Last updated 9 July 2026
Privacy Policy
IAMCastle Auditor handles sensitive identity evidence. This policy explains the categories of data processed, how the platform uses that data, and the safeguards expected for an enterprise evidence platform.
1. Overview
This Privacy Policy explains how IAMCastle collects, uses, stores, and protects personal data and customer evidence when providing IAMCastle Auditor. The service is designed for business customers that connect Microsoft Entra ID tenants for identity evidence capture and verification.
2. Customer Account Data
During signup and administration, IAMCastle may collect company name, primary domain, Microsoft tenant identifiers, administrator names, administrator email addresses, billing status, subscription details, consent status, and account configuration data.
3. Identity Evidence Data
IAMCastle Auditor may collect identity audit evidence from Microsoft Entra ID, including actor, object, timestamp, event type, plain-English change summary, previous value, new value, tenant identifier, Microsoft request identifier, source metadata, verification status, hash, and previous-hash values.
4. Authentication and Access Data
The platform may process Microsoft Entra authentication data for customer sign-in, local application credentials for IAMCastle platform administrators, role assignments, invitation status, session information, IP address, browser metadata, and security audit logs.
5. How Data Is Used
IAMCastle uses data to provide evidence capture, search, timeline, verification, tenant isolation, customer administration, billing entitlement, onboarding, security monitoring, abuse prevention, product improvement, and contractual reporting. IAMCastle does not sell customer evidence data.
6. Legal Basis
Where UK GDPR or EU GDPR applies, IAMCastle processes personal data to perform contracts, pursue legitimate interests in providing and securing the service, comply with legal obligations, and, where required, honour customer instructions as a processor.
7. Customer Control and Tenant Isolation
Customer evidence is scoped to the verified Microsoft tenant and customer account. The platform is designed so customer users can only access evidence and administration features for tenants they are authorised to manage or view.
8. Processors and Subprocessors
IAMCastle may use trusted providers to deliver the service, including AWS for hosting infrastructure, PostgreSQL-compatible database services for storage, Microsoft Entra ID and Microsoft Graph for authentication and evidence collection, Stripe for subscription billing, and email providers for operational communication.
9. Security Measures
IAMCastle applies security controls appropriate to the nature of identity evidence, including tenant isolation, encryption in transit, encryption at rest where supported by infrastructure, restricted administrative access, audit logging, secure defaults, evidence hashing, and operational monitoring.
10. Retention
Evidence records are intended to be immutable and append-only. Retention periods depend on the customer plan, commercial agreement, legal requirements, and product configuration. Account, billing, and operational records may be retained for audit, tax, dispute, security, and compliance purposes.
11. Deletion and Account Closure
Customers may request account closure. IAMCastle may restrict customer access while retaining immutable evidence where retention is required for audit integrity, legal obligations, security investigation, billing records, or the customer’s contracted retention period.
12. International Transfers
Depending on the hosting region and processors used, customer data may be processed outside the customer’s country. IAMCastle will use appropriate contractual, organisational, and technical safeguards where international transfer rules apply.
13. Data Subject Rights
Individuals may have rights to access, correct, delete, restrict, or object to processing of personal data. Where IAMCastle acts as a processor, requests should normally be directed to the customer organisation that controls the Microsoft Entra tenant.
14. Changes to This Policy
IAMCastle may update this Privacy Policy to reflect product, legal, operational, or security changes. Material updates will be communicated through the product, by email, or through the customer’s commercial contact where appropriate.
15. Contact
Privacy, data protection, and security questions should be sent by email to IAMCastle using the contact address provided during onboarding or in the customer’s commercial agreement.