HIVE SECURE ID d.o.o.
PRIVACY POLICY
for the Hive MFA mobile application, related IAM services and website
Version 1.0 | Effective date: 27 July 2026
PUBLIC DOCUMENT
Karađorđev trg 11, 11080 Belgrade – Zemun, Republic of Serbia
info@hivesecureid.com | dpo@hivesecureid.com | Hive Identity Solutions
Document control
Document title
Privacy Policy for the Hive MFA mobile application, related IAM services and website
Document owner
Data Protection Officer / Data Protection Function
Approved by
Management of Hive Secure ID d.o.o.
Version
1.0
Effective date
27 July 2026
Classification
Public
Contact
dpo@hivesecureid.com
Contents
- Document control
- Contents
- 1. Introduction and identity of Hive
- 2. Scope of this Policy
- 3. Hive MFA and related functionality
- 4. Hive roles in personal data processing
- 5. Categories of data subjects
- 6. Categories of personal data we process
- 6.1. Account, identity and organisational context data
- 6.2. TOTP accounts, tokens and authentication secrets
- 6.3. Push authentication and notifications
- 6.4. FIDO2, WebAuthn and passkey credentials
- 6.5. Biometric functionality
- 6.6. Device and device posture data
- 6.7. Authentication, risk and session data
- 6.8. Analytics, crash reports and technical logs
- 6.9. Support, communications and website data
- 7. Processing purposes and legal bases
- 8. Sources of personal data and collection methods
- 9. Mobile application permissions
- 10. Adaptive authentication, risk assessment and automated decisions
- 11. Data recipients and sub-processors
- 12. International data transfers
- 13. Data retention
- 14. Account, token and device registration deletion
- 15. Data subject rights
- 16. Data security
- 17. Children’s privacy
- 18. Advertising, sale of data and tracking
- 19. Third-party services and systems
- 20. Personal data breaches and security notifications
- 21. Changes to this Policy
- 22. Contact and complaints
- 23. Regulatory framework
1. Introduction and identity of Hive
Hive Secure ID d.o.o. respects user privacy and processes personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.
This Privacy Policy explains which personal data we process through the Hive MFA mobile application, related Hive Secure ID platform functionality and the Hive website, why we process it, with whom we share it, how long we retain it, which security measures we apply and which rights individuals have.
Legal entity
Hive Secure ID d.o.o.
Registered office and address
Karađorđev trg 11, 11080 Belgrade – Zemun, Republic of Serbia
Website
Hive Identity Solutions
General contact
info@hivesecureid.com
DPO / privacy
dpo@hivesecureid.com
In this Policy, “Hive”, “we”, “us” and “our” refer to Hive Secure ID d.o.o. The term “customer organisation” means a legal entity, institution or other organisation that uses the Hive IAM platform and provides Hive MFA to its employees, contractors, customers or other authorised users.
2. Scope of this Policy
This Policy applies to the following processing activities:
- use of the Hive MFA mobile application on Android and Apple iOS devices;
- registration and management of a device as an authentication factor;
- TOTP codes, push approvals, biometric unlocking, FIDO2/WebAuthn and passkey functionality, where enabled;
- risk-based step-up authentication, adaptive policies, device posture checks and session governance insofar as they relate to Hive MFA;
- technical and user support, diagnostics, security monitoring and incident response;
- the Hive website, contact form, strictly necessary cookies and optional analytics technologies, where used;
- personal data processed by Hive as a controller and personal data processed under the documented instructions of a customer organisation.
Separate privacy notices, internal policies and contracts of the customer organisation may apply to processing carried out by that organisation for its own purposes. This Policy does not replace the privacy notice of the organisation that manages the user account.
3. Hive MFA and related functionality
Hive MFA is a multi-factor authentication mobile application intended primarily for users of the Hive Secure ID identity and access management platform. The Hive website presents the application as a business authenticator supporting one-time codes, one-tap approval of authentication requests, biometric unlocking, FIDO2/WebAuthn and risk-based authentication.
Depending on the configuration selected by the customer organisation and the application version, Hive MFA may provide:
- registration of a mobile device by scanning a QR code, entering an activation code or using another approved process;
- generation of time-based one-time passwords (TOTP);
- receipt, review, approval or rejection of push authentication requests;
- local confirmation using a PIN, password or the device’s biometric functionality;
- registration and use of FIDO2/WebAuthn or passkey credentials;
- additional or repeated authentication where policy or risk assessment requires a higher assurance level;
- verification of device status and integrity;
- display of multiple authentication accounts and associated services;
- synchronisation of selected data, where this functionality is enabled;
- deregistration of a device, revocation of credentials and review of limited security-event information.
As a rule, Hive MFA is not a standalone consumer account service. Access to the application and connected systems normally depends on the authorisation and configuration of the customer organisation.
4. Hive roles in personal data processing
4.1. Hive as a controller
Hive acts as a controller where it independently determines the purposes and means of processing, particularly in relation to:
- management of Hive’s own business contacts, contracts, support and communications;
- security, integrity, abuse prevention and protection of the Hive application and infrastructure;
- diagnostics, analytics, vulnerability management and service improvement;
- operation of the website, contact form and cookie consent management;
- handling of data subject requests, regulatory obligations and legal claims.
4.2. Hive as a processor or sub-processor
Where the customer organisation determines who has an account, which resources the user may access, which authentication methods and risk policies apply and how long authentication records are retained, Hive will generally act as a processor or sub-processor.
In that case, Hive processes personal data under documented instructions, a data processing agreement, agreed technical and organisational measures and the configuration of the relevant customer organisation. Requests relating to an organisation-managed account, access rights or authentication history should normally be directed first to the organisation that manages the account.
5. Categories of data subjects
- employees, contractors, administrators and other personnel of customer organisations;
- customers, service users and other individuals authorised by a customer organisation;
- users of the Hive MFA application and registered devices;
- contact persons, prospective customers and website visitors;
- individuals who contact support, the DPO or the security team;
- representatives of suppliers, partners and other business organisations.
6. Categories of personal data we process
The precise scope of personal data depends on the agreed deployment model, customer configuration, operating system, enabled functionality, integrated services and permissions granted to the application.
6.1. Account, identity and organisational context data
- first and last name, where required;
- business or other email address;
- username, internal user ID or pseudonymous identifier;
- customer, tenant or organisation identifier;
- role, group, organisational affiliation and account status;
- device registration status and selected application settings;
- language, region and user preferences.
6.2. TOTP accounts, tokens and authentication secrets
When a user registers a TOTP account, the application may process the issuer or service name, account label, username or email associated with the account, algorithm, number of digits, validity period, registration QR-code data, registration date, token status and last synchronisation date.
A TOTP seed or shared secret is a confidential authentication secret. Depending on the configuration and deployment model, the secret may remain only in secure storage on the device or may be transferred and stored in encrypted form for controlled synchronisation, recovery or token management. Hive does not use TOTP secrets, valid one-time codes or recovery codes for analytics, advertising or profiling.
Operational, analytics and diagnostic logs are designed not to contain a TOTP seed, valid one-time password, private key, recovery code or other data that would enable authentication controls to be bypassed.
6.3. Push authentication and notifications
- push token and application instance identifier;
- device platform and type;
- authentication request identifier and limited routing metadata;
- sending, delivery, approval, rejection, timeout or failure status;
- date, time and service for which the request was initiated.
Push notifications may be delivered through Apple Push Notification Service or Firebase Cloud Messaging. Information displayed on a locked screen is limited in accordance with the security configuration and is designed not to disclose secrets or unnecessary confidential information.
6.4. FIDO2, WebAuthn and passkey credentials
Where FIDO2, WebAuthn or passkey authentication is enabled, Hive may process the credential identifier, public cryptographic key, user handle or another user identifier, relying party identifier, credential registration and revocation status, authentication challenges and responses, signature counter and, where necessary, limited authenticator or attestation information.
The private cryptographic key normally remains in a compatible authenticator, secure hardware element, operating system or credential manager and is not transferred to Hive. Where a passkey is synchronised through Apple, Google or another credential provider, that provider processes data under its own terms and privacy documentation.
6.5. Biometric functionality
Hive MFA may use biometric functionality provided by the device, such as fingerprint or facial recognition, to unlock the application locally or confirm an authentication action.
- Hive does not collect facial photographs, fingerprints or raw biometric templates;
- biometric templates remain under the control of the operating system or the device’s secure hardware environment;
- Hive receives only a technical indication that local authentication succeeded or failed;
- where supported, the user may use a PIN, password or another alternative method.
6.6. Device and device posture data
- device type, manufacturer and model;
- operating system, version and security patch level;
- application version and instance identifier;
- device registration identifier;
- IP address, network characteristics and approximate region derived from the IP address;
- device-lock status, availability of local authentication and secure storage;
- root, jailbreak, emulator, debug or another indicator of a compromised environment;
- application integrity, certificate status and other technical signals needed to assess device trustworthiness;
- device registration, replacement, deactivation and deregistration events.
Hive MFA does not access contacts, private photographs, message content, call history, precise GPS location or the content of other applications unless such processing becomes necessary for a clearly stated function, is explained in advance and, where required, is based on consent.
6.7. Authentication, risk and session data
- date, time, service, application or system for which access was requested;
- authentication method and factor;
- approval, rejection, failure or timeout result;
- IP address, network and time context;
- session, transaction and correlation identifiers;
- failed attempts, frequency and unusual patterns;
- risk indicators, risk score, reason code and required step-up authentication level;
- session status, identity re-verification and session termination or restriction events;
- security events associated with suspected fraud, phishing, push fatigue or account compromise.
6.8. Analytics, crash reports and technical logs
- application launches, sessions and feature usage;
- performance, response times and technical errors;
- crash reports, stack traces, application state at the time of an error and network errors;
- pseudonymous analytics identifiers and aggregated statistics;
- API requests, administrative activities, configuration changes, security monitoring and incident logs.
We do not use optional analytics for third-party advertising or tracking across unrelated applications. Where consent is required, optional analytics are not activated before consent is provided.
6.9. Support, communications and website data
When a user contacts Hive or uses the website contact form, we may process the person’s name, company name, business email address, subject, message, attachments, communication history and technical data required to resolve the request.
When a person visits the Hive website, we may process the IP address, browser, operating system, pages visited, access time, referring page, security logs and cookie preferences. Strictly necessary cookies are used for website operation and security. Optional analytics or marketing cookies are used only where permitted and, where required, after consent.
7. Processing purposes and legal bases
Hive processes personal data only where an appropriate legal basis exists. In the B2B model, some purposes and legal bases are determined by the customer organisation acting as controller.
| Purpose | Typical data | Legal basis |
|---|---|---|
| Providing Hive MFA and authentication | Account, device, TOTP, push, FIDO/WebAuthn and authentication data | Performance of a contract or steps requested by the user; legitimate interests; processing under controller instructions |
| Device registration and management | Device identifiers, registration status and posture signals | Performance of a contract; legitimate interests in secure access management |
| Risk-based step-up and session protection | Risk, session, IP, device posture and security events | Legitimate interests in protecting accounts and systems; legal obligation; controller instructions |
| Push notifications | Push token, routing and delivery metadata | Performance of a contract; legitimate interests in delivering authentication requests |
| Local biometric confirmation | Technical success/failure result | Performance of a contract; user-initiated action; legitimate interests |
| Diagnostics and security | Crash, log, performance and incident data | Legitimate interests; legal obligation; establishment or defence of legal claims |
| Optional analytics | Pseudonymous usage data | Consent where required; legitimate interests where permitted |
| Support and business communications | Contact, account, technical data and correspondence | Performance of a contract; steps at the individual’s request; legitimate interests |
| Website and strictly necessary cookies | Server logs and technical data | Legitimate interests; provision of the requested service |
| Optional cookies | Analytics or marketing identifiers | Consent |
| Legal and regulatory obligations | Contractual, audit, security and record data | Legal obligation; public interest where applicable; legal claims |
Where processing is based on legitimate interests, Hive assesses necessity, proportionality and the impact on individual rights. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
8. Sources of personal data and collection methods
- directly from the user;
- from the user’s device and operating system;
- from the organisation that manages the account;
- from authentication, access, security and server logs;
- from connected applications, relying party systems and IAM components;
- through Apple, Google and other approved technical services;
- from support communications and the website contact form;
- from security and anti-fraud mechanisms.
9. Mobile application permissions
| Permission / function | Purpose |
|---|---|
| Notifications | Delivery of push authentication requests and security messages. |
| Camera | Scanning a QR code to register a TOTP account, device or credential. The image is used for scanning and is not retained unless expressly stated. |
| Biometrics / device credential | Local application unlocking or confirmation of an action. |
| Network access | Secure communication with the Hive platform and connected services. |
| Device security information | Assessment of device integrity and application of device posture policy. |
The application will not request a permission that is not reasonably necessary for an active and clearly described function. Refusing a permission may prevent the related function from operating, but does not permit Hive to use data for other purposes.
10. Adaptive authentication, risk assessment and automated decisions
Hive MFA and the related platform may use automated rules and risk assessment to protect accounts and systems. The assessment may consider device status and integrity, IP and network context, access time and frequency, an unusual change of device or network, previous failed attempts, resource sensitivity, session state and other security indicators.
Possible outcomes include requiring an additional factor, biometric confirmation or re-authentication, temporary access denial, flagging an event for review, notifying an administrator or terminating a session.
These mechanisms are used to protect access and are generally not intended to make decisions producing legal or similarly significant effects outside the security and access context. The user may request an explanation or review from the organisation that manages the account. Certain details of detection rules may remain confidential where disclosure would enable security controls to be bypassed.
11. Data recipients and sub-processors
We share personal data only where necessary to provide the service, maintain security, provide support, comply with legal obligations or protect rights. Recipients may include:
- the organisation that manages the user account and its authorised administrators;
- Apple Inc. for the App Store, iOS and Apple Push Notification Service;
- Google LLC for Google Play, Android services and Firebase Cloud Messaging;
- approved cloud, hosting, backup, monitoring, analytics, crash-reporting, email and support providers;
- professional advisers, auditors and insurers subject to confidentiality obligations;
- courts, supervisory authorities, law-enforcement bodies or other competent authorities where a lawful and binding basis exists;
- entities involved in a corporate restructuring, merger, acquisition or business transfer, subject to appropriate safeguards.
Current information about sub-processors, service categories and processing locations may be requested at dpo@hivesecureid.com. Hive requires sub-processors to accept contractual obligations covering confidentiality, security, purpose limitation, assistance with individual rights and controlled deletion of personal data.
12. International data transfers
Hive is established in the Republic of Serbia. Where personal data is transferred from, or accessed from, the EU/EEA, the processing may constitute an international transfer to a third country. The Republic of Serbia is currently not covered by a European Commission adequacy decision.
Where the GDPR applies, Hive uses an appropriate transfer mechanism, which may include the European Commission Standard Contractual Clauses under Decision (EU) 2021/914, a transfer impact assessment, contractual commitments and supplementary technical and organisational measures. Where the Law on Personal Data Protection of the Republic of Serbia applies, Hive also complies with the requirements governing transfers from Serbia.
Supplementary measures may include encryption, pseudonymisation, access controls, restrictions on privileged access, audit logging, data minimisation, key management, onward-transfer controls and procedures for handling public-authority requests.
Information about applicable safeguards and how to obtain a copy may be requested at dpo@hivesecureid.com. Where appointment of an EU representative is required under Article 27 GDPR, the representative’s contact details will be published on the same website as this Policy.
13. Data retention
We retain personal data only for as long as necessary for the relevant purpose, contractual obligations, security requirements, instructions of the customer organisation and applicable law. Customer organisations may agree or configure different retention periods for personal data under their control.
| Category | Standard period / criterion |
|---|---|
| Account and profile | For the duration of the account and up to 30 days after termination, unless longer retention is required. |
| TOTP record and authentication secret | Until token deletion, device deregistration or account termination; backup copies are deleted or overwritten through the regular cycle, generally within 90 days. |
| FIDO2/WebAuthn public key and credential ID | Until credential revocation or account termination, followed by a controlled deletion period of up to 30 days. |
| Push token | Until replacement, deregistration or no longer required; inactive tokens are removed within a reasonable period, generally within 90 days. |
| Authentication, risk and session logs | Generally 12 months, unless the customer organisation specifies another period or longer retention is required by law or for an incident. |
| Device posture and technical security logs | Generally 12 months. |
| Crash and diagnostic data | Up to 14 months. |
| Pseudonymous analytics | Up to 14 months, unless a shorter period is configured. |
| Support requests and correspondence | Three years after closure of the request. |
| Inactive website business enquiries | Up to 24 months, unless the communication develops into a contractual relationship. |
| Consent and preference records | For the duration of the relevant processing and up to five years after withdrawal or expiry where evidence is required. |
| Security incidents and legal claims | For the duration of the investigation and up to five years, or longer where required by law or a specific proceeding. |
| Accounting and contractual documentation | As required by law, generally up to ten years. |
| Web server logs | Generally up to 12 months, except during an active security investigation. |
Personal data may be retained for longer where necessary to comply with a legal obligation, investigate an incident, resolve a dispute or establish, exercise or defend legal claims. Aggregated or irreversibly anonymised data may be retained without a fixed period because it no longer identifies an individual.
14. Account, token and device registration deletion
14.1. Organisation-managed accounts
For organisation-managed accounts, the customer organisation will normally control account creation, suspension, deactivation and deletion, as well as retention periods for authentication records. The user should first contact the organisation that provided access. Hive will assist the organisation in responding to a valid request.
14.2. Direct Hive accounts, where enabled
Where Hive enables direct account creation, a user may initiate deletion through an in-application function, the web deletion mechanism or a request to dpo@hivesecureid.com. Before deletion, Hive may conduct a reasonable verification of the requester’s identity and authority.
14.3. Removal of tokens, passkeys and local data
Deleting a TOTP account removes the active record from the application and, where applicable, from synchronised Hive storage; backup copies are removed through the regular backup cycle.
Deregistering a device revokes its use as an authentication factor in accordance with the customer organisation’s configuration.
Deleting a FIDO/WebAuthn public key on the Hive side revokes the credential for the relevant service, but may not automatically remove the passkey from the device or Apple/Google credential manager.
Uninstalling the application removes local application data in accordance with operating-system rules, but may not automatically delete server-side records or the organisation-managed account.
Certain audit, security or legal records may be retained where there is a lawful and documented reason.
15. Data subject rights
Depending on applicable law and Hive’s role in the relevant processing, an individual may have the right to:
- receive information about processing and obtain access to personal data;
- request correction of inaccurate or completion of incomplete data;
- request deletion or restriction of processing;
- object to processing based on legitimate interests;
- receive certain data in a structured, commonly used and machine-readable format;
- withdraw consent without affecting the lawfulness of processing performed before withdrawal;
- request information about international transfers and safeguards;
- request review of a relevant automated decision, where applicable;
- complain to a competent supervisory authority.
Requests may be sent to dpo@hivesecureid.com. Where Hive acts as a processor, the request may be referred to the customer organisation acting as controller. Hive may request information reasonably necessary to verify identity and prevent unauthorised disclosure.
Individuals in the Republic of Serbia may lodge a complaint with the Commissioner for Information of Public Importance and Personal Data Protection. Individuals in the EU/EEA may contact the competent supervisory authority in the country of residence, place of work or alleged infringement.
16. Data security
Hive applies technical and organisational measures appropriate to the risk, nature of the personal data and service delivery model. Depending on the architecture and deployment model, measures may include:
- encryption of communications and relevant data at rest;
- secure storage of keys and secrets, including Apple Keychain, Android Keystore, HSM or controlled KMS where applicable;
- least privilege, role-based access control, MFA and privileged access controls;
- tenant and environment segregation;
- audit logs, SIEM monitoring, anomaly detection and protection of record integrity;
- secure SDLC, code review, SAST/DAST, dependency management and vulnerability management;
- penetration testing of the mobile application and APIs;
- patch and security-update management;
- backup, recovery and continuity testing;
- incident response and notification procedures;
- supplier due diligence, contractual safeguards and periodic reviews;
- employee training, confidentiality and access controls.
No system is completely free from risk. Users must protect their device, PIN, password, recovery information and authentication requests, reject unexpected requests and immediately report a lost device, suspicious request or suspected compromise.
17. Children’s privacy
Hive MFA is a business and security application and is not directed or marketed to children. Hive does not invite children to create independent consumer accounts. Where an authorised organisation provides an account to a minor, that organisation is responsible for ensuring an appropriate legal basis and providing any notices or consents required by applicable law.
If Hive determines that a child’s personal data has been processed without an appropriate basis, Hive will take reasonable steps to delete, restrict or otherwise bring the processing into compliance.
18. Advertising, sale of data and tracking
Hive does not sell personal data. Hive MFA is not intended to display behavioural advertising, share data with data brokers, use authentication data for marketing or track users across unrelated applications and websites for targeted advertising.
If Hive introduces processing that changes this model in the future, this Policy, consent mechanisms, Google Play Data Safety disclosures and Apple App Privacy disclosures will be updated before the processing begins.
19. Third-party services and systems
Hive MFA may integrate with external services and accounts that support TOTP, FIDO2, WebAuthn or other standards. Third-party names and trademarks belong to their respective owners. Hive does not manage an external account, cannot reset its password or recovery code and does not guarantee that an external service will permanently support a particular authentication method.
The user is responsible for safeguarding recovery codes issued by an external service and for reviewing its terms and privacy notices. Hive is not responsible for the independent practices of Apple, Google, a mobile network operator, operating system, credential provider or another external service, except to the extent liability cannot be excluded by law.
20. Personal data breaches and security notifications
Hive maintains procedures to detect, assess, contain and document security incidents and personal data breaches. Where Hive acts as a processor, it notifies the relevant controller without undue delay in accordance with the contract and applicable law. Where Hive acts as a controller, it notifies the competent authority and affected individuals where the legal conditions are met.
Security notifications may be delivered through the application, email, website, customer organisation or another appropriate channel. Users should report suspicious authentication requests, lost devices or other security incidents to the organisation that manages the account and to Hive.
21. Changes to this Policy
Hive may update this Policy because of changes to functionality, architecture, SDKs, sub-processors, law, security measures or the organisational model. The current version is published on the website and made available from the application.
Where a change materially affects user rights or processing purposes, Hive will provide an appropriate notice and, where required, request renewed consent. The last-updated date identifies the current document version.
22. Contact and complaints
Company
Hive Secure ID d.o.o.
Address
Karađorđev trg 11, 11080 Belgrade – Zemun, Republic of Serbia
General contact
info@hivesecureid.com
DPO / privacy
dpo@hivesecureid.com
Website
Hive Identity Solutions
A request should include enough information to enable Hive to identify the relevant processing and verify the requester’s identity. Passwords, TOTP codes, seed values, private keys or recovery codes are not required and should not be sent by email or through a support ticket.
23. Regulatory framework
This Policy has been prepared taking into account, in particular:
- Law on Personal Data Protection of the Republic of Serbia;
- Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR), where applicable;
- Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countries;
- Google Play requirements concerning user data, Data Safety disclosures and account deletion;
- Apple App Store Review Guidelines, App Privacy disclosures and account deletion requirements;
- other applicable rules concerning privacy, electronic communications, consumer protection and information security.
Where this Policy conflicts with a binding legal requirement, the binding requirement prevails. This Policy does not limit any rights available to an individual under applicable law.

