MySSO OnTime Privacy Policy
MySSO OnTime is a customizable Single Sign-On platform used to manage authentication, identity data, users, roles, applications, and organizational information for participating client environments. This Privacy Policy explains how information may be collected, used, and protected when you visit this public website, contact us, or use a configured MySSO OnTime deployment.
Information We May Collect
Depending on the context, MySSO OnTime may process the following categories of information:
- Contact information submitted through public forms, including name, organization, email address, phone number, and message details.
- Account and profile information configured in a client deployment, such as name, email, birthdate, gender, employee ID, RFC or tax ID, profile picture, and organizational assignment.
- Access and role information, including global SSO roles, application assignments, and application-specific roles.
- Authentication and activity information, including login events, account status, approval state, lockout state, and administrative activity records.
- Technical information required to operate the website or service, such as browser type, device information, IP address, timestamps, and diagnostic logs.
How We Use Information
We use information to provide, customize, operate, support, and improve MySSO OnTime. This includes responding to inquiries, scheduling discovery meetings, managing user access, authenticating users, returning agreed identity claims to connected applications, troubleshooting issues, maintaining service records, and supporting client-specific configuration.
Client-Controlled Deployments
MySSO OnTime is customized for each client environment. The client and implementation scope determine which applications are connected, which identity fields are stored, which claims are returned, and how organizational data is modeled. Client applications remain under the client's ownership and control. Those applications may have their own privacy notices and data handling practices.
Identity Data Shared With Connected Applications
When a user signs in through MySSO OnTime, connected applications may receive identity information through an approved callback or UserInfo-style JSON response. The response can include information such as user identity, email, full name, gender, employee ID, organizational division, directorate, coordination unit, assigned applications, and roles assigned per application. The exact claims are configured according to the agreed client implementation.
How Information May Be Shared
We may share information with connected applications, service providers, technical hosting or infrastructure providers, and authorized client administrators when needed to operate or support the service. We may also disclose information if required by applicable law, legal process, or a valid governmental request.
Security
We use technical, administrative, and organizational measures designed to protect information handled by the service. No website, application, network, or storage system can be guaranteed to be completely secure. Clients are responsible for securing their own applications, local login logic, user synchronization processes, and any systems that consume identity data from MySSO OnTime.
Data Retention
Information is retained for as long as needed to provide the service, support a client deployment, comply with legal obligations, resolve disputes, enforce agreements, and maintain reasonable operational records. Retention periods may vary based on the client implementation and applicable requirements.
Cookies and Similar Technologies
The public website and configured deployments may use cookies or similar technologies for session management, authentication, security, preferences, diagnostics, and website operation. Browser settings may allow you to block or delete cookies, but some service features may not function correctly without them.
Your Choices and Requests
Depending on your relationship with the service and applicable law, you may request access, correction, deletion, or other handling of personal information. If your account is managed by a client organization, we may direct your request to that organization or work with them to respond.
Children's Privacy
MySSO OnTime is intended for organizational use and is not directed to children. The service should not be used to knowingly collect information from children unless the client implementation and applicable law permit that use and the necessary permissions and safeguards are in place.
Third-Party Websites and Applications
This website or a configured deployment may contain links to third-party websites or may connect to client applications. We are not responsible for the content, security, or privacy practices of third-party websites or client-owned applications.
Changes to This Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by the "Last updated" date above. Continued use of the website or service after an update means the revised policy applies from that date forward.
Contact
For privacy questions, support requests, or marketplace inquiries, please fill in the support form in the support section of this website..
Copyright and Trademark Notices
All contents of this website are Copyright 2026 by MySSO OnTime and/or its suppliers. All rights reserved. The names of actual companies and products mentioned on this website may be trademarks of their respective owners.