Privacy Policy

GSC Identity is the identity software division of Global Spectrum Consultants LLC
GSC Identity / Policies / Privacy Policy

Privacy Policy

How GSC Identity collects, uses, shares, and protects personal data.

Effective date: October 11, 2026 · Last updated: October 11, 2026

1. Who we are

This Privacy Policy describes how Global Spectrum Consultants LLC, doing business as GSC Identity (“GSC Identity,” “we,” “us”), handles personal data in connection with Mission Control, IDENTA, Aurelium, Identity Vault, our websites, and related services (the “Services”). Our address is 2500 Wilcrest Dr, Ste 300, Houston, TX 77042, United States.

2. Our two roles

As a processor or service provider. When business customers use Mission Control, IDENTA, or Aurelium, they connect their own directories and systems. We process that customer data (such as employee names, user principal names, group memberships, entitlements, and activity logs) only on the customer’s documented instructions and under our agreement with them. The customer is the controller of that data, and individuals should direct requests about it to their employer or organization.

As a controller. We are the controller for personal data we collect directly, including website visitors, prospective customers, business contacts, account administrators, and consumers who use Identity Vault.

3. Data we collect

  • Account and contact data: name, work email, phone number, company, job title, and sign-in identifiers, including Microsoft Entra ID tenant and object identifiers.
  • Customer content: identity and access data that customers connect to the Services, as described above.
  • Identity Vault data: email addresses and sign-in services you choose to connect, the account inventory we build from them, breach-match results, and your preferences.
  • Transaction data: subscription, plan, and billing records. For Microsoft commercial marketplace purchases, we receive subscription and purchaser details from Microsoft; payment card data is handled by Microsoft, not by us.
  • Usage and device data: log data, IP address, browser type, pages viewed, feature usage, and diagnostic information.
  • Communications: support requests, feedback, and correspondence.
  • Cookies: essential cookies to operate the Services and, where permitted, analytics cookies. You can manage non-essential cookies in your browser or through our cookie banner.

4. How we use data

  • To provide, operate, secure, and maintain the Services
  • To authenticate users and activate subscriptions, including through Microsoft Entra ID sign-in
  • To deliver breach and risk alerts you have requested
  • To provide support and respond to requests
  • To bill and manage subscriptions
  • To improve the Services using aggregated or de-identified information
  • To send service notices and, where permitted, marketing you can opt out of at any time
  • To detect and prevent fraud, abuse, and security incidents, and to comply with law

5. AI processing

Some features use AI models to analyze identity data and generate recommendations. We apply data minimization and PII redaction before data is sent to a model. Customers can restrict which models are used, including limiting processing to self-hosted models. We do not use customer content or Identity Vault data to train third-party AI models.

6. How we share data

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We share data only with:

  • Subprocessors that host or support the Services, such as Microsoft Azure, under written agreements that require appropriate protection
  • Microsoft, as required to fulfill commercial marketplace transactions
  • Professional advisers, under confidentiality obligations
  • Authorities, when required by law or to protect rights, safety, and security
  • A successor entity in a merger, acquisition, or asset sale, subject to this policy

A current list of subprocessors is available on request.

7. Data retention

We keep personal data only as long as needed for the purposes above. Customer content is deleted or returned within 30 days after a subscription ends unless the customer requests otherwise or law requires longer retention. Identity Vault users can delete their data at any time. Audit logs may be kept longer where required for security and legal obligations.

8. Security

We protect data with encryption in transit and at rest, tenant isolation, least-privilege access, managed identities, monitoring, and tamper-evident audit logging. See our Security Overview.

9. International transfers

We are based in the United States and primarily host data in U.S. Azure regions. Where we transfer personal data from other regions, we use appropriate safeguards such as Standard Contractual Clauses.

10. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to object to or restrict certain processing, to withdraw consent, and to opt out of marketing. California residents have rights under the CCPA/CPRA, and individuals in the EEA and UK have rights under the GDPR. We will not discriminate against you for exercising these rights. To make a request, email info@globalspectrumconsultants.com with the subject “Privacy Request.” We may need to verify your identity. If your data was provided by your employer through our business products, we will refer your request to that organization.

11. Children

The Services are not directed at children under 13, and we do not knowingly collect their personal data. Minors may be added to an Identity Vault Family plan only by a parent or legal guardian, who controls that data.

12. Changes

We may update this policy from time to time. We will post the updated version here and, for material changes, notify customers by email or in the product.

13. Contact us

Global Spectrum Consultants LLC — GSC Identity, Attn: Privacy
2500 Wilcrest Dr, Ste 300, Houston, TX 77042
info@globalspectrumconsultants.com · 1-888-923-1083