Template document.This is a template document. Final legal review by a qualified data protection counsel is recommended before signing commercial agreements. Contact support@cindera.eu for the signed version.

Cindera · Privacy Policy

Privacy Policy

Last updated · 2026-06-03

Section 01

Who is responsible

The data controller for this Privacy Policy is Yassin Mahouti BV("Cindera", "we", "us"), a company organised under Belgian law.

  • Registered office: [registered address placeholder], Belgium.
  • Company number (KBO/BCE): [enterprise number placeholder].
  • Contact: support@cindera.eu for any privacy question, request or complaint.

Cindera has not appointed a statutory Data Protection Officer. For data protection questions contact support@cindera.eu.

Section 02

Personal data we process

Cindera is a Microsoft 365 identity security and compliance product. We process the following categories of personal data:

Account data (customer users)

  • Identifiers from your Microsoft Entra ID sign-in: user object ID, tenant ID, email address and display name.
  • Application role within Cindera (admin, analyst, viewer), last login timestamp, and the audit-trail of actions performed in the app.

Microsoft 365 directory data (read-only)

  • User identifiers, principal names, mail addresses, account status, and last-sign-in timestamps for accounts in the customer's tenant.
  • Authentication-method registration (which factors are enrolled, not the secrets themselves) and conditional access policy configuration.
  • Directory role assignments, group memberships used for privileged access analysis, and registered/consented applications.

Scan results & audit logs

  • Findings produced by Cindera's rules, including affected resource identifiers and names, severity, control mappings and remediation steps.
  • A tamper-evident audit log of every write operation within the customer's tenant in Cindera.

Public NIS2 self-assessment

  • Email address, optional company name, and the answers submitted via the public NIS2 quiz at /assessment.

We do notread mailbox content, files, calendars, chats or any productivity data. Cindera's scanner uses an application identity with read-only Microsoft Graph permissions required to perform identity and security assessments.

Section 03

Purposes and legal bases

Each processing activity has one of the following GDPR legal bases:

  • Provision of the service (Art. 6(1)(b) — contract). Authenticating you, running scans against your tenant, presenting findings, generating reports, and storing your account.
  • Legitimate interest (Art. 6(1)(f)). Maintaining audit logs for security and accountability, debugging, fraud and abuse prevention, and product analytics on aggregated usage. We have balanced this interest against your rights and consider the processing proportionate.
  • Consent (Art. 6(1)(a)). Sending you the result of the public NIS2 self-assessment by email and contacting you about Cindera if you opted in. You can withdraw consent at any time by emailing support@cindera.eu.
  • Legal obligation (Art. 6(1)(c)). Where applicable (e.g. accounting records, statutory retention).

Section 04

How long we keep data

  • Audit logs: 7 years from creation, retained for security, accountability and audit evidence purposes.
  • Scan data (findings, scores, configuration snapshots): retained for the duration of the subscription. On disconnect, scan data is purged 30 days after the EntraConnection is marked consent_revoked, unless you request earlier deletion.
  • Lead data from the public NIS2 assessment: 24 months from submission.
  • Account data: retained while the account is active and for 90 days after closure for incident-investigation purposes, then deleted.

Section 05

Sub-processors and transfers outside the EU

Cindera relies on the following sub-processors to deliver the service. We process customer data inside the EU where possible.

  • Supabase (PostgreSQL hosting) — EU region. No non-EU transfer.
  • Vercel (application hosting) — EU region. Some edge-network telemetry may transit US infrastructure; covered by Standard Contractual Clauses (SCCs).
  • Inngest(background jobs) — see Inngest's sub-processor list for current regions; covered by SCCs.
  • Resend(transactional email) — US. Covered by SCCs and Resend's GDPR commitments.
  • Upstash (rate-limit Redis) — EU region. No customer scan data is stored here; only counter keys derived from tenant or IP identifiers.
  • Microsoft(Entra ID, Graph API) — the customer's own Microsoft tenant is the source of directory data, not a sub-processor of Cindera.

For transfers outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) together with supplementary measures where the recipient operates from a third country without an adequacy decision.

Section 06

Your rights

You may, at any time and free of charge, exercise the following rights:

  1. Access the personal data we hold about you.
  2. Have inaccurate data rectified.
  3. Have your data erased ("right to be forgotten"), subject to overriding legal obligations.
  4. Restrict processing in specific cases.
  5. Object to processing based on our legitimate interest, including for direct marketing.
  6. Receive your data in a structured, machine-readable format (portability) where the processing is based on consent or contract.
  7. Withdraw any previously given consent, without affecting the lawfulness of processing before the withdrawal.

To exercise any of these rights, email support@cindera.eu. You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, Rue de la Presse 35, 1000 Brussels, gegevensbeschermingsautoriteit.be).

Section 07

Security

  • Microsoft Graph access tokens are never persisted; they are requested per scan and discarded immediately after use.
  • Every database query is scoped by tenant identifier and every write is recorded in a tamper-evident audit log.
  • All traffic is served over TLS with HSTS, and the application sets a strict Content Security Policy and other modern security headers.
  • Customer data is primarily stored and processed in EU-hosted infrastructure.

Section 08

Cookies

Cindera uses only the cookies that are strictly necessary to provide the service:

  • Authentication cookie issued by Auth.js to keep you signed in.
  • CSRF / state cookies used during sign-in and the Microsoft 365 admin-consent flow.

Where technically necessary for authentication and session management, Cindera may also use the browser's localStorage and sessionStorage (for example, to keep transient UI state across reloads). These stores hold no marketing or tracking data.

We do not use analytics or advertising cookies. No consent banner is required because no non-essential cookies are placed.

Section 09

Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change we will update the "last updated" date at the top of the page and, where appropriate, notify you in-app or by email.