Cindera · Privacy Policy
Privacy Policy
Last updated · 2026-06-03
Section 01
Who is responsible
The data controller for this Privacy Policy is Yassin Mahouti BV("Cindera", "we", "us"), a company organised under Belgian law.
- Registered office: [registered address placeholder], Belgium.
- Company number (KBO/BCE): [enterprise number placeholder].
- Contact: support@cindera.eu for any privacy question, request or complaint.
Cindera has not appointed a statutory Data Protection Officer. For data protection questions contact support@cindera.eu.
Section 02
Personal data we process
Cindera is a Microsoft 365 identity security and compliance product. We process the following categories of personal data:
Account data (customer users)
- Identifiers from your Microsoft Entra ID sign-in: user object ID, tenant ID, email address and display name.
- Application role within Cindera (admin, analyst, viewer), last login timestamp, and the audit-trail of actions performed in the app.
Microsoft 365 directory data (read-only)
- User identifiers, principal names, mail addresses, account status, and last-sign-in timestamps for accounts in the customer's tenant.
- Authentication-method registration (which factors are enrolled, not the secrets themselves) and conditional access policy configuration.
- Directory role assignments, group memberships used for privileged access analysis, and registered/consented applications.
Scan results & audit logs
- Findings produced by Cindera's rules, including affected resource identifiers and names, severity, control mappings and remediation steps.
- A tamper-evident audit log of every write operation within the customer's tenant in Cindera.
Public NIS2 self-assessment
- Email address, optional company name, and the answers submitted via the public NIS2 quiz at
/assessment.
We do notread mailbox content, files, calendars, chats or any productivity data. Cindera's scanner uses an application identity with read-only Microsoft Graph permissions required to perform identity and security assessments.
Section 03
Purposes and legal bases
Each processing activity has one of the following GDPR legal bases:
- Provision of the service (Art. 6(1)(b) — contract). Authenticating you, running scans against your tenant, presenting findings, generating reports, and storing your account.
- Legitimate interest (Art. 6(1)(f)). Maintaining audit logs for security and accountability, debugging, fraud and abuse prevention, and product analytics on aggregated usage. We have balanced this interest against your rights and consider the processing proportionate.
- Consent (Art. 6(1)(a)). Sending you the result of the public NIS2 self-assessment by email and contacting you about Cindera if you opted in. You can withdraw consent at any time by emailing support@cindera.eu.
- Legal obligation (Art. 6(1)(c)). Where applicable (e.g. accounting records, statutory retention).
Section 04
How long we keep data
- Audit logs: 7 years from creation, retained for security, accountability and audit evidence purposes.
- Scan data (findings, scores, configuration snapshots): retained for the duration of the subscription. On disconnect, scan data is purged 30 days after the EntraConnection is marked
consent_revoked, unless you request earlier deletion. - Lead data from the public NIS2 assessment: 24 months from submission.
- Account data: retained while the account is active and for 90 days after closure for incident-investigation purposes, then deleted.
Section 05
Sub-processors and transfers outside the EU
Cindera relies on the following sub-processors to deliver the service. We process customer data inside the EU where possible.
- Supabase (PostgreSQL hosting) — EU region. No non-EU transfer.
- Vercel (application hosting) — EU region. Some edge-network telemetry may transit US infrastructure; covered by Standard Contractual Clauses (SCCs).
- Inngest(background jobs) — see Inngest's sub-processor list for current regions; covered by SCCs.
- Resend(transactional email) — US. Covered by SCCs and Resend's GDPR commitments.
- Upstash (rate-limit Redis) — EU region. No customer scan data is stored here; only counter keys derived from tenant or IP identifiers.
- Microsoft(Entra ID, Graph API) — the customer's own Microsoft tenant is the source of directory data, not a sub-processor of Cindera.
For transfers outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) together with supplementary measures where the recipient operates from a third country without an adequacy decision.
Section 06
Your rights
You may, at any time and free of charge, exercise the following rights:
- Access the personal data we hold about you.
- Have inaccurate data rectified.
- Have your data erased ("right to be forgotten"), subject to overriding legal obligations.
- Restrict processing in specific cases.
- Object to processing based on our legitimate interest, including for direct marketing.
- Receive your data in a structured, machine-readable format (portability) where the processing is based on consent or contract.
- Withdraw any previously given consent, without affecting the lawfulness of processing before the withdrawal.
To exercise any of these rights, email support@cindera.eu. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, Rue de la Presse 35, 1000 Brussels, gegevensbeschermingsautoriteit.be).
Section 07
Security
- Microsoft Graph access tokens are never persisted; they are requested per scan and discarded immediately after use.
- Every database query is scoped by tenant identifier and every write is recorded in a tamper-evident audit log.
- All traffic is served over TLS with HSTS, and the application sets a strict Content Security Policy and other modern security headers.
- Customer data is primarily stored and processed in EU-hosted infrastructure.
Section 09
Changes to this policy
We may update this Privacy Policy from time to time. When we make a material change we will update the "last updated" date at the top of the page and, where appropriate, notify you in-app or by email.