LogoLogo
SupportDeveloper Docs
  • Welcome
  • Getting Started
    • Introduction to BalkanID
      • BalkanID Onboarding
      • BalkanID Summary Dashboard
    • Setting Up BalkanID
      • User Role Management
      • Users Entitlements Discovery
      • Employee Data Extraction
      • Application Integration & Entitlement Data Extraction
      • Business Owners for Application Integrations
    • Entitlement Discovery
      • Entitlements Discovery
      • Applications Entitlements Discovery
      • Connection Entitlement Discovery
      • Resource Entitlement Discovery
      • Identities Entitlements Discovery
      • Working with Filters
      • Impact Analysis
    • Access Review Management
      • Access Review Campaigns
      • Performing Access Reviews
      • Campaign dashboard and management
      • Campaign Audit Reporting
      • Access Review Campaign Notifications and Reminders
      • Configuring Integration Specific Multi-Level Review Settings
      • Configuring Multi-Level Review Settings in Campaigns
      • Reviewer Insight Escalation for Campaigns
      • Recurring Campaigns
      • Campaign Escalation
      • Nominate Delegate In Account Preferences
      • Access Review Graphs
      • Access Review Recommendations
    • Access Request Management
      • Creating and Managing Access Requests
        • New User Access Request
        • New Service Account Access Request
        • New Identity Access Request
        • New Connection Access Request
        • New Resource Access Request
        • New SCIM Access Request
    • System Notifications & Automatic Ticket Creation
      • Notification Preferences
      • In-app Notifications
      • Supported Ticketing Systems
    • BalkanID CLI
      • BalkanID Extractor CLI
      • BalkanID API CLI
  • Configurations and Integrations
    • Integrations Overview
    • HRIS Integrations
      • Integrate via Merge
    • Direct Application Integrations
      • Asana Integration Setup
      • Atlassian Confluence Integration Setup
      • Atlassian Jira Application Integration Setup
      • AWS Application Integration Setup
      • AWS Identity Center Integration Setup
      • Bitbucket Integration Setup
      • Box Integration Setup
      • Code Climate Integration SetupPage
      • Datadog Integration Setup
      • Dropbox Integration Setup
      • GitHub Application Integration Setup
      • Gitlab Integration Setup
      • Google Cloud Platform Integration Setup
      • Google Drive Integration Setup Guide
      • Google Workspace Integration Setup
      • Jenkins Integration Setup
      • JumpCloud Integration Setup
      • MariaDB Integration Setup
      • Microsoft Azure and Active Directory (AD) Integration Setup
      • On-Prem Active Directory (AD) Integration Setup
      • Microsoft Office365 Integration Setup
      • MongoDB Integration Setup
      • MySQL Integration Setup
      • Netsuite Application Integration Setup
      • New Relic Integration Setup
      • Okta Application Integration Setup
      • Onelogin Integration Setup
      • OpenVPN Integration Setup
      • Pagerduty Integration Setup
      • Ping Identity Integration SetupPage
      • PostgreSQL Integration Setup
      • Ramp Integration Setup
      • Salesforce Application Integration Setup
      • SAP Integration Setup
      • Sendgrid Integration Setup
      • Sentry Integration Setup
      • Slack Application Integration Setup
      • Smartsheet Integration Setup
      • Snowflake Integration setup
      • Splunk Integration Setup
      • Sumologic Integration Setup
      • Twingate Integration Setup
      • Zoom Integration Setup
    • Manual Uploads
      • Application Entitlement Data
      • Employee Data
      • Mapping Identities to Employees
    • SSO Integrations
      • Ping Identity
      • Okta
      • OneLogin
      • Microsoft
    • Fulfillment Options
    • BalkanID API
  • Playbooks and Webhooks
    • Playbooks Overview
    • Configuring Global Playbooks
    • Configuring Integration Specifc Playbooks
    • Configuring Global Webhooks
    • Configuring Integration Specific Webhooks
    • Automated Employee Data Upload Playbook with AWS Lambda & S3
    • Automated Entitlement Data Upload Playbook with AWS Lambda & S3
  • IAM RISK ANALYZER
    • Findings
    • Current State RBAC
    • IAM Risk & RBAC Analysis Report
  • Insights and Rules
    • Entitlement Rules & Labels
      • Setup Rules and Labels
      • Terminated Employee Label
      • Privileged identity Label
      • Setup privileged identities
    • Entity Insights and Finding Rules
      • Creating entity filters
      • Setup insights using entity filters
      • Setup finding rules using entity filters
  • BalkanID Slackbot
    • Setting up BalkanID Slackbot
    • Access Requests and Access Review Notifications with BalkanID Slackbot
    • Findings (Daily Alert) with BalkanID Slackbot
  • JITPBAC
    • Overview of JITPBAC
    • Purposes
      • Create Purpose
      • Edit Purpose
      • Delete Purpose
      • Filtering Purposes
      • Create User-Purpose Access Request
        • Creating a Request Through the Web App
        • Creating a Request Through the Slackbot
      • Starting & Stopping Assigned Purposes
  • BalkanID Copilot
    • BalkanID Copilot
  • Updates
    • Release Notes
      • Introducing Findings: Prioritize, Act, and Automate Identity Risk Management
      • Action Center as a command hub for identity risk findings
      • Introducing Impact Analysis: Visualize, Understand, and Manage Access
      • In-app Notifications & Notification Preferences
      • Upgrades to RBAC Analyzer
      • Slackbot for Access Requests and Review Notifications
      • Playbooks and Webhooks for enhanced workflow automation
      • Introducing support assistant for BalkanID application for in-app support
      • Scheduling campaigns & multi-level approvals, nomination & delegation of reviews and graph views for
      • Campaign dashboard actions, access reviews by identity, enhanced access requests and entities connec
      • Access Provisioning & Deprovisioning, Email Notifications, Access Reviews & Campaigns Updates and Ne
      • Quickly find what you’re looking for with the new People, Applications, and Identities pages
      • Integrate your HRIS or Identity Provider without exposing sensitive personnel data or powerful admin
      • Quickly find unusual entitlements with Outliers (Early Access)
      • Announcing “Days Since Termination” filter
      • Announcing JumpCloud direct integration
      • Published Access Review Campaigns can now be deleted
      • Easily switch between tenants using the new tenant picker
      • Skip Access Review Campaigns by downloading a PDF report of your Entitlements
      • User account information now available on the Account page
      • Announcing Bulk API (Early Access)
      • Announcing HRIS integration capability with 23 new HRIS integrations
      • Privileged Identity insights help to quickly identify privileged identities
      • Terminated insights help to quickly identify and remediate entitlements held by terminated employees
      • Announcing Azure and Azure Active Directory direct integration
      • Access Review Campaign drafts can now be permanently deleted
  • Terms & Conditions
    • Privacy Policy
    • Terms of Service
    • AI Policy FAQ
    • Trust Center
Powered by GitBook

© 2025 · BalkanID, Inc. | Nothing on the BalkanID website, platform, or services, nor any portion thereof constitutes actual legal or regulatory advice, opinion, or recommendation by BalkanID, Inc.

On this page

Was this helpful?

Export as PDF
  1. Terms & Conditions

Privacy Policy

PreviousAccess Review Campaign drafts can now be permanently deletedNextTerms of Service

Last updated 1 month ago

Was this helpful?

Privacy Policy

Last updated on April 28, 2025

BalkanID Inc., a Delaware corporation (“we”, “us”, or “our”) provides this Privacy Policy (this “Policy”) to inform you about our collection, use, disclosure, and storage of data about you that we collect via our website, platform, and related services and offerings (collectively, the “Services”). Please review this Policy carefully. By registering an account for the Services, or otherwise using the Services, you agree to the terms and conditions of this Policy. We may update this Policy from time to time in our discretion, for example to keep up with changing laws regarding data processing. We will always keep the current version of this Policy posted on our website. By using the Services after a new version of this Policy has been posted, you agree to the terms and conditions of such version of this Policy.

DATA WE COLLECT

“Personal Data” means information that can be used to identify you, and may include your name, username, email address, and job title. We collect Personal Data that you voluntarily provide us, for example when you register a user account, sign up for mailing lists or newsletters, or otherwise reach out to us. Your submission of Personal Data is voluntary, but we may be unable to provide you requested information or services if you choose not to provide necessary Personal Data.

“Other Information” means information that does not identify you personally, and may include technical details regarding the device you use to access the Services, IP address, operating system, browser, referral URLs, page views, location data (if location services are enabled), clicks, etc. Our systems automatically collect this kind of Other Information when you interact with the Services. Other Information also includes information that may originally have been Personal Data but has been aggregated or anonymized such that it cannot be used to identify any individual.

COOKIES AND SIMILAR TECHNOLOGY

We and our service providers use “cookies” to obtain certain types of data when your web browser accesses our website. Cookies are alphanumeric identifiers that we transfer to your computer’s hard drive through your web browser to enable our system to recognize you and your personalized settings, to better understand how you interact with the Services, to monitor aggregate usage, and to optimize web traffic routing on our website. Most browsers have settings to disable or limit cookies, but please note that certain areas or features of the Services may not be available or fully functional if you choose to disable cookies for our websites. We may also use pixel tags, web beacons, or similar technologies to understand how our users interact with our sites and emails. Our website does not respond to “do not track” signals.

We may use third-party analytics services such as Google Analytics, which help us understand how users are finding and using our Platform. Google Analytics collects information such as how often users visit the Platform, what pages they visit when they do so, and what other sites they used prior to coming to the Platform. We use the information we get from Google Analytics to improve the Platform and our offerings and to provide more relevant advertising. To learn more about Google Analytics’ privacy practices, you can visit . To opt out of Google Analytics’ metrics, you can follow the instructions at .

We do not control third parties' collection or use of your information to serve interest-based advertising. You may be able to opt out of receiving personalized advertisements from companies who are members of the Network Advertising Initiative or who subscribe to the Digital Advertising Alliance's Self-Regulatory Principles for Online Behavioral Advertising. For more information about this practice and to understand your options, please visit: and . You may also use TRUSTe's Preference Manager at .

USE OF YOUR DATA

We use your Personal Data:

  • for the purposes for which you provided it to us (e.g., to create or update your user account, register you for newsletters, and provide access governance services);

  • to respond to your inquiries and communications to us;

  • to improve, maintain, and operate the Services;

  • to inform you about opportunities, events, or services in which you may be interested, including those offered by our affiliates;

  • to investigate and prevent possible fraud;

  • to exercise or defend our rights and comply with statutory and regulatory requirements, including responding to lawful requests for information by governmental authorities; and

  • for other reasons with your prior consent.

You can opt out of receiving promotional or marketing emails from us at any time by clicking the unsubscribe, opt-out, or similar link at the bottom of any such emails. Please note we may still contact you in connection with your account or any transactions involving you (e.g., password resets, etc.).

We may use Other Information (which does not identify you personally) for any manner we deem appropriate, including without limitation to improve, maintain, and operate the Services.

DISCLOSURE OF YOUR DATA

We will not sell your Personal Data to third parties. We may share your Personal Data with our affiliates and as needed to fulfill the purposes described in the “USE OF YOUR DATA” section above, including:

  • with our service providers, such as email service providers, customer support providers, and payment processors, who are only permitted to use the data on our behalf;

  • as necessary to exercise or defend our rights or comply with applicable law or orders from law enforcement and other governmental authorities; and

  • to other third parties with your prior consent.

Additionally, in the event of a merger, consolidation, sale, or transfer of all or substantially all of our assets or business, one of the assets that would generally be transferred is the data we have collected, which would be transferred subject to the applicable version of this Policy.

We may disclose Other Information (which does not identify you personally) to any parties and for any purposes we deem appropriate.

LOCATION; DATA RETENTION, ACCESS, AND CORRECTION; SECURITY

We are based in the United States. By using the Services, you consent to your Personal Data being transferred to and stored in the United States. We may retain your data so long as we can reasonably foresee the data may be required in connection with our business relationship with you. In some cases, we will retain the data for a longer period as necessary to comply with our legal obligations, follow records retention policies, resolve disputes, and enforce our agreements.

You may access and update your Personal Data by contacting us as set forth at the end of this Policy. You may generally delete your Personal Data by contacting us to request such deletion, though in some cases we may be entitled to retain certain information pursuant to our legal obligations, if it was provided by a third-party customer (such as your employer), or if otherwise permitted by law.

We have implemented reasonable physical, organizational, and technical procedures to secure the Personal Data we have in our possession. Unfortunately, no measures can be guaranteed to provide 100% security when dealing with internet connections, so we ask that you do not send us any sensitive information (and you assume the risk if you choose to do so).

YOUR CALIFORNIA PRIVACY RIGHTS

California law entitles California residents to certain additional protections regarding Personal Data. For purposes of this section alone, “Personal Information” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular California resident or household.

We collect the following categories of Personal Information: identifiers, commercial information, Internet or other electronic network activity information, and geolocation data. We collect, use, and disclose Personal Information in the ways described above in our Privacy Policy. We do not sell Personal Information to third parties. California residents have the following rights to the extent granted by applicable law:

  • information regarding their Personal Information we have collected in the past 12 months (including the categories of Personal Information we have collected, the categories of sources of such information, and the purposes for which we have collected such information);

  • notice of whether we have disclosed your Personal Information to third parties in the past 12 months (and if so, what categories of information we have disclosed, and what categories of third parties we have disclosed it to);

  • a copy of your Personal Information collected by us in the past 12 months; and

  • that your Personal Information be deleted.

We will not discriminate against you if you choose to exercise any of these rights. To make any of the above requests, please contact us as set forth at the end of this Policy. We may require verification of your identity before further processing your request. In certain instances, we may be permitted by law to decline some or all of such request. Please note that if you make unfounded, repetitive, or excessive requests (as determined in our reasonable discretion) to access your Personal Data, you may be charged a fee to the extent permitted by law.

Please note that if we received your Personal Information from one of our customers (such as your employer), that customer is the controlling business for purposes of California law and we may need to refer you to such customer for resolution of your inquiries or complaints.

TRANSFERS FROM THE EU, UK, AND SWITZERLAND

Because our Services are hosted on US-based servers, any information you send to us will be transferred to the United States. If such information includes Personal Data you are transferring from the EU, UK, or Switzerland, then to the extent required by applicable privacy laws (such as the EU’s GDPR or the UK or Swiss counterparts to the GDPR) such transfer will be subject to the Standard Contractual Clauses promulgated by the European Commission for transfers of personal data to non-EU/EEA jurisdictions. In such event, you will be deemed the “data controller” and we will be the “data processor” for purposes of such clauses and compliance with applicable privacy laws.

YOUR EU, UK, AND SWISS PRIVACY RIGHTS

If you are an EU, UK, or Swiss resident, applicable data protection laws may provide you with certain rights with regards to our processing of your Personal Data. To the extent established under applicable law, EU, UK, or Swiss residents may have the right:

  • to access, review, and update their Personal Data;

  • to restrict our processing of their Personal Data;

  • to request that we provide them a copy of, or access to, their Personal Data in structured, commonly used and machine-readable format (or that we transfer their Personal Data to another controller, when technically feasible);

  • to withdraw their consent when our processing of their Personal Data is based on consent (and not another legitimate basis);

  • to request that we delete their Personal Data (subject to certain limitations); and

  • to lodge a complaint with the applicable supervisory authority in the EU. Before you do this, we ask that you please contact us directly in order to give us an opportunity to work directly with you to resolve any concerns about your privacy.

To make any of the above requests, please contact us as set forth at the end of this Policy. We may require verification of your identity before further processing your request. In certain instances, we may be permitted by law to decline some or all of such request. Please note that if you make unfounded, repetitive, or excessive requests (as determined in our reasonable discretion) to access your Personal Data, you may be charged a fee to the extent permitted by law.

Please note that if we received your Personal Data from one of our customers (such as your employer), that customer is the data controller for purposes of the GDPR and similar privacy laws and we may need to refer you to such customer for resolution of your inquiries or complaints.

CHILDREN

The Services are not directed toward children under 13. If a parent or guardian becomes aware that his or her child has provided us with Personal Data, the parent or guardian should contact us as set forth at the end of this Policy, and we will take reasonable steps to promptly remove such data from our systems (subject to any applicable, legally required or permitted, retention standards).

THIRD-PARTY SITES

The Services may include links to third party sites and services. If you visit or use such third-party sites and services, please be mindful that the relevant third party controls the cookies and other technologies it uses on its sites and how it collects, uses, and shares your Personal Data. This Policy only governs our own privacy practices; please review the applicable third-party privacy policy when visiting or using any third-party sites or services. We are not responsible for any content provided by third parties or for how they collect, use, share, or otherwise process any information you provide to them.

CONTACT

To make any requests described herein, or otherwise contact us regarding this Policy or our privacy practices, please contact us at .

https://support.google.com/analytics/answer/6004245?hl=en
https://tools.google.com/dlpage/gaoptout
http://www.aboutads.info
http://www.networkadvertising.org/choices/
http://preferences-mgr.truste.com
support@balkan.id