4.4 Communication <a href="#id-44-communication" id="id-44-communication"></a>

* Send Service-related notifications
* Provide security alerts and updates
* Respond to inquiries and support requests

***

### 5. Data Sharing and Disclosure <a href="#id-5-data-sharing-and-disclosure" id="id-5-data-sharing-and-disclosure"></a>

#### 5.1 We Do NOT Sell Your Data <a href="#id-51-we-do-not-sell-your-data" id="id-51-we-do-not-sell-your-data"></a>

We do not sell, rent, or trade your personal information or cryptographic data to third parties.

#### 5.2 Limited Sharing <a href="#id-52-limited-sharing" id="id-52-limited-sharing"></a>

We may share information only in the following circumstances:

**Service Providers:** With trusted third-party vendors who assist in operating our Service, subject to confidentiality agreements.

**Legal Requirements:** When required by law, court order, or governmental authority.

**Security Incidents:** To investigate, prevent, or take action regarding potential security breaches or fraud.

**Business Transfers:** In connection with a merger, acquisition, or sale of assets, with appropriate confidentiality protections.

**With Your Consent:** When you explicitly authorize sharing with specific parties.

***

### 6. Data Security <a href="#id-6-data-security" id="id-6-data-security"></a>

#### 6.1 Security Measures <a href="#id-61-security-measures" id="id-61-security-measures"></a>

We implement industry-leading security measures including:

* End-to-end encryption for data in transit (TLS 1.3)
* AES-256 encryption for data at rest
* Hardware Security Modules (HSM) for key storage
* TEE (Trusted Execution Environment) integration
* Multi-factor authentication support
* Regular security audits and penetration testing
* SOC 2 readiness and controls aligned with SOC 2 Trust Services Criteria

#### 6.2 Access Controls <a href="#id-62-access-controls" id="id-62-access-controls"></a>

* Role-based access control (RBAC)
* Principle of least privilege
* Regular access reviews and audits
* Automated session management

#### 6.3 Incident Response <a href="#id-63-incident-response" id="id-63-incident-response"></a>

We maintain a comprehensive incident response plan and will notify affected users promptly in case of any security breach that may impact their data.

***

### 7. Data Retention <a href="#id-7-data-retention" id="id-7-data-retention"></a>

#### 7.1 Active Data <a href="#id-71-active-data" id="id-71-active-data"></a>

* Account information: Retained while account is active
* Cryptographic keys: Retained according to your key lifecycle policies
* Audit logs: Retained for the minimum period required to meet legal, security, and compliance obligations.

#### 7.2 Deleted Data <a href="#id-72-deleted-data" id="id-72-deleted-data"></a>

* Upon account termination, we will securely delete your data within 30 days
* Cryptographic keys are securely destroyed using industry-standard methods
* Some data may be retained longer if required by law

#### 7.3 Backup Data <a href="#id-73-backup-data" id="id-73-backup-data"></a>

Backup copies are retained for disaster recovery purposes and are subject to the same security controls as primary data.

***

### 8. Your Rights and Choices <a href="#id-8-your-rights-and-choices" id="id-8-your-rights-and-choices"></a>

#### 8.1 Access and Portability <a href="#id-81-access-and-portability" id="id-81-access-and-portability"></a>

You have the right to:

* Access your account information
* Export your key metadata and configurations
* Obtain copies of audit logs

#### 8.2 Correction and Deletion <a href="#id-82-correction-and-deletion" id="id-82-correction-and-deletion"></a>

You may:

* Update your account information
* Request correction of inaccurate data
* Request deletion of your account and associated data

#### 8.3 Data Processing Controls <a href="#id-83-data-processing-controls" id="id-83-data-processing-controls"></a>

You can:

* Configure key lifecycle policies
* Set access conditions and restrictions
* Manage integration permissions

#### 8.4 Opt-Out <a href="#id-84-opt-out" id="id-84-opt-out"></a>

You may opt out of:

* Marketing communications
* Non-essential data collection
* Certain analytics features
* Opt-out does not apply to data required for security, compliance, fraud prevention, or core Service operations.

***

### 9. International Data Transfers <a href="#id-9-international-data-transfers" id="id-9-international-data-transfers"></a>

#### 9.1 Data Location <a href="#id-91-data-location" id="id-91-data-location"></a>

* Primary data centers are located in regions selected by Oten, including Asia-Pacific and North America.

#### 9.2 Transfer Safeguards <a href="#id-92-transfer-safeguards" id="id-92-transfer-safeguards"></a>

For international transfers, we implement:

* Standard Contractual Clauses (SCCs)
* Appropriate security measures
* Compliance with applicable data protection laws

***

### 10. Compliance <a href="#id-10-compliance" id="id-10-compliance"></a>

#### 10.1 Regulatory Compliance <a href="#id-101-regulatory-compliance" id="id-101-regulatory-compliance"></a>

Our Service is designed with security and privacy principles aligned to widely recognized regulatory and compliance frameworks. While formal certifications or contractual arrangements may not yet be in place, Oten KMS is architected to support customer compliance efforts, including:

* GDPR (General Data Protection Regulation)
* CCPA (California Consumer Privacy Act)
* HIPAA (support planned; requires execution of a Business Associate Agreement)
* SOC 2 (controls designed to align with Trust Services Criteria)
* ISO 27001 (controls aligned; certification planned)

#### 10.2 Industry Standards <a href="#id-102-industry-standards" id="id-102-industry-standards"></a>

We adhere to:

* NIST Cybersecurity Framework
* OWASP Security Guidelines
* Industry best practices for key management

***

### 11. Third-Party Integrations <a href="#id-11-third-party-integrations" id="id-11-third-party-integrations"></a>

#### 11.1 Google Workspace CSE <a href="#id-111-google-workspace-cse" id="id-111-google-workspace-cse"></a>

When using Google Workspace Client-side Encryption integration:

* We provide key management and cryptographic authorization services used by Google Workspace Client-Side Encryption.
* Google's privacy policy applies to data within Google services
* We only access encryption key metadata, not encrypted content

#### 11.2 Google Drive Integration <a href="#id-112-google-drive-integration" id="id-112-google-drive-integration"></a>

* We facilitate key management for encrypted files
* File content remains encrypted and inaccessible to us
* Access is governed by your configured policies

#### 11.3 Other Integrations <a href="#id-113-other-integrations" id="id-113-other-integrations"></a>

Third-party integrations are subject to their respective privacy policies. We recommend reviewing those policies before enabling integrations.

***

### 12. Children's Privacy <a href="#id-12-childrens-privacy" id="id-12-childrens-privacy"></a>

Our Service is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.

***

### 13. Changes to This Policy <a href="#id-13-changes-to-this-policy" id="id-13-changes-to-this-policy"></a>

We may update this Privacy Policy periodically. We will notify you of material changes by:

* Posting the updated policy on our website
* Sending email notifications to account administrators
* Displaying in-app notifications

Continued use of the Service after changes constitutes acceptance of the updated policy.

***

### 14. Contact Us <a href="#id-14-contact-us" id="id-14-contact-us"></a>

For privacy-related inquiries, please contact: <support@oten.live>

***

### 15. Additional Information for Specific Regions <a href="#id-15-additional-information-for-specific-regions" id="id-15-additional-information-for-specific-regions"></a>

#### 15.1 European Union (GDPR) <a href="#id-151-european-union-gdpr" id="id-151-european-union-gdpr"></a>

* Legal basis for processing: Contract performance, legitimate interests, legal obligations
* Data Protection Authority: You may lodge complaints with your local supervisory authority

#### 15.2 California (CCPA) <a href="#id-152-california-ccpa" id="id-152-california-ccpa"></a>

* Categories of personal information collected: Identifiers, commercial information, internet activity
* No sale of personal information
* Right to know, delete, and opt-out

#### 15.3 Other Jurisdictions <a href="#id-153-other-jurisdictions" id="id-153-other-jurisdictions"></a>

Contact us for information about rights specific to your jurisdiction.
