Privacy and data processing
This page describes what the Sporlock app does with your data. It is the basis for the data processing agreement: when you approve Sporlock, Tielemans Software is a processor for you (the controller) for the data processed in the scan.
Data flow
- Sign-in: Microsoft sends us your name, e-mail, organization id and admin roles. We keep them in a signed cookie for 8 hours, not in a database.
- Scan: a Cloudflare Worker (Durable Object, located in the EU) fetches one file at a time from Microsoft Graph, reads the text in memory, finds CPR numbers and discards the content. File content is never written to disk, logs or a database.
- Report: for files with findings or something unreadable we store the file id, number of findings, highest confidence, whether the file was read fully, and sharing state (link type, number of external and internal people). Not the file name, not the URL, not the numbers themselves, not even masked. File names are fetched from Microsoft when you view the report.
- Lock down: when you ask, Sporlock Lockdown removes sharing permissions via Microsoft Graph. The audit log stores the time, who asked, file id, link type and role, and for people their e-mail, so the change can be undone.
- Payment: Stripe is the merchant of record. Stripe receives your payment details directly; we store only Stripe's customer and subscription ids, plan and number of users.
Hosting and storage
- Cloudflare Workers; the database is Cloudflare D1 with EU jurisdiction (data stored in the EU). The scan runs in a Durable Object with EU jurisdiction.
- Scan results: deleted after 30 days, or when a new scan finishes.
- Everything about your organization: deleted 30 days after the subscription ends, or immediately when you ask under “Data”.
- No analytics, no third-party scripts, no tracking cookies.
Subprocessors
| Who | What | Where |
|---|---|---|
| Cloudflare, Inc. | Hosting (Workers, D1, Durable Objects) | EU for data at rest; processing in EU-located Durable Objects |
| Stripe Payments Europe, Ltd. | Payment, VAT, invoices (merchant of record) | EU/US (Stripe's own privacy policy) |
| Microsoft | Sign-in (Entra ID) and access to your files (Graph); data stays in your Microsoft 365 | Your own Microsoft 365 region |
Permissions
| Permission (Microsoft Graph, application) | Why |
|---|---|
Files.Read.All | Read files in SharePoint and OneDrive and see who they are shared with. Content is read in memory, checked for CPR numbers and discarded immediately. |
Sites.Read.All | Find every SharePoint site and its document libraries. |
User.Read.All | Find each user's OneDrive, know your own domains (internal or external sharing) and count licensed users for the price. |
Files.ReadWrite.AllSeparate app, “Sporlock Lockdown”, only when you lock down | Remove sharing links and external access on the files you choose. It is the narrowest Microsoft Graph permission that can remove sharing on arbitrary files. Technically it also allows changing files; Sporlock never changes, moves or deletes a file, only sharing, and every change is in the audit log. |
Only a Global Administrator or a Privileged Role Administrator can approve application permissions for Microsoft Graph. That is Microsoft's rule; a Cloud or Application Administrator can't.
Separation between customers
Each organization has its own scanner (one Durable Object per organization), and every database query is scoped to the organization of the signed-in admin. Only users with an admin role in the organization can see the report.
Contact and DPA
Tielemans Software · CVR 46735773 · Jomfru Ane Gade 2, 1. tv., 9000 Aalborg · martin@tielemans.dev. Write to us for a signed data processing agreement or to access or delete data. The website's own privacy policy: cpr.tielemans.dev/privatliv/