Legal
Privacy Policy — IT Portal Agent
Last updated: August 2026
IT Portal Agent is an enterprise browser extension distributed by maxen and deployed by each
customer's IT department for their own staff. It connects a managed workstation to the
organisation's own portal. The extension is the sign-in agent for Wardyn, self-hosted staff
access software by maxen, and keeps its original name in the Chrome Web Store.
Data the extension handles
- Machine identifiers — computer name, BIOS serial (provided by the organisation's
installer), a randomly generated device id, and network addresses (the local network IP where
available, and the public IP address as seen by the organisation's portal). Used to bind the
workstation to an employee inside the organisation's portal.
- Authentication information — a one-time sign-in code generated locally on the device,
and resource credentials filled transiently when opening an approved work resource.
Where data goes
All of the above is transmitted only to the organisation's own portal (the domain
configured by the organisation's administrator) over HTTPS. The extension contacts the vendor
(maxen) solely to validate the software licence. No personal data, identifiers, or
credentials are sent to the vendor.
What the developer does not do
- The developer (maxen) does not collect, store, or receive end-user personal data.
- Data is not sold or shared with third parties.
- Data is not used for advertising, tracking, or any purpose unrelated to the
extension's function.
Storage and retention on the device
The device id and (after the device is synced with the organisation's portal) the sign-in secret
are stored locally in the extension's own storage on the device. Credentials are never stored —
they are used transiently and discarded immediately after use.
Website and licensing service
- Contact form — if you submit the form on this website, we receive and store the name,
company, work email address, team size and message you provide, together with anything you enter
in the “how did you hear about us” field, and the IP address the submission came from.
The IP address is kept to detect abuse of the form. This information is used solely to respond to
your request and is not shared with third parties.
- Retention — contact requests are kept for up to 24 months and then deleted. You
can ask us to delete yours sooner at any time.
- Licence validation — customer portal servers periodically send three values to
our licensing service: the licence key, a domain identifier, and the total number of employee
records held in that instance. No employee data, credentials, names, addresses or directory
contents are ever transmitted.
- No tracking — this website uses no analytics, advertising, or tracking cookies. The
vendor console at
/login sets a
session cookie that is strictly necessary to keep an authenticated session; it is not used for
tracking.
In short: what we hold about you is what you typed into a contact form. What
your employer's portal holds about your staff never reaches us — it stays on their server.
Your rights
You can ask us for a copy of the information we hold about you, ask us to correct it, or ask us
to delete it. Write to [email protected] and we will
action the request. If your data sits inside your employer's portal rather than with us, we cannot
reach it — that request goes to your organisation's IT administrator.
Contact
For questions about this policy, contact your organisation's IT administrator, or maxen at
[email protected]. See also the
Terms of Service and Licence Agreement.