Data Protection Policy

Zielgruppe: DPOs · Legal · Compliance Status: Aktiv

Version: 1.0 Last Updated: September 2026 Contact: privacy@nova-iam.com


1. Overview

Nova IAM processes identity and access management data on behalf of its customers. This document describes what data is collected, how it is processed, stored, and protected, and the rights of data subjects.

2. Data Categories

2.1 User Identity Data

Field Purpose Sensitivity
Name User identification Personal
Email Authentication, notifications Personal
Department Organizational mapping Internal
Title Role context Internal
Phone Contact information Personal
Location Organizational mapping Internal
Manager Reporting structure Internal

2.2 Access & Authorization Data

Field Purpose Sensitivity
Role assignments Access control Security-critical
Business role memberships Composite access control Security-critical
System accounts Backend system linkage Security-critical
Validity dates Time-bound access Security-critical
Assignment provenance Audit and compliance Internal

2.3 Authentication Data

Field Purpose Sensitivity
Password hash Authentication Highly sensitive
Session tokens Active session tracking Highly sensitive
Login timestamps Security monitoring Internal
Client IP addresses Audit trail Personal

2.4 Audit Data

Field Purpose Sensitivity
Event logs Compliance, forensics Security-critical
Actor identity Accountability Personal
IP addresses Security investigation Personal
Change details Change tracking Internal

3. Data Processing Principles

3.1 Purpose Limitation

  • User data is processed exclusively for identity and access management
  • Audit data is processed for security monitoring, compliance, and incident investigation
  • No data is used for advertising, profiling, or purposes unrelated to IAM

3.2 Data Minimization

  • Only data necessary for IAM operations is collected
  • Password hashes are one-way (irreversible) — original passwords cannot be recovered
  • Session data is destroyed on logout

3.3 Storage Limitation

  • Active user data is retained for the duration of the customer relationship
  • Audit log retention is managed at database level by the customer
  • Deleted users are moved to a recycle bin and purged from it manually or automatically after a configurable period (default 90 days)
  • Audit log entries keep actor and target names as written at the time of the event; anonymisation of historical audit entries is not yet supported

4. Data Storage & Location

4.1 Self-Hosted Deployments

  • All data resides on customer-controlled infrastructure
  • No data is transmitted to Nova IAM or third parties, unless the optional cloud AI mode is used (see 5.2)
  • Customer maintains full sovereignty over data location and jurisdiction

4.2 Database Security

  • PostgreSQL with parameterized queries (SQL injection prevention)
  • Foreign key constraints enforce data integrity
  • Audit log entries are not linked by foreign key and are not removed when a user is deleted

5. Third-Party Data Sharing

5.1 Backend System Integration

Nova IAM connects to customer-configured backend systems for provisioning:

  • SAP — User and role provisioning via RFC
  • LDAP — Directory group management
  • Microsoft Entra ID — Cloud identity group management

Data shared with these systems is limited to:

  • User account identifiers
  • Role/group assignments
  • Validity dates

5.2 AI Features (Optional)

When AI features are enabled:

  • Local AI (Ollama): Data is processed entirely on-premises, no external transmission
  • Cloud AI: User access data may be sent to the configured AI provider (Anthropic or OpenAI) for analysis. This is opt-in and disabled by default
  • Health check: The AI analysis in the health check has its own server-side setting. In cloud mode, finding texts (including names and account IDs) are sent to the configured provider

6. Data Subject Rights (GDPR)

Nova IAM supports the following data subject rights:

Right Implementation
Access Full user profile and assignment data available via API
Rectification User data editable through the application
Erasure Users can be deleted; deleted users are purged from the recycle bin manually or automatically after a configurable period (default 90 days). Audit log entries keep actor and target names as written at the time of the event; anonymisation of historical audit entries is not yet supported
Portability User data exportable via API in JSON format
Restriction User accounts can be deactivated (status: inactive)
Objection to AI AI features are off by default (modes: off, local, cloud). Excluding individual users from AI analysis is not supported

7. Data Breach Notification

In the event of a data breach:

  1. Affected customers are notified within 72 hours of discovery
  2. Notification includes: nature of breach, data affected, measures taken, contact information
  3. Supervisory authorities are notified as required by applicable law

See the Incident Response Plan for detailed procedures.

8. Data Processing Agreement

Where Nova IAM processes personal data on behalf of a customer (for example in a hosted variant), a Data Processing Agreement (DPA) under Art. 28 GDPR is concluded. It covers:

  • Processing scope and instructions
  • Sub-processor management
  • Security measures
  • Audit rights
  • Data return and deletion procedures
Fragen zu diesem Dokument? Schreiben Sie an trust@nova-iam.com – wir bestätigen den Eingang innerhalb von 2 Werktagen.