Last updated August 12, 2026
Last updated August 12, 2026. Contact
legal@oauth.work for the executed DPA and entity details.
Retention periods below match the platform RETENTION constants (audit 365 days,
backups 90 days) unless otherwise noted.
This notice explains how OAUTH.WORK ("we") handles personal data in connection with the OAUTH.WORK identity platform (the "Service"). It covers two distinct roles, and the distinction matters for your rights.
Determined by the customer's configuration, this can include:
As a processor: solely to provide the Service on documented instructions from the customer. As a controller: to operate and secure the platform, to bill for it, to respond to enquiries, and to meet legal obligations. Where required, our lawful bases are performance of a contract, legitimate interests in securing and operating the Service, and compliance with legal obligations.
We set four cookies, all of them strictly necessary to sign you in and keep you signed in. None are used for analytics, profiling, or advertising, so no consent banner is required.
ow_sid — your signed-in session. Issued on the host you signed in on, and
sent as __Host-ow_sid over HTTPS.ow_uid — identifies the signed-in user to the consent screen.ow_flow — binds a pending authorization request to your browser, so a request
started in one browser cannot be completed in another.ow_mfa — carries a two-step verification challenge between the sign-in
screens, so the token is never placed in a URL.
All four are HttpOnly and are cleared when you sign out. Clearing them ends your
session; nothing else on the site depends on them.
Token and credential lifetimes are set by the platform and are short by design:
Record retention:
We use the following sub-processors to deliver the Service:
We give notice before adding or replacing a sub-processor, as set out in the DPA. Note that identity providers a customer connects (for example, an enterprise directory or a social login provider) are the customer's own integrations, not our sub-processors.
Requests are handled at Cloudflare edge locations worldwide, so processing may occur in any
country where Cloudflare operates a data centre. The primary database is hosted in the United
States (AWS us-west-2); encrypted backups are stored in Cloudflare R2. Where
personal data is transferred out of the EEA, the UK, or Switzerland, we rely on [TRANSFER
MECHANISM — e.g. Standard Contractual Clauses] together with supplementary measures. Details are
in the DPA.
Signing uses EdDSA / Ed25519 throughout. Per-tenant private keys are AES-GCM envelope-encrypted at rest. Access tokens can be sender-constrained (DPoP), refresh-token reuse is detected and triggers revocation, and administrative actions are written to an append-only audit log. Verification runs on WebCrypto. Our full posture is published at Security.
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to it. If your data reached us through a customer's tenant, contact that organization — they are the controller and we will support them in responding. For data we control, write to privacy@oauth.work. You also have the right to complain to your supervisory authority.
OAUTH.WORK. Privacy enquiries: privacy@oauth.work. Legal: legal@oauth.work. Security disclosure: security@oauth.work. [EU/UK REPRESENTATIVE, if required.] [DATA PROTECTION OFFICER, if appointed.]
We will post updates here and, for material changes, notify account administrators by email at least [30] days in advance.