Data Protection Policy
Version: 1.0 Last Updated: September 2026 Contact: privacy@nova-iam.com
1. Overview
Nova IAM processes identity and access management data on behalf of its customers. This document describes what data is collected, how it is processed, stored, and protected, and the rights of data subjects.
2. Data Categories
2.1 User Identity Data
| Field | Purpose | Sensitivity |
|---|---|---|
| Name | User identification | Personal |
| Authentication, notifications | Personal | |
| Department | Organizational mapping | Internal |
| Title | Role context | Internal |
| Phone | Contact information | Personal |
| Location | Organizational mapping | Internal |
| Manager | Reporting structure | Internal |
2.2 Access & Authorization Data
| Field | Purpose | Sensitivity |
|---|---|---|
| Role assignments | Access control | Security-critical |
| Business role memberships | Composite access control | Security-critical |
| System accounts | Backend system linkage | Security-critical |
| Validity dates | Time-bound access | Security-critical |
| Assignment provenance | Audit and compliance | Internal |
2.3 Authentication Data
| Field | Purpose | Sensitivity |
|---|---|---|
| Password hash | Authentication | Highly sensitive |
| Session tokens | Active session tracking | Highly sensitive |
| Login timestamps | Security monitoring | Internal |
| Client IP addresses | Audit trail | Personal |
2.4 Audit Data
| Field | Purpose | Sensitivity |
|---|---|---|
| Event logs | Compliance, forensics | Security-critical |
| Actor identity | Accountability | Personal |
| IP addresses | Security investigation | Personal |
| Change details | Change tracking | Internal |
3. Data Processing Principles
3.1 Purpose Limitation
- User data is processed exclusively for identity and access management
- Audit data is processed for security monitoring, compliance, and incident investigation
- No data is used for advertising, profiling, or purposes unrelated to IAM
3.2 Data Minimization
- Only data necessary for IAM operations is collected
- Password hashes are one-way (irreversible) — original passwords cannot be recovered
- Session data is destroyed on logout
3.3 Storage Limitation
- Active user data is retained for the duration of the customer relationship
- Audit log retention is managed at database level by the customer
- Deleted users are moved to a recycle bin and purged from it manually or automatically after a configurable period (default 90 days)
- Audit log entries keep actor and target names as written at the time of the event; anonymisation of historical audit entries is not yet supported
4. Data Storage & Location
4.1 Self-Hosted Deployments
- All data resides on customer-controlled infrastructure
- No data is transmitted to Nova IAM or third parties, unless the optional cloud AI mode is used (see 5.2)
- Customer maintains full sovereignty over data location and jurisdiction
4.2 Database Security
- PostgreSQL with parameterized queries (SQL injection prevention)
- Foreign key constraints enforce data integrity
- Audit log entries are not linked by foreign key and are not removed when a user is deleted
5. Third-Party Data Sharing
5.1 Backend System Integration
Nova IAM connects to customer-configured backend systems for provisioning:
- SAP — User and role provisioning via RFC
- LDAP — Directory group management
- Microsoft Entra ID — Cloud identity group management
Data shared with these systems is limited to:
- User account identifiers
- Role/group assignments
- Validity dates
5.2 AI Features (Optional)
When AI features are enabled:
- Local AI (Ollama): Data is processed entirely on-premises, no external transmission
- Cloud AI: User access data may be sent to the configured AI provider (Anthropic or OpenAI) for analysis. This is opt-in and disabled by default
- Health check: The AI analysis in the health check has its own server-side setting. In cloud mode, finding texts (including names and account IDs) are sent to the configured provider
6. Data Subject Rights (GDPR)
Nova IAM supports the following data subject rights:
| Right | Implementation |
|---|---|
| Access | Full user profile and assignment data available via API |
| Rectification | User data editable through the application |
| Erasure | Users can be deleted; deleted users are purged from the recycle bin manually or automatically after a configurable period (default 90 days). Audit log entries keep actor and target names as written at the time of the event; anonymisation of historical audit entries is not yet supported |
| Portability | User data exportable via API in JSON format |
| Restriction | User accounts can be deactivated (status: inactive) |
| Objection to AI | AI features are off by default (modes: off, local, cloud). Excluding individual users from AI analysis is not supported |
7. Data Breach Notification
In the event of a data breach:
- Affected customers are notified within 72 hours of discovery
- Notification includes: nature of breach, data affected, measures taken, contact information
- Supervisory authorities are notified as required by applicable law
See the Incident Response Plan for detailed procedures.
8. Data Processing Agreement
Where Nova IAM processes personal data on behalf of a customer (for example in a hosted variant), a Data Processing Agreement (DPA) under Art. 28 GDPR is concluded. It covers:
- Processing scope and instructions
- Sub-processor management
- Security measures
- Audit rights
- Data return and deletion procedures
Fragen zu diesem Dokument? Schreiben Sie an
trust@nova-iam.com –
wir bestätigen den Eingang innerhalb von 2 Werktagen.