← Conflikt

Privacy Policy

Version 2026-08-06 · effective 2026-08-06

Revision history
  • 2026-08-06re-acceptance required

    Listed Sentry among the processors that receive data, with the same scrubbing detail.

This document is not yet complete.

The operating entity has not been published. Until it is, this page does not satisfy GDPR Art. 13(1)(a) and must not be relied on as the notice given to data subjects. Missing: name, address, registrationNumber, vatNumber, contactEmail, supervisoryAuthority. Set them in src/lib/legal/entity.ts.

What we store

Your account (email address, subscription state), the tenants you connect (tenant id, directory name, domain, consent timestamps), per-app deployment preferences (auto-update settings, packaging options), and an audit trail of actions taken through Conflikt (action, target, timestamp, IP address, browser user-agent). Billing details are held by Stripe; we store only your Stripe customer reference.

What we do not store

Conflikt does not store your Intune data. Device lists, profiles, compliance states and app inventories are fetched live from the Microsoft Graph API when you view them and cached only in your own browser. Installer binaries are processed in memory during packaging and are not retained.

Access to your tenant

Delegated access acts as the signed-in administrator and lives in your browser. If you enable background access, an application credential lets Conflikt's servers read app metadata and publish app updates without your session — scoped to the permissions consented in your tenant, revocable at any time by removing the enterprise application in Microsoft Entra.

Cookies

Conflikt sets only strictly necessary cookies: your sign-in session (Supabase authentication) and, on payment pages, Stripe's fraud-prevention cookies. Preferences such as your viewed tenant and cached tenant data live in your browser's local storage and never leave it. We use no analytics, advertising or cross-site tracking cookies — which is why you don't see a consent banner.

Processors

Supabase (database and authentication), Vercel (hosting), Stripe (payments), Microsoft (Graph API), Sentry (error monitoring — diagnostic data only, with tokens, request bodies and query strings stripped before they leave our servers), and — when notifications are enabled — Resend (email delivery). Each receives only what its function requires.

Why we may process it (legal bases)

Running your account, connecting tenants and publishing the apps you ask us to publish are processing necessary to perform our contract with you (GDPR Art. 6(1)(b)). The audit trail, rate limiting, and error monitoring rest on our legitimate interest in operating a secure service and being able to show what an account did in someone's tenant (Art. 6(1)(f)) — an interest we consider to outweigh the limited impact, since the data is operational and short-lived. Retaining billing records is a legal obligation (Art. 6(1)(c)). We do not rely on consent for anything, which is why there is no consent banner: the only cookies we set are strictly necessary.

Where your data goes

Our database and authentication run in the EU (Supabase, eu-west-1) and our application in Dublin (Vercel, dub1). Some processors are established in the United States and may process data there: Stripe, Vercel, Sentry and Resend. Those transfers rely on the European Commission's Standard Contractual Clauses, incorporated into each provider's data processing terms, together with the EU-U.S. Data Privacy Framework where the provider is certified. Your Microsoft 365 tenant data stays in your own tenant — we read it live and do not store it.

Retention and deletion

Audit entries are retained per your plan (30 days to 1 year). Disconnecting a tenant removes its stored metadata; deleting your account removes your profile, tenant records, deployment preferences and audit trail.

Your rights

Under the GDPR you may request access to your personal data, correction of it, deletion of it, restriction of its processing, and a portable copy; and you may object to processing we base on legitimate interest. Account export and deletion are available directly under Settings → Account without contacting us. For anything else, write to the address below — we respond within one month. You also have the right to lodge a complaint with a data protection supervisory authority, in the member state of your habitual residence, place of work, or where you believe an infringement occurred.

Providing your data

The email address and payment details you give us are required to enter into and perform the contract — without them we cannot create an account or bill you. Everything else, including whether you grant background access to a tenant, is optional and affects only which features work.

Automated decision-making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. Automatic app updates act on the deployment rules you configure, not on any evaluation of a person.

Who we are

Data controller: [legal entity not yet published]. Contact: [legal entity not yet published].