← Conflikt

Data Processing Agreement

Version 2026-08-06 · effective 2026-08-06

Revision history
  • 2026-08-06re-acceptance required

    Named Sentry (Functional Software, Inc.) as a sub-processor for error monitoring, and described the scrubbing applied before diagnostic data leaves our servers.

This document is not yet complete.

The operating entity has not been published. Until it is, this page does not satisfy GDPR Art. 13(1)(a) and must not be relied on as the notice given to data subjects. Missing: name, address, registrationNumber, vatNumber, contactEmail, supervisoryAuthority. Set them in src/lib/legal/entity.ts.

Pending legal review. Enterprise customers who need a countersigned DPA can request one through the in-app support channel.

1. Parties and scope

This Data Processing Agreement (“DPA”) forms part of the agreement between [legal entity not yet published] (“Processor”, “Conflikt”) and the customer accepting it (“Controller”). It governs the processing of personal data that Conflikt performs on the Controller's behalf when providing the Conflikt service.

2. Subject matter and nature of processing

Conflikt reads Microsoft Intune configuration, device and application inventory from the Controller's Microsoft 365 tenants through the Microsoft Graph API, and publishes applications and updates to those tenants on the Controller's instruction or through automation the Controller enables. Processing consists of reading, temporary caching, aggregation and display of this data, and storage of derived summaries.

3. Categories of data and data subjects

Personal data processed: names, email addresses (user principal names) and device assignments of the Controller's tenant users; device names, identifiers and compliance state; names and email addresses of the Controller's Conflikt team members. Data subjects: the Controller's employees and other users managed in its Microsoft 365 tenants. Conflikt does not process special categories of personal data.

4. Duration

Processing lasts for the term of the service agreement. Live Graph data is cached only transiently; stored derived data (daily snapshots, audit trail, deployment records) is deleted on account deletion, and audit records additionally age out per the plan's retention window (30/90/365 days).

5. Controller instructions

Conflikt processes personal data only on documented instructions from the Controller — the configuration and actions the Controller takes in the app, including automation it enables — unless processing is required by law, in which case Conflikt informs the Controller unless legally prohibited.

6. Confidentiality and personnel

Persons authorized to process personal data are bound by confidentiality obligations. Access to production systems is restricted to personnel who need it to operate the service.

7. Security measures (Annex)

Conflikt implements appropriate technical and organizational measures, including: encryption in transit (TLS) everywhere; row-level security on all customer data; per-workspace isolation with server-side tenant-ownership verification on every request; role-based access with separation of duties; signed webhooks; SSRF-guarded outbound requests; durable rate limiting; a complete audit trail of mutating actions; daily off-hours processing limited to tenants that granted background access; EU data residency (hosting in eu-west-1 / Dublin with compute pinned to the same region).

8. Subprocessors

The Controller authorizes these subprocessors: Vercel Inc. (application hosting), Supabase Inc. (database and authentication, EU region), Stripe Inc. (payment processing), Resend (transactional email), Functional Software, Inc. dba Sentry (error monitoring — diagnostic data only, scrubbed of tokens and request bodies before transmission), Microsoft Corporation (Graph API, as directed by the Controller's own tenant). Conflikt notifies the Controller of intended subprocessor changes at least 14 days in advance, giving the Controller the opportunity to object.

9. International transfers

Customer tenant data is stored in the EU. Where a subprocessor processes personal data outside the EU/EEA (e.g. support metadata or billing), transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, as implemented in the subprocessor's own data processing terms.

10. Data subject rights and assistance

Taking into account the nature of processing, Conflikt assists the Controller with data subject requests: the account export provides all stored personal data in machine-readable form, and account deletion removes it. Conflikt forwards any data subject request it receives directly to the Controller without responding to it.

11. Personal data breaches

Conflikt notifies the Controller without undue delay, and at the latest within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably required for the Controller's own notification obligations.

12. Audits

Conflikt makes available the information necessary to demonstrate compliance with this DPA — including the audit-trail export and this document's security annex — and allows for audits conducted by the Controller or an auditor it mandates, at reasonable intervals, upon reasonable notice, and at the Controller's expense.

13. Deletion and return

Upon termination, the Controller can export stored data (account export, CSV exports, audit export) and delete the account, which removes stored personal data. Residual copies in encrypted backups are overwritten in the backup rotation.

14. Liability and precedence

Liability under this DPA follows the liability provisions of the service agreement. In case of conflict between this DPA and the Terms of Service, this DPA prevails for data protection matters.

See also the Privacy Policy and Terms of Service.