We have a high resolution version you can download on our press kit page.
Read the latest about our MFA app and other updates from our Product Team
See how simple it is to manage secure access for all users.
Learn more about five obstacles to employee productivity
Contact your Partner Manager >
Featured Customer Story Lincoln Investment >
Got the Free Trial?Follow these steps to add apps, add users, and evaluate OneLogin.
Last modified May 15, 2018
You may contact us under OneLogin Inc., 848 Battery Street, San Francisco, CA 94111.
Our EU representative is: OneLogin Ltd, 2 Sheraton Street, W1F 8BH London.
You may contact our Data Protection Officer at firstname.lastname@example.org.
Information you provide: When a Subscriber registers for the Service, we require a first and last name, company name, email, and phone number. After the initial registration, the Subscriber’s designated Client Administrator can share additional end user information with OneLogin in order to enable those end users to use the Service; however, OneLogin never directly collects any end user information, personal or otherwise, without the explicit direction of the Client Administrator. Subscribers are responsible for providing notice to end users concerning the information they collect and share with OneLogin as part of their use of the Service.
If you do not provide the listed personal data to us, we may not be able to provide you with certain features of our Web site.
OneLogin uses the personal data including your use of the Service to operate and make the Service available to you, for billing, identification and authentication, to contact you about your use of the Service, research purposes, and to generally improve the content, functionality, and security of the Web site and the Service. OneLogin will also use the collected personal information to send you periodic newsletters to inform you about OneLogin and our services.
The processing is based on our legitimate interests (Art. 6 (1)(f) of the GDPR).
We may use personal data provided as testimonials, which is always based on consent (Art. 6(1)(a) of the GDPR).
We do not use automated decision-making, including profiling.
OneLogin uses a third party intermediary to perform credit card processing when registering for the paid Subscription plans of the Service. This intermediary is not permitted to store, retain, or use your billing information except for the sole purpose of credit card processing on OneLogin’s behalf.
OneLogin may also transmit personal data to its third party vendors and the hosting partners that provide the necessary hardware, software, networking, storage, and other technology and maintenance services required to operate and maintain the Web site and the Service. Transfers to subsequent third parties are covered by the provisions in this Policy regarding notice and choice and the service agreements with our Clients. This may require that your personal data be transferred from your current location to the offices and servers of OneLogin and these authorized third parties.
We share personal data with the following categories of recipients:
For a list of our current subprocessors, follow this link: https://www.onelogin.com/data-subscribe.
We intend to transfer personal data to the following third countries:
You may get a copy of the respective safeguards by requesting these from email@example.com.
Except as described in this Policy, OneLogin will not give, sell, rent, share or loan any personal information to any third party other than as outlined in this Policy.
OneLogin maintains reasonable security measures to protect your information from loss, destruction, misuse, unauthorized access or disclosure. These technologies help ensure that your data is safe, secure, and only available to you and to those you provided authorized access. When you enter sensitive information (such as your login information) on our Web site or connect to our Service, we encrypt the transmission of that information using Transport Layer Security (TLS). If you have any questions about security on our Web site, you can contact us at firstname.lastname@example.org.
We use session “cookies” to allow the Web site or Service to uniquely identify your browser while you are logged in and to enable OneLogin to process your online transactions. We do not link the information we store in cookies to personal data you submit while using the Web site other than the email address you provide. Session cookies also help us verify your identity and are required in order to use the Service. OneLogin uses persistent cookies, that only OneLogin can read and use, to identify you as a valid user of a OneLogin Subscription plan and make it easier for you to log in to the Service. Analytical cookies and similar technologies are also used to allow OneLogin to recognize how visitors move around the Web site and the Service when they’re using it. We use this information, which is aggregated and does not uniquely identify end users, to analyze trends, to troubleshoot the Web site and Service, to track end users’ movements while on the site and to gather demographic information about our user base as a whole. This helps us improve the overall user experience.
We use the following cookies on our Web site:
You may set your browser to block all cookies, including cookies associated with our Service. Users who disable their browsers’ ability to accept cookies will be able to browse our Web site, but will not be able to access or take advantage of the Service.
You can also opt out of our newsletters and surveys and you may follow the unsubscribe/opt out instructions contained in each of those communications.
We retain your personal data as long as it is necessary for the purposes stated above, if not stated otherwise in this Policy. We might process your personal data longer than stated above if it is necessary because of legal requirements or decisions made by authorities.
If you would like to exercise any of your rights, or receive more information about them, please contact us via the contact details at the bottom of this Policy and we will help you out. Please note that some of the following rights may not be applicable to your situation:
Right of access: You have the right to gain access to information about the personal data that we process about you. Should you have any questions regarding the processing or want more insight into the personal data we process from you, you are always welcome to contact us and we will provide you with further information.
Right to rectification: You can request us to correct information inaccurately stored by us without undue delay. You also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Right to erasure/right to be forgotten: You have the right to request of us to permanently delete your personal information. You can make such a request if you for example believe that the personal data are no longer necessary in relation to the purpose for which the personal data were collected or otherwise processed.
Right to restrict the processing activities: You have the right to restrict our processing activities. If you choose to restrict our processing activities regarding certain personal data, note that you may not be able to use our Web site properly.
If you are unsatisfied with the way we treat your personal data, you may reach out to us at all times to solve the issue. However, you always have the right to lodge a complaint to a supervisory authority.
OneLogin participates in and has certified its compliance with both the EU-U.S. Privacy Shield Framework and the Swiss-US Privacy Shield Framework (collectively, the “Frameworks”). We are committed to subjecting all personal data received from European Union (EU) member countries and Switzerland, in reliance on the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework, respectively, to the Frameworks’ applicable Principles. To learn more about the Privacy Shield program, and view our certifications, visit the U.S. Department of Commerce’s Privacy Shield List, https://www.privacyshield.gov/list.
Under the Frameworks, OneLogin is responsible for the processing of personal data it receives and subsequently transfers to a third party acting as an agent on its behalf. We comply with the Privacy Shield Principles for all onward transfers of personal data from the EU and Switzerland, including the onward transfer liability provisions.
With respect to personal data received or transferred pursuant to the Frameworks, OneLogin is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, we may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Under certain conditions, more fully described on the Privacy Shield Web site, https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
If you have any questions regarding this Policy you may contact us at email@example.com or via postal mail at:
100 California Street
San Francisco, CA 94111