This policy is provided for transparency about how the Service handles data. It is not a substitute for your own legal review; contact us with any questions.
1. Who we are
Patch Console is a vulnerability-driven patch-management service for Windows, operated by Tiny Electrons LLC ("we", "us", "our"). The Service consists of:
- A web admin console where your IT administrators manage devices, vulnerabilities, patch groups, and deployments.
- A lightweight Windows inventory Agent deployed on your endpoints that reports installed software, local administrators, and basic device facts.
- Integrations with Microsoft Intune and Entra ID (via Microsoft Graph) to sync managed devices and users and to deploy patches.
You (the customer organization) are the data controller for the device and user data in your tenant; we act as a data processor on your behalf.
2. What we collect
From the Agent on each managed endpoint:
- Installed software inventory: product name, version, publisher, install date, and the source that detected it (registry, Microsoft Store, winget, or path/portable).
- Device facts: hostname, OS version, hardware identifiers, and basic specs.
- Local administrators: the membership of the device's local Administrators group.
From Microsoft Graph (when you connect Intune/Entra): managed-device records, primary/assigned users, and license/assignment data, scoped to the domains you approve.
From vulnerability reports you import: CVE identifiers, affected products and versions, and severity, which we map to the products on your fleet.
From the admin console: your administrators' account details (name, email), authentication data (password hashes, MFA secrets, passkeys), and an audit trail of actions taken.
What we do NOT collect: keystrokes, screen captures, browsing history, document or file contents, microphone/camera input, or biometric templates. The Agent reports software inventory and device facts only.
3. How we use it
- Operate the Service: correlate vulnerabilities to installed software, build patch groups, deploy fixes through Intune, and verify remediation.
- Authenticate and authorize your administrators (including SSO and MFA).
- Maintain an audit trail of deployments, ignores, overrides, and other sensitive actions.
- Secure and support the Service (troubleshooting, abuse prevention).
We do not sell your data or use it for advertising.
4. Tenant isolation
Every device, vulnerability, deployment, and user record is scoped to your tenant. The Service enforces tenant isolation on every query; we do not perform cross-tenant reads.
5. Sub-processors
We use a small number of infrastructure sub-processors to run the Service, including a cloud hosting provider (AWS) and Microsoft (for the Graph/Intune/Entra integration you initiate). We require sub-processors to protect data consistent with this policy.
6. Retention
- Device & software inventory: retained while the device is active in your tenant; uninstall history is kept so you can see what changed.
- Audit logs: retained for your compliance needs; configurable.
- Account data: retained for the life of your account and deleted on request after termination.
7. Security
- Data encrypted in transit (TLS) and at rest.
- The Agent's per-device key is stored encrypted on the endpoint and is scoped to reporting only.
- Role-based access control and MFA on the admin console.
8. Your rights
Depending on your jurisdiction you may have rights to access, correct, export, or delete personal data. As the controller, your organization manages most of this directly in the console; for anything else, contact us.
9. Contact
Questions about this policy or your data: support@patchconsole.com.