Legal

Workplace privacy notice

What iLocking sees when you use your work account · Last updated: 2026-07-29

This notice is for people who hold an @ilocking.io account — employees, contractors, and anyone else we give access to. If you are a visitor to our website, the notice you want is the site privacy notice.

Who we are

iLocking Informatikai Szolgáltató Kft. ("iLocking"), a limited liability company registered in Hungary. Registered office: 8600 Siófok, Vajda János utca 4., Hungary. Company registration number (cégjegyzékszám): 14-09-305627. EU VAT number: HU13150686. Hungarian tax number (adószám): 13150686-2-14. Full company details are on the imprint page.

We are the controller for the data described here. We have not appointed a data protection officer, because we are not required to. Write to privacy [at] ilocking.io instead — a real person reads it.

The short version

We give you an account so you can do your work. Microsoft, who runs the platform, records that you signed in and keeps what you write in your mailbox and files. We look at the security records. We do not read your mail to see how hard you are working, we do not track where you are, and there is no software watching your screen or your keystrokes.

What we hold

Your account. Name, work email address, job title, and the phone number you give us for account recovery. You choose whether to add a profile photo.

Your authentication methods. Which second factor you registered — the Microsoft Authenticator app, a passkey, or a security key — and the name of the device it lives on. We never see the secret itself, and we cannot approve a sign-in on your behalf.

Sign-in and audit records. Microsoft Entra records each sign-in: the time, the IP address, the application, the operating system and browser, and whether multi-factor authentication succeeded. It also records administrative changes to accounts. On our current plan Microsoft keeps these for 7 days.

Microsoft 365 audit records. A separate log of actions taken in Exchange, SharePoint, OneDrive and Teams — file opened, message sent, permission changed. Microsoft keeps these for 180 days.

What you create with the account. The contents of your mailbox, your OneDrive, the Teams conversations and the SharePoint documents. This is your work product and it sits in our tenant.

Why, and on what legal basis

What we doWhyLegal basis (GDPR)
Run your account, mailbox and filesSo you can do the jobArt. 6(1)(b) — performance of your contract
Require multi-factor authentication; block outdated sign-in methodsTo stop somebody else using your identityArt. 6(1)(f) — our legitimate interest in securing the company
Review sign-in and audit recordsTo spot and investigate compromised accountsArt. 6(1)(f) — same
Keep records that law requires us to keepAccounting, tax, employment lawArt. 6(1)(c) — legal obligation
Preserve material relevant to a disputeTo establish or defend a legal claimArt. 6(1)(f) — our legitimate interest

If you are an employee, we also process your personal data for the employment relationship itself; that is covered separately in your employment documentation.

What we do not do

We do not monitor productivity. We do not read your mailbox to assess your performance. There is no keystroke logging, no screen recording, no webcam access, and no location tracking. We do not profile you, and no decision about you is made automatically.

When we would open your mailbox or files

Four situations, and only these:

  1. A court, tax authority or other body with legal power requires it.
  2. We are investigating a documented security incident involving your account.
  3. Business continuity — you are unavailable and something in the account is needed to keep operations running. We take only what is needed.
  4. After you leave, to hand over your work.

Every such access is recorded in the audit log. We tell you when it happens, unless the law prevents us from telling you.

How long we keep it

Entra sign-in and audit records7 days (Microsoft's retention on our plan)
Microsoft 365 audit records180 days
Account and directory dataWhile you hold the account
Mailbox and files after you leave90 days, then deleted. Anything needed for the business is moved out first
Records law requires us to keepFor the statutory period, then deleted

Who else sees it

Microsoft. Microsoft Ireland Operations Limited processes this data on our behalf under the Microsoft Products and Services Data Protection Addendum. Our tenant's core customer data is stored in the European Union under the Microsoft EU Data Boundary. Where Microsoft transfers data outside the EU for support or engineering, it does so under the European Commission's Standard Contractual Clauses.

Nobody else. We do not sell anything, we do not share your account data with third parties, and there is no advertising anywhere in this picture.

Your rights

You can ask us to show you what we hold about you, correct it, delete it, restrict what we do with it, hand it to you in a portable format, or object to processing we base on legitimate interest. Write to privacy [at] ilocking.io and we will answer within one month.

Deletion has limits: where the law requires us to keep a record, or where we need it to defend a legal claim, we keep it and tell you why.

Complaints

Tell us first if something is wrong — we would rather fix it than argue about it. You also have the right to complain to the Hungarian supervisory authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) 1055 Budapest, Falk Miksa utca 9–11., HungaryPostal address: 1363 Budapest, Pf. 9.ugyfelszolgalat@naih.hu · +36 1 391 1400 · naih.hu naih.hu

Changes

If we change how the account works — a new security control, a new tool, a different retention period — we update this notice and tell you. The date at the top tells you when it last changed.