Privacy Policy
Last updated
Last updated
This Privacy Policy describes how Oten ("we," "us," or "our") collects, uses, discloses, and protects information in connection with our Key Management Service ("Oten KMS" or the "Service"). This policy applies to all users of our Oten KMS platform, including administrators, developers, and end-users.
We are committed to protecting your privacy and ensuring the security of all data processed through our Service.
Organization name and contact details
Administrator names and email addresses
Billing information (processed by third-party payment providers)
Authentication credentials (hashed credentials, public keys, or identity tokens; passwords are never stored in plaintext)
API call logs and timestamps
Key creation, rotation, and management activities
Authentication events and access logs
Error logs and diagnostic information
Important: Our Oten KMS is designed with zero-knowledge principles for customer-managed cryptographic material (CMKs), including plaintext keys and encrypted customer content.
We do not sell, rent, or trade your personal information or cryptographic data to third parties.
We may share information only in the following circumstances:
Service Providers: With trusted third-party vendors who assist in operating our Service, subject to confidentiality agreements.
Legal Requirements: When required by law, court order, or governmental authority.
Security Incidents: To investigate, prevent, or take action regarding potential security breaches or fraud.
Business Transfers: In connection with a merger, acquisition, or sale of assets, with appropriate confidentiality protections.
With Your Consent: When you explicitly authorize sharing with specific parties.
We implement industry-leading security measures including:
We maintain a comprehensive incident response plan and will notify affected users promptly in case of any security breach that may impact their data.
Backup copies are retained for disaster recovery purposes and are subject to the same security controls as primary data.
You have the right to:
You may:
You can:
You may opt out of:
For international transfers, we implement:
Our Service is designed with security and privacy principles aligned to widely recognized regulatory and compliance frameworks. While formal certifications or contractual arrangements may not yet be in place, Oten KMS is architected to support customer compliance efforts, including:
We adhere to:
When using Google Workspace Client-side Encryption integration:
Third-party integrations are subject to their respective privacy policies. We recommend reviewing those policies before enabling integrations.
Our Service is not intended for use by individuals under 18 years of age. We do not knowingly collect information from children.
We may update this Privacy Policy periodically. We will notify you of material changes by:
Continued use of the Service after changes constitutes acceptance of the updated policy.
For privacy-related inquiries, please contact: support@oten.live
Contact us for information about rights specific to your jurisdiction.
Key identifiers (Key IDs)
Key configurations and policies
Key version information
Access control settings and conditions
Cryptographic metadata does not include key material, key derivation secrets, or plaintext cryptographic parameters.
Google Workspace CSE configuration data
Google Drive integration metadata
Third-party service connection details
TEE (Trusted Execution Environment) attestation data is used solely to verify trusted execution environments and is not used for profiling or tracking users.
IP addresses
Device identifiers
Browser type and version
Operating system information
We do NOT have access to your plaintext encryption keys
We do NOT store or access data encrypted using your Customer Managed Keys (CMKs)
We do NOT retain the content of wrap/unwrap operations
We do NOT access files stored in your Google Drive or other integrated services
Authenticate users and manage access controls
Process key management operations
Maintain and improve Service performance
Provide customer support
Detect and prevent fraudulent or unauthorized activities
Monitor for security threats and vulnerabilities
Comply with legal obligations and regulatory requirements
Generate audit logs for compliance purposes
Analyze usage patterns to improve Service features
Identify and fix technical issues
Develop new features and capabilities
Send Service-related notifications
Provide security alerts and updates
Respond to inquiries and support requests
End-to-end encryption for data in transit (TLS 1.3)
AES-256 encryption for data at rest
Hardware Security Modules (HSM) for key storage
TEE (Trusted Execution Environment) integration
Multi-factor authentication support
Regular security audits and penetration testing
SOC 2 readiness and controls aligned with SOC 2 Trust Services Criteria
Role-based access control (RBAC)
Principle of least privilege
Regular access reviews and audits
Automated session management
Account information: Retained while account is active
Cryptographic keys: Retained according to your key lifecycle policies
Audit logs: Retained for the minimum period required to meet legal, security, and compliance obligations.
Upon account termination, we will securely delete your data within 30 days
Cryptographic keys are securely destroyed using industry-standard methods
Some data may be retained longer if required by law
Access your account information
Export your key metadata and configurations
Obtain copies of audit logs
Update your account information
Request correction of inaccurate data
Request deletion of your account and associated data
Configure key lifecycle policies
Set access conditions and restrictions
Manage integration permissions
Marketing communications
Non-essential data collection
Certain analytics features
Opt-out does not apply to data required for security, compliance, fraud prevention, or core Service operations.
Primary data centers are located in regions selected by Oten, including Asia-Pacific and North America.
Standard Contractual Clauses (SCCs)
Appropriate security measures
Compliance with applicable data protection laws
GDPR (General Data Protection Regulation)
CCPA (California Consumer Privacy Act)
HIPAA (support planned; requires execution of a Business Associate Agreement)
SOC 2 (controls designed to align with Trust Services Criteria)
ISO 27001 (controls aligned; certification planned)
NIST Cybersecurity Framework
OWASP Security Guidelines
Industry best practices for key management
We provide key management and cryptographic authorization services used by Google Workspace Client-Side Encryption.
Google's privacy policy applies to data within Google services
We only access encryption key metadata, not encrypted content
We facilitate key management for encrypted files
File content remains encrypted and inaccessible to us
Access is governed by your configured policies
Posting the updated policy on our website
Sending email notifications to account administrators
Displaying in-app notifications
Legal basis for processing: Contract performance, legitimate interests, legal obligations
Data Protection Authority: You may lodge complaints with your local supervisory authority
Categories of personal information collected: Identifiers, commercial information, internet activity
No sale of personal information
Right to know, delete, and opt-out