Data protection
Privacy notice
Last updated: 16 August 2026
This notice covers the public website and free guide, branded previews, hosted branded-guide enquiries and delivery, optional connected personalisation for a directly opened paid-org guide, the separate legacy Rollout Kit, and business outreach. The homepage, generic setup guide, public branding preview and enquiry never connect to a Microsoft tenant, request Graph permissions or make a hidden sign-in request. Connected personalisation is a separate customer-enabled feature described below.
None of these free or public actions connects to your Microsoft tenant.
Who is responsible for the data?
Kinane Labs Ltd, operator of SetupPasskeys, is the controller for order administration, enquiries, service security, product measurement and its own business outreach. Contact: privacy@setuppasskeys.com.
For payment data, Stripe also acts under its own legal responsibilities. Where an organisation asks SetupPasskeys to host personal data in a branded guide, or places personal data in legacy kit content and instructs SetupPasskeys to render, store or deliver it solely for that organisation, the organisation is normally the controller and Kinane Labs Ltd acts as processor for that limited processing. The offered processor terms are in the Data Processing Addendum. Do not submit Customer Personal Data that requires an executed DPA until that process is complete.
For connected personalisation ordered by an organisation, that organisation is normally the controller, or a processor acting on its controller’s instructions, for its employees’ Microsoft identifiers, group-match result and registered-passkey status. Kinane Labs Ltd acts as processor or subprocessor for that customer-directed processing. The customer decides its lawful basis, audience, notices, approved route mapping and retention instructions. Microsoft administrator consent authorises application access; it does not by itself decide the customer’s data-protection lawful basis.
Free and unconnected hosted-guide choices
The interactive guide keeps device type, platform, software-version, passkey-method, sign-in-mode and current-step choices in session storage so the visitor can continue in the same browser session. The guide does not need a name, work email, employee account, password or passkey, and those choices are not sent to Microsoft or the organisation’s tenant.
The same non-identifying choices are reflected in the current SetupPasskeys page URL so browser Back and shareable guide links work. As with other URLs, that address can appear in hosting request logs or a referrer. It contains the selected route and step, not an employee identity or authentication secret.
Public branded-guide preview
The public branded-guide preview asks only for a public company domain. SetupPasskeys sends that domain in a private request to its branding service to look for public Microsoft Entra sign-in branding and, where needed, public website or logo assets. This lookup uses public information and does not authenticate to the organisation’s tenant.
The preview does not ask for a work email, password, tenant admin connection or Microsoft consent, and the domain is not treated as a sales enquiry. Only the derived organisation domain and sanitised preview branding are kept in session storage for the current browser tab. The permissioned Dillons example runs locally without making a branding request or writing preview storage. A sales enquiry is sent only when you submit the separate enquiry form.
Hosted branded-guide service
To prepare an ordered guide, an organisation may supply its name, logo, colours, hosted address, employee-support route, intended audience and the passkey methods, providers, device types, platforms, software versions and sign-in situations it approves. This configuration is prepared manually by default. Unless the customer separately orders and enables connected personalisation, SetupPasskeys does not read it from the tenant or infer which Entra group an employee belongs to. The customer approves the guide before employee use.
Hosted-guide content is intended to use organisation-level details and a team support route rather than employee directory data. If a customer deliberately supplies a named support contact or other personal data for publication, it will be processed only for the agreed guide and should not be supplied until the order and any required DPA are complete. Do not include secrets, authentication data, special-category data or confidential incident material.
Optional connected paid-org personalisation
A paying customer may separately authorise a Microsoft Entra connection for its direct
employee guide. An authorised IT administrator must grant the stated read-only Microsoft
permissions on behalf of that tenant. This never starts from the homepage, generic
/setup/ route, public branding preview or enquiry, and entering a company
domain is not consent to it.
Opening an identity-enabled direct organisation guide can start one non-interactive
Microsoft account check automatically. If the browser already has a suitable Microsoft
work session and the administrator-approved permissions allow it, SetupPasskeys receives
the immutable Microsoft tenant and user object identifiers (tid and
oid) needed to bind the session to the correct customer. It asks Microsoft
Graph whether that user matches only the group identifiers referenced by the customer’s
approved passkey profiles. The service uses the returned match to choose an allow-listed
route; it does not request or show an employee’s general group list. If Microsoft requires
interaction, the automatic check stops without opening a login page.
SetupPasskeys can also request the work account’s registered Passkey (FIDO2) methods. The response is reduced to passkey type and count. Credential identifiers, display names, authenticator model or AAGUID metadata, attestation certificates and raw Graph responses are not returned to the browser or retained as an employee method history. SetupPasskeys does not receive the passkey private key, PIN, biometric data, recovery material or any secret that can use the credential.
Microsoft access and refresh tokens are kept in an encrypted server-side session. The
browser receives only an opaque, secure, HTTP-only session cookie and a reduced result
such as synced passkey detected
, device-bound passkey detected
or
couldn’t check
. Personalised results, group/profile identifiers and Microsoft
tokens are not written to the guide URL, local storage or session storage.
A registered method belongs to the work account. It is not proof that the passkey is available on the phone or computer currently viewing the guide. Connected personalisation does not evaluate Conditional Access, authentication strengths, device compliance, risk, licensing or every control that may affect registration or sign-in, and it does not register, use, delete or change a passkey or tenant policy.
Administrator consent does not guarantee silent single sign-on. An existing SetupPasskeys
session can be used immediately. Otherwise an eligible direct organisation guide makes at
most one non-interactive prompt=none attempt while the branded guide stays
available. If that attempt requires interaction, it stops and presents an explicit
Microsoft sign-in button; it does not automatically open an interactive login or loop.
To prevent automated identity-start abuse, a direct connected guide reduces the request’s network address and browser user-agent to a daily, server-keyed hash. The raw values are not stored in that quota ledger. The hash is used only for a ten-minute start limit and stops counting after ten minutes. Rows older than twenty minutes are removed on a later start for that organisation or by the daily purge, normally within approximately 24 hours.
Legacy Rollout Kit preview
The separate, unlinked and noindex Rollout Kit builder processes the
organisation domain, name, colours, logo, selected passkey methods, example work-email
format, helpdesk details, rollout date and custom notes that you enter. Public checkout is
currently unavailable.
The Rollout Kit renders the preview in your browser and remembers its functional builder choices in that browser’s local storage. Entering a domain or opening the public example does not create a lead, enquiry or standalone commercial record. For preview generation, the domain is sent to the branding lookup needed to retrieve public assets, subject to the ordinary network and service-log processing described below. A commercial record is created only if you separately submit an enquiry or start a purchase.
Please use a synthetic example account and do not enter passwords, passkeys, device or security-key PINs, Temporary Access Pass values, recovery codes, authentication tokens, live enrolment QR codes, special-category data or confidential incident evidence.
Legacy kit drafts, purchases and recovery
Before checkout, the kit configuration is stored with a random private token and recovery code so it can survive the Stripe redirect. Unpaid drafts expire seven days after the last save. After payment, the order record also holds the purchase email, Stripe Checkout session reference, payment and delivery state, package configuration and email-delivery timestamps.
The private token is an access credential. Anyone holding the private link may be able to restore and edit the associated kit. The shorter recovery code is used only with the purchase email to resend that link; it does not return the configuration directly.
Legacy kit payments and transaction emails
Stripe collects and processes payment-card, billing and tax information. SetupPasskeys does not receive or store full card numbers. Resend processes the recipient address and message content needed to deliver purchase, recovery and support emails. The service records delivery status so a confirmed purchase is not silently left without its link.
Enquiries and support
An enquiry may include name, work email, company domain, organisation-size band, intended rollout date, product interests, message, form location, landing URL and campaign parameters. The request user-agent and referrer are stored for context and spam triage. A truncated daily hash of the request IP address is retained for rate limiting; the enquiry row does not store the raw address. Separate daily server-keyed hashes of the request IP and submitted email are held in a quota ledger for about 25 hours so simultaneous spam requests cannot bypass the limit. Submitting an enquiry does not by itself subscribe the address to marketing.
A browser-generated submission UUID can be stored with the enquiry so a safe retry does not create a second record. After the enquiry is stored, Resend is used to attempt a notification to the controlled SetupPasskeys inbox containing the submitted enquiry details. The service records notification status, attempt time, attempt count, a bounded error message and the provider message identifier when supplied. If notification delivery fails, the enquiry remains in the service-role-only database and is marked for attention in the private admin; a public success response means the enquiry record was received, not that an email provider accepted the notification.
Preview domains are not commercial records
The public Rollout Kit does not send a preview or example domain to the historical domain-submission endpoint and does not create a standalone database row from that action. The preview domain remains part of the functional builder state in your browser. If you choose optional product measurement, it may also be included in that consented, pseudonymous visitor journey; that measurement is not treated as a sales lead and does not trigger follow-up.
Submitting the separate enquiry form creates an enquiry record. Starting a purchase creates the private draft and order records needed for checkout, delivery and recovery. Historical standalone domain-submission rows created by an earlier version of the Kit are not used to infer current interest or initiate follow-up and remain subject to the 90-day deletion schedule below.
Optional legacy-kit product and visitor measurement
First-party visitor measurement is off unless you actively choose “Allow analytics” in the legacy Rollout Kit privacy choices. If allowed, it records a random browser identifier, a separate per-tab visit identifier, campaign labels, funnel stages, the guides and guide pages viewed, and cumulative time while the page is visible. A deliberately submitted domain may also be attached to that visitor journey. This helps Kinane Labs Ltd understand return visits, multi-domain evaluation and which product material is useful. A preview measurement record is not a sales enquiry or commercial follow-up instruction.
The random browser identifier expires after 90 days and is not made from an IP address,
browser characteristics or another fingerprint. These measurement rows do not contain an
email address, IP address or IP hash, raw referrer, user-agent, precise location, prospect
token, guide text, helpdesk details or Microsoft tenant credentials. Campaign source may
use a tagged value such as reddit; an untagged referral is reduced to a
hostname in the browser.
Business prospect and outreach data
Private sales tooling may store organisation domains, public DNS/Entra signals, public website branding and business contact details published on the organisation’s own website, together with source URLs and evidence. A personalised preview link can record a truncated hash of the visitor IP address, user-agent, referrer, visit timing and product progression. That particular visit hash is not daily-rotated and can associate repeat visits from the same address.
Outreach email records can include delivery, first-open, click/preview engagement, suppression and unsubscribe state. Open detection uses a small remote image; mail-client privacy features may block or proxy it, so it is not treated as proof that a person read an email. Every marketing message must provide a suppression or unsubscribe route.
Request metadata and service security
Hosting, database and email providers necessarily process network and diagnostic data such as IP address, request time, URL, response status and user-agent in their service logs. SetupPasskeys also uses daily server-keyed hashes to limit anonymous kit saves, branding image proxy requests and enquiry submissions. They also limit paid-link recovery attempts, purchase verification and document downloads. Connected identity starts use the separate twenty-minute quota described above. Short database leases prevent duplicate verification and document-generation work. Raw IP addresses, email addresses, recovery codes, Stripe session IDs and private kit tokens are used only in memory for those calculations; the other keyed quota and expired lease records are deleted after approximately 25 hours.
Cookies and browser storage
The public website does not use an advertising cookie or a third-party analytics cookie. Stripe may use cookies or similar technology after you open the legacy kit’s hosted checkout under Stripe’s own notice.
If you use connected personalisation on a directly opened paid-org guide, SetupPasskeys uses strictly functional, first-party cookies for the one-use Microsoft authorisation transaction and the resulting server session. The session cookie is opaque, secure and HTTP-only; it does not contain a Microsoft token, group or passkey record. It expires under the session limits described below and is removed on sign-out. Choosing “Forget account check” also stores an identity-free, HTTP-only preference for up to 30 days so the guide does not immediately repeat the automatic Microsoft check. Choosing the explicit Microsoft work-account check clears that preference.
The active public and hosted-guide experience uses session storage for:
- device, platform, version, passkey method, sign-in mode and current guide step, so the visitor can continue during the browser session;
- the public domain and sanitised branding returned for a branded preview, for the current tab only.
The enquiry form does not store campaign attribution in the browser. If a visitor uses the explicit free-guide link for organisations, that one navigation may carry only allowlisted campaign or advertising identifiers already present in the current URL; the guide does not store them. If the enquiry page’s current URL contains those identifiers, their values and the current referrer are submitted only when the visitor explicitly sends that enquiry. Those identifiers are currently used only for SetupPasskeys’ internal attribution and are not uploaded or imported back to Google, Meta or another advertising platform. Any future platform upload requires an approved geography-specific lawful-basis or consent design, matching notice and point-of-collection disclosure before it begins.
The separate legacy kit uses browser storage for these functional purposes:
- Local storage: builder choices (including the preview domain), tour state, the most recent unpaid draft token, a paid private-link/unlock reference and an internal-testing marker. It also remembers whether optional analytics were allowed or kept off. Only after analytics are allowed does local storage hold the random first-party visitor identifier, for no longer than 90 days.
- Session storage: after analytics are allowed, a random per-tab visit identifier, one-time event flags and the cumulative visible-time counter for the current browser session.
Local-storage values remain on that browser until they are replaced or you clear site data. Session-storage values normally disappear when the tab or browser session ends. Blocking storage does not prevent viewing the site, but it can stop a guide or preview remembering choices during the session, or stop the legacy builder remembering choices or a purchase on that device. An emailed private link can restore a paid legacy kit.
Visitor analytics remain off until you allow them. You can reopen “Privacy choices” in the Rollout Kit and keep analytics off at any time; doing so removes the optional visitor and visit identifiers from that browser. Global Privacy Control and Do Not Track keep analytics off. Email privacy@setuppasskeys.com to withdraw consent or request erasure. Collected rows expire under the 90-day rule unless erased earlier following a valid request.
Purposes and lawful bases
| Purpose | Usual GDPR basis |
|---|---|
| Prepare, host and support an ordered branded guide | Contract; steps requested before contract |
| Match a signed-in employee to approved paid-org routes and show a reduced registered-passkey summary | The customer determines and documents its basis as controller; Kinane Labs Ltd processes on the customer’s instructions under the order and any executed DPA |
| Build, sell, deliver, recover and support an ordered legacy kit | Contract; steps requested before contract |
| Invoices, tax records and responding to statutory rights | Legal obligation |
| Prevent abuse, secure private links and diagnose delivery failures | Legitimate interests in operating a safe and reliable service |
| Retrieve public branding and render the local preview requested by the visitor | Steps requested before contract, where applicable |
| Optional legacy-kit product and visitor measurement | Consent, which may be withdrawn at any time |
| Answer enquiries and manage relevant business outreach | Steps requested before contract and/or legitimate interests; consent where required |
Where processing relies on legitimate interests, you may object. Direct marketing will stop for the address when you unsubscribe or ask for suppression.
Retention and deletion
| Record | Retention approach |
|---|---|
| Guide and branded-preview session storage | Normally until the tab or browser session ends, or earlier if the visitor clears site data |
| Hosted-guide configuration and customer-supplied assets | Kept while the agreed hosted guide is provided, then returned, deleted or minimised under the order and any executed DPA, subject to legal records and provider backup cycles |
| Connected Microsoft authorisation transaction | One use and short-lived; deleted after completion, failure or expiry. Authorisation codes and tokens are not placed in guide URLs or retained in browser storage |
| Connected employee session and reduced passkey result | Until sign-out or the configured idle or absolute session expiry, whichever comes first. Invalidated when the customer disconnects or Microsoft consent is revoked. It is not retained as an employee passkey-history record |
| Connected tenant policy and approved route mapping | The current Microsoft policy response is validated and reduced in server memory for the account check, not retained as a tenant-policy snapshot. The separate Customer-approved route mapping is kept while the ordered connection is active and deleted or minimised when the service ends |
| Connected identity-start quota hash | Stops counting after ten minutes; deleted on a later organisation start or by the daily purge, normally within approximately 24 hours |
| Abuse-control quota events and expired request leases | Deleted after approximately 25 hours |
| Unpaid kit drafts | Seven days after the most recent save |
| Paid kit configuration and private-link record | Kept while edit and re-download are provided, or until a valid deletion request, subject to records that must be retained |
| Invoices and transaction records | Normally six years, or longer where a tax, audit, dispute or legal requirement requires it |
| Enquiries and support correspondence | Reviewed against the active enquiry or customer relationship and deleted or minimised when no longer needed, subject to any related claim or records requirement. These records are not covered by the 90-day automated cleanup below |
| Historical Rollout Kit domain submissions and consented visitor measurement | Historical domain-submission rows and consented visitor-measurement rows are deleted by the daily retention job once they are older than 90 days; the admin reporting view normally displays the latest 30 days |
| Funnel, prospect and outreach records | Reviewed against the active business relationship and deleted or aggregated when no longer necessary; suppression records are retained to honour opt-outs |
Deletion from live systems may not immediately remove encrypted backup copies; those age out under the relevant provider’s backup cycle and are not restored except for disaster recovery. A deletion request does not require erasure of data that must be retained by law or for the establishment, exercise or defence of legal claims.
Your rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict personal data; receive portable data; object to processing based on legitimate interests or direct marketing; and withdraw consent without affecting earlier lawful processing. Route personalisation supplies guidance only. There is no solely automated SetupPasskeys decision that produces legal or similarly significant effects.
Email privacy@setuppasskeys.com. Enough information may be requested to verify that the response is sent to the right person, but do not send identity documents unless specifically and securely requested. You may also complain to the Irish Data Protection Commission or your local supervisory authority.
Changes to this notice
Material changes are dated here. If a change materially affects an active paid order and contact is reasonably possible, an additional notice may be sent to the purchase email.