winserv · wifi corporate sign-in for UniFi (Ubiquiti) Wi-Fi

Privacy notice

Privacy

This site is the commercial page of the winserv-unifi-portal product. It does not authenticate users or process data from your network — that happens in the product you subscribe to, not here.

Who the controller is

WinServ Tecnologia da Informação. Contact: contact@winserv-auth.com.

Measurement cookies (opt-in)

This site sets no measurement cookies today. If we ever turn on Meta Pixel or Google Analytics 4, to understand where visits come from, they will load only after you click "Accept" on the cookie notice; if you click "Decline", nothing loads, and the button below appears so you can change your mind at any time.

The application in your Microsoft Entra

This section is what you are looking for if you came here from Microsoft's consent screen. There are two applications, with purposes kept apart on purpose — you create neither of them: they appear in your directory when someone consents, and that is where you remove them whenever you want.

ApplicationWhat it readsWhat for
Winserv WiFi Portal The basic profile of whoever signs in (name, e-mail) and that user's groups Deciding whether that person may use the network. Read at sign-in, with the user's own consent
Winserv WiFi Portal, at sign-up The directory's groups and the organization's data (verified domains), with an administrator's consent Checking, before the portal is created, that the groups you entered exist, are security groups and have members. Read once, not kept
Winserv WiFi Directory Reader The members of the authorized group and whether each account is enabled Cutting access within 5 minutes for anyone who was offboarded or removed from the group, without waiting for someone to tell us. Optional: it only works if one of your administrators turns it on

The second permission is broad because Microsoft does not offer a version limited to one group: to know whether an account is still enabled, the permission to read the directory's users is required. We read the group you named and nothing else — but the permission granted is larger than that use, and we would rather say so than hide it.

What we keep: the device's MAC address; for people who sign in with a Microsoft account, their identifier and e-mail, and an encrypted token that renews the session without asking for a new sign-in; for people who use a voucher, the code used and the note your operator wrote on it; for your organization, the controller account's credential (encrypted) and the e-mail of whoever subscribed. In the technical logs, the IP address of each access to the portal. We do not read e-mail, files, calendars or network traffic.

For how long: while access is active. A visitor's MAC and finished vouchers are deleted 90 days after access ends; technical logs, within 90 days; database backups, within 30 days.

Where and with whom: the data is on servers in the United States (Hetzner), with backups at Cloudflare. Sign-in goes through Microsoft, and billing through Stripe, which receives the e-mail of whoever subscribed. We do not sell data, and nobody beyond these providers receives it.

How to revoke: in the Microsoft Entra admin center, Entra IDEnterprise apps | All applications → select the application → PropertiesDelete. Fast offboarding stops working immediately; removing the sign-in application blocks the next sign-ins.

Contact details

The "Contact us" button opens your own e-mail client. What you send us through it is used only to answer your commercial inquiry. The site does not store forms.