UWA Authentication

Central Identity Provider for uwa.agency projects

OAuth2 / OpenID Connect SSO

Privacy policy

PRIVACY NOTICE

Notice pursuant to Arts. 13-14 of EU Regulation 2016/679

Pursuant to Art. 13 of EU Regulation 2016/679 ("GDPR"), you are informed that the personal data you provide to Giacomo Rizzotti will be processed in compliance with the above regulation and the confidentiality obligations it imposes. Please find the details below:

1. Data Controller

The Data Controller is:

Giacomo Rizzotti

Via Riccardo Mella 30, Novara (NO), 28100, Italia

hereinafter "the Controller", pursuant to Art. 24 GDPR.

2. Purposes of processing

"Processing" means any operation performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, retrieval, use, disclosure, restriction, erasure or destruction.

Your personal data is processed for the following purposes:

  1. to authenticate the user and provide access, via a Single Sign-On system, to the applications connected to this service
  2. compliance with legal obligations or orders issued by a competent Authority

Your personal data may be processed without your consent (Art. 6(1)(b), (e) GDPR) where necessary for the Controller to exercise its own rights (e.g. defence in legal proceedings) or to comply with obligations under law, EU regulation, or an order of an Authority.

3. Categories of data processed

To carry out the purposes listed in point 2, the Controller processes the following personal data:

  • identifying data (username, first name, last name, email address)
  • authentication data (password, stored exclusively in encrypted/hashed form — never readable in plain text, not even by the Controller)
  • technical access data (IP address, date and time of access)
  • authorization data (roles and groups assigned within the connected applications)

Cookies are also processed automatically — see the cookie policy for details.

4. Provision of data

Providing your personal data is strictly necessary to carry out the activities described in point 2. Declining to provide it means the Controller cannot carry out those activities for you.

5. Legal basis

performance of a contract to which the data subject is party, or the taking of pre-contractual steps at their request (Art. 6(1)(b) GDPR), together with the Controller's legitimate interest in maintaining the security of the service, e.g. by retaining access logs (Art. 6(1)(f) GDPR).

6. Processing methods and retention

Processing is carried out, whether by automated or manual means, in accordance with Art. 32 GDPR, by specifically authorised personnel.

In line with the principles of lawfulness, purpose limitation and data minimisation (Art. 5 GDPR), the Controller retains personal data only for as long as necessary to achieve the purposes for which it was collected.

7. Data recipients

Because this service provides centralized authentication (Single Sign-On), identifying and authorization data (username, first/last name, email, roles, groups) is disclosed, on every sign-in, to the applications connected to this service, currently: brff.doingthings.space, optcg.doingthings.space, jpm.uwa.agency. Those applications act as independent data controllers for their own subsequent use of the data received; please refer to their respective privacy policies.

A full list of data processors can be requested in writing at:

giacomo.rizzotti@uwa.agency

Without requiring your express consent (Art. 6(b), (c) GDPR), the Controller may disclose your data to supervisory bodies, judicial authorities, or other parties to whom disclosure is mandatory by law. Such parties process the data as autonomous data controllers.

8. Dissemination

Your personal data is not disseminated (i.e. made available to an indefinite number of parties).

9. International data transfers

The Controller informs the data subject that their personal data is not transferred to countries outside the European Union or European Economic Area: the servers are located within the European Union.

10. Your rights

At any time, pursuant to Articles 15-22 GDPR, you may:

  1. ask for confirmation of whether personal data concerning you exists
  2. obtain information on the purposes, categories of data, recipients, and (where possible) retention period
  3. obtain rectification and erasure of your data
  4. obtain restriction of processing
  5. obtain data portability — receiving your data in a structured, commonly-used, machine-readable format and transmitting it to another controller
  6. object to processing at any time, including for direct-marketing purposes
  7. object to a decision based solely on automated processing, including profiling
  8. withdraw consent at any time, without affecting the lawfulness of processing based on consent given before withdrawal
  9. lodge a complaint with the competent supervisory authority (Garante per la protezione dei dati personali, www.garanteprivacy.it)

You may exercise these rights by written request to Giacomo Rizzotti or by email to: giacomo.rizzotti@uwa.agency

11. Security measures

The Controller has adopted and documented appropriate technical and organisational security measures, in accordance with Art. 32 GDPR, aimed at minimising the risk of data destruction, loss, unlawful or improper use, unauthorised access, or processing not consistent with the purposes for which the data was collected.

Data shared through sign-in

Because this server provides Single Sign-On, every time you sign in to a connected application it receives your name, username, email, and your roles for that specific application.

Your group memberships work differently: they are not scoped to one application — every connected application receives the same list of groups, regardless of which one you're signing in to.

Retention

Access tokens expire after 24 hours and refresh tokens after 30 days; both are purged automatically once expired by a daily cleanup job. Your account itself is kept until you or an administrator deletes it.