Privacy Policy

Introduction

Okta, Inc. (“us,” “we,” “our,” “Okta,” or the “Company”) is committed to protecting the privacy of your information. This Privacy Statement describes Okta’s Web site privacy practices. Okta has therefore established this Privacy Policy to assist you to understand how Okta collects and uses personally identifiable information (“Personal Information”). By using the www.okta.com Web site and any other linked pages, features, content, software (including any browser plug-in software), data or our hosted application service or related support services (collectively, the “Website” or the “Services”), you are agreeing to the collection and use of Personal Information in the manner described in this Privacy Policy. This Privacy Policy does not apply to the practices of companies that Okta does not own or control, or to individuals that Okta does not employ or manage.

Information Collected by Okta

Personal Information You Provide to Us. We receive and store any information you enter on the Service or provide to us in any other way. For example, when expressing an interest in obtaining information about the Services or registering to use the Services, Okta may require you to provide personal contact information, such as name, company name, address, phone number, email address, and any other information necessary for us to provide you with access to the various aspects of the Services. You can choose not to provide us with certain information, but then you may not be able to take advantage of many of our special features. The Personal Information you provide is used for such purposes as answering questions, improving the content of the Website, customizing the content you see, and communicating with you about Okta’s products and services, including specials and new features.

Personal Information Collected Automatically. As you navigate or interact with Okta’s Services, Okta may also automatically collect information through the use of commonly-used information-gathering tools, such as cookies and Web beacons.

  1. Cookies

    Okta uses cookies to make interactions with the Services easy and meaningful. When you visit or interact with the Services, Okta’s servers send a cookie to your computer. Standing alone, cookies do not personally identify you. They merely recognize your Web browser. Unless you choose to identify yourself to Okta, either by responding to a promotional offer, opening an account, or filling out a Web form (such as a “Contact Me” or a “30 Day Free Trial” Web form), Okta has no way to associate this cookie data with your Personal Information.

    Okta uses cookies that are session-based and persistent-based. Session cookies exist only during one session. They disappear from your computer when you log out of the Okta Service, close your browser software or turn off your computer. Persistent cookies remain on your computer after you close your browser or turn off your computer.

    If you have chosen to identify yourself to Okta, the Company uses session cookies containing encrypted information to allow the Company to uniquely identify you. Each time you log into the Services, a session cookie containing an encrypted, unique identifier that is tied to your account is placed your browser. These session cookies allow the Company to uniquely identify you when you are logged into the Services and to process your online transactions and requests. Session cookies are required to use many features of the Services.

    Okta also uses an opt-in persistent cookie to remember your username. This opt-in persistent cookie allows you to log into the Okta Service without entering your username every time you use the Service.

    Most browsers have an option for turning off cookies, which will prevent your browser from accepting new cookies, as well as (depending on the sophistication of your browser software) allowing you to decide on acceptance of each new cookie in a variety of ways. We strongly recommend that you leave cookies activated, however, because many aspects of the Service require that cookies be enabled in order to function properly.

  2. Web Beacons

    Okta uses Web beacons alone or in conjunction with cookies to compile information about your usage of the Services and interaction with emails from the Company, and to operate and improve the Services. Web beacons are invisible electronic images that can recognize certain types of information on your computer, such as (1) cookies, (2) the time you viewed a particular Web site tied to the Web beacon, or (3) a description of a Web site tied to the Web beacon.

  3. IP Addresses and Browser Information

    When you visit or use the Services, the Company collects your Internet Protocol (“IP”) addresses, browser information and operating system to track and aggregate non-personal information. For example, Okta uses IP addresses to monitor the regions from which Customers and Visitors navigate the Company’s Web sites.

Use of Information Collected

Okta also collects IP addresses from Customers whey they log into the Services as part of the Company’s “Identity Confirmation” and “IP Range Restrictions” security features.

Okta may use the collected Personal Information and other information Okta collects about your use of the Service to operate and make the Service available to you; for billing, identification and authentication; to send updates about our company and our products; to contact you about your use of the Service; for research purposes, and to generally improve the content and functionality of the Service and Site.

Okta may also transmit or share your Personal Information with its third party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and other technology and services required to operate and maintain the Service, which may require that your personal information be transferred from your current location to the offices and servers of Okta and the authorized third parties referred to in this paragraph. Unless we tell you differently, Okta’s agents and service providers do not have any right to use Personal Information we share with them beyond what is necessary to assist us. You hereby consent to our sharing of Personal Information for the above purposes.

We may occasionally run contests or other special promotions on the Website in which we ask persons who choose to participate for contact information (like an e-mail address) or demographic information (like a zip code, industry or country). We may use the data we collect from you in these contests and promotions to send you promotional material about our company or our partners. Your contact information collected from these contests and promotions may be used to administer the contest and notify winners and contact you when necessary.

Except as described in this policy, Okta will not give, sell, rent, or loan any identifiable personal information to any third party. We may disclose such information to respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims. We may also share such information if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Terms of Service, or as otherwise required by law. Okta may also provide non-personal, summary or group statistics about our customers, sales, traffic patterns, and related Services information to reputable third-party vendors, but these statistics will include no Personal Information.

Protection of Information

Your Okta account Personal Information is protected by a password for your privacy and security. You need to ensure that there is no unauthorized access to your account and Personal Information by selecting and protecting your password appropriately and limiting access to your computer (or other device) and browser by signing off after you have finished accessing your account.

Okta maintains reasonable security measures to protect your information from loss, destruction, misuse, unauthorized access or disclosure. These technologies help ensure that your data is safe, secure, and only available to you and to those you provided authorized access. However, no data transmission over the Internet or information storage technology is 100% secure; and Okta cannot guarantee the security of user account information. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time.

The Service may contain links to other sites. Okta is not responsible for the privacy policies and/or practices on other sites. When linking to another site you should read the privacy policy stated on that site. This Privacy Policy only governs information collected on the Website.

What Personal Information Can I Access?

Okta allows you to access the following information about you for the purpose of viewing, and in certain situations, updating or deleting that information. This list may change as the Services change.

  • Real name
  • Account and user profile information
  • User e-mail address
  • Username and password
  • User preferences

What Choices Do I Have?

  • As stated previously, you can always opt not to disclose information, even though it may be needed to take advantage of or register for certain features of the Services.
  • You are able to add or update certain information on pages, such as those listed in the “What Personal Information Can I Access?” section above. When you update information, however, we often maintain a copy of the unrevised information in our records.
  • You may request deletion of your Okta account by sending an e-mail to accounts@okta.com. Please note that some information may remain in our records after deletion of your account.
  • If you do not wish to receive email or other mail from us, please indicate this preference during the registration process, by changing your account settings, or by notifying us at accounts@okta.com. Please note that if you do not want to receive legal notices from us, such as this Privacy Policy, those legal notices will still govern your use of the Website, and you are responsible for reviewing such legal notices for changes.

Changes to Privacy Policy

Okta may amend or update this policy from time to time. You can review the most current version of this privacy policy at any time at http://www.okta.com/privacy/index.html. Use of information we collect now is subject to the Privacy Policy in effect at the time such information is used. If we make changes in the way we use Personal Information, we will notify you by posting an announcement on the Website or sending you an email. Your continued use of the Services following any such change constitutes your agreement to be bound by such changes to the privacy policy. Your only remedy, if you do not accept the terms of this privacy policy, is to discontinue use of the Services.

Business Transactions

In some cases, we may choose to buy or sell assets. In these types of transactions, user information is typically one of the business assets that are transferred. Moreover, if Okta, or substantially all of its assets were acquired, or in the unlikely event that Okta goes out of business or enters bankruptcy, user information would be one of the assets that is transferred or acquired by a third party. You acknowledge that such transfers may occur, that Okta may assign this policy and your Personal Information in connection with such a transfer, and that any acquirer of Okta or its assets may continue to use your Personal Information as set forth in this policy.

Contact Us

If you have any questions about this Privacy Policy or this Web site, please contact us directly at: info@okta.com.

Written inquiries may be addressed to:

Okta, Inc.,
Chief Information Officer,
400 2nd Street, Suite 350
San Francisco, CA 94107

Effective Date: January 1, 2011