You put Login Broker in your app, so your users' email addresses pass through our service. This page is what your data protection officer, your procurement team or your own conscience will want to see: what we do with that data, who we use underneath, and what we commit to.
Signing in to somebody else's app rather than building one? The page you want is privacy for people signing in.
Last updated 17 August 2026
Login Broker is operated by Gyxi, a company registered in Denmark, VAT number DK28916779. For anything on this page, write to nb@gyxi.com.
This is the part that trips people up, so it is worth being blunt. There are two separate relationships going on at once.
Every email address that passes through a login on your tenant belongs to your relationship with that person. You are the controller: you decide why they are signing in and what your app does next. We only ever act on your instructions, which in practice means the API calls your app makes. We never use your users' data for our own purposes — not to market to them, not to profile them, not to train anything.
Your own login to login.broker, your tenant list and your billing details are ours to look after, on our own account. We hold them to run the service and bill you, and for no other reason.
The processing terms below apply to the first of those. They form part of the Terms, so accepting those accepts these. If your procurement process needs a separately signed data processing agreement on your own paper, ask and you will get one.
The end users of your application who choose to sign in.
Email address. Alongside it, the login attempt itself: a random session id, your tenant name, which provider was used, whether it succeeded, any error, the address the user was returned to, and a timestamp.
None. The service has no field for it and we ask providers for no scope that could carry it.
Verifying that a person controls an email address, and returning that address to your application.
For as long as your account is open, and then no longer.
Notice how short that list is. We do not request names, profile pictures, friend lists or anything else the identity providers would happily hand over — the OAuth scopes we ask for are the narrowest each provider offers. There is nothing for you to switch off, because it was never collected.
A login session is valid for ten minutes. After that it cannot be read or exchanged for anything, and the record is cleared out in routine housekeeping. This is the important number: we are not a shadow copy of your user table sitting around indefinitely.
On termination we delete or return the personal data we hold for you, at your choice, unless the law requires us to keep something. Tell us which you want when you close the account.
Our sub-processors, in full:
Hosting and Azure Table Storage.
Record storage. Also the operator of Login Broker, wearing a different hat.
Each is bound by terms no weaker than these, and we stay responsible to you for what they do. If we take on another one, account holders hear about it by email at least 30 days beforehand, and you can object — which, if we cannot resolve it, means you may terminate without penalty.
The identity providers — Google, GitHub, Facebook, LinkedIn, Microsoft, Apple — are not sub-processors. Your user goes to them directly and independently, under whichever provider you chose to offer. That visit is between them and the provider.
The service runs on Microsoft Azure. If your compliance work needs a specific hosting region named and committed to in writing, ask us before you build — we would rather answer that question early than have you discover the answer late.
Everything moves over TLS. Session records are scoped to the tenant that started the login — another customer with a perfectly valid API key cannot read your sessions or your users' addresses. Access to production is limited to the people who need it.
The strongest control here is design rather than policy: the less we hold, the less there is to lose. An email address and a ten-minute session is a small blast radius.
We are not certified to ISO 27001 or SOC 2 and we are not going to imply otherwise. If your procurement requires a certificate, say so early and we will tell you honestly whether we can meet it.
If we become aware of a breach affecting data we process for you, we will tell you without undue delay and in any case within 48 hours, with what we know, what we are doing and what we suggest you do. You have your own 72-hour clock to the regulator; our job is to make sure you can start it in time.
If one of your users exercises a right — access, correction, deletion, portability, objection — you handle it, because you hold their account and we hold at most a long-expired session. We will help where we can. If a user comes to us directly, we point them at you rather than acting on it ourselves.
We will also give you what you reasonably need for a data protection impact assessment or a supervisory authority consultation, and we will make available the information needed to demonstrate compliance with these terms — including submitting to an audit, on reasonable notice and not more than once a year unless a regulator says otherwise.
Everyone with access to your data at our end is under a duty of confidence.
Two things. Have a lawful basis for signing your users in and tell them, in your own privacy policy, that their address is verified through Login Broker. And keep your API key secret — it is the thing that reads your sessions, so on the client side it is a door left open.
Your instructions to us are the API calls you make. If you ever instruct us to do something we think breaks data protection law, we will say so rather than quietly doing it.
Separately from all of the above: to run your account we hold your email address, the sign-in tokens that keep you logged in, the tenants you administer, and billing details if you are on Pro. We do that to provide the service you signed up for and to meet our accounting obligations, and we keep it while the account is open.
You have the usual rights over it — access, correction, deletion, export, objection. Email nb@gyxi.com and we will sort it out within a month. If we handle it badly you can complain to Datatilsynet, the Danish data protection authority, or to the one where you live.
Signed DPA, standard contractual clauses, a security questionnaire, a named hosting region. Ask and you will get a real answer, including when the answer is no.