MFAPortal

Privacy policy

Effective 4 September 2026. Covers mfaportal.net and the authentication service operated under it.

Who is responsible

Harborline Systems, Inc., 1180 Centre Street, Suite 405, Newton, MA 02459, United States. For user accounts, the organisation that subscribes to MFA Portal is the controller and we act as its processor; the subscription agreement includes a data processing addendum. For our own website and sales enquiries, we are the controller. Questions: privacy@mfaportal.net.

Data we process

We do not store password hashes, session cookies for your applications, mailbox contents or file data.

Why we process it

Where it is stored

In the region selected at account setup, either eu-central-1 (Frankfurt) or us-east-1 (Virginia). Data is not replicated to other regions. Sub-processors are listed on the security page: Amazon Web Services (hosting), Mailgun Technologies (account email), Twilio (optional SMS codes) and Datadog (monitoring). We do not sell personal data and do not use it for advertising.

How long we keep it

Your rights

Access, correction, deletion, restriction and portability requests go to the organisation that manages your account, which holds the record and gives us the instruction. You may also write to privacy@mfaportal.net: we will pass the request to the controller and confirm that we did. If you are in the European Union or the United Kingdom, you may complain to your local supervisory authority; we answer controller requests within 30 days.

International transfers

Where a tenant is hosted in the European Union, support access from the United States is limited to a named engineer, granted per incident, logged, and covered by the Standard Contractual Clauses in the data processing addendum.

Changes

The effective date changes when this policy changes. Material changes affecting tenants are notified to the account owner by email at least 30 days in advance.