Skip to main content

Privacy and Data Protection

Controlio is a security assessment product and, by design, works with the least personal data possible. This page explains the principles we follow while monitoring. It is not a compliance certification or a statement of full compliance; specific legal assessments are settled with your legal counsel and contract structure.

Data minimization and masking by default

On our monitoring surfaces, identity data is masked by default (for example o***@company.com). Processing is designed to be connected to the purpose, limited and proportionate. Default access shows only as much data as needed (need-to-know).

Full user or email lists are not stored in bulk; counts are kept, not lists. Only the identity needed to explain a specific security finding may be kept.

This approach aligns with:

  • KVKK — personal data being connected to the purpose for which it is processed, limited and proportionate.
  • GDPR Article 5 — data minimisation.
  • GDPR Article 25 — data protection by design and by default.
  • EDPB guidance — need-to-know and restricting access by default.

Administrator access is not full visibility

An administrator being able to access the product does not mean they need to see all personal data continuously. Including active Global Administrator and Security Administrator roles, the standard view shows masked values. Access to full identity depends on a separately designed evidence-access flow that runs short-lived and with a justification (see Security Activity).

Tenant isolation

Each customer's data is resolved by its own immutable tenant id. One tenant's data is never returned to another tenant; queries are scoped by the tenant id from the verified session, not one supplied by the client.

Two different processes: data-subject request and incident evidence access

These are not the same process and must not be conflated:

  • A data subject's data access request is handled in a separate privacy / data-subject-request (DSR) process.
  • The security team seeing evidence during an incident investigation is a separate access whose purpose and legal basis are determined by the customer (the data controller).

Roles

Whether Controlio acts as a data processor or a data controller depends on the scenario and is defined by the existing Data Processing Agreement (DPA) and your contract. The exact wording of this role distinction is subject to legal-counsel approval.