Privacy notice
Privacy
This site is the commercial page of the winserv-unifi-portal product. It does not authenticate users or process data from your network — that happens in the product you subscribe to, not here.
Who the controller is
M. SAMOILENKO INFORMATICA, trading as WinServ Tecnologia da Informação, Brazilian company registration (CNPJ) 10.411.266/0001-80, Av. Almirante Tamandaré, 106, apto 201, Vila Nossa Senhora dos Navegantes, Rio Grande/RS, CEP 96202-570, Brazil. Contact: contact@winserv-auth.com.
We are the controller of the data of whoever subscribes and of visitors to this site. For the data of a customer's employees and guests we are a processor, and what we do with it is in the data processing agreement.
Data protection officer
WinServ's data protection officer (encarregado, under Brazil's LGPD) is Marcelo Samoilenko, at dpo@winserv-auth.com. The officer receives requests and complaints from data subjects, answers the Brazilian data protection authority (ANPD), and advises our team on data protection.
If you are an employee or guest of a company that uses our portal, that company is the controller of your data. You may ask them, or ask our officer directly; whatever is theirs, we forward to them.
Measurement cookies (opt-in)
This site sets no measurement cookies today. If we ever turn on Meta Pixel or Google Analytics 4, to understand where visits come from, they will load only after you click "Accept" on the cookie notice; if you click "Decline", nothing loads, and the button below appears so you can change your mind at any time.
The application in your Microsoft Entra
This section is what you are looking for if you came here from Microsoft's consent screen. There are two applications, with purposes kept apart on purpose — you create neither of them: they appear in your directory when someone consents, and that is where you remove them whenever you want.
| Application | What it reads | What for |
|---|---|---|
| Winserv WiFi | The basic profile of whoever signs in (name, e-mail) and that user's groups | Deciding whether that person may use the network. Read at sign-in, with the user's own consent |
| Winserv WiFi, at sign-up | The directory's groups and the organization's data (verified domains), with an administrator's consent | Checking, before the portal is created, that the groups you entered exist, are security groups and have members. Read once, not kept |
| Winserv WiFi Directory Reader | The members of the authorized group and whether each account is enabled | Cutting access within 5 minutes for anyone who was offboarded or removed from the group, without waiting for someone to tell us. Optional: it only works if one of your administrators turns it on |
The second permission is broad because Microsoft does not offer a version limited to one group: to know whether an account is still enabled, the permission to read the directory's users is required. We read the group you named and nothing else — but the permission granted is larger than that use, and we would rather say so than hide it.
What we keep: the device's MAC address; for people who sign in with a Microsoft account, their identifier and e-mail, and an encrypted token that renews the session without asking for a new sign-in; for people who use a voucher, the code used and the note your operator wrote on it; for your organization, the controller account's credential (encrypted) and the e-mail of whoever subscribed. In the technical logs, the IP address of each access to the portal. We do not read e-mail, files, calendars or network traffic.
For how long: while access is active. A visitor's MAC and finished vouchers are deleted 90 days after access ends; technical access logs are kept for 6 months, as Brazil's Marco Civil da Internet requires, and then discarded; database backups, within 30 days.
Where and with whom: the data is on servers in Germany, in the European Union (Hetzner), with backups at Cloudflare, stored in the European Union. Sign-in goes through Microsoft, the service's e-mails go out through our Microsoft 365, and billing goes through Stripe, which receives the e-mail of whoever subscribed. We do not sell data, and nobody beyond these providers receives it. The detail, with each one's country, is under international transfers.
How to revoke: in the Microsoft Entra admin center, Entra ID → Enterprise apps | All applications → select the application → Properties → Delete. Fast offboarding stops working immediately; removing the sign-in application blocks the next sign-ins.
International transfers
The data the portal processes is stored in the European Union, which Brazil recognizes as providing adequate protection (LGPD art. 33, I; ANPD Resolution CD/ANPD No. 32/2026). The European Commission recognizes Brazil in the same way (adequacy decision announced on 27 January 2026), which covers a European customer that entrusts data to us.
Three providers sit outside that design, and we would rather name them:
- Cloudflare, Inc. (USA) keeps the database backups and archived technical logs in a bucket under European Union jurisdiction. The storage is in the EU; the company is American.
- Microsoft 365: the service's e-mails (welcome, setup and plan notices) go out through WinServ's mailbox on Microsoft 365. They go to whoever subscribed and to our operations team, carry at most the address of whoever subscribed and the text of the notice, and never employee or visitor data.
- Stripe (USA) receives the e-mail of whoever subscribed, for billing, with the ANPD standard contractual clauses in its data transfer addendum (LGPD art. 33, II, b).
Sign-in goes through the customer organization's own Microsoft Entra, which is its identity provider.
Contact details
The "Contact us" button opens your own e-mail client. What you send us through it is used only to answer your commercial inquiry. The site does not store forms.