Legal
Workplace privacy notice
What iLocking sees when you use your work account · Last updated: 2026-07-29
This notice is for people who hold an @ilocking.io account — employees, contractors, and anyone else we give access to. If you are a visitor to our website, the notice you want is the site privacy notice.
Who we are
iLocking Informatikai Szolgáltató Kft. ("iLocking"), a limited liability company registered in Hungary. Registered office: 8600 Siófok, Vajda János utca 4., Hungary. Company registration number (cégjegyzékszám): 14-09-305627. EU VAT number: HU13150686. Hungarian tax number (adószám): 13150686-2-14. Full company details are on the imprint page.
We are the controller for the data described here. We have not appointed a data protection officer, because we are not required to. Write to privacy [at] ilocking.io instead — a real person reads it.
The short version
We give you an account so you can do your work. Microsoft, who runs the platform, records that you signed in and keeps what you write in your mailbox and files. We look at the security records. We do not read your mail to see how hard you are working, we do not track where you are, and there is no software watching your screen or your keystrokes.
What we hold
Your account. Name, work email address, job title, and the phone number you give us for account recovery. You choose whether to add a profile photo.
Your authentication methods. Which second factor you registered — the Microsoft Authenticator app, a passkey, or a security key — and the name of the device it lives on. We never see the secret itself, and we cannot approve a sign-in on your behalf.
Sign-in and audit records. Microsoft Entra records each sign-in: the time, the IP address, the application, the operating system and browser, and whether multi-factor authentication succeeded. It also records administrative changes to accounts. On our current plan Microsoft keeps these for 7 days.
Microsoft 365 audit records. A separate log of actions taken in Exchange, SharePoint, OneDrive and Teams — file opened, message sent, permission changed. Microsoft keeps these for 180 days.
What you create with the account. The contents of your mailbox, your OneDrive, the Teams conversations and the SharePoint documents. This is your work product and it sits in our tenant.
Why, and on what legal basis
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Run your account, mailbox and files | So you can do the job | Art. 6(1)(b) — performance of your contract |
| Require multi-factor authentication; block outdated sign-in methods | To stop somebody else using your identity | Art. 6(1)(f) — our legitimate interest in securing the company |
| Review sign-in and audit records | To spot and investigate compromised accounts | Art. 6(1)(f) — same |
| Keep records that law requires us to keep | Accounting, tax, employment law | Art. 6(1)(c) — legal obligation |
| Preserve material relevant to a dispute | To establish or defend a legal claim | Art. 6(1)(f) — our legitimate interest |
If you are an employee, we also process your personal data for the employment relationship itself; that is covered separately in your employment documentation.
What we do not do
We do not monitor productivity. We do not read your mailbox to assess your performance. There is no keystroke logging, no screen recording, no webcam access, and no location tracking. We do not profile you, and no decision about you is made automatically.
When we would open your mailbox or files
Four situations, and only these:
- A court, tax authority or other body with legal power requires it.
- We are investigating a documented security incident involving your account.
- Business continuity — you are unavailable and something in the account is needed to keep operations running. We take only what is needed.
- After you leave, to hand over your work.
Every such access is recorded in the audit log. We tell you when it happens, unless the law prevents us from telling you.
How long we keep it
| Entra sign-in and audit records | 7 days (Microsoft's retention on our plan) |
|---|---|
| Microsoft 365 audit records | 180 days |
| Account and directory data | While you hold the account |
| Mailbox and files after you leave | 90 days, then deleted. Anything needed for the business is moved out first |
| Records law requires us to keep | For the statutory period, then deleted |
Who else sees it
Microsoft. Microsoft Ireland Operations Limited processes this data on our behalf under the Microsoft Products and Services Data Protection Addendum. Our tenant's core customer data is stored in the European Union under the Microsoft EU Data Boundary. Where Microsoft transfers data outside the EU for support or engineering, it does so under the European Commission's Standard Contractual Clauses.
Nobody else. We do not sell anything, we do not share your account data with third parties, and there is no advertising anywhere in this picture.
Your rights
You can ask us to show you what we hold about you, correct it, delete it, restrict what we do with it, hand it to you in a portable format, or object to processing we base on legitimate interest. Write to privacy [at] ilocking.io and we will answer within one month.
Deletion has limits: where the law requires us to keep a record, or where we need it to defend a legal claim, we keep it and tell you why.
Complaints
Tell us first if something is wrong — we would rather fix it than argue about it. You also have the right to complain to the Hungarian supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) 1055 Budapest, Falk Miksa utca 9–11., HungaryPostal address: 1363 Budapest, Pf. 9.ugyfelszolgalat@naih.hu · +36 1 391 1400 · naih.hu naih.huChanges
If we change how the account works — a new security control, a new tool, a different retention period — we update this notice and tell you. The date at the top tells you when it last changed.