Skip to content
Back to home

Privacy

Privacy Policy

How Awesome Intune processes personal data when you browse the directory, search with AI, vote, subscribe, submit content, or take part in community recognition.

Last updated: August 16, 2026

1. Controller

The controller responsible for processing personal data on this website is:

Ugurlabs UG (haftungsbeschränkt)
Fährstraße 217
40221 Düsseldorf
Germany

Managing Director: Ugur Koc
Email: support@ugurlabs.com

This policy applies to the Awesome Intune website at www.awesomeintune.com. Where we refer to “we”, “us”, or “Awesome Intune”, we mean Ugurlabs UG (haftungsbeschränkt).

2. Hosting, access data, and security

We host this website with Vercel Inc. When you open a page, your browser necessarily sends technical information to our hosting systems. This can include your IP address, date and time, requested URL, referrer, browser and operating-system information, and HTTP response data.

We process this data to deliver the website, maintain its security and stability, diagnose errors, and defend against abuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable, and efficient operation of this website.

For abuse prevention, the application also uses IP addresses in short-lived, in-memory rate-limit records. These records normally expire after about one minute. For view-count deduplication, an IP address may be converted to a SHA-256 hash held in application memory for up to five minutes. The database receives only an aggregate view increment, not that IP hash.

Vercel processes hosting data on our behalf. Its retention depends on the applicable service and account configuration. We retain or permit access to logs only for as long as they are needed for the purposes above or to meet legal obligations. See the Vercel Privacy Notice.

3. Privacy-focused analytics

We use Plausible Analytics, provided by Plausible Insights OÜ, Estonia, to understand how the website is used and improve the directory. Plausible does not set analytics cookies or create a persistent cross-site identifier.

Plausible processes the visited page, referrer, campaign parameters, browser, operating system, device type, and approximate location derived from the IP address. It also receives events generated by the site, such as category and tool interactions, outbound and sponsor clicks, form type, newsletter-signup source, and the text and type of an AI search. Do not put names, email addresses, tenant details, or other confidential information into the search field.

According to Plausible, raw IP addresses and full user-agent strings are not stored. They are used to create a daily identifier with a salt that is deleted every 24 hours. Visitor analytics are processed and stored in the EU and are presented to us in aggregate form.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to measure the usefulness and performance of the website without cross-site tracking or advertising profiles. For details, see Plausible’s Data Policy.

5. Forms and Cloudflare Turnstile

Our tool-submission, tool-idea, and developer API-key forms use Cloudflare Turnstile to distinguish legitimate submissions from automated abuse. The widget runs browser checks and processes signals such as IP address, browser and device characteristics, interaction data, and the resulting challenge token. Our server sends the token to Cloudflare for verification.

The provider is Cloudflare, Inc., United States. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are protecting the forms, infrastructure, and community from spam and automated attacks. Without successful verification, the protected form cannot be sent. See Cloudflare’s Turnstile Privacy Addendum.

6. Newsletter

If you subscribe, we process your email address, subscription time, confirmation status, and confirmation and unsubscribe tokens. We use a double-opt-in process: you receive updates only after confirming the address through the link in our email.

The legal basis for sending the newsletter is your consent under Article 6(1)(a) GDPR. We may retain limited evidence of the consent process under Article 6(1)(f) GDPR to demonstrate compliance. You can withdraw consent at any time using the unsubscribe link in each email or by contacting us. Withdrawal does not affect processing that was lawful before it.

Subscriber data is stored with Supabase. Emails are sent through Resend, operated by Plus Five Five, Inc. Resend receives the recipient address and message content required for delivery. Confirmed records remain until you unsubscribe or request deletion. Unsubscribing through our link deletes the subscriber record from our database. Unconfirmed records may remain until deleted; you may ask us to remove one at any time. Provider-side delivery logs are retained under the provider’s applicable settings and legal requirements. See the Resend Privacy Policy.

7. Tool submissions and tool ideas

Tool submissions can contain the tool name and description, repository and product links, additional notes, and up to five authors’ names and optional GitHub, LinkedIn, and X profile links. Tool ideas contain a title, description, optional use case, and category.

These submissions are intended for public disclosure. We create a public issue in the Awesome Intune GitHub repository with the submitted content. Tool ideas are also stored in Supabase so they can be displayed and ranked on the site. GitHub may retain public issues and their history until they are removed under the project’s and GitHub’s rules.

The legal basis is Article 6(1)(b) GDPR for processing the submission you request and Article 6(1)(f) GDPR for reviewing, documenting, and curating community contributions. Our legitimate interests are a transparent submission process and the operation of a reliable public directory.

Do not submit private contact details, credentials, customer or tenant data, or information about another person unless you are entitled to make it public. Submissions may be checked using automated security tools and AI-assisted analysis. Maintainers make the final publication decision; there is no solely automated decision with legal or similarly significant effects.

GitHub, Inc. processes the public issue and ordinary connection data. See the GitHub General Privacy Statement.

8. Awesome Pick recognition

To identify potential Awesome Picks, we manually review posts shared in the Awesome Intune LinkedIn group. We may process the poster's name, LinkedIn profile URL, post URL, the public or group-visible contribution, group-membership status, and limited notes about eligibility, conflicts, and how the contribution meets the published selection criteria. The source of this data is the member's LinkedIn post and profile.

The legal basis for this initial review is Article 6(1)(f) GDPR. Our legitimate interest is to recognize and make useful, free, vendor-neutral community knowledge easier to discover. Selection is performed manually. We do not save or score likes, comments, views, impressions, audience size, personal-profile follows, or other engagement metrics, and there is no solely automated decision-making.

Selected Picks may be announced on the Hall of Fame and Awesome Intune social channels before direct contact. We limit publication to the winner's name, LinkedIn profile link, post link, and a short description of the recognized contribution. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to give visible credit for useful community knowledge. A winner may object to this processing or request removal by LinkedIn direct message or email. We will remove or anonymize references under our control where reasonably possible. Copies already shared by third parties may remain outside our control.

Winners contact us through LinkedIn after the announcement if they want to claim the prize. To handle a claim, we may process the LinkedIn message, eligibility record, subscription receipt, reimbursement amount, and payment details required to reimburse the winner. Please redact unrelated transaction or account information before sending a receipt. The legal basis is Article 6(1)(b) GDPR for taking steps at the winner's request and administering the claimed prize, and Article 6(1)(c) GDPR where accounting or tax law requires us to retain a record.

We delete review notes for people who are not selected within 90 days after the announcement. Public winner information remains in the program archive unless the winner objects or requests removal. Prize claim, receipt, and payment records are retained for the applicable statutory accounting and tax periods and then deleted. Data may be shared with LinkedIn when a recognition post is published, with website visitors, and with the organizer's bank or payment provider where needed for reimbursement.

9. Developer API keys

When you request a developer API key, we process your name, email address, Turnstile token, a cryptographic hash and prefix of the key, its active status, creation and last-use timestamps, and request counters. The plaintext key is sent once by email through Resend and is not stored in plaintext in our database.

The legal basis is Article 6(1)(b) GDPR. The required name, email, and security verification are necessary to issue and administer a key; we cannot provide one without them. API records are stored with Supabase while the key is active and afterward only for as long as needed for security, abuse prevention, dispute handling, or legal obligations.

10. Voting and aggregate view statistics

When you vote for a tool or idea, we assign a random voter identifier. The server places a signed ai_voter cookie with a lifetime of one year. The cookie is HttpOnly, Secure in production, and SameSite=Lax. We store the identifier with the selected item in Supabase to prevent duplicate votes. Your browser also stores a random voter ID and lists of items voted for so the interface can display your choices.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are maintaining fair community rankings, preventing manipulation, and showing a consistent voting state. The cookie is used for the voting feature you request and not for advertising or cross-site tracking.

Tool views increment aggregate counters in Supabase. To avoid counting immediate repeats, we temporarily use the voter identifier where available or otherwise a one-way hash of the IP address for up to five minutes in application memory. The deduplication key is not written to the view-count database.

11. Cookies and browser storage

We do not use advertising cookies. Plausible Analytics does not set analytics cookies. The site uses the following first-party storage to provide requested features and remember interface preferences:

StoragePurposeDuration
ai_voter cookieVote integrityOne year
Local storageTheme, sound, layout, voter state, and newsletter-prompt stateUntil cleared; the newsletter prompt uses its timestamp to determine when it may be shown again
Session storageTemporary interface and scroll stateUntil the session ends

Where these entries involve personal data, the legal basis is Article 6(1)(f) GDPR. Our legitimate interest is to provide the selected feature and retain user-requested preferences. You can remove stored data in your browser settings, although doing so may reset preferences and voting indicators.

Access to or storage of information on your device is based on Section 25(2)(2) of the German Telecommunications Digital Services Data Protection Act (TDDDG) where it is strictly necessary to provide a feature you expressly request. The voting cookie is set when you use the voting feature; preference entries are created when you select the corresponding setting.

12. Recipients and international transfers

Depending on the feature you use, recipients or processors can include Vercel (hosting), Supabase (database), Plausible (analytics), OpenAI (AI processing), Cloudflare (bot protection), Resend (email delivery), GitHub (public submissions and repository services), LinkedIn (Awesome Pick recognition posts and contact), and banks or payment providers used for prize reimbursement. We also disclose data where required by law or necessary to establish, exercise, or defend legal claims.

Plausible states that visitor analytics are processed in the EU. Some other providers are headquartered in the United States or use subprocessors in countries outside the EEA. Where personal data is transferred outside the EEA, the transfer is based on an applicable adequacy decision, including the EU–U.S. Data Privacy Framework where available, or on the European Commission’s Standard Contractual Clauses and supplementary safeguards as applicable. Provider details and subprocessor locations can change; the linked provider notices contain their current information.

Supabase processes database data on our behalf under its data processing terms. See the Supabase Privacy Policy.

13. Retention principles

The feature-specific periods above take priority. Where no fixed period is stated, we retain personal data only while it is needed for the stated purpose. We then delete or anonymize it unless a legal duty requires longer retention or it remains necessary for the establishment, exercise, or defense of legal claims.

Factors used to set a period include the duration of the user-requested service, account or key status, whether content is deliberately public, security and abuse-prevention needs, statutory limitation periods, community-recognition publication and objections, and tax or commercial record-keeping duties. Public GitHub content and repository history may remain available until removed in accordance with GitHub’s and the project’s rules.

If you contact us by email, we process your address, message, and related metadata to answer the inquiry. The legal basis is Article 6(1)(b) GDPR for contract-related inquiries and otherwise Article 6(1)(f) GDPR. We normally delete correspondence after the matter is resolved unless follow-up, legal retention, or claim-defense needs require it for longer.

14. Your data-protection rights

Subject to the conditions in the GDPR, you have the right to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, and data portability. You may also object to processing based on Article 6(1)(f) GDPR for reasons arising from your particular situation. Where processing is based on consent, you may withdraw that consent at any time for the future.

To exercise a right, email support@ugurlabs.com. We may need to verify your identity before acting on a request. Some rights can be limited where an exemption applies or retention is required by law.

You also have the right to lodge a complaint with a data-protection supervisory authority. Our competent authority is:

State Commissioner for Data Protection and Freedom of Information North Rhine-Westphalia (LDI NRW)
Kavalleriestraße 2–4
40213 Düsseldorf
Germany
Email: poststelle@ldi.nrw.de
Website: www.ldi.nrw.de

We may revise this policy when the website, providers, or legal requirements change. The date at the top identifies the current version.