PRIVACY.policy()
RGPDLast updated: February 2026
1. Data controller
The data controller is:
Sendouk
47 rue Vivienne
75002 Paris, France
mycontact+privacy@autoappsdeploy.com
2. Data collected
We collect the following categories of data:
Identification data
- • First and last name
- • Professional email address
- • Microsoft identifier (via Azure AD)
Technical data
- • Microsoft tenant identifier
- • OAuth tokens (AES-256 encrypted)
- • IP address and browsing data
- • Activity logs
Usage data
- • Deployed applications
- • Deployment history
- • Notification preferences
Security data
Collected automatically for platform protection
- • IP address during connections and sensitive actions
- • Login attempt timestamps
- • Security alerts (brute force, anomalies)
3. Processing purposes
Your data is processed for the following purposes:
| Purpose | Legal basis |
|---|---|
| Authentication and account management | Contract execution |
| Application deployment to Intune | Contract execution |
| CVE vulnerability detection | Legitimate interest |
| CVE newsletter sending | Consent |
| Service improvement | Legitimate interest |
| Billing and accounting | Legal obligation |
| Security and threat detection | Legitimate interest |
4. Data retention
| Data type | Duration |
|---|---|
| Account data | Contract duration + 3 years |
| OAuth tokens | Token validity period |
| Activity logs | 12 months |
| Billing data | 10 years (legal obligation) |
| Cookies | 13 months maximum |
| Security alerts and logs | 90 days |
5. Your rights
In accordance with the GDPR, you have the following rights over your data:
Right of access
Obtain a copy of your personal data
Right to rectification
Correct inaccurate or incomplete data
Right to erasure
Request deletion of your data
Right to portability
Receive your data in a structured format
Right to object
Object to the processing of your data
Right to restriction
Restrict the processing of your data
Right to withdraw consent
Withdraw your consent at any time for processing based on it (cookies, newsletter)
To exercise your rights: mycontact+privacy@autoappsdeploy.com
Complaint to the CNIL: www.cnil.fr
6. Transfers outside the European Union
In the context of using Microsoft Azure and Graph API services, some data may be transferred to servers located outside the European Union.
These transfers are governed by:
- • Standard Contractual Clauses (SCC) of the European Commission
- • Microsoft's Data Processing Agreement
- • ISO 27001 and SOC 2 certifications of Microsoft Azure
- • OVHcloud's Data Processing Agreement (hosting, servers in France)
7. Microsoft Graph API Permissions
Our application uses the Microsoft Graph API to interact with Microsoft Intune. Here are the requested permissions:
Login permissions (Delegated)
Used only to identify you during login
- •
User.Read- Read your Microsoft profile - •
openid, profile, email- OpenID Connect authentication
Intune permissions (Application)
Granted to the application during administrator consent
- •
DeviceManagementApps.ReadWrite.All- Deploy Win32 applications - •
DeviceManagementConfiguration.ReadWrite.All- Manage assignments - •
DeviceManagementManagedDevices.Read.All- Read managed devices - •
Directory.Read.All- Read users and groups - •
Group.Read.All- Target deployments by group
Important note: Intune permissions are of type "Application" and not "Delegated". This means the application acts on its own behalf to perform deployments, without using your personal rights. You can revoke these permissions from your organization's Azure AD portal.
8. Cookies
Our site uses the following cookies:
| Cookie | Type | Purpose |
|---|---|---|
| __session | Essential | User session |
| sidebar_state | Functional | Interface preference |
| app-ui-theme | Functional | Light/dark theme |
Essential cookies cannot be disabled as they are necessary for the service to function.
8.5. Indexing by AI crawlers
AutoAppsDeploy explicitly authorizes the following AI crawlers to index its public content (marketing pages, pricing, documentation, legal notices):
- • GPTBot, ChatGPT-User, OAI-SearchBot (OpenAI / ChatGPT search)
- • ClaudeBot, anthropic-ai, Claude-Web (Anthropic / Claude)
- • Google-Extended (Google Gemini training)
- • PerplexityBot (Perplexity AI)
- • CCBot (Common Crawl, feeding many LLMs)
- • Applebot-Extended (Apple AI training)
This authorization applies only to public pages. No user data, dashboard content, or private information is accessible to these crawlers (blocked by robots.txt and auth-required).
This policy aims to maximize AutoAppsDeploy's visibility in modern AI searches while strictly preserving user data privacy.
No personal data (email, name, user IP) is exposed to AI crawlers. Only public marketing content, product features, and terms of service are indexable.
If you are a user and wish to exclude your specific content from AI indexing, contact us: your dashboard and all data concerning you are already inaccessible to AI crawlers by default.
9. Data security
We implement appropriate technical and organizational measures to protect your data:
- ✓ AES-256 encryption of sensitive data
- ✓ HTTPS/TLS connections
- ✓ OAuth 2.0 authentication via Azure AD
- ✓ Hosting on ISO 27001 certified infrastructure
- ✓ Regular encrypted backups
- ✓ Restricted access based on the principle of least privilege
10. Contact
For any questions regarding this privacy policy or to exercise your rights:
Privacy contact
mycontact+privacy@autoappsdeploy.com