Repolicy Privacy Policy
Last updated: 2026-07-23
This Privacy Policy explains what data Repolicy processes, why, where it is stored, and your rights. Repolicy is provided by Circle Of Bytes ApS ("Circle Of Bytes", "we", "us"), Denmark. For privacy questions, contact tma@circleofbytes.com.
Repolicy is a business tool for managing Microsoft Intune policy as code. It is designed to hold the minimum data needed to operate, and to keep your policy content and your credentials out of our database wherever possible.
1. Who is the controller
For the account, sign-in and billing data described below, Circle Of Bytes is the controller. For the Microsoft Intune configuration data we process on your instruction when managing your (or your customers') tenants, you are the controller and Circle Of Bytes acts as your processor.
2. Data we process
Account and sign-in data. When operators sign in with Microsoft Entra, we process the identifiers Entra returns (such as name, email/UPN and tenant id) to authenticate you and record who performed operator actions. Customer users signing in to the read-only portal are authenticated against their own Entra directory and are scoped to their own tenant.
Microsoft Graph / Intune data. With a Global Administrator's one-time admin consent to our multi-tenant "Repolicy Connector" application, we access each connected tenant with app-only (application) Microsoft Graph permissions to provide the service:
- DeviceManagementConfiguration.ReadWrite.All - read and write device configuration
profiles, Settings Catalog, compliance policies, Windows Update rings and endpoint-security intents.
- DeviceManagementApps.ReadWrite.All - read and write app protection policies.
- DeviceManagementScripts.ReadWrite.All - read and write platform scripts and proactive
remediations.
- DeviceManagementServiceConfig.ReadWrite.All - read and write enrollment-time
configuration (Autopilot, enrollment configs including the Enrollment Status Page, enrollment platform restrictions, Windows Hello for Business).
- DeviceManagementManagedDevices.Read.All - read managed-device state for compliance
context (read-only).
- Group.Read.All - resolve assignment target groups (read-only).
We request no directory-write, user-management, mail or delegated Graph access. Repolicy only ever modifies policies it created (marker-gated) and writes nothing without a planned diff and an explicit approval. Live Intune state read during a job is held transiently in a per-job temporary directory and best-effort deleted afterward.
Policy configuration content. Your policy content lives in your own (or your customer's) GitHub repository, not in our database. We access it through a scoped GitHub App installation only to render, diff, plan and apply changes.
Operational and audit data. Our database stores jobs, rendered plans (diffs), tenant pointers, and an append-only audit log of operator actions (actor, timestamp, tenant, subject, short detail). Audit entries are retained by default for 365 days.
Payment data. Paid subscriptions are processed by Stripe, our payment processor. Stripe collects and processes your payment details; we do not receive or store card data. We store only the minimum subscription facts needed to grant access (status, plan, seat cap and the Stripe subscription id).
3. Credentials handling
Microsoft Graph access tokens are minted per tenant using the OAuth2 client_credentials grant, cached in memory only, never written to disk or database, and never logged. GitHub access uses short-lived GitHub App installation tokens (or a static token fallback). Application secrets are held in Azure Key Vault and read via managed identity. Operator and customer browser sessions never hold a Graph or backend token.
4. Where data is stored (residency)
- Compute runs on Azure Container Apps in North Europe.
- The application database (Azure SQL) is in Sweden Central.
- Your policy content stays in your GitHub repository; payment data stays with Stripe.
Where a subprocessor (Microsoft Azure, GitHub, Stripe) processes data outside the EEA, it does so under appropriate safeguards such as Standard Contractual Clauses.
5. Subprocessors
- Microsoft Azure - hosting, compute, database, Key Vault (North Europe / Sweden
Central).
- Microsoft Graph - the API through which connected Intune tenants are managed, on
your instruction.
- GitHub - source of truth for your policy configuration.
- Stripe - payment processing for paid subscriptions.
6. Legal bases (GDPR)
We process operator account data and operational data to perform our contract with you and for our legitimate interest in securing and operating the service. We process connected Intune data as your processor, on your documented instructions. We process billing data to perform the subscription contract and to meet legal (accounting) obligations.
7. Retention
Audit entries are retained for 365 days by default. Operational records (jobs, plans, tenant pointers) are retained while your account is active and deleted or anonymized after account closure per our retention practices. Billing records are retained as required by Stripe and by applicable accounting law. Revoking tenant consent immediately ends our Graph access; your policies remain in place in your tenant.
8. Your rights
Subject to applicable law (including the GDPR), you have the right to access, correct, export, restrict, object to, and request deletion of personal data we hold about you. To exercise any right, including deletion, email tma@circleofbytes.com; we will respond within the timeframes required by law. You also have the right to lodge a complaint with a supervisory authority (in Denmark, Datatilsynet).
9. Security
We use app-only least-privilege Graph access, marker-gated writes, server-side allowlists, approval gates, tenant isolation between the operator and read-only customer surfaces, secrets in Azure Key Vault, and an append-only audit log. See the Repolicy security overview for detail.
10. Changes
We may update this policy from time to time. Material changes will be posted at https://www.repolicy.io/privacy with an updated "Last updated" date.
11. Contact
Circle Of Bytes ApS, Denmark. Privacy contact: tma@circleofbytes.com.