v1.0.0 - Oten Identity - Privacy Policy
When you use our identity services, you trust us with your personal information. We recognize that this is a significant responsibility. Our priority is to protect your data with the highest standards of security and transparency, while giving you full control over your identity.
This Privacy Policy is designed to help you clearly understand:
What information we collect;
Why we collect it;
How we use and protect it;
How you can access, manage, export, or delete your information at any time.
Your trust matters to us. We are committed to building a secure, privacy-first identity platform that empowers individuals and organizations.
Effective October 28, 2025
1. INTRODUCTION
1.1 Introduction
This Privacy Policy explains how Oten Technologies LLC (“Oten”, “we”, “our”, or “us”) collects, uses, stores, shares, and protects personal data when individuals and organizations access or interact with our cloud-based identity and access management platform (“Oten IDP”). By using our Services, you acknowledge that you have read, understood, and agreed to this Policy.
1.2 Nature of the Service
Oten IDP operates as a cloud-based Identity-as-a-Service (IDaaS) platform. It serves as a primary identity provider, where all user accounts—whether created by individuals or organizational administrators—are registered and managed directly on Oten IDP. Third-party applications do not directly provision user identities into Oten. Instead, when users choose to authenticate to external applications using the “Sign in with Oten” option, they are redirected to Oten IDP to register or sign in, and their identity is created or confirmed under Oten’s control.
Oten IDP enables secure authentication, single sign-on (SSO), identity verification, role-based access control, and multi-factor authentication (MFA) using methods such as Passkey (WebAuthn/FIDO2), OTP, or device-based authentication. It is designed to support both individual users and enterprise organizations across Southeast Asia, with current service availability in the United Arab Emirates (UAE) and Vietnam.
1.3 Services Covered Under This Policy
This Privacy Policy applies to identity-related services provided by Oten IDP, including but not limited to:
Account registration and identity management;
Authentication, Single Sign-On (SSO), and token issuance;
Multi-Factor Authentication (MFA) via Passkey, WebAuthn, OTP;
Role, authorization, and access policy management;
Activity logs, session tracking, and security monitoring;
API and SDK-based authentication services for integrated applications.
Note: The Oten Open Platform, which allows developers to register applications, declare permission scopes, and publish integrations, operates as a separate product with its own Terms of Service and Privacy Policy. This Privacy Policy applies only to Oten IDP.
1.4 Categories of Users Covered
This Policy applies to all users interacting with Oten IDP, including:
Individual users creating accounts directly on Oten for personal or developer use;
Enterprise users, including Organization Administrators and Workspace Administrators, who manage access for business environments;
End-users of third-party applications who choose to authenticate via Oten using SSO;
Developers who integrate their applications with Oten IDP through OAuth, OIDC, or other supported protocols (authentication operations only; app registration is handled via Oten Open Platform).
1.5 Identity Ownership and Consent Principle
Oten is the primary provider of identities created within Oten IDP. All authentication flows involving third-party applications begin with a user-initiated action. When users authenticate to external applications, Oten presents a Consent Screen, clearly listing the data that will be shared. Data is shared only with the user’s explicit permission.
Controller/Processor roles. Oten acts as the Data Controller for identities created directly by users or enterprise administrators within Oten IDP. In scenarios where an enterprise customer manages its own user directory and instructs Oten to process identity data for that tenant, Oten acts as a Data Processor under the customer’s instructions.
Users may choose to remember their consent for future logins and can revoke or manage consents at any time through their Oten account settings.
1.6 Geographic Scope of Service
At this stage, Oten IDP is available to users and organizations located in:
United Arab Emirates (UAE)
Vietnam
Future expansion to other jurisdictions may occur, at which time this Policy will be updated.
1.7 Oten’s Role in Data Protection
Depending on the context:
Oten acts as a Data Controller when users create accounts directly on the Oten platform;
Oten acts as a Data Processor when issuing identity tokens or sharing user data with third-party applications upon user consent, or when processing under enterprise customer instructions.
1.8 Legal Compliance
We are committed to complying with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and Vietnam Decree No. 13/2023/ND-CP on Personal Data Protection.
1.9 Acceptance of Policy
By accessing or using Oten IDP, you agree that your personal data will be collected and processed in accordance with this Policy. If you do not agree with any provisions, you should discontinue the use of Oten IDP.
2. INFORMATION WE COLLECT
2.1 Overview
We collect only the information necessary to create and maintain a secure digital identity, perform authentication, protect our services, and enable access management for individuals and organizations. Collection and processing occur under appropriate legal bases (consent, performance of contract, legitimate interests, or legal obligation) and in line with our transparency and data-minimization principles.
2.2 Categories of Personal Data We Collect
2.2.1 Account Registration Information
When you create an Oten account (individual or enterprise), we collect information you provide directly, such as:
Full name;
Email address and/or mobile phone number;
Username or display name;
Password (stored as a salted, hashed value; never in plain text);
Optional profile information (e.g., avatar, preferred language, time zone).
For enterprise workspaces, we may also collect the organization name, business contact details, and information necessary to configure a workspace and designate administrators.
2.2.2 Authentication and Security Data
When you sign in or enable advanced security features, we process:
Public keys and cryptographic material produced during Passkey/WebAuthn registration and use;
Multi-factor authentication artifacts (e.g., OTP codes, authenticator app secrets, device trust status);
OAuth 2.0 / OpenID Connect artifacts, including authorization codes, access tokens and ID tokens (JWT), and refresh tokens (signed with RS256 or ES256);
Session identifiers, authorization scopes, nonce and state values, and anti-abuse signals.
Biometric handling. We do not collect, access, or store raw biometric data (e.g., fingerprint images, facial images, voiceprints). If you choose biometric sign-in, biometric capture and matching occur locally on your device or through Oten Pass, a separate product in the Oten ecosystem that supports FIDO2/WebAuthn platform authenticators. Oten IDP receives only non-reversible cryptographic proofs (e.g., public keys or signed assertions) and never receives raw biometric templates.
2.2.3 Device and Technical Data
To secure our platform, prevent fraud, and improve reliability, we automatically collect:
Device type, operating system, and browser version;
IP address and approximate geolocation derived from IP (we do not collect GPS-level location);
Timestamps, session duration, error codes, and failed/successful login indicators;
Limited identifiers used for threat detection and rate limiting.
2.2.4 Log and Activity Data
For security, troubleshooting, and compliance, we maintain encrypted logs of:
Authentication attempts and outcomes;
Session creation and termination;
Token issuance, revocation, and API calls;
Administrator actions (e.g., role assignments, policy changes);
Alerts related to anomalies or suspected abuse.
Unless a longer period is required by law, logs are retained based on the retention period configured by the user or organization.
2.2.5 Consent and Authorization Data
When you use “Sign in with Oten” to access a third-party application, we record:
The application you authorized and the scopes requested;
The specific attributes you agreed to share (e.g., name, email, basic profile);
The timestamp of consent and whether you chose to “remember” the consent;
Any subsequent revocation events. We share only the attributes you approve on the consent screen.
2.3 Data Flows for Third-Party Application Sign-In
When you choose “Sign in with Oten” on a third-party application, you are redirected to Oten to authenticate or create your account. If this is your first time, your Oten account is created instantly by you during that process through Just-in-Time (JIT) provisioning. After you successfully sign in and provide consent, Oten returns you to the application and issues tokens that include only the attributes you have approved for sharing.
Third-party applications may request optional attributes to enhance your experience (such as customer tier or personalization data). You may choose whether to share these attributes during the consent step, and you can revoke any previously granted permissions at any time in your Oten account.
2.4 Enterprise and Administrator Data
For organizations using Oten IDP, we collect information required to operate enterprise features, including:
Organization and workspace configuration (tenant name, domains, SSO settings);
Administrator identities, roles, and actions taken in the admin console;
Membership lists and role assignments performed within Oten;
Billing contact details and subscription tier (for paid plans).
Enterprise administrators are responsible for ensuring they have appropriate authorization to enroll users into their workspace and assign roles.
2.5 Developers and Application Metadata
Developers register applications and declare permission scopes on Oten Open Platform, a separate product with its own Terms and Privacy Policy. Oten IDP consumes application metadata (e.g., client identifiers, declared scopes) to execute authentication and authorization flows but does not directly collect developer registration data within IDP. Tokens issued by Oten IDP reflect permissions assigned within Oten and approved by the user; we do not ingest roles or permissions from third-party applications.
2.6 Data We Do Not Collect
To reduce risk and respect user privacy, we do not collect or store:
Raw biometric templates (fingerprint, facial images, voiceprints) or KYC documents;
National ID numbers or passport scans;
Personal communications (emails, messages, documents) unrelated to identity operations;
Financial transaction histories unrelated to billing for Oten services;
Behavioral tracking data for advertising or user profiling purposes.
We also do not create shadow profiles. Data about you comes from your direct interactions with Oten and, when you authorize it, from your consented sharing to relying applications via standard OAuth/OIDC flows.
2.7 Legal Bases for Processing
Depending on the context, we process personal data under one or more of the following legal bases:
Consent – for sharing identity attributes with third-party applications via the consent screen;
Performance of Contract – to provide authentication, SSO, account management, and related services you request;
Legitimate Interests – to secure our platform, prevent fraud, ensure service reliability, and improve the user experience;
Legal Obligation – to comply with applicable data protection and security laws in jurisdictions where we operate (currently UAE and Vietnam).
2.8 Retention and Deletion
We retain personal data only for as long as necessary to provide the services, meet security and Activity needs, and comply with legal obligations. By default:
Authentication and security logs are retained based on the retention period configured by the user or organization;
Account profile data persists while your account remains active and is deleted or anonymized upon verified deletion requests, subject to legal holds or backup constraints;
Remembered consents persist until you revoke them in your account settings.
When you delete data, we follow a controlled deletion process. Some artifacts may remain in backups for a limited period before being overwritten, after which they are irreversibly removed.
2.9 Data Minimization and Optional Information
Providing optional profile fields (e.g., avatar, preferred language, time zone) is voluntary and not required to use core authentication features. You may update or remove optional data at any time. We do not condition service access on the provision of optional personal information.
2.10 Geographic Scope and Data Residency Oten IDP currently serves users and organizations in limited geographic markets. Personal data may be stored or processed in cloud data centers located in various regions, depending on the infrastructure providers we use. We do not currently offer customer-selectable data residency. Any transfer of data across borders is conducted in compliance with applicable data protection regulations and is subject to appropriate safeguards to ensure the security and confidentiality of the data.
2.11 Children’s Data
Our services are not intended for individuals under the age specified by applicable law (typically 16). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can take appropriate action.
2.12 Changes to This Chapter
We may update this Chapter to reflect service changes, new regulatory guidance, or security improvements. We will indicate the effective date and, where changes are material, provide a more prominent notice.
3. HOW WE USE PERSONAL DATA
3.1 Purpose of Data Processing
We process personal data solely to provide, secure, and improve Oten IDP. Our uses align with applicable legal bases (consent, performance of contract, legitimate interests, or legal obligation) and follow the principles of transparency, purpose limitation, and data minimization.
3.2 Identity Verification and Account Management
We use account information to:
Create and maintain your Oten IDP account;
Authenticate you to Oten and to third-party applications at your direction;
Manage profile settings, preferences, and remembered consents;
Provide customer support and communicate about service changes, security notices, or feature updates.
3.3 Authentication, MFA, and Single Sign-On
We process authentication and security data to:
Verify credentials and cryptographic assertions (e.g., Passkey/WebAuthn);
Issue and validate OAuth/OIDC tokens (including JWT access and refresh tokens);
Enforce Single Sign-On (SSO), session continuity, and logout;
Support multi-factor authentication (e.g., OTP, authenticator apps, device-based prompts). Where you authenticate to a third-party application using “Sign in with Oten,” we share only the attributes you approve on the Consent Screen.
3.4 Security, Fraud Prevention, and Threat Detection
We use device, log, and technical data to protect accounts and our platform, including:
Detecting suspicious or anomalous sign-in patterns;
Preventing credential stuffing, brute force attempts, and token abuse;
Monitoring service health, abuse rates, and error conditions;
Investigating and remedying incidents. Challenge-based response. If we detect unusual activity, we may require additional verification (step-up MFA) before granting access. We do not automatically lock accounts or make irreversible access decisions without an opportunity for user interaction, except where required by law or to prevent immediate harm.
3.5 Enterprise Administration Features
For organizational tenants, we use data to:
Operate admin consoles and apply role-based access controls;
Record administrative actions (e.g., role assignments, policy changes) for Activityability;
Support billing, subscription, and plan management for paid tiers;
Provide usage summaries to authorized administrators (not for advertising or end-user profiling).
3.6 Aggregated, De-Identified Service Improvement
We analyze aggregated and/or de-identified metrics (e.g., sign-in success rates, MFA adoption, error frequencies) to improve reliability, performance, security, and usability. These analyses do not identify individuals and are not used for advertising, behavioral profiling, or sales to third parties.
3.7 Compliance with Legal Requirements
We may process and preserve data to:
Comply with applicable laws, regulations, and lawful requests;
Enforce our Terms, investigate violations, and protect rights, safety, and property;
Maintain appropriate records for security, Activitying, and dispute resolution. Where disclosure is required, we assess the scope and legality of each request and limit responses to what is necessary.
3.8 No Use for Advertising or Behavioral Profiling
We do not use personal data for targeted advertising, cross-context behavioral advertising, or the creation of marketing profiles about end users. We do not sell personal data.
3.9 Automated Processes and User Control
We employ automated systems to support authentication, token validation, anomaly detection, rate limiting, and abuse prevention. These systems may dynamically prompt for additional verification (e.g., MFA) but do not make automated decisions that produce legal or similarly significant effects on users without an opportunity for user action. Final access outcomes remain subject to user completion of the required challenge and applicable security policies.
4. DATA SHARING AND DISCLOSURE
4.1 General Principle
We only share personal data where it is necessary to provide our services, comply with legal obligations, or where the user has explicitly consented. We do not sell, rent, or use personal data for advertising, behavioral profiling, or commercial monetization unrelated to the identity services provided by Oten IDP.
4.2 Sharing Based on User Consent
When a user chooses to authenticate into a third-party application using Oten IDP:
The user is presented with a Consent Screen clearly identifying the information requested by the application;
We only share the data fields the user has explicitly approved;
The user may revoke consent at any time through their Oten account settings.
This sharing occurs solely for the purpose of enabling authentication and access to the selected application.
4.3 Sharing with Service Providers Acting on Our Behalf
We may engage third-party service providers to host, store, process, or secure data on our behalf. These providers operate under written agreements that:
Prohibit them from using personal data for any purpose other than delivering services to Oten;
Require implementation of appropriate technical and organizational security measures;
Subject them to confidentiality obligations and data protection requirements.
Such providers may include cloud infrastructure, authentication infrastructure, backup, security, or logging services.
4.4 Sharing with Third-Party Applications via Single Sign-On (SSO)
When you use Single Sign-On:
We disclose authentication assertions, access tokens, and permitted user attributes to the application that you have chosen to access;
Only the attributes authorized on the Consent Screen are shared;
Applications do not receive any backend access to your Oten account, nor can they provision or modify user identities within Oten IDP unless explicitly permitted.
4.5 Cross-Border Data Transfers
Personal data may be processed or stored in data centers located in different regions, depending on the cloud infrastructure we use. Where personal data is transferred across borders:
We ensure that such transfers comply with applicable data protection regulations;
We apply appropriate technical, contractual, and organizational safeguards to protect the confidentiality and integrity of the data.
We do not currently offer customer-selectable data residency.
4.6 Legal Compliance and Protection of Rights
We may disclose personal data if we believe it is reasonably necessary to:
Comply with a valid legal obligation or governmental request;
Enforce our Terms of Service or investigate potential violations;
Protect the rights, safety, or property of Oten, our users, or the public;
Detect, prevent, or investigate fraud, abuse, security threats, or technical issues.
Such disclosures are limited to what is legally required and subject to a validation process.
4.7 No Sharing for Advertising or Profiling
We do not:
Sell or rent personal data to third parties;
Share personal data with data brokers or advertising networks;
Use personal data to create marketing or behavioral profiles for targeted advertising.
Any aggregated or anonymized data used for analytics does not identify individual users.
4.8 Scope Limitation – Third-Party Services Outside Oten IDP
Certain commercial, billing, or application publishing functions are provided through Oten Open Platform, which operates as a separate product with its own Terms of Service and Privacy Policy. This Policy applies exclusively to Oten IDP and does not govern personal data processed by the Open Platform or other services within the Oten ecosystem.
5. HOW WE STORE AND SECURE INFORMATION
5.1 Where and how we store information
We store personal data on reputable cloud infrastructure. Depending on the infrastructure we use, data may be processed in multiple regions. We do not currently offer customer-selectable data residency. Regardless of location, we apply consistent privacy and security controls designed to protect your information.
5.2 Safeguards we apply
We implement layered technical and organizational measures to protect personal data, including:
Encryption of data in transit and at rest.
Access controls based on least privilege and role-based permissions.
Network and application safeguards, including segregation of environments and protective monitoring.
Logging and monitoring to help detect suspicious activity and support security investigations.
Vulnerability management and regular security testing appropriate to the risks.
Secure development practices, including change management and peer review.
Employee safeguards, such as confidentiality obligations and security awareness training.
5.3 Protection of credentials and tokens
We do not store passwords in plain text. Authentication artifacts (such as session identifiers and tokens) are protected and validated by our systems. Where passkeys/WebAuthn are used, we rely on public-key proofs and do not receive raw biometric data. Secrets and keys are handled under access controls and security procedures appropriate to their sensitivity.
5.4 Third-party service providers
When we use service providers (for example, cloud hosting or security tooling), they act on our instructions under written agreements that require appropriate confidentiality and security measures and prohibit using personal data for their own purposes.
5.5 Detecting and responding to incidents
We maintain processes to identify, assess, and respond to security incidents. If we determine that an incident affects your personal data, we will notify you and/or the relevant authorities when required by law and will take steps to mitigate harm and prevent recurrence.
5.6 Data retention and deletion
We retain information only as long as necessary for the purposes described in this Policy or as required by law. Specific retention periods (for example, security logs) are described in earlier chapters. When data is deleted, we follow a controlled process; residual copies may persist in backups for a limited time before being overwritten.
5.7 Your role in protecting your account
Security is a shared responsibility. You should use strong, unique credentials, enable multi-factor authentication where available, keep your devices and browsers up to date, review connected apps and remembered consents, and notify us promptly if you suspect unauthorized access.
6. DATA RETENTION
6.1 General Retention Principles
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including providing our Services, maintaining security, complying with legal obligations, resolving disputes, and enforcing our agreements. Once data is no longer needed, it will be securely deleted, anonymized, or removed from active processing systems in accordance with industry standards and applicable laws.
6.2 Specific Retention Periods
User Account Information: Retained for as long as the account is active. If you request account deletion, associated data will be deleted or anonymized, unless legal obligations require longer retention.
Authentication Data (tokens, session information, login artifacts): Retained only for the duration necessary to maintain session integrity and account security. Expired tokens are automatically invalidated and removed.
Security Logs: Retained for the period required under applicable security and regulatory compliance obligations.
Activity Records: Retained based on the retention period configured by the user or organization.
These records are maintained to support fraud detection, security investigations, and compliance requirements.
Billing and Transactional Records (for enterprise customers): Retained in accordance with applicable financial and tax regulations.
Consent Records (related to third-party applications): Retained until you revoke such consent from your Oten account settings.
6.3 Legal and Regulatory Obligations
We may retain certain information beyond standard retention periods where required by applicable law, regulatory authorities, or court orders, or when necessary to protect our legal rights or respond to legal claims.
6.4 Data Deletion and Backup Copies
When data is deleted from our active systems, residual copies may temporarily remain in encrypted backup archives. These backups are retained only for business continuity and disaster recovery purposes and are automatically overwritten after a limited period.
6.5 Your Rights Regarding Data Retention
Depending on your jurisdiction and account type, you may have the right to:
Request deletion of your personal data when it is no longer required for the original purpose.
Obtain confirmation of what data is being retained and the reasons for retention.
Request restriction of processing in certain circumstances as permitted by law.
All such requests are subject to identity verification and applicable legal limitations.
7. HOW YOU CAN ACCESS AND CONTROL YOUR INFORMATION
7.1 User Rights
Depending on your jurisdiction and account type, you may have certain rights regarding your personal data. These include the right to:
Access the personal data we hold about you;
Update or correct inaccurate or incomplete information;
Delete your account or request the deletion of your personal data;
Restrict or object to certain types of processing;
Withdraw previously granted consent;
Manage connected applications and revoke access;
Export or download your personal data in a structured, commonly used format (where technically feasible).
7.2 Accessing and Updating Your Information
You can review and update most information directly through your Oten account dashboard. This includes profile details, authentication methods, security settings, and application consents. Certain enterprise users may need to contact their organization’s administrator to request changes.
7.3 Managing Authentication and Consent
When you use Oten to sign in to third-party applications, you may review and revoke previously granted permissions at any time via your account settings. Revoking consent will prevent the application from further accessing your information but may limit your ability to use its features.
7.4 Account Deletion
You may request permanent deletion of your account at any time. Deleting your account will:
Remove your access to all Oten IDP services;
Invalidate authentication tokens and sessions;
Revoke access to third-party applications authenticated via Oten;
Trigger deletion or anonymization of your personal data, subject to legal retention requirements.
Once processed, this action cannot be undone.
7.5 Administrator and Enterprise Controls
For enterprise environments, certain identity and access configurations are managed by organization or workspace administrators. Oten acts as a processor in such cases, and you should direct requests related to provisioning or access rights to your organization’s administrator.
7.6 Exercising Your Rights
You may exercise your privacy rights by:
Accessing account settings and privacy controls within your dashboard;
Managing authentication preferences and consents;
Submitting a request through our support channels or verified contact methods.
We may request additional information to verify your identity before processing your request. We will respond within the timeframes required by applicable law.
7.7 Limitations
Your requests may be limited in certain cases, such as when:
Disclosure would violate the rights or privacy of another individual;
We are required by law to retain certain data;
The request would interfere with ongoing security or fraud prevention measures.
We are committed to transparency and will inform you if such limitations apply.
8. OUR POLICY TOWARDS CHILDREN
8.1 Eligibility Requirements
Our Services are not intended for, and may not be used by, individuals under the age of legal consent applicable in their jurisdiction (typically 16 years old or older). We do not knowingly collect or process personal data from children under this age.
8.2 No Intentional Collection of Children's Data
If we discover that we have unintentionally collected personal information from a child without appropriate consent or legal basis, we will take immediate steps to delete such data from our systems.
8.3 Parental or Guardian Responsibility
In cases where a user is identified as a minor under applicable laws, access to our Services must be supervised and authorized by a parent or legal guardian. Organizations using Oten IDP for educational or internal identity purposes are responsible for ensuring compliance with child data protection regulations.
8.4 User Responsibility
By using our Services, you confirm that you meet the minimum age requirement or that you are authorized by a parent, guardian, or organization with the appropriate legal basis.
9. REGIONAL DISCLOSURES
This Chapter provides additional privacy information for users in regions with specific legal requirements. These disclosures apply only to users located in the respective jurisdictions and supplement the other sections of this Privacy Policy.
9.1 United Arab Emirates (UAE)
For users located in the UAE, we process personal data in accordance with the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
Your rights under UAE law may include:
The right to be informed about data processing activities;
The right to access and request corrections to your personal data;
The right to request deletion when data is no longer required;
The right to withdraw consent, except where processing is legally required;
The right to object to certain types of processing.
We ensure that any transfer of personal data outside the UAE is conducted with adequate protection measures, in compliance with applicable UAE regulations.
9.2 Vietnam
For users located in Vietnam, we comply with the Decree No. 13/2023/ND-CP on Personal Data Protection (PDPD).
Your rights under Vietnamese law include:
The right to know the purposes and scope of data processing;
The right to access, update, or request deletion of your personal data;
The right to withdraw consent, except where processing is required by law;
The right to restrict or object to processing within the limit of applicable regulations;
The right to request information regarding cross-border data transfers.
Personal data may be processed or transferred internationally only where necessary to provide our Services and in accordance with Vietnamese data protection requirements.
9.4 Exercising Regional Rights
Users in the EU, UAE, or Vietnam may exercise their rights through:
Self-service privacy and account management tools in their Oten account; or
Submitting a request via our designated privacy contact channels.
We may request identity verification to protect your account and ensure legal compliance. We will respond within the timeframes required by applicable law.
10. CHANGES TO THIS POLICY & CONTACT INFORMATION
10.1 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, security practices, or legal requirements. When we make material changes, we will notify you through appropriate channels, such as email notifications, in-product alerts, or updates on our official website. The “Effective Date” at the top of this Policy indicates when it was last revised.
Your continued use of the Services after the updated Policy becomes effective constitutes your acceptance of the revised terms. If you do not agree with any updates, you should discontinue use of the Services and request account deletion.
10.2 How We Will Notify You
Depending on the nature of the change, notification may be provided by:
Posting the updated Policy in our platform or website;
Emailing registered users;
Displaying a notice within the user dashboard prior to the change taking effect.
We encourage you to review this Policy periodically to stay informed about how we protect your information.
10.3 Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, you may contact us using the information below:
Oten Technologies LLC Help Center
Email: support@oten.live
Depending on your jurisdiction, you may also have the right to file a complaint with your local data protection authority. We are committed to working with you to resolve any concerns regarding your privacy.
Last updated