MaksIT.IdentityHubPrivacy statement
Updated: 2026-09-24
This statement describes how MaksIT.IdentityHub (MaksIT) processes personal data when you sign in with Google or Microsoft, or when an operator uses the admin WebUI. MaksIT operates Identity Hub from Italy, in the European Union. The EU General Data Protection Regulation (GDPR) and the Italian Privacy Code (Legislative Decree 196/2003, as amended) apply because the controller is established in the EU, including when you connect from outside the EEA.
Who we are
Controller: Maksym Sadovnychyy, operating Identity Hub as MaksIT. privacy@maks-it.com.
Identity Hub is a confidential OAuth client and trusted middleware for MaksIT products on maks-it.com. Products receive a Hub JWT, not IdP tokens. The covered application name used by Postclient is MaksIT.PostClient.
Legal bases
- Contract (GDPR Art. 6(1)(b)): completing sign-in or mailbox consent that you request, issuing a Hub JWT, and vaulting a mailbox refresh token when that flow is used.
- Legitimate interests (GDPR Art. 6(1)(f)): keeping the service secure, detecting abuse and fraud, investigating failed or unauthorized logins, and demonstrating accountability. For that purpose we log the Google or Microsoft account you used to authenticate (email and IdP subject), together with time, provider, outcome, destination host, client IP, and user agent. Access, refresh, and ID tokens are not stored in audit records. Those interests are balanced against your rights by using limited fields, operator-only access, and timed deletion. You may object under Art. 21; security logs may continue where we have compelling legitimate grounds (for example ongoing incident response or the establishment, exercise, or defence of legal claims).
- Language cookie (
maksit_ui_locale): first-party cookie that stores the interface language you choose on these pages, for up to one year. Legitimate interest in keeping the page in the language you selected — Art. 6(1)(f).
Sign-in claims are required to complete the sign-in you start. Security logs are not optional for that request. Giving a contact email to privacy@maks-it.com is optional; without it we cannot answer that message.
Data we process
- Identity claims from the IdP (subject, email, name / profile) needed to complete sign-in. External identities are stored separately from admin users.
- Mailbox refresh tokens encrypted in a Hub vault when a covered app starts a mailbox flow. Hub issues a short-lived mailbox access token (XOAUTH2) against a Hub JWT. IdP tokens are not returned to the product on redeem.
- Login audit: time, provider, outcome, the account identifiers used to authenticate (email, subject), destination host, client IP, user agent, and error codes. Access, refresh, and ID tokens are not stored in audit records.
- Pending one-time codes: a short-lived relay code after callback, deleted on redeem or when it expires.
- Admin WebUI (operators only): local username, password hash, and session JWTs in the browser's local storage.
Google and Microsoft user data
For sign-in the hub requests OpenID openid, email, and profile. When a covered product starts a mailbox flow, the hub may also request Gmail or Outlook IMAP/POP/SMTP scopes configured for this deployment. Identity Hub does not read your messages for its own features, does not sell user data, and does not use Google or Microsoft data for advertising. There is no advertising pixel, no profiling cookie, and no analytics. We do not use your data for automated decisions that produce legal or similar effects.
Google and Microsoft are independent controllers for their sign-in and mailbox APIs. They may process that data outside the EEA under their own terms.
Cookies
During an external login the hub sets short-lived, HTTP-only cookies (ext_csrf, ext_pkce, ext_nonce) to protect the Hub↔IdP OAuth round-trip. They are cleared after callback. Desktop redeem uses PKCE from this origin, not an API key. The language cookie is described above.
Sharing and international use
Hub JWTs are issued only to covered MaksIT applications on allowed HTTPS hosts. Google and Microsoft receive the OAuth request as the identity providers. We do not sell personal data. Hub-held data is processed on servers in Italy. If you connect from another country, you send data into the EEA; that inbound connection is not a transfer of Hub-held data out of the EEA. GDPR still applies. IdP processing outside the EEA is the providers' own processing, under their terms.
Retention
One-time codes remain redeemable for about 1 minute and are deleted on redeem or after expiry. Vaulted mailbox refresh tokens remain until replaced or the identity is removed. Login audit events, including the account used to authenticate, are kept for 180 days (default 180 days, aligned with Italian guidance on access logs) and then deleted automatically. Operators may configure these periods in Hub settings.
Your rights
You can cancel consent at Google or Microsoft and revoke the app in that provider's account settings. For Hub-held data you may request access, rectification, erasure, restriction, or portability, object to processing based on legitimate interests, and withdraw consent where processing is based on consent. Contact privacy@maks-it.com. You may lodge a complaint with the Italian Data Protection Authority or with another EEA supervisory authority.