Legal

Privacy Policy

How we handle your information and the Microsoft 365 data we assess.

Template: pending legal review. This is a starter privacy policy written to describe how the product works. It is not legal advice and must be reviewed and completed by qualified counsel before launch. Highlighted items are placeholders.

Last updated: [Effective date]

This Privacy Policy explains how [Company legal name] ("M365Assessments", "we", "us") collects, uses and protects information when you visit m365assessments.com, sign in to app.m365assessments.com, or connect a Microsoft 365 tenant for assessment (together, the "Service").

1. Our role

For account and workspace information, we act as a controller. For data collected from Microsoft 365 tenants during an assessment, we act as a processor (service provider) on behalf of the customer who connects the tenant, whether that's an organization assessing its own tenant or an MSP assessing a tenant with its customer's consent.

2. Information we collect

Account and workspace information

  • Profile details from Microsoft sign-in: name, email address, and Microsoft Entra user and tenant identifiers. We request only the openid, profile, email and User.Read scopes.
  • Workspace details: organization name, team members and their roles, plan and usage (for example, the number of assessments run).
  • Communications you send us, such as demo requests and support emails.

Assessment data

When a tenant administrator grants consent, our assessment applications (one per module the administrator approves) read configuration data from that tenant through Microsoft Graph and the Exchange Online, Purview, Teams, SharePoint and Power Platform admin interfaces. Standard modules use read-only permissions; the opt-in Power Platform and SharePoint Advanced modules need broader access, which we use only to read (see the full list). This can include:

  • Directory objects such as users, groups, roles, applications and devices, including names, user principal names and email addresses;
  • Security and policy configuration (for example Conditional Access, authentication methods and Intune policies);
  • Sign-in and audit information relevant to findings (for example legacy-authentication usage and last sign-in dates);
  • Subscription, license and usage report data.

We do not request access to the contents of email, files, chats, calendars or documents.

Website data

This marketing website doesn't use advertising or third-party tracking cookies. Our hosting provider may process standard server logs (such as IP address and user agent) for security and reliability. [Confirm and describe any analytics before launch.]

3. How we use information

  • To provide the Service: authenticate you, run assessments, generate and display reports, and enforce plan limits.
  • To secure the Service: detect abuse, investigate incidents and keep audit records.
  • To communicate with you about your account, the Service and your requests.
  • To improve the Service, using aggregated or de-identified information where possible.

We don't sell personal information, and we don't use assessment data to train machine-learning models or for advertising. [Confirm.]

4. Where data is stored and how it's protected

The Service runs on Microsoft Azure in data centers in the United States. Assessment results for each tenant are stored in a separate storage container; our database applies row-level security by organization; data is encrypted in transit (TLS) and at rest. More detail is on our Security page.

5. Sharing

We share information only:

  • With service providers that host and operate the Service on our behalf, principally Microsoft Azure [list other subprocessors, e.g. email provider];
  • Within your workspace, according to the roles your organization assigns;
  • When required by law, or to protect the rights, property or safety of our users or others;
  • In connection with a merger, acquisition or sale of assets, subject to this policy.

6. Retention and deletion

We keep account information for as long as your workspace is active. Assessment results and reports are kept [retention period] or until you delete them or close your workspace. You can ask us to delete a tenant's assessment data at any time by emailing hello@m365assessments.com. Revoking consent in Microsoft Entra stops future collection immediately.

7. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal information, or to object to certain processing. If your information was collected from a Microsoft 365 tenant assessed by one of our customers, please contact that organization first. We'll support them in responding. To make a request, email privacy@m365assessments.com. [Confirm contact; add GDPR/UK/CCPA specifics as applicable.]

8. International transfers

We store data in the United States. If you access the Service from outside the US, your information will be transferred to and processed in the US. [Describe transfer mechanisms, e.g. Standard Contractual Clauses, if serving EU/UK customers.]

9. Children

The Service is intended for businesses and isn't directed to children under 16.

10. Changes to this policy

We may update this policy from time to time. We'll post the new version here and update the date above, and we'll notify workspace owners of material changes.

11. Contact

[Company legal name]
[Postal address]
Email: privacy@m365assessments.com