Skip to main content

Privacy and Data Protection

Controlio is a security assessment product and, by design, works with the least personal data possible. This page explains the principles we follow while processing your data. Contractual commitments are set out in the Data Processing Agreement (DPA).

Data minimization

Processing is designed to be connected to the purpose, limited and proportionate. We keep what we collect to what the monitoring purpose requires: full user and mail lists are not stored, phone numbers and mail addresses in VIP identity records are stored masked, and full configuration copies are never carried in a response body.

Full user or email lists are not stored in bulk; counts are kept, not lists. Only the identity needed to explain a specific security finding may be kept.

This approach aligns with:

  • KVKK — personal data being connected to the purpose for which it is processed, limited and proportionate.
  • GDPR Article 5 — data minimisation.
  • GDPR Article 25 — data protection by design and by default.
  • EDPB guidance — need-to-know and restricting access by default.

Access is limited by role

Identity data on the monitoring surfaces is shown in full to the tenant's own administrators — Global Administrator, Security Administrator, Global Reader and Security Reader. A security record exists to show who did what, and for that audience identity is already accessible information. The boundary is not masking of the data but who can reach it: the role check runs on the API that produces the response, and each tenant sees only its own records (see Security Activity).

Tenant isolation

Each customer's data is resolved by its own immutable tenant id. One tenant's data is never returned to another tenant; queries are scoped by the tenant id from the verified session, not one supplied by the client.

Two different processes: data-subject request and incident evidence access

These are not the same process and must not be conflated:

  • A data subject's data access request is handled in a separate privacy / data-subject-request (DSR) process.
  • The security team seeing evidence during an incident investigation is a separate access whose purpose and legal basis are determined by the customer (the data controller).

Roles

Controlio acts as a data processor on behalf of its customer; the customer is the data controller. This role distinction is defined in the Data Processing Agreement (DPA) and your contract.