DeliverablesHow it worksSecurityPricingLog in
Legal · last updated 2 June 2026

Privacy policy

Plain language about what we see, where it lives, and what we never touch.

SimpleEntra is a read-only security posture tool. We have made this page straightforward for CISOs, DPOs and auditors to get an overview. For more technical depth — see our technical walkthrough.

1 · Who we are

SimpleEntra is provided by Zaulich ApS (company registration details provided to contracting parties as part of the Data Processing Agreement). Under GDPR we are a data processor — your organisation (or your MSP) is the data controller. We only process data on instruction from the data controller, documented in the Data Processing Agreement.

2 · What data we process

We read Microsoft Graph data from your Entra ID tenant via a set of read-only Application permissions. Specifically:

  • User metadata (name, UPN, last login, licence, MFA registration status)
  • Device metadata (OS, compliance status, last seen)
  • Sign-in logs (last 30 days)
  • Conditional Access policies
  • App registrations + service principals (metadata on secrets, not values)
  • Security signals — risky users, risk events

We never read email, calendars, OneDrive files, SharePoint content, Teams messages or any user-generated content. Mail.Send, Mail.Read or similar do not exist in our permission set.

3 · Legal basis

We process personal data on the basis of the Data Processing Agreement with you (data controller), pursuant to art. 28 GDPR. The data controller decides purpose and means. SimpleEntra's purpose is limited to:

  • Generating security posture reports
  • Identifying configuration risks
  • Mapping to compliance frameworks (NIS2, ISO 27001, DORA, CIS)
  • Audit trail of findings and actions

4 · Where data is stored

All persisted data is stored in Supabase Postgres in AWS eu-central-1 (Frankfurt). We store all your data in the EU. Supabase is certified under SOC 2 Type II and HIPAA.

Connections between all components (customer browser → portal → database) are TLS 1.2+. Data at rest is encrypted by Supabase (AES-256 via AWS KMS). Graph tokens are not stored permanently — they are fetched fresh on each call via client credentials flow.

5 · Retention period

Data is retained while you're an active customer. On cancellation we delete everything within 30 days — findings, sign-ins, devices, users. If you revoke consent, contact us for immediate deletion.

If you delete your tenant from the portal, we delete all associated data immediately. If you revoke admin consent in Microsoft Entra, our next Graph call will fail and our scans will stop. Contact us if you want the historical data deleted right away.

6 · Sub-processors

We use the following third-party processors. The list is exhaustive — there are no others.

ProviderPurpose
SupabasePostgres database + authentication · Region: EU-Frankfurt · Scope: all persisted customer data · DPA via Supabase
Microsoft GraphRead-only data collection from your tenant's region · Transient — data processed in transit
VercelHosting of portal frontend · Region: Frankfurt (fra1) · Processes no customer data persistently — request/response stream only

7 · Frameworks we map to

We map every check to publicly available standards — CIS Microsoft 365 Benchmarks, CISA SCuBA and EIDSCA. We do not invent our own controls. The test catalog itself is developed and maintained by the SimpleEntra team based on real-world experience with Entra ID configurations.

No affiliation: SimpleEntra is not affiliated with, endorsed by or sponsored by Microsoft unless explicitly stated.

8 · Data Processing Agreement

A signed Data Processing Agreement is a mandatory prerequisite for production use. Contact us for a copy.

Read the current draft (GDPR Art. 28 — final document reviewed by legal counsel before signing): SimpleEntra-DPA-en.pdf.

9 · Your rights under GDPR

As a data subject you have the right to:

  • Access your data (art. 15)
  • Rectification of incorrect data (art. 16)
  • Erasure (“right to be forgotten”, art. 17)
  • Restriction of processing (art. 18)
  • Data portability (art. 20)
  • Objection (art. 21)

Requests about these rights are handled primarily by the data controller (your MSP or organisation). For technical questions about what data SimpleEntra holds, contact us directly — see below.

10 · Cookies on the marketing site

We use no tracking cookies on simpleentra.com. No Google Analytics, no Meta Pixel, no advertising trackers. If we add analytics later, we will use a privacy-first solution (Plausible or similar) and update this page.

The demo at /demo (proxied from our portal) sets one technical cookie (simpleentra_demo) to give you access to the demo tenant. It expires after 4 hours.

11 · Personal data breaches

If we discover a personal data breach involving your data, we will notify the data controller without undue delay — at the latest within 72 hours of becoming aware (the GDPR standard). The notification will include the nature of the breach, categories and approximate number of affected individuals, consequences, and remedial measures.

12 · Contact

Questions about data handling, DPA, deletion or rights:

Mads Zaulich
Zaulich ApS
hello@simpleentra.com

Complaints can also be submitted to the Danish Data Protection Authority (datatilsynet.dk).