Privacy Policy
How Cyninges handles information across cyninges.com, our cybersecurity products and services, and our Microsoft Marketplace offerings.
EFFECTIVE DATE: 5 AUGUST 2026 · LAST UPDATED: 10 SEPTEMBER 2026
Contents
- Who we are & scope
- Information we handle
- Microsoft Marketplace transactions
- Marketplace landing page
- Marketplace subscription notifications
- Microsoft Entra ID / sign-in
- Your Azure environment
- How we use information
- Cookies & translation
- Sharing with third parties
- International handling
- Retention
- Your rights & choices
- Enterprise customers
- Protecting information
- Children
- Changes to this policy
- Contact
1. Who we are & scope
Cyninges ("Cyninges", "we", "us") provides this website, our cybersecurity products and services, and offerings distributed through Microsoft Azure Marketplace and AppSource. This policy applies to cyninges.com, the Marketplace landing page and subscription notification service described below, Microsoft Entra ID sign-in where used, customer provisioning and support, and our other technical and business communications. It is not limited to website cookies.
2. Information we handle
Depending on how you or your organization use our site, products or Marketplace offerings, we may handle information such as:
- Information you provide — for example your name, work email, organization and message, when you submit a form.
- Account & identity information — where applicable, business contact details and identifiers associated with your organization's use of our products.
- Marketplace subscription information — see Section 3.
- Technical & security information — IP address, browser/device information, timestamps, request identifiers, error information, authentication events and security logs, generated by using our site, products or APIs.
- Preference information — such as your language and cookie choices.
Not every category applies to every product or interaction; we aim to collect only what is reasonably necessary for the service, transaction, security or legal purpose involved.
3. Microsoft Marketplace transactions
When your organization acquires or manages a Cyninges offer through Microsoft Azure Marketplace or AppSource, Cyninges may receive information from Microsoft that is reasonably necessary to process and support that transaction. Where made available by Microsoft, this may include a Marketplace subscription identifier, offer and plan identifiers, quantity, subscription status, an operation identifier, your organization's Microsoft tenant identifier, organization/customer information, contact information, and status information relating to purchase, provisioning, renewal, suspension, reinstatement or cancellation. Microsoft determines what it makes available to publishers for this purpose; Cyninges does not claim to receive fields beyond what Microsoft actually provides.
4. Marketplace landing page
Immediately after a purchase or configuration action on Microsoft Marketplace, Microsoft may direct your organization's administrator to a Cyninges landing page. That page processes a one-time, Microsoft-issued authentication/purchase token only as technically necessary to identify and validate the subscription, complete onboarding and, where applicable, begin provisioning; the token itself is not intended to be publicly displayed, permanently stored or emailed. Resulting subscription and transaction information is used for subscription identification, transaction validation, customer onboarding, account association, provisioning and support.
5. Marketplace subscription notifications
Microsoft may also send Cyninges automated subscription lifecycle notifications — for example when a subscription is created, its plan or quantity changes, it renews, is suspended, reinstated, or unsubscribed/cancelled. We use this information for subscription administration, entitlement and licensing, provisioning, customer support, security, audit and general service operations. These notifications are also used internally to alert authorized Cyninges personnel so subscription events are handled promptly; internal recipients are configured in our backend systems and are not published here.
6. Microsoft Entra ID / sign-in
Where a Cyninges product or Marketplace offer uses Microsoft Entra ID for sign-in or service-to-service authentication, we may receive permitted identity information such as name, business email or user principal name, tenant identifier, organization identifiers and authentication identifiers, depending on the permissions granted and configuration in place. This information is used for authentication, authorization, account association, administration, support and security. Cyninges does not have unrestricted access to your organization's Microsoft tenant beyond what is explicitly authorized.
7. Your Azure environment
It's important to distinguish between (a) systems Cyninges controls (this website, our Marketplace backend, our support and business systems) and (b) resources that may be deployed into your own organization's Azure subscription as part of a Cyninges offer. Where an offer deploys resources into your Azure environment, Cyninges' ability to access or act on those resources depends on the authorization, permissions, deployment architecture and support arrangement you or your organization have configured. Cyninges does not claim ownership of resources deployed into your Azure subscription.
8. How we use information
- To respond to enquiries and requests you send us, and deliver our products and services.
- To process Marketplace transactions, validate subscriptions, and manage licensing and entitlements.
- To provision, configure, support and operate the services you or your organization have subscribed to.
- For authentication, account administration, and security monitoring, audit and troubleshooting.
- To meet contractual and legal obligations, and to prevent fraud or abuse of our services.
- To operate, maintain and improve this website and remember your preferences.
We do not use Marketplace or subscription data for advertising or marketing purposes.
9. Cookies & translation
We aim to use cookies and similar storage only where reasonably necessary to run the site, such as remembering your language and cookie preferences. An optional language switcher, where offered, may rely on a third-party translation service, which can set its own cookies and process the page text you choose to translate. Where a cookie banner is presented, optional features are enabled only after your choice, and you can generally change your choice at any time via the site's cookie settings.
10. Sharing with third parties
We do not sell personal information. We may share information with categories of third parties where reasonably necessary to deliver our services, including: Microsoft (as the Marketplace and, where applicable, identity platform through which your organization transacts), hosting and infrastructure providers, email/communications providers, professional advisers and auditors, authorized contractors who support our operations, and government or regulatory authorities where required by law. We do not disclose confidential details of our vendor or technology-partner relationships beyond what is already public.
11. International handling
Cyninges operates internationally, and Microsoft Azure infrastructure spans multiple regions. Depending on the deployment region you or your organization select, and on where our own operations and service providers are located, information may be processed in more than one jurisdiction. Where legally required, we use appropriate safeguards for such transfers. We do not promise that all information stays within a single country unless a specific service technically guarantees that.
12. Retention
We retain information for as long as reasonably necessary for the service term, transaction and support requirements, security, accounting and legal obligations, and dispute resolution, after which it is deleted, anonymized or otherwise disposed of, subject to any obligation to retain it longer.
13. Your rights & choices
You can generally choose not to provide certain information, though this may limit some features (for example, a contact form requires an email address to respond). Depending on applicable law, you may have rights to access, correct, delete, restrict or object to certain processing of your information, to receive a copy of it, and to lodge a complaint with a relevant authority. Some information may need to be retained despite a request, where necessary for legal, accounting, security, transaction or dispute-resolution purposes. To exercise a privacy right or ask a question, use the contact details in Section 17. Operational, service and security communications (such as Marketplace subscription or provisioning notices) are necessary to deliver the service and are not treated as optional marketing you can opt out of.
14. Enterprise customers
Cyninges primarily serves organizations rather than individual consumers. Your organization may manage its own users' accounts and access. Depending on the context, Cyninges may act as a processor/service provider handling information on your organization's behalf, or as a controller/business for information relating to our own relationship with you; where this distinction matters, it will generally be addressed in the applicable commercial agreement. Requests relating to information within your organization's control may need to be coordinated with your organization.
15. Protecting information
We use safeguards such as access controls, authentication, encryption in transit, least-privilege permissions, monitoring and logging, vulnerability management, secure development practices, and backup and incident-response processes appropriate to the information involved. We do not publish the details of our defensive architecture, as doing so could assist an attacker. No method of storing or transmitting information over the internet can be guaranteed completely secure, and we cannot guarantee absolute security. Where required by law or contract, we maintain a process to investigate and respond to security incidents.
16. Children
Cyninges is a business-to-business technology provider. Our services are intended for use by business and government customers and are not directed at, or knowingly offered to, children.
17. Changes to this policy
We may update this policy from time to time to reflect changes to our site, products, Marketplace offerings or practices. The effective and last-updated dates above reflect the current version. Continued use of our site or services after an update constitutes acknowledgement of the revised policy.
18. Contact
Questions about this policy, or requests relating to your information, are welcome via our contact page. This policy is provided for general information about our approach to privacy and does not itself create additional rights or obligations beyond those provided under applicable law.