Effective 4 September 2026. Covers mfaportal.net and the authentication service operated under it.
Harborline Systems, Inc., 1180 Centre Street, Suite 405, Newton, MA 02459, United States. For user accounts, the organisation that subscribes to MFA Portal is the controller and we act as its processor; the subscription agreement includes a data processing addendum. For our own website and sales enquiries, we are the controller. Questions: privacy@mfaportal.net.
We do not store password hashes, session cookies for your applications, mailbox contents or file data.
In the region selected at account setup, either eu-central-1 (Frankfurt) or us-east-1 (Virginia). Data is not replicated to other regions. Sub-processors are listed on the security page: Amazon Web Services (hosting), Mailgun Technologies (account email), Twilio (optional SMS codes) and Datadog (monitoring). We do not sell personal data and do not use it for advertising.
Access, correction, deletion, restriction and portability requests go to the organisation that manages your account, which holds the record and gives us the instruction. You may also write to privacy@mfaportal.net: we will pass the request to the controller and confirm that we did. If you are in the European Union or the United Kingdom, you may complain to your local supervisory authority; we answer controller requests within 30 days.
Where a tenant is hosted in the European Union, support access from the United States is limited to a named engineer, granted per incident, logged, and covered by the Standard Contractual Clauses in the data processing addendum.
The effective date changes when this policy changes. Material changes affecting tenants are notified to the account owner by email at least 30 days in advance.