This policy is provided for transparency about how the Service handles data. It is not a substitute for your own legal review; contact us with any questions.

1. Who we are

Patch Console is a vulnerability-driven patch-management service for Windows, operated by Tiny Electrons LLC ("we", "us", "our"). The Service consists of:

You (the customer organization) are the data controller for the device and user data in your tenant; we act as a data processor on your behalf.

2. What we collect

From the Agent on each managed endpoint:

From Microsoft Graph (when you connect Intune/Entra): managed-device records, primary/assigned users, and license/assignment data, scoped to the domains you approve.

From vulnerability reports you import: CVE identifiers, affected products and versions, and severity, which we map to the products on your fleet.

From the admin console: your administrators' account details (name, email), authentication data (password hashes, MFA secrets, passkeys), and an audit trail of actions taken.

What we do NOT collect: keystrokes, screen captures, browsing history, document or file contents, microphone/camera input, or biometric templates. The Agent reports software inventory and device facts only.

3. How we use it

We do not sell your data or use it for advertising.

4. Tenant isolation

Every device, vulnerability, deployment, and user record is scoped to your tenant. The Service enforces tenant isolation on every query; we do not perform cross-tenant reads.

5. Sub-processors

We use a small number of sub-processors to run the Service. We require each of them to protect data consistent with this policy.

Sub-processorPurposeData it may receive
Amazon Web Services Cloud hosting, databases, file storage, and outbound email (SES). All Service data, as the underlying infrastructure.
Microsoft The Intune / Entra ID integration you initiate, via Microsoft Graph. Managed-device and user records in the scopes you approve.
Stripe Subscription billing and payment processing. Billing contact details and subscription state. Card details go directly to Stripe; we never receive or store them.
Sentry Application error monitoring, so we can diagnose faults. Error diagnostics, which may include the URL, browser details, and the account identifier associated with a failing request.
Google (Gemini API) Generating plain-language summaries of software packages and remediation scripts. Software package names, versions, and script text. Prompts are constructed to exclude device names, user identities, and other tenant-identifying facts.

We update this list when we add or remove a sub-processor. If you would like advance notice of changes, contact us.

6. Retention

7. Security

8. Your rights

Depending on your jurisdiction you may have rights to access, correct, export, or delete personal data. As the controller, your organization manages most of this directly in the console; for anything else, contact us.

9. Contact

Questions about this policy or your data: support@patchconsole.com.