Privacy Policy
Effective Date: 06/20/2026
Last Updated: 07/06/2026
Ido Homri Software ("we," "us," or "our") is committed to protecting the privacy and security of our users and their organizations. This Privacy Policy explains how we collect, use, disclose, and protect personal and organizational information when you use IT Directory and its related services.
IT Directory is not intended to process highly sensitive data. However, IT inventory, employee directory, asset, domain, and operational metadata may still constitute personal data and business-sensitive operational data.
By accessing or using our Services, you agree to the terms of this Privacy Policy.
1. Scope of Policy
This Privacy Policy applies to:
- The IT Directory platform, including modules for IT inventory, asset management, employee directory management, software asset tracking, domain monitoring, connector integrations, and organizational metadata management.
- Websites, applications, APIs, and communications provided by Ido Homri Software.
- IT staff and administrators with login accounts, as well as employees, contractors, and end users whose data is managed through the platform on behalf of a customer organization.
Unless specifically agreed in writing, the Services are not intended for the storage or processing of sensitive personal data, medical data, regulated financial data, government identifiers, payment card data, passwords, secrets, private keys, source code, or highly confidential business documents.
2. Controller vs. Processor
IT Directory serves organizations ("Customers") as a multi-tenant platform. The nature of our role depends on the category of data:
We are the data controller for information users provide directly when creating and managing their own accounts.
We are a data processor acting on behalf of the Customer for employee records, device and inventory data, asset assignments, organizational metadata, and information imported through Customer-managed integrations. In these cases, the Customer organization is the data controller and is responsible for determining the lawful basis for processing employee, device, and organizational data.
3. Information We Collect
3.1 Information You Provide
- Account Details: Name, email address, password, role, and related account settings.
- Organization Data: Company name, structure, sub-organization relationships, departments, locations, and related organizational metadata.
- Employee Records: Staff information entered or imported by Customer administrators, including names, business contact details, job titles, departments, reporting relationships, and asset assignments.
- Device and Inventory Data: Device name, hostname, serial number, operating system, installed software, IP address, MAC address, assigned user, asset status, lifecycle information, domain records, DNS records, and related metadata.
3.2 Information from Third-Party Connectors
When Customers enable integrations, we import data on their behalf from third-party systems the Customer connects to IT Directory, such as:
- Identity providers and directory services.
- Device management systems and MDM/UEM tools.
- DNS providers, domain registrars, and domain monitoring services.
- Cloud platforms, SaaS services, and other Customer-authorized systems.
The type and scope of imported data depends on the integration configured by the Customer and the permissions the Customer grants. Imported data may include employee directory information, device inventory details, software inventory, domain records, DNS records, integration metadata, and related operational information.
3.3 Information Collected Automatically
- Session Data: An authentication cookie is set when you log in to maintain your session.
- Usage and Performance Data: We may collect information about how you interact with the platform, including pages visited, features used, and performance metrics, to operate and improve the Services.
- Technical Information: This may include your IP address, browser type, operating system, and device information.
- Audit and Security Logs: We may collect records of login activity, administrative actions, configuration changes, integration activity, system events, and security-related events.
4. How We Use Information
We use your data to:
- Deliver and maintain platform functionality and user experience.
- Authenticate users and enforce role-based access within organizations.
- Maintain IT inventory, employee directory, asset, software, domain, and organizational metadata records.
- Synchronize Customer-authorized connected systems and integrations.
- Generate reports, support asset lifecycle management, and support audit or compliance activities.
- Send transactional emails such as password resets and email verification links.
- Investigate security, availability, integration, or support issues.
- Respond to security incidents and user support requests.
- Comply with legal obligations and regulatory frameworks, where applicable.
We do not use personal data to serve advertising or train machine learning models.
5. Customer Responsibilities
Customers are responsible for ensuring that they have the necessary lawful basis, notices, permissions, and internal approvals to upload, sync, and process employee, device, asset, domain, and organizational data through the Services.
Where employee, contractor, or end-user data is entered into or imported through the Services, the Customer is responsible for providing any notices and obtaining any consents or approvals required by applicable law, employment policy, contract, or internal procedure.
6. Sensitive Data Restriction
Unless expressly authorized by us in writing, Customers must not upload, sync, store, or otherwise process sensitive personal data, health information, regulated financial data, government identifiers, payment card data, passwords, secrets, private keys, source code, or other highly confidential information through the Services.
7. Legal Basis for Processing (for GDPR Users)
For information we process as a controller, we process data based on:
- Contractual necessity, to deliver the Services.
- Legitimate interests, such as maintaining platform security, reliability, and service quality.
- Legal obligation, such as responding to lawful requests.
- Consent, where required by applicable law.
For employee, device, inventory, asset, domain, and organizational data processed on behalf of Customers, we process the data based on Customer instructions. The Customer is responsible for determining the applicable legal basis for that processing.
8. Data Sharing and Disclosure
We do not sell your data. We may share data with:
- Authorized Users: Within your organization based on assigned roles and permissions.
- Vetted Subprocessors: Including email delivery providers, cloud infrastructure providers, and other service providers that help us operate the Services, each subject to contractual data protection obligations. A list of subprocessors may be made available upon request or published on our website.
- Third-Party Connectors: We access third-party services only as configured and authorized by the Customer. We do not control the availability, security, privacy practices, or data handling of those third-party services.
- Regulators or Legal Entities: When required by law or lawful request.
Where applicable, Customer Data processing may also be governed by a separate Data Processing Addendum.
9. Data Security
We implement reasonable administrative, technical, and organizational safeguards designed to protect Customer Data, including access controls, encryption in transit, tenant separation, and secure handling of integration credentials where applicable.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Data Retention
We retain data only for as long as necessary to:
- Fulfill the purposes described in this policy.
- Provide the Services to the Customer.
- Meet audit, compliance, security, and legal requirements.
Upon account termination or a verified written deletion request, we will delete Customer Data within 90 days unless a longer retention period is required by law, necessary for legitimate legal or security purposes, or agreed in a separate written agreement.
Backup copies may remain for a limited period according to our backup retention cycle and will be securely deleted or overwritten in the ordinary course of business.
11. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the data we hold about you.
- Correct inaccurate information.
- Delete your personal data (right to erasure).
- Restrict or object to processing.
- Data Portability: Receive your data in a structured format.
- Withdraw consent where applicable.
If you are an employee, contractor, or end user whose data was imported by a Customer organization, please direct your request to that organization, as they are the data controller for that data.
To exercise your rights, contact us at info@itdirectory.app
12. International Data Transfers
Your data may be transferred and stored in countries where we or our service providers operate. Where required by applicable law, we use appropriate safeguards, such as Standard Contractual Clauses or equivalent mechanisms, for such transfers.
13. Children's Privacy
Our Services are intended for IT professionals and are not directed to individuals under 18. We do not knowingly collect data from children. If you believe a child has provided personal data, contact us immediately.
14. Cookies and Tracking Technologies
We use an authentication session cookie to maintain your logged-in session. You can clear this cookie at any time by logging out or clearing your browser cookies.
If we use additional cookies or similar technologies for analytics, monitoring, support chat, session recording, marketing, or performance purposes, we will disclose those tools in this Privacy Policy or a separate Cookie Notice.
15. Vulnerability Reporting
If you discover a vulnerability or security issue affecting the Services, please report it to security@itdirectory.app. If that mailbox is unavailable, you may contact us at info@itdirectory.app.
16. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be notified via email or platform banner. Continued use after changes constitutes acceptance.
17. Contact Us
If you have questions, requests, or complaints about this Privacy Policy or our data practices, contact:
Email: info@itdirectory.app
Security: security@itdirectory.app
Website: https://itdirectory.app