Last Updated: February 2026
Effective Date: February 2026
This Privacy Policy describes how Coax ApS ("Coax," "we," "us," or "our") collects, uses, stores, and protects personal data when you use our SaaS management platform ("Service"). Coax helps organizations discover, track, and optimize their software subscriptions by integrating with Microsoft 365.
We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Danish data protection laws.
Coax ApS Copenhagen, Denmark
For privacy inquiries, contact us at: privacy@coaxsecurity.com
When you sign in with Microsoft 365, we collect:
With appropriate permissions, we access your Microsoft 365 organization directory to collect:
To analyze application usage, we collect sign-in activity including:
To discover SaaS subscriptions and billing information, we access:
Important Privacy Safeguard: We do NOT store email body content. Emails are processed in-memory only for SaaS detection and billing extraction. Only extracted metadata (application name, amounts, dates, sender domain) is persisted.
When billing emails contain PDF or image attachments:
We use Mixpanel to understand how users interact with our Service:
We process your personal data for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide and maintain the Service | Contract performance (Art. 6(1)(b)) |
| Discover and track SaaS applications | Contract performance (Art. 6(1)(b)) |
| Extract billing and cost information | Contract performance (Art. 6(1)(b)) |
| Analyze SSO activity for optimization | Contract performance (Art. 6(1)(b)) |
| Send service notifications | Contract performance (Art. 6(1)(b)) |
| Improve our Service | Legitimate interest (Art. 6(1)(f)) |
| Product analytics and usage insights | Legitimate interest (Art. 6(1)(f)) |
| Respond to support requests | Contract performance (Art. 6(1)(b)) |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) |
We share data with the following third-party service providers (subprocessors):
For a complete list of our subprocessors, see our Subprocessor List.
| Cookie/Storage | Type | Purpose | Duration |
|---|---|---|---|
session_id | HttpOnly Cookie | Session authentication | 24 hours |
mp_* | Mixpanel Cookie | Analytics tracking | 1 year |
__mp_opt_in_out_* | Mixpanel Cookie | Consent preferences | 1 year |
We use browser localStorage for:
You can manage or disable cookies through:
Note: Disabling the session cookie will prevent you from using the Service, as it is required for authentication.
We retain your personal data as follows:
Upon Account Deletion: Personal data is deleted within 30 days of your deletion request. Some data may be retained longer if required by law or for legitimate business purposes (e.g., billing records).
We implement appropriate technical and organizational measures to protect your data:
For more details, see our Security Practices.
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. When we transfer data outside the EEA, we ensure appropriate safeguards are in place:
Under GDPR, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete personal data.
Request deletion of your personal data ("right to be forgotten").
Request limitation of processing of your personal data.
Receive your personal data in a structured, machine-readable format.
Object to processing based on legitimate interests, including profiling.
We do not make decisions based solely on automated processing that produce legal effects.
To exercise any of these rights, contact us at:
Email: privacy@coaxsecurity.com
Response Time: We will respond to your request within 30 days. If we need more time (up to 60 additional days for complex requests), we will inform you.
Verification: We may need to verify your identity before processing your request.
Our Service is designed for business use and is not directed at individuals under 16 years of age. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
We encourage you to review this policy periodically.
If you are not satisfied with our response to your privacy concerns, you have the right to lodge a complaint with the Danish Data Protection Agency:
Datatilsynet Carl Jacobsens Vej 35 2500 Valby, Denmark Website: https://www.datatilsynet.dk/ Email: dt@datatilsynet.dk
For any questions about this Privacy Policy or our data practices:
Email: privacy@coaxsecurity.com
Legal Inquiries: legal@coaxsecurity.com
Mailing Address: Coax ApS Copenhagen, Denmark
This Privacy Policy is also available at: https://coaxsecurity.com/legal/privacy