Template document.This is a template document. Final legal review by a qualified data protection counsel is recommended before signing commercial agreements. Contact support@cindera.eu for the signed version.

Cindera · Privacy Policy

Privacy Policy

Last updated · 2026-09-05

Section 01

Who is responsible

The data controller for this Privacy Policy is YM Group BV("Cindera", "we", "us"), a company organised under Belgian law.

  • Registered office: Giervalkenlaan 34/10, 1170 Watermaal-Bosvoorde, Belgium.
  • Company number (KBO/BCE): BE 1021.794.535.
  • Contact: support@cindera.eu for any privacy question, request or complaint.

Cindera has not appointed a statutory Data Protection Officer. For data protection questions contact support@cindera.eu.

Section 02

Two different roles, two different documents

Cindera handles two kinds of personal data, and the GDPR treats them differently. Which one applies decides who answers a request and which document governs it, so it is worth being precise.

  • Your customer's directory data: we are the processor.Everything Cindera reads from a Microsoft 365 tenant, the accounts, their roles, whether they have registered a second factor, and the findings derived from it, is processed on the customer's documented instructions. The customer is the controller and decides the purposes. Our obligations there are set out in the Data Processing Agreement, not in this policy.
  • Our own account and business data: we are the controller. The email address and name of whoever signs in, billing and company details, the record of who did what inside the console, support correspondence, and details submitted through the public NIS2 assessment or a demo request. This policy governs that data, and the rights described below apply to it.

In practice: an employee of a Cindera customer who wants to know what is held about them should ask their own employer, who is the controller. We will support that employer in answering, which is what Article 28 requires of a processor. Anyone who has signed in to Cindera themselves, or submitted the assessment form, can come to us directly.

Section 03

Personal data we process

Cindera is a Microsoft 365 identity security and compliance product. We process the following categories of personal data:

Account data (customer users)

  • Identifiers from your Microsoft Entra ID sign-in: user object ID, tenant ID, email address and display name.
  • Application role within Cindera (admin, analyst, viewer), last login timestamp, and the audit-trail of actions performed in the app.

Microsoft 365 directory data (read-only)

  • User identifiers, principal names, mail addresses, account status, and last-sign-in timestamps for accounts in the customer's tenant.
  • Authentication-method registration (which factors are enrolled, not the secrets themselves) and conditional access policy configuration.
  • Directory role assignments, group memberships used for privileged access analysis, and registered/consented applications.

Scan results & audit logs

  • Findings produced by Cindera's rules, including affected resource identifiers and names, severity, control mappings and remediation steps.
  • A tamper-evident audit log of every write operation within the customer's tenant in Cindera.

Public NIS2 self-assessment

  • Email address, optional company name, and the answers submitted via the public NIS2 quiz at /assessment.

We do notread mailbox content, files, calendars, chats or any productivity data. Cindera's scanner uses an application identity with read-only Microsoft Graph permissions required to perform identity and security assessments.

Section 04

Purposes and legal bases

Each processing activity has one of the following GDPR legal bases:

  • Provision of the service (Art. 6(1)(b), contract). Authenticating you, running scans against your tenant, presenting findings, generating reports, and storing your account.
  • Legitimate interest (Art. 6(1)(f)). Maintaining audit logs for security and accountability, debugging, fraud and abuse prevention, and product analytics on aggregated usage. We have balanced this interest against your rights and consider the processing proportionate.
  • Consent (Art. 6(1)(a)). Sending you the result of the public NIS2 self-assessment by email and contacting you about Cindera if you opted in. You can withdraw consent at any time by emailing support@cindera.eu.
  • Legal obligation (Art. 6(1)(c)). Where applicable (e.g. accounting records, statutory retention).

Section 05

How long we keep data

  • Audit logs: 24 months from creation, retained for security, accountability and audit evidence purposes. This window covers two full annual compliance and cyber-insurance cycles, which is the period over which this evidence is actually called upon.
  • Scan data (findings, scores, configuration snapshots): retained for the duration of the subscription. On disconnect, scan data is purged 30 days after the EntraConnection is marked consent_revoked, unless you request earlier deletion.
  • Generated report PDFs: stored in an EU (Frankfurt) bucket that is not publicly readable, and covered by the same 30-day purge as the scan data they were generated from. They are deleted in the same run, before the scans themselves, so a purge never leaves a document behind without the record that pointed at it. Scheduled reports are emailed as a link rather than an attachment; that link stops working 72 hours after it is sent, whether or not it was used.
  • Lead data from the public NIS2 assessment and demo requests: these submissions are delivered to us by email and are not stored in the Cindera database. They exist only in our mailbox and at our email provider, so their deletion is governed by our internal mailbox policy, under which we remove them within 24 months of submission, rather than by an automated purge in the application.
  • Account data: retained while the account is active and for 90 days after closure for incident-investigation purposes, then deleted.

Section 06

Sub-processors and transfers outside the EU

Cindera relies on the following sub-processors to deliver the service. We process customer data inside the EU where possible.

  • Supabase (PostgreSQL hosting): EU region. No non-EU transfer.
  • Vercel (application hosting): EU region. Some edge-network telemetry may transit US infrastructure; covered by Standard Contractual Clauses (SCCs).
  • Inngest (background jobs): US-hosted, covered by SCCs. It receives pseudonymous record references only, meaning tenant, scan and finding identifiers. Those identifiers remain personal data in the sense of the GDPR, but they cannot be resolved to a person without our database, which is in Frankfurt. Names, titles, email addresses and domains are not transmitted; each job reads what it needs from the EU database when it runs.
  • Resend(transactional email): US, covered by SCCs and Resend's GDPR commitments. It receives the recipient's email address and a generic subject line. Reports are not attached and our emails name no accounts, tenants or findings: they link to the console, or to a time-limited download whose document stays in Frankfurt.
  • Upstash (rate-limit Redis): EU region. No customer scan data is stored here; only counter keys derived from tenant or IP identifiers.
  • Sentry (error monitoring): EU region (Germany). Receives exception messages and stack traces when the application fails. Configured so that user identifiers and request bodies are not transmitted, which keeps directory data and scan results out of it.
  • Stripe(subscription billing): billing contact details and payment-method data for paying customers; covered by SCCs. Card details are captured by Stripe directly and never reach Cindera's systems.
  • Microsoft(Entra ID, Graph API): the customer's own Microsoft tenant is the source of directory data, not a sub-processor of Cindera.

For transfers outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) together with supplementary measures where the recipient operates from a third country without an adequacy decision.

Section 07

Your rights

You may, at any time and free of charge, exercise the following rights:

  1. Access the personal data we hold about you.
  2. Have inaccurate data rectified.
  3. Have your data erased ("right to be forgotten"), subject to overriding legal obligations.
  4. Restrict processing in specific cases.
  5. Object to processing based on our legitimate interest, including for direct marketing.
  6. Receive your data in a structured, machine-readable format (portability) where the processing is based on consent or contract.
  7. Withdraw any previously given consent, without affecting the lawfulness of processing before the withdrawal.

To exercise any of these rights, email support@cindera.eu. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, Rue de la Presse 35, 1000 Brussels, gegevensbeschermingsautoriteit.be).

Section 08

Security

  • Microsoft Graph access tokens are never persisted; they are requested per scan and discarded immediately after use.
  • Every database query is scoped by tenant identifier and every write is recorded in a tamper-evident audit log.
  • All traffic is served over TLS with HSTS, and the application sets a strict Content Security Policy and other modern security headers.
  • Customer data is primarily stored and processed in EU-hosted infrastructure.

Section 09

Cookies

Cindera uses only the cookies that are strictly necessary to provide the service:

  • Authentication cookie issued by Auth.js to keep you signed in.
  • CSRF / state cookies used during sign-in and the Microsoft 365 admin-consent flow.

Where technically necessary for authentication and session management, Cindera may also use the browser's localStorage and sessionStorage (for example, to keep transient UI state across reloads). These stores hold no marketing or tracking data.

We do not use analytics or advertising cookies. No consent banner is required because no non-essential cookies are placed.

Section 10

Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change we will update the "last updated" date at the top of the page and, where appropriate, notify you in-app or by email.