This privacy policy only covers Okta's own website and marketing activities — if you log into an app using Okta or Auth0, your data there is handled under a separate agreement between Okta and that app's operator, not this policy.
This analysis describes what Auth0's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause creates a carve-out from the general privacy policy framework, establishing that customer-specific data processing obligations are defined through individual service agreements rather than through this public-facing policy. This distinction separates Okta's obligations as a data controller under this policy from its obligations as a processor under customer contracts.
If your personal data — including login history, device information, and access logs — is processed through an Okta-powered application, this policy does not protect you; you must seek rights through the application operator, who may have separate and less visible data practices.
Cross-platform context
See how other platforms handle Product Data Carve-Out and similar clauses.
Compare across platforms →"This Privacy Policy does not apply to personal data that Okta processes on behalf of its customers as a data processor or service provider in connection with Okta's identity products and platform services, which are governed by the applicable agreements between Okta and its customers.Excerpt from Auth0's Privacy Policy
(1) REGULATORY FRAMEWORK: This carve-out implicates GDPR Art.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This clause creates a carve-out from the general privacy policy framework, establishing that customer-specific data processing obligations are defined through individual service agreements rather than through this public-facing policy. This distinction separates Okta's obligations as a data controller under this policy from its obligations as a processor under customer contracts.
If your personal data — including login history, device information, and access logs — is processed through an Okta-powered application, this policy does not protect you; you must seek rights through the application operator, who may have separate and less visible data practices.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Auth0.