This Section 16 provides feature-specific descriptions of how Junify processes personal data for particular product capabilities.
It should be read together with the main body of this Privacy Policy, in particular:
Information about Junify's own third-party processors (sub-processors) is not repeated in these Annexes. Junify maintains a separate, standalone Sub-Processor List, which describes:
Each feature-specific Annex follows a common structure and covers at least the following items:
Feature Overview
A high-level description of the feature, its purpose, typical users and usage scenarios.
Who Enables It
Who can enable or configure the feature (e.g. Customer Admin, End User, system default), and the default state (ON / OFF).
Data Collected / Processed
The categories of personal data processed by the feature, mapped to the data categories described in Section 5, with representative examples.
Purposes of Processing
The purposes for which the feature processes personal data, mapped to the purpose categories in Section 6 (for example, service provision, security, compliance).
Third-Party Services and Integrations (Customer-Controlled)
Where relevant, a description of third-party systems that the Customer chooses to integrate with Junify in connection with the feature (for example, IdPs, email providers or endpoint management tools). These entities usually act as independent controllers under the Customer's control.
Junify's own processors are described only in the separate Sub-Processor List, not in these Annexes.
Retention
A high-level description of how long different categories of data (such as content, logs and metadata) are retained in connection with the feature.
Admin & User Controls
The configuration options and controls available to Customer Admins and End Users (such as enable/disable, scope settings, role-based access, opt-out mechanisms).
What We Do Not Collect or Do
Negative assurances that clarify what the feature does not collect or do, to avoid misunderstandings and to show that the feature is not designed for excessive or invasive monitoring.
This Annex describes processing related to the identity and authentication features provided by Junify. Junify offers two broad types of authentication functionality:
Junify Authentication
QR code based sign-in instead of passwords
Junify Authentication uses a QR code based sign-in flow. Junify does not require or store a traditional password for this authentication method.
The user scans a QR code presented in the Junify interface using the Junify mobile application installed on the user's smartphone. The Junify mobile application functions as a key, and the server stores identifiers that uniquely associate the Junify application on a device with the corresponding Junify account.
Use of the Junify mobile application, device passcode, and biometric authentication
When a user opens the Junify mobile application, the smartphone may require biometric verification or a device passcode, as configured on that device.
The passcode used to unlock the Junify mobile application is stored on the device and is not transmitted to Junify's servers.
When the smartphone's built-in biometric functions are used, such as fingerprint or face recognition provided by the operating system, biometric templates and similar data remain on the device and are not transmitted to Junify.
Optional Junify provided facial recognition
In addition to the smartphone's own biometric functions, Junify may offer an optional facial recognition feature that Junify itself provides. This feature is distinct from the operating system level biometric functions.
Where this Junify provided facial recognition feature is enabled, biometric templates or similar personal data are stored on Junify's servers and used to verify the user's identity when the user attempts to authenticate.
This feature is available only where a Customer's Admin has explicitly chosen to enable it and, where required, has ensured that appropriate notices and consents for biometric processing have been provided under Applicable Data Protection Laws.
Limited email based verification
Where an email address is registered for an account, Junify may provide limited email based verification or step up authentication. For example, Junify may send a one time link or code to the registered email address to confirm that the person attempting to sign in has access to that email account. This is used as a supplementary control and does not replace Junify's primary QR code based authentication flow.
Use of a Customer's external identity provider for Junify Authentication
Where a Customer configures Junify to trust an external identity provider that the Customer controls, Junify can act as a service provider and accept single sign on initiated by that external identity provider. In this case, Junify relies on identity assertions from the Customer's identity provider to authenticate the user to Junify, subject to the Customer's configuration.
This capability is available only where a Customer's Admin has expressly enabled and configured the connection to the external identity provider.
SSO
Junify as an identity provider for other applications
In the SSO mode, Junify can act as an identity provider for other applications. Junify may store authentication credentials for connected applications or use federated identity protocols to authenticate on behalf of the user.
Junify can act as a SAML identity provider or use similar protocols to issue assertions or tokens that allow End Users to sign in to applications that trust Junify.
Junify as a second factor authenticator
Junify can act as a second factor authenticator for connected services. For example, Junify may generate or validate one time passcodes, text or similar second factor credentials used together with a primary factor such as a password.
Credential storage and use on the user's behalf
For some applications, Junify may store credentials or secrets and then use those credentials on the End User's behalf when performing SSO. Depending on the Customer's configuration, these credentials may either be stored individually for each End User or be defined and managed centrally by the Customer's Admin as organization-managed credentials that remain under the organization's control, are not visible to End Users, and can be assigned by the Admin to specific users, groups, or the entire organization.
Junify Authentication
QR code based Junify Authentication
QR code based Junify Authentication is a core element of the Service and is available by default. It can be used when an End User installs the Junify mobile application and is enrolled in Junify by their organization.
Biometric and passcode protection in the Junify mobile application
Biometric and passcode protection within the Junify mobile application can be enabled by the End User on their device.
A Customer's Admin may enforce that the Junify mobile application can be unlocked only with a passcode, device level biometric authentication, the Junify provided facial recognition feature where available, or a combination of these methods, in accordance with the organization's security policy.
Use of a Customer's external identity provider for Junify Authentication
Use of a Customer's external identity provider to authenticate to Junify is enabled and configured by the Customer's Admin. Admins decide which identity provider to use, which attributes to release to Junify, and which users or groups may authenticate to Junify in this way.
SSO
User managed credentials
Where credentials for connected applications are managed by individual End Users, SSO is activated when the End User chooses to store and manage those credentials in Junify, within the permissions and policies defined by the Customer.
In this model, the End User may, for example, register a username and password for a specific application inside Junify so that Junify can perform sign in on their behalf.
Organization managed credentials
Where credentials are managed centrally by the Customer, SSO is enabled when the Customer's Admin configures the relevant connections and credentials in Junify.
Admins may, for example, configure a SAML integration, OpenID Connect integration, or shared credentials for certain applications, assign those applications to specific users or groups, and define any conditional access settings that apply.
This section describes, at a high level, the categories of data that may be processed when Junify Authentication or SSO are used. These data are processed as part of the Service Data described in the Privacy Policy and fall into the following categories:
Junify Authentication
Account Information
For Junify Authentication, we may process:
Third Party App or Integration Data
Where a Customer's external identity provider is used for Junify Authentication, we receive identity attributes from that provider, as configured by the Customer's Admin. These attributes may include:
These attributes are treated as Third Party App or Integration Data and, in some cases, also as Account Information.
Device and Technical Information
For device and technical information, we may collect minimum necessary information about the smartphone or device used with the Junify mobile application, such as:
Where an Admin enables risk based or context aware authentication, we may also process additional information such as approximate location derived from network information, time of access, device posture, or other contextual signals in order to help determine whether an authentication attempt appears consistent with the Customer's policies.
Usage Information
For usage information, we log:
Authentication logs are used for security monitoring, auditing, and troubleshooting as described in the Privacy Policy.
Biometric and passcode data
The passcode used to unlock the Junify mobile application is stored on the device and is not transmitted to the Junify server.
When device level biometric functions provided by the smartphone operating system are used, biometric templates and similar data remain on the device and are not transmitted to the Junify server.
Where the optional Junify provided facial recognition feature is enabled, biometric templates or similar data are stored and processed by Junify solely for the purpose of verifying the user's identity and only under the Customer's configuration and Applicable Data Protection Laws.
SSO
Account Information
For SSO, we may process identifiers and account related information needed to link a user's Junify account to connected applications and represent the user to those applications, for example:
Third Party App or Integration Data
For SSO, we process information exchanged with connected applications and services, including:
Device and Technical Information
To evaluate whether an SSO attempt meets the Customer's configured conditions, Junify may process:
This information is used, for example, to enforce policies that restrict access by location, network, device type, or similar conditions.
Usage Information
For SSO, we log:
These logs form part of the audit trail and are used for security monitoring and troubleshooting.
Authentication logs
Both Junify Authentication and SSO generate authentication logs and related Usage Information. These logs are stored and retained for the periods described in Section A.6 of this Annex and in the Retention section of the Privacy Policy.
We process the data described in this Annex in order to:
These purposes are consistent with the high level purposes of processing described in the Privacy Policy.
We may rely on third party services in connection with identity and authentication, including:
Where an external identity provider owned or operated by the Customer is used, such as a corporate identity platform, that provider acts as an independent controller for its own authentication processes and the personal data it processes. Junify receives only the attributes and assertions that the Customer has configured the identity provider to release and processes them in accordance with the Customer's instructions.
Junify Authentication controls
SSO controls
Junify does not use authentication data, for example login history, for advertising or third party marketing.
This Annex describes Junify features that perform server-side content analysis and automation, including:
The primary goal of these features is to automate manual tasks, improve visibility into SaaS usage and support security and compliance.
End Users typically use these features (for example by uploading files or triggering analyses) within the parameters defined by the Admin.
In connection with Content Analysis & Automation, Junify may process:
Junify uses this data to:
Content Analysis & Automation may interact with third-party services chosen and managed by the Customer, such as:
These services typically operate under the Customer's control and act as independent controllers.
This Annex focuses on how Junify processes personal data once the relevant content has been provided to Junify or when Junify sends outputs back to such systems.
This Annex covers Junify features that collect activity and device information using:
The primary purposes of these features are to detect Shadow IT, increase visibility into SaaS usage, support security incident detection and fulfil certain compliance logging requirements.
End Users typically do not enable the agent or extension on their own; installation and configuration are managed by the Customer.
In connection with Endpoint & Activity Monitoring, Junify may process:
Junify uses the above data to:
Endpoint & Activity Monitoring may interact with third-party tools and services under the Customer's control, such as:
These third parties are typically independent controllers or processors under the Customer's own arrangements.
This Annex describes Junify's processing of personal data received from or sent to such systems; it does not govern those systems' own internal data practices.
For data processed in connection with Endpoint and Activity Monitoring, including activity logs, location information and other Admin-Authorized Data, retention works as follows.
Junify-defined retention periods and options
Junify defines default retention periods for Endpoint and Activity Monitoring data and, for certain data types or features, provides a limited set of configurable retention options that are appropriate for security monitoring, audit and technical operation.
Role of Customer Admins
Customer Admins are responsible for understanding the retention periods and configuration options that Junify makes available and, where a retention setting can be adjusted, selecting a value that aligns with their organisation's internal policies and legal obligations. Customer Admins do not define arbitrary retention periods beyond the options provided by Junify.
Deletion and de-identification by Junify
Junify applies the relevant default or Admin-selected retention period by storing Endpoint and Activity Monitoring data only for the applicable period and then deleting or de-identifying it, subject to any limited additional retention in backups as described in the Privacy Policy.
This Annex describes Junify features that use generative AI, primarily large language models, as a component of the Service. Generative AI is used to:
Generative AI outputs are intended to assist users and Admins in working with complex information and workflows. Where such outputs are presented directly to the Customer (for example as summaries, suggestions or recommended actions), they are provided for assistance only and do not replace the Customer's responsibility to review and validate the results before relying on them or acting on them.
In connection with Generative AI features, Junify may process the following data.
Input data sent to generative AI
This is data used as prompts or context when Junify calls generative AI services. It may include:
Input data is drawn from information that users provide to Junify or that Junify processes on behalf of the Customer under the other Annexes.
AI-generated outputs returned to Junify
These are the responses that the generative AI service returns to Junify, such as:
Depending on the feature, these outputs may be displayed to users, used to drive automated actions, or stored as part of Customer Content or Service Data.
Usage and performance data
Junify may also record limited metadata about AI feature usage, such as timestamps, feature identifiers and technical error information, as part of Usage Information for monitoring, troubleshooting and security.
Junify uses the data described in this Annex for the following purposes.
To analyse and transform complex inputs provided by users, such as PDFs, other documents or configuration data, and to produce summaries, extracted fields or other structured representations that are easier to work with.
To interpret relevant logs and activity histories, including data related to Shadow IT or security events, and to derive higher-level insights such as categories, intents or risk indicators.
To control and support AI agents that can, within the limits configured by the Customer Admin, suggest or perform certain browser-based or workflow actions on behalf of users.
Generative AI outputs are assistive tools. Customers remain responsible for reviewing AI outputs and for any decisions or actions taken based on them.
Retention of data used in connection with Generative AI features on the Junify side follows these principles.
Prompts and outputs as content
Where prompts or AI-generated outputs are stored as part of Customer Content or configuration within Junify (for example, saved summaries, explanations or agent outcomes), they are retained in line with the retention rules that apply to the underlying content or feature, as described in the Privacy Policy and relevant Annexes.
Transient or session-based processing
For features that operate on a transient or session basis, Junify aims to process prompts and outputs only for as long as needed to complete the requested operation and maintain short-term reliability and security, after which the data is deleted or de-identified.
Usage logs and metadata
Metadata and logs relating to AI feature usage, such as timestamps, feature identifiers and error information, are retained as Usage Information for limited periods appropriate for security monitoring, troubleshooting and audit, and are then deleted or de-identified in accordance with the Privacy Policy.
Customer Admin controls
Customer Admins can:
End User controls
End Users can:
This Annex describes Junify's APIs, Webhooks and SDKs, which enable programmatic integration with other systems.
Covered capabilities include:
If certain APIs are not generally available at a given time, this Annex may indicate that they are in development or available only under specific programmes, and details will be provided in developer documentation.
These interfaces are primarily designed for server-to-server or application-to-application communication, rather than for direct use by End Users.
Depending on the specific endpoint and configuration, APIs and Webhooks may process:
Data required to identify and manage users, groups or accounts.
Data about events, actions or metrics that are pushed via Webhooks or retrieved via APIs.
Data categories and records that the Customer Admin has made accessible via APIs or included in Webhook payloads.
Data exchanged between Junify and integrated systems when APIs and Webhooks are used.
In some cases, identifiers, timestamps or classification labels related to Customer Content.
An optional Endpoint Mapping Appendix may document, for each endpoint, which categories of data it processes.
Junify uses APIs, Webhooks and SDKs to:
APIs, Webhooks and SDKs are often used to connect Junify with other systems that are selected and controlled by the Customer, such as:
These systems typically act as independent controllers (or processors under the Customer's arrangements).
This Annex describes how Junify processes and exposes data via APIs and Webhooks; it does not govern those external systems' internal processing.
Junify may retain metadata about API calls and Webhook deliveries (for example, timestamps, endpoint names, response codes, request identifiers) for a defined period for security, reliability and troubleshooting.
Retention periods are set in Junify's internal policies and may be aligned with the Customer's requirements where applicable.