How Sixfold OS collects, uses, and protects personal data, structured to Articles 13 and 14 of the EU General Data Protection Regulation (Regulation (EU) 2016/679).
Last updated: 4 July 2026
This document is a template provided for information only. It is not legal advice and not a certification. Any remaining placeholders in square brackets must be completed, and the whole text reviewed by qualified counsel, before it is relied upon.
The controller responsible for the processing of personal data on this website and across the Sixfold OS ecosystem, within the meaning of Article 4(7) GDPR, is:
Data protection officer (where a DPO has been appointed under Article 37 GDPR): [DPO contact]. Questions about this policy or your rights can be sent to admin@sixfoldux.com.
Depending on how you interact with Sixfold OS, we process the following categories of personal data:
Name, email address, and the identity attributes returned by our authentication provider (see Section 4). Sixfold OS mirrors only the minimal identity claims needed to establish a session and does not store passwords.
Role assignments and access scopes (for example workspace and module scopes) used to enforce role-based access control and tenant/workspace boundaries.
Server logs, IP address, device/browser metadata, and timestamps generated when you access the site or a module, used for security, diagnostics, and audit records.
Information you or your organization enter into a module workspace. This data is isolated per tenant, per workspace, and per module namespace.
Messages, support requests, and contact-form submissions you send to us, including the contents and the metadata of that correspondence.
Where personal data is obtained from a source other than you (Article 14 GDPR) — for example identity attributes relayed by your organization's identity provider — the categories above still apply and the source is your organization or its chosen identity provider.
We process personal data for the following purposes and on the following legal bases under Article 6(1) GDPR:
Authenticating you, provisioning access, and operating the module workspaces you or your organization use, on the basis of the contract or pre-contractual measures.
Maintaining audit records, security event logging, and access controls, on the basis of our legitimate interest in operating a secure and accountable platform.
Retaining records and responding to lawful requests where required by applicable law.
Responding to enquiries and providing support, on the basis of the contract or our legitimate interest in assisting users.
Any optional processing (for example non-essential analytics or marketing) is carried out only with your consent, which you may withdraw at any time.
Authentication is delegated to Auth0 (Okta, Inc.), which acts as a processor under Article 28 GDPR on the basis of a data processing agreement. Auth0 handles login, session issuance, and single sign-on; Sixfold OS receives only the minimal identity claims needed for a session.
Further processors and recipients may include:
We do not sell personal data. Data is shared with processors only under contract and only to the extent necessary to provide the service. A current list of sub-processors is maintained on the Security & Trust page.
Where personal data is transferred to a country outside the European Economic Area, we rely on an appropriate safeguard under Chapter V GDPR — typically an adequacy decision or the European Commission's Standard Contractual Clauses, supplemented by additional technical and organizational measures where required.
Our authentication provider is configured in the European region (Auth0 EU tenant). Specific transfer mechanisms for each sub-processor are documented on request at admin@sixfoldux.com.
Personal data is retained only as long as necessary for the purposes for which it was collected, or as required by applicable law:
Subject to the conditions in the GDPR, you have the right to:
To exercise any of these rights, contact admin@sixfoldux.com. You also have the right to lodge a complaint with a supervisory authority (Art. 77). The competent authority is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Vienna.
Where Sixfold OS acts as a processor for your organization (for example over content you enter into a workspace), please direct data-subject requests to your organization as the controller; we will support them under our processing agreement.
Sixfold OS does not make decisions producing legal or similarly significant effects about you based solely on automated processing within the meaning of Article 22 GDPR. Where a module surfaces automated suggestions, these are informational outputs subject to human review — not legal advice or certification.