DiodeMatrix-ID privacy notice

Privacy Policy for DiodeMatrix-ID

This privacy notice explains how DiodeMatrix processes personal data for DiodeMatrix-ID at id.diodematrix.com and for DiodeMatrix services that use DiodeMatrix-ID for sign-in and account access.

We aim to keep account data limited, transparent and under your control. Where possible, we recommend registering and signing in with an existing OAuth account so the external identity provider can clearly ask what information you agree to share.

Last updated: 7 July 2026 DiodeMatrix-ID English

Data minimisation

DiodeMatrix-ID only keeps the account information needed to identify you, authenticate you and connect you to approved services.

OAuth recommended

Using an OAuth sign-in button can reduce the amount of data you type into DiodeMatrix-ID directly. The OAuth provider shows what it will share before you continue.

User control

You can request access, correction, restriction, deletion or disconnection of services connected to your DiodeMatrix-ID account.

1. Who is responsible for your data?

DiodeMatrix is responsible for the processing of personal data in DiodeMatrix-ID and in DiodeMatrix services that use DiodeMatrix-ID. You can contact DiodeMatrix through the contact page at diodematrix.com/contact.

2. What data do we collect?

DiodeMatrix-ID collects account information through id.diodematrix.com. The information depends on how you create or use your account.

Situation Data processed Purpose
Direct DiodeMatrix-ID registration Username, password credential, email address and given name. To create your account, authenticate you and provide account access.
OAuth registration or sign-in Information approved through the OAuth provider, such as an account identifier, email address and name, depending on what the provider asks you to share. To sign you in while collecting as little information directly from you as possible.
Security and service operation Authentication events and technical security information may be processed, such as sign-in time, failed sign-in attempts, session identifiers, IP address and browser/device information. To protect accounts, detect abuse, troubleshoot access and keep DiodeMatrix-ID reliable.

DiodeMatrix does not ask for unnecessary profile details in DiodeMatrix-ID. OAuth providers may process your data under their own privacy notices when you use their login button.

3. Why do we process your data?

  • Account creation and sign-in: to create and maintain your DiodeMatrix-ID account.
  • Single sign-on: to let approved DiodeMatrix services recognise your account and give you access.
  • Security: to protect user accounts, prevent misuse and investigate suspicious activity.
  • Support and administration: to help you with account, billing, support or access questions.
  • Legal compliance: to comply with applicable data protection, security, accounting or legal obligations where required.

4. Legal bases under the GDPR

Depending on the situation, DiodeMatrix processes personal data because it is necessary to provide the account service, because DiodeMatrix has a legitimate interest in securing and operating its services, because you gave consent for a specific connection or sharing action, or because DiodeMatrix must comply with a legal obligation.

5. Services using DiodeMatrix-ID

DiodeMatrix services that use DiodeMatrix-ID may access the account information needed to authenticate you and provide the service. Examples include:

  • DiodeMatrix Support
  • DiodeMatrix Billing Portal
  • DiodeMatrix DEVBOX
  • HIM

Other DiodeMatrix services may also use DiodeMatrix-ID. Access is limited to what is needed for sign-in, account identification, security and service operation.

6. Non-DiodeMatrix services

Non-DiodeMatrix services do not automatically receive your DiodeMatrix-ID data. When a non-DiodeMatrix service requests account information, you must approve the sharing before data is provided. An example of a non-DiodeMatrix service that requires approval is Skept.nl.

Only the data shown or described during the approval process should be shared with the requesting service. You can request restriction or removal of connected services where technically and legally possible.

7. OAuth and data minimisation

DiodeMatrix recommends using an existing OAuth account button where available. OAuth sign-in can reduce the amount of information DiodeMatrix-ID needs to collect directly from you. The OAuth provider will prompt you before sharing account data with DiodeMatrix-ID. DiodeMatrix-ID does not receive your password for that OAuth provider.

8. Custom authentik-based identity platform

DiodeMatrix-ID is based on a custom version of authentik, an identity provider and single sign-on platform. DiodeMatrix operates and configures its own DiodeMatrix-ID environment. The security and privacy of DiodeMatrix-ID therefore depend on DiodeMatrix's deployment, configuration, access controls, updates and operational safeguards.

DiodeMatrix applies reasonable technical and organisational measures for DiodeMatrix-ID, such as access control, account security settings, authentication/session controls, security logging, updates and hardening where appropriate. No online service can be guaranteed to be completely secure, but DiodeMatrix works to keep account data protected and access limited to authorised purposes.

9. Sharing of personal data

DiodeMatrix does not sell your personal data. Personal data may be shared only when necessary with:

  • DiodeMatrix services that use DiodeMatrix-ID for authentication and account access;
  • non-DiodeMatrix services after your approval, such as Skept.nl;
  • service providers or processors that help operate infrastructure, security, support or communications;
  • authorities or other parties when required by law or necessary to protect rights, security or integrity.

10. How long do we keep data?

Account data is kept for as long as your DiodeMatrix-ID account exists or as long as needed to provide services, resolve issues, meet legal obligations or protect security. If you delete your account or request restriction, DiodeMatrix will remove or restrict personal data where technically and legally possible. Some limited records may need to be retained for security, fraud prevention, billing, accounting or legal reasons.

11. Your rights

Under the GDPR, you may have the right to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, data portability, objection to certain processing, and withdrawal of consent where processing is based on consent.

You may also have the right to lodge a complaint with your local data protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.

12. Account deletion and connected services

You can request deletion of your DiodeMatrix-ID account or restriction of data shared with a service connected to DiodeMatrix-ID. Deleting or restricting your account may remove access to DiodeMatrix services or non-DiodeMatrix services that rely on DiodeMatrix-ID for authentication.

13. Changes to this notice

DiodeMatrix may update this privacy notice when services, security measures, legal requirements or data practices change. The latest version should be published on the DiodeMatrix privacy page.